---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Evidence request workflow

# Evidence request workflow {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Evidence request workflow

The Evidence request workflow in ServiceNow enables audit users to electronically request and collect required information from first and second lines of defense.
This digital process allows assignees to upload evidence directly into the system, reducing manual handling and accelerating audit cycles.
The workflow supports both two-step and three-step evidence request flows, with confidentiality maintained by restricting request visibility to assigned users only.
Show full answer Show less  

## Workflow Steps

* An audit user with the **snaudit.user** role initiates an evidence request and assigns it to a user, either for themselves or on behalf of another audit or GRC user.
* The requester can cancel the request while it is in Draft or before it reaches the Review state, providing flexibility to manage erroneous requests.
* The assignee receives an email notification with a link to provide the requested evidence, which can be uploaded as attachments or shared via URLs/locations.
* For sensitive evidence, an approver can be added to verify and approve or request revisions on the submitted evidence.
* Once approved, the requester reviews the evidence and can accept it, request further details, ask for a review, cancel, or delete the request.
* When all evidence tasks are accepted, the evidence request is closed.

## Key Roles and Responsibilities

* **Internal Auditor:** Performs audit testing, requests evidence, reviews findings and evidence, and tracks compliance activities.
* **Compliance Manager / Audit Manager:** Requests and reviews evidence related to compliance testing and tracks compliance findings.
* **Compliance User / Control Owner:** Verifies, attests, and tests controls, provides requested audit evidence, and manages assigned tasks.

## Practical Benefits for ServiceNow Customers

This workflow streamlines evidence collection, reduces manual effort, and enhances audit and compliance visibility through role-based task management and notifications. Customers can expect faster evidence submission, improved confidentiality controls, and an organized approach to managing audit and compliance evidence requests within ServiceNow.  
Evidence request helps users to electronically request the information that they
need from the first and second line of defense. The individuals being audited can then immediately
upload their documents to the system, significantly reducing manual processing time.  
The evidence request workflow is as follows:

1. An audit user with the sn_audit.user role requests evidence and assigns the request to another user. This requester can either request the evidence for themselves or raise a request on behalf of another audit user or GRC user. If the requester determines that an evidence task has been created erroneously, then the requester can cancel that particular evidence task. The ability to cancel the evidence request is available when the request is in Draft state. A requester can cancel the evidence request tasks any time until the tasks reach the Review state.
2. While creating an evidence request, you can choose between the two-step or three-step flow.  
   Note:  
   The two-step evidence request functionality is available starting with GRC: Advanced Core, version 23.0.2.
3. The assignee then receives an email with the link to provide the requested evidence.  
   Note:  
   If the requester changes the assignee after requesting evidence, then the original assignee can no longer view the request. Only the person who is assigned the request can view the request. This feature provides confidentiality.
4. The assignee can either attach the requested evidence or provide a URL or location that contains the required evidence.
5. The assignee can also add an approver for verifying and approving the evidence. Adding approvers is necessary if the evidence is sensitive and confidential in nature.
6. The approver can then review the evidence and either approve it, request revision, or request further details about the evidence.
7. If the approver approves the evidence, the requester receives the evidence and can process it further.
8. The requester can then review the evidence and do one of the following:
   * accept the evidence.
   * request a review.
   * request further details about the evidence.
   * cancel the evidence request if it is not required anymore.
   * delete the request.
   {#evidence-request-workflow__ul_ist_z3y_qmb}
9. If the requester accepts all the evidence tasks, the request is closed.

{#evidence-request-workflow__ol_ojh_lfp_qmb} The evidence request workflow is shown in the following figure:

## Roles and their responsibilities during the evidence request workflow {#evidence-request-workflow__section_cft_r1x_3kc}

The following table describes the roles and their responsibilities during the evidence request workflow:{#evidence-request-workflow__table_sqs_lmf_nmb__entry__3}

| User | Responsibilities | Requirements |
|-|-|-|
| Internal auditor | * Perform audit testing. * Request audit testing. * Review all audit findings and the evidence collected. {#evidence-request-workflow__ul_c5w_rmf_nmb} | * Visibility into compliance and risk activity. * A job queue (pending, current, upcoming) to plan their team efforts. * Track and monitor audit findings and activities. {#evidence-request-workflow__ul_lhl_zqf_nmb} |
| Compliance manager, Audit manager | * Request evidence and compliance test evidence. * Review all findings and evidence collected. {#evidence-request-workflow__ul_zj1_xrf_nmb} | * Visibility into compliance activities. * A job queue (pending, current, upcoming) to plan their team efforts. * Track compliance findings. {#evidence-request-workflow__ul_fpg_nsf_nmb} |
| Compliance user, Control owner | * Verify that the controls are implemented. * Attest to the controls. * Test the controls. * Provide audit evidence requested by the auditor. {#evidence-request-workflow__ul_kdg_f5f_nmb} | * A job queue to direct their day-to-day activities. * Track time spent and performance of owned activities and tasks. * Fulfill owned tasks and additional requests from the auditor. {#evidence-request-workflow__ul_ad5_35f_nmb} |
[Table 1. Evidence request users, responsibilities, and requirements]

{#evidence-request-workflow__table_sqs_lmf_nmb}

