The Zurich release has arrived! Interested in new features and functionalities? Click here for more

Recurring Evidence Requests for Audit Documentation

brandoncalero
Tera Contributor

Hello,

 

My internal GRC Audit team needs to perform semi-annual audits and we need a way to make these requests recurring or to re-initiate the request. Here are some details on our use case:

 

- Need to collect user access lists for each application

- users provide an attachment to our audit team

- request sent to approximately 200 or so applications/IT owners

- Process needs to be able to be reproduced every 6 months to the same applications/IT owners

 

Is there a way to automate this process within the system? 

1 ACCEPTED SOLUTION

@brandoncalero the use case you have described is what control indicators have been designed for.

 

The process for creating them is: 

  1. Create a single control objective (make sure "Creates control automatically" is true)
  2. (Optional) Create an entity type for all applicable applications with an entity filter pointed to the Business application table to automatically create controls for the applicable applications
  3. Create an indicator template off of the Control objective. This indicator template can be manual to start off with and provide some guidance to the user of what they need to do and what you expect them to upload
  4. (Optional) Create a test template for the control objective and click generate test plans. This will create a copy of the test template as a test plan for each control

This is a once off activity and then will then run throughout the year and send tasks to users to upload data.

 

When it is time to test you can do the following:

  1. Create an engagement
  2. Bring the applications in scope
  3. (Optional) you can configure control tests to not require test plans by removing the mandatory flag. This will allow users to create control tests directly.
  4. Create the control tests either from the test plans or manually create individual control tests. This can be done in bulk. You can also config this list to allow you to select all test plans if you want to make this even faster

     

ConnorLevien_2-1698292916715.png

 

Once you create a control test it will automatically bring in the manual indicators or the uploaded evidence in the control test for the audit user to review (see below screenshot example of an indicator result on a control test)

ConnorLevien_0-1698292728907.png

 

 

Once you do this once you can copy the engagement following the below guide and it can copy all the set up for you each time so you dont have to repeat these steps

https://docs.servicenow.com/en-US/bundle/vancouver-governance-risk-compliance/page/product/grc-audit... 

 

I hope this is helpful, if you still have questions I would suggest to reach out to your ServiceNow account team and they could connect you with your local Risk Specialist to help you through the process.

View solution in original post

11 REPLIES 11

brandoncalero
Tera Contributor

Is there a way for Indicator Templates to only to apply to a subset of Controls within a Control Objective?

Currently, there is no OOTB way to have an Indicator Template only apply to a subset of controls within a control objective. If you need to do this I would make a duplicate control objective which is a child and only have the indicator template applied to that control objective and apply it out to the subsets of control objectives.