---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Governance, Risk, and Compliance

# Governance, Risk, and Compliance {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Governance, Risk, and Compliance

ServiceNow Governance, Risk, and Compliance (GRC) provides an integrated platform for managing business risks in real time.
This solution connects security, IT, and compliance efforts through continuous monitoring and automation, enhancing decision-making and performance across organizations and vendor relationships.
Show full answer Show less  

## Key Features

* **AI Risk and Compliance:** Manage AI capabilities ethically and ensure compliance.
* **Audit Management:** Utilize risk data for effective audit planning and process automation.
* **Business Continuity Management:** Plan for and recover from disasters, ensuring operational resilience.
* **Compliance Case Management:** Report and resolve compliance issues efficiently.
* **Continuous Authorization and Monitoring:** Streamline the process of IT system onboarding and ongoing monitoring.
* **Policy and Compliance Management:** Automate policy management and monitor compliance continuously.
* **Privacy Management:** Oversee privacy risks and compliance in real time.
* **Regulatory Change Management:** Stay updated with regulatory changes and assess their impacts.
* **Risk Management:** Conduct thorough business impact analysis to prioritize risk responses.
* **Smart Assessment Engine:** Automate risk assessment processes to reduce manual work and costs.
* **Third-party Risk Management:** Monitor and manage risks associated with vendors effectively.

## Key Outcomes

By implementing ServiceNow GRC, organizations can transform inefficient and manual processes into a cohesive risk management framework that enhances operational efficiency. The integration of various GRC features allows for streamlined audits, proactive vendor risk management, and improved compliance monitoring, ultimately leading to a more resilient enterprise. Organizations can expect a clearer view of compliance status, enhanced decision-making capabilities, and a stronger risk posture across their extended enterprise.  
Respond to business risks in real time. Connect security and IT with an integrated risk
program offering continuous monitoring, prioritization, and automation.

## Governance, Risk, and Compliance applications {#r_WhatIsGRC__section_xxs_dj1_pjb}

|-|-|-|
| [AI Risk and ComplianceLearn how you can use the AI Risk and Compliance application to manage your artificial intelligence (AI) capabilities ethically, mitigate AI risks, and ensure compliance.](https://www.servicenow.com/docs/lABgtu7kC5R6aI8cUZNZAw "The ServiceNow AI Risk and Compliance application, along with the ServiceNow AI Control Tower, enables the risk and compliance managers to ensure that the organizations comply with the regulations and policies with respect to their AI systems.") | [Audit Management Use risk data to scope and prioritize audit plans and automate cross-functional processes.](https://www.servicenow.com/docs/mJCqVXq86dZZAWGmQoNkeA "The ServiceNow Audit Management application involves a set of activities related to planning audit engagements, executing engagements, and reporting findings to the audit committee and executive board. Engagement reporting assures key stakeholders that the organization's risk and compliance management strategy is effective.") | [Business Continuity Management Plan, exercise, and recover from disasters effectively and efficiently.](https://www.servicenow.com/docs/OeeSDC1w389ugW__RRmemw "ServiceNow Business Continuity Management application gives your organization the capability to continue to deliver products and services at an acceptable level when a disruptive incident occurs. The ongoing activities of this application are aimed to reduce the operational risks and improve your organizational ability to respond, react, and recover from issues and disruptions.") |
| [Compliance Case Management Report, investigate, analyze, and resolve compliance cases.](https://www.servicenow.com/docs/HpeHKsgtV7d7zK79UpOuRg "Report, investigate, analyze, and resolve a compliance case or raise a compliance request by using the ServiceNow GRC: Compliance Case Management application.") | [Continuous Authorization and Monitoring Accelerate the process of bringing IT systems online and continuously monitoring them.](https://www.servicenow.com/docs/h3gzNp_jxonigLFyLYLQCw "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.") | [Operational Resilience Gain real-time visibility into the resilience of your technology, people, processes, and facilities.](https://www.servicenow.com/docs/IUAEWTbEI~375URUkx0NEA "Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.") |
| [Policy and Compliance Management Automate and manage policy life-cycles and continuously monitor for compliance.](https://www.servicenow.com/docs/2ef2Kljgt4SEwle34PT51w "The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.") | [Privacy Management Manage privacy risk and compliance across the enterprise in real time.](https://www.servicenow.com/docs/R7tVI~FBDiiNXr1wNSMNwg "Use the Governance, Risk, and Compliance: Privacy Management application to help protect your customers, employees, and suppliers with integrated data privacy risk and compliance management solutions and privacy by design concepts​.") | [Regulatory Change Management Keep pace with today's complex regulatory landscape with integration to leading content providers.](https://www.servicenow.com/docs/ooKQs3gZg5VMottXtWUgPQ "The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application verifies the overall regulatory compliance for your organization.") |
| [Risk Management Enable fine-grained business impact analysis to appropriately prioritize and respond to risks.](https://www.servicenow.com/docs/6h4iv6tnhGmFGOM5zCkpRA "Use the Governance, Risk, and Compliance: Risk Management application to continuously monitor to identify high-impact risks, improve your risk-based decision-making, and reduce reaction time effectively. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.") | [Smart Assessment EngineReduce the manual burden and costs of your risk assessment processes through automation.](https://www.servicenow.com/docs/CZInBv2SnFbfzGIR5WrnHg "The ServiceNow Smart Assessment Engine (SAE) application helps you to reduce the manual burden and costs of your assessment processes through automation.") | [Third-party Risk Management Continuously monitor, detect, assess, mitigate, and remediate risks in third-party ecosystems.](https://www.servicenow.com/docs/XT_s4OKsgYe7JgCQWxggiw "The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.") |
| Common GRC features[Leverage the power of entities, 360 degree views, the tasks landing page, and security features across GRC products.](https://www.servicenow.com/docs/uCsuDR8c05tHyF4IzOS0NQ "Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.") |   |   |
[ ]

{#r_WhatIsGRC__table_iwv_lpv_klb}

## Request apps on the Store {#r_WhatIsGRC__section_tcm_hsr_ckb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#r_WhatIsGRC__inline-send-to-store}

## Respond to business risks in real time with ServiceNow
GRC {#r_WhatIsGRC__section_kys_xfv_rjb}

ServiceNow
Governance, Risk, and Compliance (GRC) helps transform inefficient processes
across your extended enterprise into an integrated risk program. Through continuous
monitoring and automation, the GRC applications deliver a real time
view of compliance and risk, improve decision making, and increase performance across your
organization and with vendors.

Only ServiceNow applications can connect the business, security, and
IT with an integrated risk framework that transforms manual, siloed, and inefficient
processes into a unified program that is built on a single platform.

[View and download the full info card](https://downloads.docs.servicenow.com/resource/enus/infocard/grc_statcard_infographic.pdf) for a highlight
of GRC features.

|-|-|
| ![Emergency Response Management]() | Streamline and automate activities in the face of an emergency :   Mobilize your business continuity efforts during natural disasters and pandemics like COVID-19. |
| ![Automate and manage]() | Automate and manage policy life cycles and continuously monitor for compliance. :   It makes perfect sense to embrace a single platform that can make all compliance efforts more organized, simpler, more transparent, and highly reliable. |
| ![Risk Management]() | Enable fine-grained business impact analysis to appropriately prioritize and respond to risks. :   Respond to business risks in real-time with integrated risk management. |
| ![Audit Management]() | Use risk data to scope and prioritize audit plans and automate cross-functional processes. :   Reduce audit costs, improve efficiency, and minimize risk. |
| ![Vendor Risk Management]() | Continuously monitor, detect, assess, mitigate, and remediate risk in vendor ecosystems. :   As your vendors become privy to more of your sensitive systems and data, their risk and compliance posture becomes even more important to your security. It's important to assess your vendors regularly and proactively mitigate any issues that arise. |
[ ]

{#r_WhatIsGRC__table_uw5_lxw_sjb}

## Automate and manage policy life cycles and continuously monitor for compliance {#r_WhatIsGRC__section_tzz_1kr_qjb}

The ServiceNow® Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures. The process automatically cross-maps the procedures to external regulations. Also, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.{#r_WhatIsGRC__ph_PCMgmtDescrip}

## Enable fine-grained business impact analysis to appropriately prioritize and respond to risks {#r_WhatIsGRC__section_jzr_jmr_qjb}

The ServiceNow
Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides
structured workflows for the management of risk assessments, risk indicators, and risk issues.

## Use risk data to scope and prioritize audit plans and automate cross-functional processes {#r_WhatIsGRC__section_z1v_jkr_qjb}

The ServiceNow
Audit Management product automates the work streams of internal audits teams, optimizing resources and productivity, and eliminating recurring audit findings. Audit Management uses compliance and risk data to scope, plan, and prioritize audit engagements. The ongoing review of policies and procedures, risks, and control breakdowns provide an opportunity for fixing issues
before they become audit failures.

The ServiceNow
Regulatory Change Management application empowers the customers to check upcoming regulatory changes, assess their impact, and implement risk and compliance related changes, ensuring overall regulatory
compliance.

## Continuously monitor, detect, assess, mitigate, and remediate risk in vendor ecosystems {#r_WhatIsGRC__section_v2b_jy1_yjb}

As your vendors become privy to more of your sensitive systems and data, their risk and compliance posture becomes even more important to your security. It's important to assess your vendors regularly, but until now, it has been
a time-consuming and error-prone exercise comprised of spreadsheets, email, and rudimentary legacy risk management tools.

The Vendor Risk Management application transforms the way you manage vendor risk through vital reporting of vendor risk and issues, a consistent assessment and remediation process, and automated assessment procedures. It
provides a means to facilitate stakeholder interactions, drive transparency and accountability, and effectively monitor vendor-related risks.

By aligning Vendor Risk Management with overall enterprise risk management priorities, you can create an essential integrated view of risk and a stronger extended enterprise risk posture.

## Learn {#r_WhatIsGRC__section_nkg_gl3_5rb}

* [What is a business continuity plan?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-business-continuity-plan.html)
* [What is business resilience?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-business-resilience.html)
* [What is Compliance Management?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-compliance-management.html)
* [What is GRC?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-grc.html)
* [What is operational resilience?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-operational-resilience.html)
* [What is operational risk management?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-operational-risk-management.html)
* [What is ransomware?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-ransomware.html)
* [What is third party risk management (TPRM)?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-third-party-risk-management.html)
{#r_WhatIsGRC__ul_q4v_hl3_5rb}

## Get started {#r_WhatIsGRC__section_pqm_vfr_qjb}

* Work with an implementation specialist to achieve your desired business outcomes. To learn more, visit the [Customer Success Center](https://www.servicenow.com/success.html).
* Take a Governance, Risk, and Compliance course to build expertise and realize ROI faster. To sign up, see [ServiceNow training and certification](https://www.servicenow.com/services/training-and-certification.html).
{#r_WhatIsGRC__ul_bpv_zmr_sjb}

## Applications and features {#r_WhatIsGRC__section_vpq_1j1_pjb}

* [AI Risk and Compliance](https://www.servicenow.com/docs/lABgtu7kC5R6aI8cUZNZAw "The ServiceNow AI Risk and Compliance application, along with the ServiceNow AI Control Tower, enables the risk and compliance managers to ensure that the organizations comply with the regulations and policies with respect to their AI systems.")
* [Audit Management](https://www.servicenow.com/docs/mJCqVXq86dZZAWGmQoNkeA "The ServiceNow Audit Management application involves a set of activities related to planning audit engagements, executing engagements, and reporting findings to the audit committee and executive board. Engagement reporting assures key stakeholders that the organization's risk and compliance management strategy is effective.")
* [Business Continuity
  Management](https://www.servicenow.com/docs/OeeSDC1w389ugW__RRmemw "ServiceNow Business Continuity Management application gives your organization the capability to continue to deliver products and services at an acceptable level when a disruptive incident occurs. The ongoing activities of this application are aimed to reduce the operational risks and improve your organizational ability to respond, react, and recover from issues and disruptions.")
* [Compliance Case Management](https://www.servicenow.com/docs/HpeHKsgtV7d7zK79UpOuRg "Report, investigate, analyze, and resolve a compliance case or raise a compliance request by using the ServiceNow GRC: Compliance Case Management application.")
* [Continuous Authorization and Monitoring](https://www.servicenow.com/docs/h3gzNp_jxonigLFyLYLQCw "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.")
* [Operational Resilience](https://www.servicenow.com/docs/IUAEWTbEI~375URUkx0NEA "Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.")
* [Policy and Compliance
  Management](https://www.servicenow.com/docs/2ef2Kljgt4SEwle34PT51w "The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.")
* [Privacy Management](https://www.servicenow.com/docs/R7tVI~FBDiiNXr1wNSMNwg "Use the Governance, Risk, and Compliance: Privacy Management application to help protect your customers, employees, and suppliers with integrated data privacy risk and compliance management solutions and privacy by design concepts​.")
* [Regulatory Change
  Management](https://www.servicenow.com/docs/ooKQs3gZg5VMottXtWUgPQ "The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application verifies the overall regulatory compliance for your organization.")
* [Risk Management](https://www.servicenow.com/docs/6h4iv6tnhGmFGOM5zCkpRA "Use the Governance, Risk, and Compliance: Risk Management application to continuously monitor to identify high-impact risks, improve your risk-based decision-making, and reduce reaction time effectively. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.")
* [Smart Assessment Engine](https://www.servicenow.com/docs/CZInBv2SnFbfzGIR5WrnHg "The ServiceNow Smart Assessment Engine (SAE) application helps you to reduce the manual burden and costs of your assessment processes through automation.")
* [Third-party Risk Management](https://www.servicenow.com/docs/XT_s4OKsgYe7JgCQWxggiw "The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.")
* [GRC and the ServiceNow
  Store](https://www.servicenow.com/docs/MWpViLHAbDvmVIu0U30pEQ "All GRC applications are available from the ServiceNow Store, allowing you to obtain new and updated features more rapidly. Before you can use any GRC applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them). Then, you can download them from the ServiceNow Store and activate them.")
* [Common GRC Features](https://www.servicenow.com/docs/uCsuDR8c05tHyF4IzOS0NQ "Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.")
{#r_WhatIsGRC__ul_od3_cj1_pjb}

