Flag changes that affect internal controls

Shanedd22
Tera Contributor

We have had instances where a change has been implemented that has made an internal control obsolete e.g. - all sales documents need to state trading T&C's. The change that was implemented created some sales documents where T&C's weren't displayed by design. When the control was audited it failed as this internal control document wasn't updated to reflect the change.

 

Is there functionality in ServiceNow that can do the follow:

- include a step in the change approval process, that flags whether or not the change will affect an internal control stored in IRM / GRC. e.g. - if a change to SAP sales documents is requested, the change approver selects from a drop down (YES/NO), whilst given visibility to all controls in place for SAP sales documents.

- add a task to a change before the implementation step - so that the control owner updates their control policy if they answered YES to the question above.

 

Any advice would be much appreciated.

0 REPLIES 0