Evidence Requests in GRC: Audit Management and Security Constraints

mdeandrea08
Tera Contributor

We're using Evidence Requests to request documentation while planning an audit.  We want to gather evidence (maybe a sample of journal entries for testing a financial control) and then attach that evidence to an audit task, so that it's available to the auditor during fieldwork.   The problem we're running into is that while the person who requested the evidence (the Audit Manager) can view it and attach it to the audit task, the auditor performing the task can't view the evidence because it is being blocked by "Security Constraints."   I'm guessing this is being caused by a clashing of roles, possibly?  The persona requesting the evidence has an audit manager role.  The persona performing the control testing has an audit user role. And, the person providing the evidence in response to an evidence request has a business user lite role.  All the personas can perform the required activities without problem.  The only issue we're having is that the auditor can't read the evidence that was requested by the audit manager and provided by the control owner.  Any and all help is greatly appreciated.  Thanks in advance for your help.

1 REPLY 1

Community Alums
Not applicable

Hi @mdeandrea08 ,

Role you will need for your auditor is sn_audit.user and sn_compliance.manager.

Please refer to my answer : https://www.servicenow.com/community/grc-forum/auditor-access-for-compliance-records/m-p/2961094