---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Case summarization for privacy cases

# GRC case summarization skill for privacy cases {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of GRC case summarization skill for privacy cases

The GRC case summarization skill leverages a large language model (LLM) to create concise, structured AI-generated summaries of privacy case records in ServiceNow.
It helps case assignees and approvers quickly grasp key details from complex cases involving multiple coordinators, activity logs, and breach assessments.
Summaries are generated on demand from predefined case data, editable, and can be saved for future reference.
Show full answer Show less  
This skill must be activated via the AI Admin Hub. Once enabled, authorized privacy case analysts can trigger it on relevant case records to support efficient decision-making.

## User Roles and Access

* **snnowassistadmin.nsaadmin**: Admin role to activate or edit the skill.
* **snprivacycase.privacycaseanalyst**: Grants access to privacy case records.
* **snprmgenai.user**: Provides access to ServiceNow Otto for Privacy Management skills and includes the minimum role to use this summarization skill.

All members of a case's Assignment group can view saved summaries.

## LLM Service Providers

An administrator must configure a default LLM provider before use. Supported providers include:

* Azure OpenAI
* AWS Claude
* Google Gemini

Setting the default provider enables the summarization skill to generate AI summaries by integrating with the chosen LLM service.

## Privacy Case Summary Structure

The AI-generated summary reflects the case data at generation time and can be updated as the case evolves. After creation, summaries can be reviewed, edited, and saved, appearing in the Overview tab and Activity stream.

The summary includes the following sections:

* **Case Overview:** Core details like case name, description, dates, priority, and assigned analyst.
* **Events Timeline:** Key dates including occurrence, discovery, investigation, and remediation timelines.
* **Scope of Impact:** Summary of impacted areas and regulatory frameworks, including counts of affected controls, entities, policies, and regulations.
* **Data Impacted:** Types of personal data exposed or compromised.
* **Evidence \& Worknotes:** Investigation notes and comments.
* **Causes \& Consequences:** Confirmed and suspected causes, plus incident impacts and penalties.
* **Actions \& Outcomes:** Summary of investigation tasks, breach assessments, and additional resolution activities.
* **Lessons Learned:** AI-driven analysis of investigation velocity and effort, categorizing investigation complexity and timelines.

## Practical Benefits for ServiceNow Customers

This skill streamlines privacy case management by providing quick, AI-powered insights into complex cases, enabling faster understanding and better decision-making. By automating summary generation from comprehensive case data, it reduces manual effort and helps maintain consistent documentation of investigation progress and outcomes.  
The GRC case summarization skill uses a large language model (LLM) to generate a structured AI summary of a privacy case record. The summary is generated on demand from case data and can be saved to the record for
future reference.

## Overview of the GRC case summarization skill {#privacy-case-summarization-skill__section_wyh_zk5_2hc}

Privacy cases can involve multiple coordinators, complex activity logs, and breach assessments. The GRC case summarization skill generates a concise AI summary of key case details, so assignees and approvers can quickly understand
the context and support efficient decision-making.

The GRC case summarization skill collects data from predefined fields and related lists across the case record. This data is assembled into a prompt and sent to the configured LLM service provider, which then
returns a structured summary.

To summarize privacy case records, the skill must be activated from the AI Admin Hub. Once it's activated, case analysts with the appropriate user role can trigger the skill on a privacy case.

## User roles {#privacy-case-summarization-skill__section_vzm_d5z_k3c}

Important user roles to activate and use this skill are:

* sn_nowassist_admin.nsa_admin: Grants an admin access to activate or edit a ServiceNow Otto skill.
* sn_privacy_case.privacy_case_analyst: Grants access to privacy case records.
* sn_prm_gen_ai.user: Grants access to the ServiceNow Otto for Privacy Management skills.  
  Note:  
  Users with the sn_prm_gen_ai.user role automatically have the sn_grc_sharegenai.grc_case_ai_user role, which is the minimum role required to use the GRC case summarization skill.
{#privacy-case-summarization-skill__ul_vcw_w3l_k3c}

All members of the Assignment group on a case record can view the summary that has been saved to the record.

## LLM service providers {#privacy-case-summarization-skill__section_x5j_pl5_2hc}

An administrator must set a default LLM provider before the skill can be used. The following providers are supported:

* Azure OpenAI
* AWS Claude
* Google Gemini

{#privacy-case-summarization-skill__ul_jcx_q3l_k3c}

To set a default provider for the GRC case summarization skill, see [Manage
model providers](https://www.servicenow.com/docs/access?context=edit-model-providers&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US).

## Components of a privacy case summary {#privacy-case-summarization-skill__section_rfw_5rz_k3c}

The summary reflects case data at the time of generation. As the case progresses, you can regenerate the summary to capture the latest information. Once generated, you can review and edit the summary before saving it to the privacy
case record. The saved summary appears in the Overview tab and in the Activity stream of the Details tab.  
{#privacy-case-summarization-skill__privacy_summary_structure__entry__2}

| Section | What it captures |
|-|-|
| Case Overview | Core case details, such as name, description, start date, priority, and assigned analyst, captured from the Details tab. |
| Events Timeline | Date of occurrence, date of discovery, investigation start and end dates, and remediation start and end dates, captured from the Schedule section on the Details tab. |
| Scope of Impact | Blast Radius Breakdown- Summary of the areas and regulatory frameworks impacted by the privacy case, captured from the Impacted Areas, Related Areas, and Regulations tabs. * Impacted areas- Number of areas, such as control, entity, location, company, and users, impacted by the reported privacy case. * Related areas- Number of areas, such as policies, citations, control objectives, and risk events, related to the privacy case. * Regulations/Standards- Number of regulations that are or can be impacted by the reported privacy case. {#privacy-case-summarization-skill__ul_sdj_n45_l3c} |
| Data Impacted | Types of personal data exposed or compromised during the incident, captured from the \[PI\] Information Objects tab. |
| Evidence \& Worknotes | Work notes and comments recorded during the investigation, captured from the Activity section on the Details tab. |
| Causes \& Consequences | Causes and consequences of the privacy case, captured from the Causes and Consequences tab. * Cause (Confirmed)- Confirmed cause of the incident. * Contributing Cause (Suspected)- Suspected cause of the incident. * Consequences- Resulting impact or penalties arising from the incident. {#privacy-case-summarization-skill__ul_qpq_hg5_l3c} |
| Actions \& Outcomes | Summary of actions taken during the investigation, captured from the Action Tasks and Breach assessment tabs. * Investigation- Initial investigation tasks to examine the reported incident. * Assessment- Breach assessment to evaluate the risk and extent of compromised data. * Additional Actions Taken- Supplementary actions to support a resolution. {#privacy-case-summarization-skill__ul_j5p_fh5_l3c} |
| Lessons Learned | AI-powered analysis of the case timeline and overall investigation effort. * Velocity analysis- Time to detect, investigate, and remediate. * Investigation effort level- Effort assessment ranked as low, medium, or high, based on case complexity, activity log, and timelines. {#privacy-case-summarization-skill__ul_cky_rh5_l3c} |
[Table 1. Privacy case summary structure]

{#privacy-case-summarization-skill__privacy_summary_structure}
**Related tasks**   

* [Activate the GRC case summarization skill](https://www.servicenow.com/docs/nNkUCfYruYSnk~sz5PNxpw "Activate the GRC case summarization skill from the AI Admin Hub to generate AI-powered summaries of privacy case records.")
* [Summarize a privacy case using the GRC case summarization skill](https://www.servicenow.com/docs/i_F8t0kNcSJ2uFiUPSUnuA "Use the GRC case summarization skill to generate an AI summary of a privacy case. The summary provides a consolidated view of the case life cycle, including breach-related assessment activity.")

