GRC Compliance Workspace
Summarize
Summary of GRC Compliance Workspace
The GRC Compliance Workspace provides a unified and streamlined interface for managing compliance-related tasks such as policies, control objectives, controls, and policy exceptions. It is designed to support different compliance user roles with tailored views and functionalities to optimize business goal fulfillment.
Show less
Key Features
- Reimagined User Experience: The workspace home page consolidates all possible tasks in one place, enhancing efficiency.
- Role-Specific Views: Separate page views exist for Corporate Compliance Manager, Corporate Compliance Analyst, and IT Compliance Manager, enabling role-targeted task management.
- Home Page Sections:
- Overview: Donut charts visualize compliant vs. non-compliant authority documents, policies, and entities.
- Control Assurance: Displays control status and attestations with bar charts grouped by control effectiveness and classification.
- Tracking: Controls widget shows controls grouped by state and classification.
- Tasks: Pending tasks for individuals and groups with navigation to a unified tasks page.
- Unified Tasks Page: Allows users to track personal and team tasks, filter by categories, monitor initiated tasks, and manage a watchlist from a single interface.
- Lists View: Provides summaries of all compliance-related records for analysis and informed decision-making.
- Conditional Widgets: Control tests, regulatory changes, compliance cases, and privacy widgets appear based on installed plugins such as audit, regulatory change management, and privacy management.
- Email Notification Redirection: Clicking links in policy and compliance management email notifications redirects users to the relevant workspace or task page based on their assigned roles and installed workspaces.
Roles and Access
Access to the Compliance Workspace requires one of these roles:
- IT Compliance Manager (sncompliancews.itcompliancemanager)
- Corporate Compliance Manager (sncompliancews.corporatecompliancemanager)
- Corporate Compliance Analyst (sncompliancews.corporatecomplianceanalyst)
Each role has specific responsibilities and tailored workspace views to support efficient compliance management.
Email Notification Redirection Behavior
Users receive email notifications related to compliance records such as controls, evidence responses, indicator tasks, policy acknowledgments, and policy exceptions. Clicking these links redirects them according to their roles:
- Corporate Compliance Manager and Analyst roles redirect to Compliance Workspace.
- Compliance Managers and Approvers redirect to the GRC Task page.
If users have multiple workspace roles (Risk, Privacy, AI Risk and Compliance, Audit, CAM), the system routes them to the highest-priority workspace based on a defined order. Without any workspace role, users are directed to the GRC Task Page or the classic UI if the common workspace is not installed.
Practical Benefits for ServiceNow Customers
- Centralized management of compliance activities tailored by user role enhances operational efficiency.
- Visual dashboards provide quick insights into compliance status and controls effectiveness.
- Unified task management simplifies tracking and collaboration within compliance teams.
- Role-based email redirection ensures users access the appropriate workspace, improving navigation and response times.
- Conditional widget visibility allows customers to extend functionality by installing relevant plugins based on their compliance needs.
Compliance Workspace is a unified interface where you can manage all your tasks related to policies, control objectives, controls, and policy exceptions.
Compliance Workspace overview
- Reimagined user experience
- From the minute you navigate to the Compliance Workspace home page, all the tasks that you can possibly do in the workspace are streamlined to fulfill your business goals.
- Workspace designed for different compliance user roles
- Distinct page views for the exclusive activities of a Corporate compliance manager, Corporate compliance analyst, and IT compliance manager.
- Home page with different sections
-
- Overview
- Donut charts display the categorical data of compliant and non-compliant authority documents, policies, and entities.
Figure 1. Compliance workspace home page - Control assurance
- Displays the donut charts, grouping indicators by status, and attestations by state. Control test horizontal bar grouped by control and classification stacked by control effectiveness.
- Tracking
- Displays controls widget grouped by state and stacked by classification.
- Tasks
- View your pending tasks and the group's tasks. You can navigate to the unified tasks page by clicking the View all tasks link.
Note:Control tests widget, Regulatory change, Compliance case, and Privacy widgets are conditionally visible based on the respective plugins installation status. - Unified Tasks page
- Track your tasks and team's tasks from a single interface. View your tasks by categories, filter them by various parameters, monitor those tasks that you've initiated, and track through the watchlist.
- Lists
- List view of all compliance-related records, providing the summary of the record in a single view that helps in your analyses and take an informed decision.
Roles in the Compliance Workspace
The targeted users of the Compliance Workspace are the corporate compliance managers, the corporate IT compliance managers, and the corporate compliance analysts.
- IT Compliance Manager role: sn_compliance_ws.it_compliance_manager
- Corporate Compliance Manager role: sn_compliance_ws.corporate_compliance_manager
- Corporate Compliance Analyst role: sn_compliance_ws.corporate_compliance_analyst
Email notification redirection
When users receive email notifications for Policy and Compliance Management records, clicking a record link in the notification opens the record in the appropriate workspace, based on the user's assigned roles and installed workspace applications.
- Controls
- Evidence response
- Indicator tasks
- Policy acknowledgments/Policy acknowledgment instances
- Policy exceptions
| User role | Redirected to |
|---|---|
| BU User | GRC Task page |
| Compliance Manager | GRC Task page |
| Corporate Compliance Manager | Compliance Workspace |
| Corporate Compliance Analyst | Compliance Workspace |
| Approver (policy exception) | Compliance Workspace |
| Approver | GRC Task Page |
In addition, if a user has roles associated with other workspaces such as Risk, Privacy, Audit, CAM, or AI Risk and Compliance, the system redirects to the highest-priority workspace based on the role.
- Risk Workspace
- Privacy Workspace
- AI Risk and Compliance Workspace
- Audit Workspace
- CAM Workspace
If no workspace role is assigned and the common workspace is installed, the user is redirected to the GRC Task Page. If the common workspace is not installed, the user is redirected to the classic UI.