---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Evidence request workflow

# Evidence request workflow {#ariaid-title1}

Release version: Australia  
Updated September 1, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Evidence Request Workflow

The evidence request workflow streamlines how users electronically request and collect necessary audit evidence from first and second line defense personnel.
This process reduces manual effort by allowing those being audited to upload documents directly into the system.
It supports both two-step and three-step workflows for evidence collection and verification.
Show full answer Show less  

## Key Features

* **Requesting Evidence:** Audit users with the *snaudit.user* role can create evidence requests for themselves or on behalf of other audit or GRC users.
* **Task Management:** Requesters can cancel evidence tasks while they are in Draft or any state before Review, allowing correction of erroneous requests.
* **Two-step or Three-step Workflow:** Users can select between a simpler two-step or a more detailed three-step evidence request process, with the two-step available from GRC: Advanced Core version 23.0.2 onwards.
* **Assignee Confidentiality:** Only the assigned individual can access the evidence request. Changing the assignee removes access from the previous assignee to ensure confidentiality.
* **Evidence Submission:** Assignees can upload evidence directly or provide a URL/location where the evidence is stored.
* **Approver Role:** When evidence is sensitive, approvers can be added to verify and approve, request revisions, or ask for more details before final acceptance.
* **Requester Actions:** Requesters review evidence and can accept it, request further review or details, cancel, or delete the request as needed.
* **Completion:** Once all evidence tasks are accepted by the requester, the evidence request is closed.

## Roles and Responsibilities

* **Internal Auditor:** Requests and performs audit testing, reviews audit findings and evidence, monitors compliance and risk activities, and manages a job queue for audit tasks.
* **Compliance Manager / Audit Manager:** Requests and reviews evidence and compliance tests, tracks compliance findings, and manages their team's workflow through job queues.
* **Compliance User / Control Owner:** Verifies and attests to controls, tests controls, provides requested audit evidence, manages daily tasks via job queues, and fulfills requests from auditors.

## Practical Benefits

This workflow enables ServiceNow customers to efficiently manage audit evidence requests with improved transparency, confidentiality, and streamlined collaboration across audit and compliance teams. It reduces manual processing time, ensures proper verification of sensitive evidence, and provides clear task visibility and control for all parties involved.  
Evidence request helps users to electronically request the information that they
need from the first and second line of defense. The individuals being audited can then immediately
upload their documents to the system, significantly reducing manual processing time.  
The evidence request workflow is as follows:

1. An audit user with the sn_audit.user role requests evidence and assigns the request to another user. This requester can either request the evidence for themselves or raise a request on behalf of another audit user or GRC user. If the requester determines that an evidence task has been created erroneously, then the requester can cancel that particular evidence task. The ability to cancel the evidence request is available when the request is in Draft state. A requester can cancel the evidence request tasks any time until the tasks reach the Review state.
2. While creating an evidence request, you can choose between the two-step or three-step flow.  
   Note:  
   The two-step evidence request functionality is available starting with GRC: Advanced Core, version 23.0.2.
3. The assignee then receives an email with the link to provide the requested evidence.  
   Note:  
   If the requester changes the assignee after requesting evidence, then the original assignee can no longer view the request. Only the person who is assigned the request can view the request. This feature provides confidentiality.
4. The assignee can either attach the requested evidence or provide a URL or location that contains the required evidence.
5. The assignee can also add an approver for verifying and approving the evidence. Adding approvers is necessary if the evidence is sensitive and confidential in nature.
6. The approver can then review the evidence and either approve it, request revision, or request further details about the evidence.
7. If the approver approves the evidence, the requester receives the evidence and can process it further.
8. The requester can then review the evidence and do one of the following:
   * accept the evidence.
   * request a review.
   * request further details about the evidence.
   * cancel the evidence request if it is not required anymore.
   * delete the request.
   {#evidence-request-workflow__ul_ist_z3y_qmb}
9. If the requester accepts all the evidence tasks, the request is closed.

{#evidence-request-workflow__ol_ojh_lfp_qmb} The evidence request workflow is shown in the following figure:

## Roles and their responsibilities during the evidence request workflow {#evidence-request-workflow__section_cft_r1x_3kc}

The following table describes the roles and their responsibilities during the evidence request workflow:{#evidence-request-workflow__table_sqs_lmf_nmb__entry__3}

| User | Responsibilities | Requirements |
|-|-|-|
| Internal auditor | * Perform audit testing. * Request audit testing. * Review all audit findings and the evidence collected. {#evidence-request-workflow__ul_c5w_rmf_nmb} | * Visibility into compliance and risk activity. * A job queue (pending, current, upcoming) to plan their team efforts. * Track and monitor audit findings and activities. {#evidence-request-workflow__ul_lhl_zqf_nmb} |
| Compliance manager, Audit manager | * Request evidence and compliance test evidence. * Review all findings and evidence collected. {#evidence-request-workflow__ul_zj1_xrf_nmb} | * Visibility into compliance activities. * A job queue (pending, current, upcoming) to plan their team efforts. * Track compliance findings. {#evidence-request-workflow__ul_fpg_nsf_nmb} |
| Compliance user, Control owner | * Verify that the controls are implemented. * Attest to the controls. * Test the controls. * Provide audit evidence requested by the auditor. {#evidence-request-workflow__ul_kdg_f5f_nmb} | * A job queue to direct their day-to-day activities. * Track time spent and performance of owned activities and tasks. * Fulfill owned tasks and additional requests from the auditor. {#evidence-request-workflow__ul_ad5_35f_nmb} |
[Table 1. Evidence request users, responsibilities, and requirements]

{#evidence-request-workflow__table_sqs_lmf_nmb}

