---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Control assessment through attestation

# Control assessment based on GRC attestation template {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Control assessment based on GRC attestation template

This feature enables ServiceNow customers to perform control assessments using a smart assessment method based on the GRC attestation template, providing an AI-driven alternative to the classic assessment approach.
It is designed to streamline and enhance the attestation process within Policy and Compliance Management.
Show full answer Show less  

## Prerequisites and Setup

* Installation of the **GRC: Policy and Compliance Management (sncompliance)** plugin is required.
* Additional scoped applications must be installed: **Smart Assessment core (snsmartasmt)** , **Smart Assessment Migration tools (snsmartasmtmig)** , **Smart Assessment Connected (snsmartasmtconn)** , and **Smart Assessment Designer (snsmartasmtdesg)**.
* The system property **Enable smart assessments on control** must be set to **true** to activate the smart assessment method.
* Migration of legacy assessment templates to the new smart assessment template format is supported using migration tables.

## User Roles and Permissions

* **sngrc.businessuser** and **sngrc.businessuserlite**: Respond to attestations via Compliance Workspace, Risk Portal, and Employee Center.
* **sncompliancews.corporatecompliancemanager** and **sncompliancews.itcompliancemanager**: View and edit assessment templates.
* **sncompliance.attestationcreator**: Create template categories and perform template migration.
* **sncompliance.user**: Read all assessments related to control categories.

## Control and Control Objective Behavior

* When smart assessments are enabled and the Control Objective's Attestation method is set to **Attestation**, controls generated inherit these attestation settings automatically.
* Controls linked to a Control Objective inherit attestation method and template values; these are read-only unless the control has no linked Control Objective.
* Controls automatically created from Control Objectives reflect the attestation method and are updated when the Control Objective changes.
* Attestation-related assessments are triggered when controls move to the **Attest** state, prompting email notifications to control owners and respondents.
* Changing attestation methods from classic to smart is reflected across all related controls, with the ability to update until the control is attested.
* Controls in Draft or Retired state cancel active assessments; controls marked Exempt cancel assessments but can re-trigger assessments if exemption is removed.
* Policy publication locks Control Objective fields to read-only.
* Assessment results impact compliance status: failed attestations create or update issues and mark controls as non-compliant; passing attestations close issues and mark controls compliant.

## Assessment Interaction and Visibility

* Attestations can be responded to through multiple portals: Employee Center, Risk Portal, and Compliance Workspace Tasks page.
* Controls and Control Objectives have updated forms and UI widgets to support smart assessments and provide attestation visibility.
* 360° Relationship Visualization is available for comprehensive control attestation views.

## Practical Benefits for ServiceNow Customers

This smart assessment approach offers a more automated, AI-driven way to manage control attestations, improving efficiency and accuracy in compliance workflows. It provides flexible user role management for attestation responses and template management, seamless migration from legacy templates, and real-time compliance status updates based on attestation results. Customers can expect enhanced control and policy governance with improved visibility and user experience across multiple ServiceNow portals.  
You can select the option to attest controls using an assessment method. This assessment is an alternative method to the classic assessment that is based on ServiceNow AI Platform method of assessment.

## Pre-requisites to enable smart assessment in Policy and Compliance Management {#smart-assessments-controls__section_hvm_trk_g1c}

Smart assessment scoped applications
:   The base system ships the GRC smart assessment template to the users when the GRC: Policy and Compliance Management (sn_compliance) plugin is installed. However, the following scoped applications are required:

    1. Smart Assessment core (sn_smart_asmt)
    2. Smart assessment Migration tools (sn_smart_asmt_mig). For more information, see [Migrate a legacy metric type to an assessment template](https://www.servicenow.com/docs/uja4aJOXvHRjTMnqkS6qlw "Migrate an existing metric type to an SAE assessment template. You can leverage the existing assessment designs while using Smart Assessment Engine.")
    3. Smart Assessment Connected (sn_smart_asmt_conn)
    4. Smart Assessment Designer (sn_smart_asmt_desg). For more information, see [Using the template designer](https://www.servicenow.com/docs/yGs5gBuG8OXGRpsDJ4YOnw "You can create assessment templates and add instructions, questions, and reference information by using the template designer in the Smart Assessment Engine application. Smart assessments can help you to evaluate various situations, aspects, or records.")
    {#smart-assessments-controls__ul_ygq_njl_g1c}

Enable smart assessments system property
:   The Enable smart assessments on control system property must be set to true if you want to assess the controls using the assessment method based on GRC attestation template. For more information on the
    system property, see [Enable smart assessments on control](https://www.servicenow.com/docs/0ZkKR4AN6wn5juPwkIAzTQ#r_PropInstWPolAndCompl__smart-assessment).

Migrate the template
:   Create a new template in Smart Assessment Engine. For more information, see [Creating an assessment template from legacy assessment metric types](https://www.servicenow.com/docs/dIw0TX6XS~ZUnM5sKxADYQ "You can use the assessment designs that you have already created by migrating the metric types to the Smart Assessment Engine assessment templates. You can leverage the existing assessment designs to support SAE assessment automation, analysis, and reporting.").

## Access control limitations for smart assessment user roles {#smart-assessments-controls__section_esy_cyt_g1c}

sn_grc.business_user and sn_grc.business_user_lite
:   As logged in users they can respond to attestations in My Attestations on the Task page of Compliance Workspace, Risk Portal, and Employee Center.

sn_compliance_ws.corporate_compliance_manager and sn_compliance_ws.it_compliance_manager
:   Can view and edit the templates.

sn_compliance.attestation_creator
:   Can create template category and template migration.

sn_compliance.user
:   Can read all the assessments related to control category.

## Assessment template category and migration tables {#smart-assessments-controls__section_ex5_r4r_g1c}

Assessment template categories \[sn_smart_asmt_template_category\]
:   The Category role field has the configuration of the minimum reader role required to read the template of this category. The role must contain sn_smart_asmt.template_reader role.

Assessment template migrations \[sn_smart_asmt_mig_template_migration\]
:   Used to migrate the existing source metric type and template category to the new assessment template format.

## Impact of attestation method on control objective and control generation {#smart-assessments-controls__section_dnx_4wk_g1c}

When the Enable smart assessments on control system property is set to true and the Control objective record has the value Attestation in the Attestation method
field, then all the controls that are generated for this control objective record after attestation has values defaulted from the control objective. The Attestation method field value defaults to
Attestation.  
Note:  
The old control objectives will have default assessment method as classic assessment. If you would like to explore smart assessment method, then you should make necessary changes to either the control objective or the control. The control can be updated only if it does not have any control objective. After you create a new record, you can either opt the classic attestation or attestation as your attestation method.

* If the control objective is associated with the control, then the generated control inherits the Attestation method and Attestation field values.
* If a control is created from a control objective, the Attestation method and the Attestation fields are pre-populated, if the control objective has values in these fields.  
  Note:  
  The controls are automatically created if the Create controls automatically option is enabled for the control objective.

  The Attestation method field is read only. However, you
  can edit the Attestation field and select a different template for attestation. Any changes done to the control objective are automatically updated in the associated controls.
* After the control is saved and attested, the Attestations related list appears in the Control record. This related list displays all Assessment instances that are in Open and Completed states.

  If the
  assessment method is changed from Classic attestation to Attestation in the control objective record, then the changes are reflected in all the control records generated for the control objective. Up until the control moves to
  the Attest state, the Attestation method and Attestation field values can be updated.
* If the control was previously generated opting the classic attestation method, then the Classic attestation related list has the details of all completed attestations.
* If the control is moved to the Draft state by selecting the Return to Draft button, all the assessments that were active are canceled. Similarly, if the control retires, all related assessments are canceled as well.
* If the control is marked Exempt owing to a policy exception, all the associated assessments are canceled. However, if the Exempt option is cleared for the control and if the control is in the Attest state, then the assessments are re-triggered. And, all the fields in the Attestation section of the control becomes read only.
* If a policy is associated to the control objective, and the policy is published, then all the fields of the control objective form become read only.
* When the control moves to the Attest state, the assessments are triggered. An email notification is sent to the control owner and the attestation respondents of the control, with the subject line referencing the new attestation name of the control number and the due date by which the attestation must be completed.
* If an attestation fails for one of the controls generated from a control objective, then the control becomes non-compliant and an issue is created. Or, if the control has an issue that already exists, then the Issue source field is updated. If the control moves to the Attest state and if the attestation passes, then the existing issues are closed, and the control becomes compliant.
{#smart-assessments-controls__ul_el2_hnl_g1c}
* You can respond to the attestations from any of these portals:
  * [Respond to attestations from the Employee Center](https://www.servicenow.com/docs/yOXW_N7~Qg7LRQziop8A0Q "Respond to your attestations by logging in to the Employee Center.").
  * [Respond to attestations on the Risk Portal](https://www.servicenow.com/docs/MRLKQJ_MeihxLZ4297xATA "Respond to your attestations by logging in to the Risk Portal.").
  * [Respond to attestations from Tasks page of Compliance Workspace](https://www.servicenow.com/docs/w2oA5EbwC5VluTiqc7ttUw "Respond to your attestations by logging in to the Tasks page of the Compliance Workspace.").
  {#smart-assessments-controls__ul_pyj_clc_pdc}
* To view the Control objective and Control form changes, see:
  * [Create a control objective using the Compliance Workspace](https://www.servicenow.com/docs/oNh9N27HKbz7cOtEXtRvPw "A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies using the Compliance Workspace.").
  * [Create a control using the Compliance Workspace](https://www.servicenow.com/docs/AhCzhuDPWYzAjDaw1_GyrA "Controls can either be automatically generated or manually created. A control is created for each entity listed in the entity type for the control objective.").
  {#smart-assessments-controls__ul_ukq_vlc_pdc}
* To view the attestation widgets in the control and control objective overview pages, see [User interface changes for assessments based on GRC attestation](https://www.servicenow.com/docs/o_4iSIan_d270Sk11ZTr7Q "The Lists pane of the Compliance Workspace is updated with assessments link to navigate to the assessments. The attestation and classic attestation widgets are displayed in the home pages of the compliance manager, compliance analyst, and the IT compliance manager.").
* To view the control attestations in 360° view, see [360° Relationship Visualization for Policy and Compliance Management](https://www.servicenow.com/docs/l3F27WUa~YyPK9~XgVwWeg "When you launch the 360° view from a particular compliance record, you can instantly explore the relationship between the selected record and all its associated objects in a distinctive visualization.").
{#smart-assessments-controls__ul_u2s_nkc_pdc}

