How to enable control test functionality, generate control test in servicenow GRC.

Praju_123
Tera Contributor
I would like to understand the complete process for enabling Control Tests within ServiceNow, specifically focusing on how to configure and generate control tests and define their execution logic. Additionally, I need clarity on how the system evaluates the responses of these control tests and the mechanism through which issues (or findings) are automatically created based on test outcomes. It would be helpful to know the required configurations, workflows, or policies involved in linking control test responses to issue generation, along with any best practices to ensure accurate and efficient tracking of control effectiveness.
1 REPLY 1

Vinod54
Tera Guru

Hello @Praju_123 ,


When?

In OOTB, control test records will be created manually by Audit manager primarily in Validate & Plan state of Audit engagement record. It can also be created in other active states but not widely. 
No script available OOTB but you can create custom automations to create. 

 

How?

  •  "Generate Control Tests" button: Audit manager opens the Test Plans related list, selects required test plans, and clicks Generate Control Tests. ServiceNow creates one Control Test task record per selected test plan, pre-populated with the test steps. 
  • Manual via Audit Tasks related list: Audit manager clicks New Activity → New Control Test to create an ad hoc test not tied to a test plan.
    This is mostly done before moving to the audit engagement record to Fieldwork state

What happens after control test?
Positive - Control test completed as Effective

No issue record is created, control sets to Compliant or stays at compliant, related Compliance/ Risk score are improved. 

Negative- Control test completed as ineffective

Issue record is created, control sets to non-compliant or stays at non-compliant, engagement records cannot be closed, related Compliance/ Risk score are decreases. 

Best Practice:
- Stay OOTB, do not include any automation. 
- If required align with the Validate and Plan state of audit engagement

- Use Test plan, test template to have generic testing steps and questions. 

 

Related SN Docs

https://www.servicenow.com/docs/bundle/yokohama-governance-risk-compliance/page/product/grc-audit/co...

https://www.servicenow.com/docs/bundle/yokohama-governance-risk-compliance/page/product/grc-audit/ta...

 

If my answer helped you, hit the helpful button. 

 

Thanks,

Vinod Kumar M

Technology Architect