Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Common Governance, Risk, and Compliance features

Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.

For example, you can run GRC applications by using the ServiceNow® mobile application. Content packs and integrations are available from multiple GRC applications. Information such as domain separation support levels is also included.

  • Assignment Configurator for non-regulatory alerts
    Assignment rules help in automating organization’s task records such as action tasks, and non-task records such as issues, incidents, regulatory alerts, and so on.
  • Regulatory Agency Library
    Regulatory Agency Library is a new application available in the ServiceNow Store for download and activation.
  • Recommendation contexts and templates
    By using the Governance, Risk, and Compliance recommendations framework, you can use recommendation contexts and templates to deliver AI-driven insights directly to your users within the user interface. With these insights, your users can make informed decisions and take prompt actions.
  • Mobile experience for Governance, Risk, and Compliance
    Manage your work, task assignments, requests, approvals, and other follow-up actions for GRC applications directly from your mobile device. Receive timely notifications for current alerts, as well as risk and compliance status for your critical assets, vendors, and impacted essential business services.
  • GRC notification redirection
    When you receive notifications for GRC records, you're directed to either the workspace view or classic view based on your access permissions and role. This feature enables you to work directly in the appropriate interface without manual navigation.
  • Governance, Risk, and Compliance application nomenclature updates and industry terminology
    The following terms are used within GRC applications and/or within the GRC industry.
  • Governance, Risk, and Compliance content packs
    Content packs may include pre-defined scopes, specific policies, controls, risks, audit, test plans, dashboards, and reports that provides customers an operational head-start when adopting various regulations and frameworks.
  • Governance, Risk, and Compliance integrations
    Integrations enhance the ServiceNow® GRC product offering, providing users the ability to integrate with third-party applications.
  • Governance, Risk, and Compliance use case accelerators
    Use case accelerators may include pre-defined scopes, specific policies, controls, risks, audit, test plans, dashboards, and reports that provides customers an operational head-start when adopting various regulations and frameworks.
  • 360° Relationship Visualization
    The 360° Relationship Visualization application allows you to visually explore the relationships between the different types of critical data that affect your business, such as controls, risks, and issues. The visualization also facilitates quick actions upon the information, such as adding a relationship, closing an issue, or approving a policy exception.
  • Tagging records with functional domain
    Functional domain tagging is a mechanism that allows you to classify risk records based on the specific business function, process, or use case they support. A functional domain represents a logical grouping, such as Cybersecurity and risk, IT risk and compliance, Compliance, Third-Party Risk, or Operational Risk.
  • Using the item generation process to generate controls and risks
    The ServiceNow® GRC suite of applications can automatically generate controls and risks for your organization with the enhanced item generation process. The enhanced item generation process (v2) in version 13.x.x fixes the stalling and performance issues from the item generation process (v1) in version 12.x.x and earlier releases.
  • Using Approver Configurator for setting up approvals
    The GRC: Approver Configurator application provides you with capabilities to define multiple levels of approvals based on the business assignment rule configurations.
  • Confidential records
    You can mark sensitive GRC records as confidential. You can then make sure that the right people have access to these records.
  • User hierarchy
    With a user hierarchy, your managers can see the records of those users who report to them.
  • User group-based access on the GRC tables
    You can allow a set of users to access only specific records by creating user groups on the GRC tables. When you have created the user groups, you can segregate your data based on a specific criteria and allow only those users who belong to a user group to view the data.
  • Content references in GRC
    You can add tags to virtually any type of record defined in GRC applications that reference GRC content packs, integrations, use case accelerators, or any new regulations that use those records. After the records have been tagged, you can filter the content reference tags to identify which records are used within each application.
  • Entity Based Access
    The Entity Based Access (EBA) application enables you to segregate data on the records that are based on entities. Entity-based access administrators can use this tool to set up secure, controlled access to various objects.
  • Manage issues
    You can measure the effectiveness of your company's risk management program by how quickly and completely it identifies and reacts to risk and compliance issues.
  • Domain separation in GRC
    This is an overview of domain separation and the Governance, Risk, and Compliance applications. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
  • Breadcrumb navigation
    The ServiceNow® Australia release supports breadcrumb navigation for all GRC modules including workspaces. Breadcrumbs provide a browser path to navigate a hierarchy of linked pages with related content.
  • Taxonomy management in GRC
    Taxonomy is used to organize, classify, and label the elements of the unstructured content. The content is organized into granular elements that provide more information about the context of the content.
  • Landing Page Configurations module
    GRC administrators can now configure the Tasks and Issues overview landing pages in the workspaces by using the GRC Landing Page Configurations module in the classic user interface. The role required to configure the tasks, issues, and other items in the Landing Page Configurations module is the sn_grc_workspace.task_admin role. GRC administrators are assigned the sn_grc_workspace.task_admin role by default.
  • My tasks in the workspace
    GRC administrators can configure the tasks for the individual users and user groups in the GRC Landing Page Configurations module. Based on these configurations, the workspace users can view the individual user tasks, user group tasks, my items, and watchlist on the Tasks page in the workspace view.
  • Exploring the entities
    Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications, or objects that are examined for risks.
  • Viewing and updating Governance, Risk, and Compliance exceptions
    Report exceptions as it is critical for businesses to quickly identify and address key business process issues before they become a problem. Using exceptions to manage errors has advantages over traditional error-management techniques.
  • Cybersecurity Executive dashboard for Chief Information Security Officers
    The Cybersecurity Executive Dashboard gives the Chief Information Security officer a comprehensive overview of the security posture score of an organization. However, the compliance and risk users can use the risk and compliance page to get an all-inclusive picture of all the GRC metrics.
  • Advanced Governance, Risk, and Compliance Application Risk dashboard
    The GRC Application Risk and Compliance Overview Dashboard provides the latest view of risk and compliance aspects for the business applications that are used in an enterprise.
  • GRC licensing summary dashboard
    Use the GRC licensing summary dashboard to track license usage trends and next month's projected usage. You can see the aggregated counts of license consumption across different product families. You can also search for roles to identify their combined GRC license treatment when these roles are assigned to a user.
  • Microsoft Word based audit report templates using Document designer
    The Microsoft Word based audit report is accessible and user-friendly for audit administrators. Even users without technical expertise can easily configure the template to meet their specific needs.
  • Workspace page configuration
    A common record page can be used and configured within all the GRC applications.
  • Governance, Risk, and Compliance reference
    Reference topics provide information about tables, roles, and properties installed with the GRC application.
  • Anonymous Reporting Center
    The Anonymous Reporting Center (ARC) enables employees to submit compliance, privacy, or AI‑related concerns without revealing their identity. Employees are automatically signed out of the Employee Center when ARC opens.

Parent Topic:Governance, Risk, and Compliance