Manage engagements

  • Release version: Zurich
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Manage Engagements

    The audit engagement process in ServiceNow's Zurich release enables audit managers and auditors to efficiently manage the lifecycle of audit engagements. This process covers creating, planning, scoping, conducting, reviewing, and closing audit engagements, ensuring thorough documentation and compliance with internal policies and external regulations.

    Show full answer Show less

    Engagement Process Stages

    • Scope: Define involved entities such as departments and business services related to the audit. Adding entities automatically includes associated risks, controls, test plans, and indicator results.
    • Validate: Review and update risks, controls, test plans, and indicator results within the engagement scope. Begin planning audit tasks.
    • Fieldwork: Auditors complete assigned tasks like control testing, interviews, and walkthroughs. Document issues found and specify overall engagement results.
    • Awaiting Approval: Assigned approvers review audit results and issues, then approve or reject the engagement.
    • Follow Up: Address and close any remaining open tasks, issues, or milestones to finalize the engagement.
    • Closed: Engagements are closed either as incomplete during early stages or automatically upon resolution of all tasks and issues post-approval.

    Audit Task Management

    Audit tasks provide evidence of compliance and include activities such as creating control tests, interviews, walkthroughs, and other audit activities tied to controls.

    • Create Engagements: Initiate audits and define scope, auditors, and approvers. You can also create new engagements from previous ones to save setup time.
    • Control Tests and Activities: Define and schedule tests and activities to verify control effectiveness.
    • Interviews and Walkthroughs: Engage control owners and observe processes to collect audit evidence.
    • Generate Reports and Knowledge Base Articles: Produce audit reports and KB articles summarizing findings for executive communication.
    • Approvals: Approvers can approve or reject engagements during the Awaiting Approval stage.

    Practical Tools

    The Engagement Workbench offers a timeline view for easy navigation of audit engagements, allowing users to view details or create new engagements efficiently.

    The audit engagement process involves creating, planning, scoping, and conducting engagements as well as reporting on engagement findings.

    Engagement process

    The base system audit engagement process includes steps for scoping, validating, conducting, and approving engagement results. It also contains steps for following up on open audit tasks and issues, and finally closing out the audit engagement.

    Table 1. States of the engagement process
    State Description
    Scope

    During the Scope state, audit managers define which entities are involved in the audit engagement. For example, for a financial audit, one may include all business services that the finance department relies on and the finance department itself.

    See Add entities to an engagement scope.

    Validate

    After an engagement has moved to the Validate state, all the risks, controls, and test plans associated with the entities in the engagement's scope will be associated with the audit. Indicator results that were collected during the audit period of the engagement will also be associated with the audit. Audit managers can review the risks, controls, test plans, and indicator results, and update the scope of the engagement, if necessary. Audit managers can also begin creating and planning audit tasks for the engagement.

    To move an engagement into the Validate state, click Validate on any engagement currently in the Scope state.

    Fieldwork

    Auditors complete their assigned audit tasks during the Fieldwork state. These tasks include control testing, interviews, walkthroughs, and other activities. Issues that are found during control testing are associated with the engagement. Auditors can also create general issues associated with the engagement. Audit managers can create additional audit tasks as needed. When the audit is done, audit managers specify the result of the engagement, whether it's satisfactory, adequate or inadequate, and provide details on their opinion.

    To move an engagement into the Fieldwork state, click Advance to Fieldwork on any engagement currently in the Validate state.

    See Audit task management.

    Awaiting Approval

    During the "Awaiting Approval" state, the approvers specified in the Approvers field of the engagement review the results of the audit tasks conducted and the issues that were created. After reviewing the results of the engagements, approvers approve or reject the engagement.

    To move an engagement into the Awaiting Approval state, click Request approval on any engagement currently in the Fieldwork state.

    See Approve or reject an engagement.

    Follow Up After an engagement has been approved, if there are any remaining open tasks, issues or milestones, in case of GRC Advanced Audit, associated with the engagement, the engagement automatically goes into the Follow Up state. During this stage, auditors must close out all remaining issues, tasks, and milestones before the engagement are marked as complete.
    Closed
    Engagements move into the "Closed" state under one of three conditions:
    • The engagement is closed as incomplete during the Scope, Validate, or Fieldwork states.
    • There are no open audit tasks, issues, and milestones after the engagement is approved. In this case, the engagement automatically moves from the Awaiting Approval state to the Closed state.
    • All follow-up tasks, issues, and milestones are closed out. In this case, the engagement automatically moves from the Follow Up state to the Closed state.