- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
2 hours ago
The Brazil (Q3 2026) Governance, Risk, and Compliance release addresses a common theme in GRC work: the manual effort required to assemble information before any action can be taken, whether it’s reading fragmented alerts, searching control libraries, tracking issues across an enterprise, or performing ad hoc data searches.
With the new features announced below, ServiceNow Risk is leveraging ServiceNow platform functionality to streamline workflows, compile relevant data into a usable format, and speed up decision-making, so risk teams can quickly decide what to do next. Below, we describe each feature’s function, the problem it addresses, and its value to the organization.
Check out the Risk Demo library to see how these new capabilities work.
Enterprise-wide Issue Management (GRC Issue Management) consolidates audit findings, control failures, and compliance and risk issues into a single application that spans the organization. Demo
- Organizations can define their own issue types, each with its own fields and forms, lifecycle, and guided steps.
- This replaces the current process, where all issue types share one screen and one process and changes required a higher level of configuration. In addition, issue owners also have no clear indication of the record state or the next step, and sign-offs are chased by email.
- New issue types, their lifecycles, and their approvals can be easily configured without code in days rather than weeks and can support multiple types of issues from across the enterprise.
- A guided record view makes the application usable by control owners, risk and compliance teams, and internal audit, all without role-specific training.
AI Reporting Assistant uses simple, natural language conversations to generate reports from live ServiceNow data. Demo
- This feature can generate complex narratives, tables, and supporting charts, with clickable links to live data in ServiceNow list views.
- This replaces manually generated reports, which offer point-in-time information that can easily become outdated, forcing Risk teams to continually regenerate them.
- Using Knowledge Graph technology, data is always up-to-date because it’s linked directly to the instance.
AI-Powered Data Explorer. AI Data Explorer blog with demo
- This feature turns every user into a data power user by recommending actions based on your goals and exploration content. The system returns analyzed data without the need to build a manual report.
- Natural-language requests deliver interactive charts and breakdowns of regulatory alert and privacy incident volumes, trends, patterns, and activity segmented by status, source, severity, and other attributes for improved analysis.
- Previously, with data distributed across systems, users had to move between tools to gather data, thus losing context, depend on IT for report building and query execution, and either build reports manually or export data to spreadsheets to answer questions.
- Outcomes include self-service data exploration without technical skill requirements, faster root cause analysis, and reduced dependency on ad-hoc queries by the analytics team.
Actionable Regulatory Alert Insights (Regulatory Change Management) generates AI summaries of regulatory alerts by synthesizing the regulatory source, affected jurisdictions, amendment details, and other alert components into a single summary that covers what changed, its business impact, and the required next steps.
- Alert information is currently fragmented across multiple fields and attachments with no consolidated view, requiring analysts to read each component and assemble the impact assessment themselves.
- These summaries reduce average alert review and triage time, enabling the regulatory and compliance team to process, review, and act on a higher volume of alerts more quickly.
AI Reviewer Assist (Privacy Management) uses AI to recommend the risk statements and control objectives most applicable to a processing activity's assessment within privacy.
- With AI Reviewer Assist, the recommendation engine uses multiple matching signals, including named information on the processing activity record and semantic similarity across the risk and control library, to identify the relevant risk statements and control objectives.
- Currently, privacy analysts search the library by trial and error, including searching on risk names, control objectives, and framework mappings.
- This feature reduces the time required to identify and map applicable risks and controls for a processing activity (from days to hours). An analyst can then shift from manual tasks to reviewing, editing, and confirming AI-generated recommendations.
