Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Mary Hain
Administrator

This is a developing series, and we'll continue to release new content over time. Bookmark this page to stay up to date and let us know in the comments what topics you'd like to see.

 

Welcome to the Speed Learning Series for Policy and Compliance Management (P&C), an application within the Integrated Risk Management (IRM) product. You'll find everything you need to implement and operate a structured compliance program on ServiceNow.

 

Note: We are transitioning from Now Assist to ServiceNow Otto. This change may affect your search results.

 

Speed Learning Series – Policy and Compliance Management  ▶ YouTube playlist

Policy and Compliance Management connects external regulations to your internal policies, control objectives, and controls, and then lets you test and monitor those controls. Regulatory and internal requirements are tracked in one place, and every compliance result can be traced back to the obligation it supports.

 

1. Foundational Data Management

Everything else in P&C runs on its library. Authority documents hold the external regulations (HIPAA, GDPR, PCI DSS, and others), citations break them into individual obligations, and policies capture your internal rules. Control objectives connect the two, so a single control objective can satisfy a regulation and an internal policy at the same time. The library can be built manually or imported from the Unified Compliance Framework (UCF) Common Controls Hub or other sources.

 

Control objectives are then mapped to entity types (departments, systems, vendors, production lines), and a control is generated for each entity in scope. Entity filters and hierarchies keep that scope current as source data changes, and the same structure determines how compliance scores roll up.

 

This work, along with policy approvals and task management, is done in the Compliance Workspace. Corporate Compliance Managers, Corporate Compliance Analysts, and IT Compliance Managers each get a role-based home page that shows compliance status across authority documents, policies, and entities, plus their own tasks and their team's.

 

Review these Speed Learning content on the data model and architecture powering P&C application and further details on setting up and scaling a control management program on ServiceNow.

2. Policy Lifecycle Management

A policy can move through various stages (Draft, Review, Awaiting Approval, and Published) with reviewers and approvers assigned along the way, and is ultimately published as a Knowledge Base article. Retired policies stay on record for audit, and when a policy or control can't be met, the Policy Exception module records the requests and approved deviation against the policy itself.

Policy text can be typed into the record, extracted from a Word upload, or connected to a live document in Microsoft OneDrive, Microsoft SharePoint, or Google Drive. With the connected option, owners, reviewers, and approvers redline the same document during Draft and Review, and each revision cycle is saved as a new policy version.

Policy Authoring and Redlining with Office 365 >

 

The policy acknowledgment workflow sends the policy to a defined audience and creates one record per person, so you can see who accepted it, who declined or asked for an exception, and who hasn't responded.

3. Control Management, Assessment and Continuous Monitoring

Effective control management starts by defining which assets, systems, departments, and processes carry compliance obligations—and linking those obligations to testable controls in ServiceNow. Every organization has a compliance universe, but it's usually scattered across spreadsheets and institutional knowledge, leaving no reliable answer to what auditors always ask: which controls apply to which systems, and how can you prove it?

 

 

ServiceNow makes that provable through three types of testing: scheduled indicators that create an issue on failure, attestations powered by the Smart Assessment Engine, and on-demand testing. Any gap becomes an issue that's tracked to closure and visible in both Risk Management and Audit Management, while each result rolls up into the compliance score for its objectives, policies, citations, authority documents and entities.

 

Additional Resources

Learn through ServiceNow University:

The GRC: Policy and Compliance Management Implementation learning path on ServiceNow University packages the required content and assessments for implementation specialists. Courses cover authority document setup, policy and control configuration, attestation workflows, and Compliance Workspace operation.

 

Policy and Compliance Management FAQs

What is Policy and Compliance Management in ServiceNow?

Policy and Compliance Management is ServiceNow's centralized solution for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. It provides structured workflows for identifying, assessing, and continuously monitoring control activities across the organization.

 

What is the relationship between authority documents, citations, policies, and control objectives?

Authority documents are the external regulations your organization must comply with. Citations are the specific passages within those documents that create obligations. Policies define how your organization will respond internally. Control objectives sit at the center — they tie authority documents and policies together and define exactly how adherence is achieved. One control objective can simultaneously fulfill multiple internal and external requirements.

 

What is entity scoping, and why does it matter for compliance scoring?

Entity scoping is the process of modeling your real-world assets — departments, systems, vendors, production lines — as Entities, then mapping Control Objectives to Entity Types so a Control is auto-generated for every entity in scope. It matters because a compliance score is only as defensible as the entity model beneath it: the wrong hierarchy, an unscoped entity, or an out-of-date filter produces a number that looks precise but doesn't hold up under audit.

 

How does the policy lifecycle work?

A policy moves through five states: Draft (created and defined), Review (reviewed and edited by assigned reviewers), Awaiting Approval (approval task routed to the approver), Published (active, with KB article auto-generated), and Retired (inactive, record preserved for audit). During the Draft and Review states, owners, collaborators, reviewers, and approvers can also author and redline the policy document collaboratively. Each state has specific roles and available actions, and policies can be rolled back if further work is needed.

 

What is policy authoring and redlining, and who can use it?

Policy text can be entered three ways: typed directly into the policy record, uploaded as a Word document, or connected to a live cloud document. Policy authoring and redlining is that third, cloud-connected option, and it operates within the Draft and Review states of the policy lifecycle. It lets policy owners, collaborators, reviewers, and approvers draft and redline policy documents together using Microsoft OneDrive, Microsoft SharePoint, or Google Drive — directly from the Compliance Workspace. Full version history is maintained for audit purposes. The feature is available exclusively to ServiceNow cloud-based customers and requires specific spoke and Integration Hub entitlements for cloud integration.

 

What happens after a policy is published — how do I prove employees read it?

Publishing makes a policy active, but it doesn't by itself prove anyone read it. An acknowledgment campaign closes that gap: a compliance user defines an audience, then submits the campaign, which emails each audience member and creates an individually trackable record. Audience members accept, decline, or request an exception through My Acknowledgements or the Service Portal, and overdue responses are tracked in dedicated modules.

 

How do controls get created and what is a control test?

Controls are specific implementations of a control objective. They can be generated automatically when a policy is associated with an entity type or created manually. A control test verifies whether the control is effective in achieving its objective. Indicators allow control tests to run on a schedule and automatically create an issue if the test fails.

 

What is the difference between an attestation and an indicator?

Indicators are scheduled, recurring tests of a control — run daily, weekly, monthly, or quarterly — with a Pass/Fail result. Attestations are ad hoc assessments powered by the Smart Assessment Engine that gather compliance evidence at a point in time. Both can trigger issue creation when compliance is not confirmed.

 

What is the Compliance Workspace and who uses it?

The Compliance Workspace is the unified interface where compliance managers and analysts carry out the day-to-day work described above — policy approvals, control objective and control management, and task tracking — from role-specific home pages for the Corporate Compliance Manager, Corporate Compliance Analyst, and IT Compliance Manager, each with relevant dashboards, task queues, and record lists.

 

How does Policy and Compliance Management connect to the rest of the GRC suite?

Issues are shared across Policy and Compliance, Risk Management, and Audit Management — meaning a control failure identified in compliance can be tracked and remediated in a shared context. Controls and control objectives can also be linked to risks, and control test results feed into the broader risk posture visible in the Risk Workspace.

 

Have feedback on the Speed Learning experience? Leave a comment below and let us know which topics you'd like to see covered next.

Comments
nathan_oj
Tera Explorer

Very insightful read, thank you

Version history
Last update:
a week ago
Updated by: