GRC case summarization skill for privacy cases
Summarize
Summary of GRC Case Summarization Skill for Privacy Cases
The GRC case summarization skill leverages a large language model (LLM) to generate concise, structured AI summaries of privacy case records within ServiceNow. This functionality helps case assignees and approvers quickly grasp critical case details, enabling more efficient decision-making. Summaries are created on demand from predefined fields and related lists in the case record, then saved for future reference. The skill is designed to handle complex privacy cases involving multiple coordinators, detailed activity logs, and breach assessments.
Show less
To use this skill, it must be activated via the Now Assist Admin console. Authorized case analysts can then trigger the summarization on privacy cases as needed.
User Roles and Permissions
- snnowassistadmin.nsaadmin: Enables administrators to activate or edit Now Assist skills.
- snprivacycase.privacycaseanalyst: Grants access to privacy case records for analysts.
- snprmgenai.user: Provides access to Now Assist for Privacy Management skills, including the GRC case summarization skill (users with this role automatically receive the minimum required grccaseaiuser role).
All members of a case’s Assignment group can view any saved summary on that record.
LLM Service Providers
An administrator must configure a default LLM provider before the skill can be used. Supported providers include:
- Azure OpenAI
- AWS Claude
- Google Gemini
Setting the default provider is essential to enable AI summary generation.
Privacy Case Summary Components
The AI-generated summary captures the privacy case data as it exists at the time of generation and can be regenerated to reflect updates. Summaries are reviewable and editable prior to saving and appear in the Overview tab and Activity stream of the case record.
The summary is structured into the following key sections:
- Case Overview: Core details such as case name, description, start date, priority, and assigned analyst.
- Events Timeline: Important dates including occurrence, discovery, investigation, and remediation periods.
- Scope of Impact (Blast Radius Breakdown): Summary of impacted areas, related areas, and applicable regulations or standards.
- Data Impacted: Types of personal data exposed or compromised.
- Evidence & Worknotes: Investigation notes and comments.
- Causes & Consequences: Confirmed and suspected causes, along with resulting impacts or penalties.
- Actions & Outcomes: Overview of investigative tasks, breach assessments, and additional resolution actions.
- Lessons Learned: AI-driven analysis of investigation velocity and effort level, classified by case complexity and activity.
Practical Benefits for ServiceNow Customers
This skill streamlines privacy case management by providing a clear, AI-generated summary that consolidates multifaceted case data. It supports faster understanding and more informed decisions for case analysts and approvers, reduces manual summarization effort, and promotes consistency in documenting case progress and outcomes.
The GRC case summarization skill uses a large language model (LLM) to generate a structured AI summary of a privacy case record. The summary is generated on demand from case data and can be saved to the record for future reference.
Overview of the GRC case summarization skill
Privacy cases can involve multiple coordinators, complex activity logs, and breach assessments. The GRC case summarization skill generates a concise AI summary of key case details, so assignees and approvers can quickly understand the context and support efficient decision-making.
The GRC case summarization skill collects data from predefined fields and related lists across the case record. This data is assembled into a prompt and sent to the configured LLM service provider, which then returns a structured summary.
To summarize privacy case records, the skill must be activated from the Now Assist Admin console. Once it's activated, case analysts with the appropriate user role can trigger the skill on a privacy case.
User roles
- sn_nowassist_admin.nsa_admin: Grants an admin access to activate or edit a Now Assist skill.
- sn_privacy_case.privacy_case_analyst: Grants access to privacy case records.
- sn_prm_gen_ai.user: Grants access to the Now Assist for Privacy Management skills. Note:Users with the sn_prm_gen_ai.user role automatically have the sn_grc_sharegenai.grc_case_ai_user role, which is the minimum role required to use the GRC case summarization skill.
All members of the Assignment group on a case record can view any summary that has been saved to that record.
LLM service providers
An administrator must set a default LLM provider before the skill can be used. The following providers are supported:
- Azure OpenAI
- AWS Claude
- Google Gemini
To set a default provider for the GRC case summarization skill, see Manage model providers.
Components of a privacy case summary
The summary reflects case data at the time of generation. As the case progresses, you can regenerate the summary to capture the latest information. Once generated, you can review and edit the summary before saving it to the privacy case record. The saved summary appears in the Overview tab and in the Activity stream of the Details tab.
| Section | What it captures |
|---|---|
| Case Overview | Core case details, such as name, description, start date, priority, and assigned analyst, captured from the Details tab. |
| Events Timeline | Date of occurrence, date of discovery, investigation start and end dates, and remediation start and end dates, captured from the Schedule section on the Details tab. |
| Scope of Impact | Blast Radius Breakdown- Summary of the areas and regulatory frameworks impacted by the privacy case, captured from the Impacted Areas, Related
Areas, and Regulations tabs.
|
| Data Impacted | Types of personal data exposed or compromised during the incident, captured from the [PI] Information Objects tab. |
| Evidence & Worknotes | Work notes and comments recorded during the investigation, captured from the Activity section on the Details tab. |
| Causes & Consequences | Causes and consequences of the privacy case, captured from the Causes and Consequences tab.
|
| Actions & Outcomes | Summary of actions taken during the investigation, captured from the Action Tasks and Breach assessment tabs.
|
| Lessons Learned | AI-powered analysis of the case timeline and overall investigation effort.
|