---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# ServiceNow Otto for AI Risk and Compliance

# ServiceNow Otto for AI Risk and Compliance {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of ServiceNow Otto for AI Risk and Compliance

ServiceNow Otto for AI Risk and Compliance, part of the Integrated Risk Management (IRM) application, leverages agentic workflows and generative AI skills to help organizations efficiently manage AI-related risks and compliance.
It automates issue summarization, control objective creation, and generates smart assessment responses, addressing common challenges such as manual risk evaluations, regulatory monitoring, and governance compliance.
Show full answer Show less  
This solution is designed to reduce delays and inconsistencies in risk assessments and improve tracking of mitigation efforts across the enterprise.

## Key Features

* **Generative AI Skills:** Automate reporting and summarization of AI system risks and issues, generate executive-level risk assessment summaries, assist with contextually relevant assessment responses, and recommend control objectives.
* **Agentic Workflows:** Enhance AI risk records with regulatory and governance context, automate control mapping by identifying affected governance controls and compliance policies, accelerating impact analysis and reducing control gaps.
* **Specific AI Skills Include:**
  * **Report a GRC Issue:** Simplifies flagging governance, risk, and compliance (GRC) issues with structured context for quick escalation.
  * **Issue Summarization:** Produces concise summaries of reported issues highlighting key details and impact to speed triage.
  * **Risk Assessment Summarization:** Generates natural language summaries of risk assessments for executive insights.
  * **Smart Assessment Response Assist:** Recommends compliant remediation actions based on policies, historical data, and industry standards.
  * **Recommendation for Similar Control Objectives:** Identifies relevant controls across risk domains based on risk profiles.
  * **Common Control Objective Creation:** Creates reusable control objectives to ensure consistency and reduce duplication across governance portfolios.

## Benefits for ServiceNow Customers

* **Efficiency:** Significantly reduces manual effort in AI risk reporting, assessment responses, and control design.
* **Consistency:** Improves uniformity of risk evaluations and remediation recommendations by leveraging organizational policies and historical data.
* **Scalability and Adaptability:** Supports integration of new AI risk and compliance skills and workflows to keep pace with evolving regulations and organizational needs.
* **Enhanced Risk Context:** Automated enrichment of risk records with relevant regulatory and governance information reduces manual research time.
* **Improved Control Mapping:** Accelerates the identification of affected controls and reduces control gaps, strengthening overall governance.

## Important Considerations

* Availability of AI models and features may vary by region and deployment environment, including limitations for customers in restricted data centers or regulated markets.
* AI outputs are predictive and may not always be accurate or complete; human oversight and validation are essential, especially for critical use cases.
* Customers must comply with ServiceNow's AI Acceptable Use Policy when using these AI capabilities.  
With ServiceNow Otto for AI Risk and Compliance, part of the ServiceNow Otto for Integrated Risk Management (IRM) application, use agentic workflows and generative AI skills to streamline issue summarization, control objective creation, and smart assessment responses.

## ServiceNow Otto for AI Risk and Compliance overview {#airc-exploring-now-assist__cf-exploring-parent-overview}

Organizations deploying AI systems must continuously evaluate AI-related risks, monitor regulatory requirements, and ensure compliance with evolving AI governance standards. These activities are often performed manually, which can
result in delays, inconsistent risk assessments, and difficulty tracking mitigation efforts across the enterprise.

ServiceNow Otto for AI Risk and Compliance provides a set of generative AI skills and agentic workflows designed to address these challenges.

The summarization skill enables you to generate concise summaries of issues, highlighting key details, impact scope, and required actions to accelerate triage and response. The assessment summarization skill creates comprehensive risk evaluation summaries that distill complex risk factors, assessment findings, and remediation priorities into actionable insights. The response assist skill generates contextually relevant response recommendations for assessments based on past responses and uploaded documents to improve consistency and reduce repetitive work.

## ServiceNow Otto for AI Risk and Compliance benefits {#airc-exploring-now-assist__cf-exploring-parent-benefits}

The generative AI skills for ServiceNow Otto in AI Risk and Compliance offer the following benefits:

* Automated assessment of AI systems, reducing manual effort in reporting issues, summarizing issues for context, responding to assessments, and rationalizing control objectives.
* Minimized human intervention in repetitive tasks, enabling risk and compliance analysts to focus on strategic planning, risk mitigation, and stakeholder engagement.
* Scalable and configurable framework, supporting integration of new AI Risk and Compliance skills and workflows to adapt to evolving regulatory landscapes and organizational needs.
{#airc-exploring-now-assist__ul_ymj_zkz_vgc}  
The agentic workflows for ServiceNow Otto for AI Risk and Compliance offer the following benefits:

* Context-enriched risk analysis, enabling you to enhance AI risk records through an automated agent that surfaces relevant regulatory guidance, industry standards, and internal governance references, helping to reduce time spent manually researching compliance context.
* Automated control mapping, enabling workflows to recommend affected and duplicate governance controls, compliance policies, and regulatory requirements based on historical data and organizational risk frameworks, helping to accelerate impact analysis and reduce the risk of control gaps.
{#airc-exploring-now-assist__ul_azj_3tg_dhc}

## ServiceNow Otto for AI Risk and Compliance skills {#airc-exploring-now-assist__cf-exploring-parent-skills}

The following generative AI skills are available in ServiceNow Otto for AI Risk and Compliance:
{#airc-exploring-now-assist__table_p1h_lgx_12c__entry__3}

| Skill | Description | User |
|-|-|-|
| Report a GRC issue | Flag GRC issues to the Virtual Agent through utterances. Catalog the issue with completed form fields and simplify reporting across development, data science, and operations teams. For example, an AI Steward discovers anomalous results in a customer segmentation model affecting a specific demographic. With Report a GRC Issue, the concern is immediately escalated with structured context rather than waiting for scheduled audits. This enables the compliance team to address the issue within hours of discovery. For more information, see [Report a GRC issue AI agent](https://www.servicenow.com/docs/MRcPDBat2XmA9Df~H~14_w "The report a GRC issue AI agent enables employees to report GRC issues through the Employee Center using a guided, conversational experience. It organizes the information provided by the user, facilitates review, suggests relevant details, and streamlines submission, reducing barriers to reporting issues."). | To report a GRC issue, you need the sn_airc_gen_ai.airc_ai_agent_user role. |
| Issue Summarization | Automatically generates concise summaries of issues, highlighting key details, impact scope, and required actions to accelerate triage and response. For example, an AI Risk and Compliance Manager receives numerous issue reports about an AI-powered fraud detection system within a week. With Issue Summarization, these reports are distilled into a ranked list of concerns by category: data privacy gaps, performance degradation, and model drift. This enables the manager to focus resolution efforts on high-impact categories, reducing triage time from four hours to thirty minutes. For more information, see [Issue Summarization skill](https://www.servicenow.com/docs/T4JUpiNdfSBVSwZC8kNOHw "Use the Issue Summarization skill to view a concise summary of an issue based on its life-cycle data. The skill analyzes the issue’s context and generates a short, readable overview that includes key details such as status, actions, and relevant metadata. This helps you quickly understand the issue without reviewing the full record."). | To use the issue summarization skill, you need the sn_airc_gen_ai.airc_ai_agent_user and sn_airc_gen_ai.airc_ai_user roles. |
| Risk Assessment Summarization | Analyzes risk assessment data and generates natural language summaries of identified risks, trends, and patterns for specific AI systems, providing executive-level insights and highlighting critical risks requiring attention. For example, an AI Risk and Compliance Manager oversees several AI systems and is working on presenting findings to the Board Audit Committee. With Risk Assessment Summarization, assessment data is consolidated into executive insights highlighting regulatory, fairness, and operational risks across the portfolio. This enables the manager to present a brief strategic summary instead of a long form report, enabling swifter board decisions. For more information, see [Generate an AI risk assessment summary](https://www.servicenow.com/docs/9AQLE5DcIqPq9L~W4_8Ujw "Generate an AI risk assessment summary that is based on your inherent risks, residual risks, target risks, and control effectiveness data by using the ServiceNow Otto for IRM application. Your approvers get the key insights to understand the context quickly, and you reduce the time involved in creating summaries manually."). | To use the risk assessment summarization skill, you need the sn_airc_gen_ai.airc_ai_agent_user or sn_airc_gen_ai.airc_ai_user roles. |
| Smart Assessment Response Assist | Generate contextually relevant response recommendations for assessments based on organizational policies, historical patterns, and industry standards to improve consistency and efficiency. For example, an AI Risk and Compliance Manager assesses an AI model for diagnostic recommendations and identifies data bias risk in the training data. With Smart Assessment Response Assist, the system recommends compliant remediation paths based on organizational policies and similar successful implementations. This enables consensus on the optimal approach in one meeting rather than extended debate. For more information, see [Smart Assessment response assist skill](https://www.servicenow.com/docs/JQmWinLTzp2eB_XE~DsfZw "The GenAI-powered Smart Assessment Response Assist skill automatically drafts answers by using past smart assessments, classic assessments, and supporting documents."). | To use the smart assessment response assist skill, you need the sn_airc_gen_ai.airc_ai_agent_user or sn_airc_gen_ai.airc_ai_user roles. |
| Recommendation for similar control objectives | Automatically identify control objectives across risk domains by analyzing related risks, compliance requirements, and existing governance frameworks. For example, an AI Product Owner launches a new algorithmic trading AI system and needs applicable controls from an enterprise library. With Recommendation for Similar Control Objectives, the most relevant controls are recommended based on the system's risk profile. This enables the product owner to validate suggestions quickly, reducing control design time. For more information, see [Generate recommendation for similar control objective](https://www.servicenow.com/docs/ceKe6TyY_PC1hI5ptQ_zAg "Generate recommendations by identifying, deduplicating, and rationalizing similar control objectives within the compliance library. This enables identification of redundant control objectives, making it easier to maintain a clean and efficient compliance library."). | To use the skill for recommendation for similar control objectives, you need the sn_airc_gen_ai.airc_ai_agent_user or sn_airc_gen_ai.airc_ai_user roles. |
| Common control objective creation | Identify and create reusable control objectives for the compliance library. Reduces duplication and ensures consistent control implementation across governance portfolios. For example, an AI Risk and Compliance Manager oversees AI models across different business functions. With Common Control Objective Creation, a few reusable control objectives are identified from the portfolio. This enables new AI projects to inherit existing controls from a central library, reducing governance design time. For more information, see [Generate recommendation for similar control objective](https://www.servicenow.com/docs/ceKe6TyY_PC1hI5ptQ_zAg "Generate recommendations by identifying, deduplicating, and rationalizing similar control objectives within the compliance library. This enables identification of redundant control objectives, making it easier to maintain a clean and efficient compliance library."). | To use the common control objective creation, you need the sn_airc_gen_ai.airc_ai_agent_user or sn_airc_gen_ai.airc_ai_user roles. |
[ ]

{#airc-exploring-now-assist__table_p1h_lgx_12c} Important:  
* Not all model providers are available for customers with in-country SKUs, and some AI products/features are currently unavailable for in-country customers. For more information, see the [KB1584492](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1584492) article in the Now Support Knowledge Base. Be sure to check for model provider availability updates in future releases.{#airc-exploring-now-assist__na-in-country-notice}
* Some AI products/features are currently unavailable for customers in the FedRAMP, NSC DOD IL5, or Australia IRAP-Protected data centers, self-hosted customers, or in other restricted environments. For more information, see the [KB0743854](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0743854) article in the Now Support Knowledge Base. Be sure to check for availability updates in future releases.{#airc-exploring-now-assist__na-restricted-envs-notice}
* Some AI products/features are currently available only for customers in some regions. Be sure to check for availability updates in future releases.{#airc-exploring-now-assist__na-standalone-language-notice}
* Some AI products and skills are not available in Regulated Markets. For more information, see [KB2593939: Regulated Markets AI Products/Skills Not Available](https://support.servicenow.com/kb?id=kb_article_view&sys_kb_id=e8d7cc82475aba90b7832920326d4362). Be sure to check for availability updates in future releases.
{#airc-exploring-now-assist__ul_j3b_4vd_wcc}

## AI limitations {#airc-exploring-now-assist__section_oj4_m4c_qjc}

This application uses artificial intelligence (AI) and machine learning, which are rapidly evolving fields of study that generate predictions based on patterns in data. As a result, this application may not
always produce accurate, complete, or appropriate information. Furthermore, there is no guarantee that this application has been fully trained or tested for your use case. To mitigate these issues, it is your responsibility
to test and evaluate your use of this application for accuracy, harm, and appropriateness for your use case, employ human oversight of output, and refrain from relying solely on AI-generated outputs for decision-making
purposes. This is especially important if you choose to deploy this application in areas with consequential impacts such as healthcare, finance, legal, employment, security, or infrastructure. You agree to abide by [ServiceNow's AI Acceptable Use Policy](https://www.servicenow.com/ai-acceptable-use-policy.html), which may be updated by ServiceNow.{#airc-exploring-now-assist__p_kv2_nfg_h1c}

