GRC: SOX content pack release notes
Summarize
Summary of GRC: SOX Content Pack Release Notes
The Governance, Risk, and Compliance (GRC) Sarbanes-Oxley (SOX) content pack on the ServiceNow Store provides a comprehensive set of predefined profiles, policies, controls, risks, audit templates, and dashboards designed to support SOX compliance management. It integrates tightly with the ServiceNow platform to enable organizations to efficiently manage SOX-related compliance, risk, and audit processes.
Show less
Key Features
- Content Elements: Includes SOX-specific profiles, policies, control attestations, risk statements, audit engagement templates, test plans, reports, and dashboards.
- Relationship Mapping: Establishes clear relationships among policies, controls, risks, indicators, and test plans to support comprehensive compliance tracking and control testing.
- Role-Based Access: Provides granular access through predefined GRC roles such as Compliance Reader, Compliance Manager, Compliance Admin, Risk Reader, Risk Manager, Risk Admin, Audit User, and Audit Admin, each with tailored permissions to view or edit specific dashboards and processes.
- Security Enhancements: Version 22.3.0 introduces standardized query range ACLs across all tables to ensure consistent and secure data access, automated upgrade scripts for seamless transitions, and validation of plugin dependencies to avoid broken ACL references.
- Content Updates: Recent updates include improved control objective content status management and enhanced read-only field security.
Practical Benefits for ServiceNow Customers
- Enables streamlined SOX compliance management with ready-to-use templates and dashboards tailored for SOX requirements.
- Ensures consistent and secure data access across the platform through standardized ACLs, reducing administration overhead and risks related to access control misconfigurations.
- Facilitates smooth upgrades with minimal manual intervention and safeguards existing customizations.
- Supports compliance and risk teams with appropriate role-based access to relevant dashboards and processes, enhancing collaboration and accountability.
- Helps maintain up-to-date compliance content with regular version updates addressing security and content accuracy.
Next Steps
Before upgrading to the latest version, review any customized query range ACLs to ensure alignment with your access policies. Verify that all required plugins are installed to avoid dependency issues. Utilize the predefined roles to assign proper permissions to your GRC team members for efficient SOX program management.
Version history for the Governance, Risk, and Compliance Sarbanes-Oxley (SOX) content pack on the ServiceNow Store.
Version history
- Version 22.3.0 - June 2026 (Australia)
-
- New:
- Query range ACLs include the following enhancements:
- Consistent access control — All tables include standardized query range security ACLs. These ACLs ensure that authenticated users with appropriate read permissions can query records consistently across the platform.
- Seamless upgrade experience — New query ACL rules are installed automatically during upgrade, with no administrator action required. Automated upgrade scripts handle the transition, including detecting and processing previously customized ACLs to ensure existing processes continue without interruption.
- Post-upgrade review for customized ACLs:
- If the instance includes administrator-modified query range ACLs, review those records after upgrade to confirm they align with the intended access policy.
- Query range ACLs include the following enhancements:
- Changed: Validated plugin dependencies to prevent ACLs from referencing roles provided by uninstalled optional plugins.
- New:
- Version 22.0.1 - March 2026
- Changed: Updated control objective content records with Record nature field as Current version and State as Published.
- Version 21.1.0 - December 2025 (Zurich)
- Fixed: Added read-only attribute to read-only fields for enhanced security
- Version 5.0.2 (Kingson, London) - October 2018
- The Sarbanes-Oxley (SOX) Content Pack includes the following content elements:
- Pre-defined profile type and profiles
- SOX policies
- Policy statements and controls
- SOX control attestation template
- Risk statements and risks
- Indicator templates and indicators
- SOX audit engagement
- Audit tasks
- Test templates and test plans
- Reports and dashboards
- The following relationships are also established:
- Policy statements to policies
- Controls to policies (through policy statements)
- Indicators to controls
- Risks to risk statements
- Risks to profiles
- Risks to controls (mitigating controls)
- Test plans to controls for control testing
- Other GRC roles:
- Compliance Reader (sn_compliance_reader) can read SOX Compliance Dashboard and SOX Processes
- Compliance Manager (sn_compliance_manager) can read SOX Compliance Dashboard, SOX Risk Dashboard, and edit SOX Processes
- Compliance Admin (sn_compliance_admin) can read SOX Risk Dashboard and edit SOX Compliance Dashboard and SOX Processes
- Risk Reader (sn_risk_reader) can read SOX Risk Dashboard and SOX Processes
- Risk Manager (sn_risk_manager) can read SOX Compliance Dashboard, SOX Risk Dashboard, and edit SOX Processes
- Risk Admin (sn_risk_admin) can read SOX Compliance Dashboard and edit SOX Risk Dashboard and SOX Processes
- Audit User (sn_audit_user) can read SOX Compliance Dashboard, SOX Risk Dashboard, and SOX Processes
- Audit Admin (sn_audit_admin) can read SOX Compliance Dashboard, SOX Risk Dashboard, and edit SOX Audit Dashboard and SOX Processes
- The Sarbanes-Oxley (SOX) Content Pack includes the following content elements: