---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Exploring Regulatory Change Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Regulatory Change Management

The Regulatory Change Management application in ServiceNow provides a structured framework to help organizations efficiently manage regulatory changes by integrating with third-party regulatory intelligence providers.
This application supports tracking regulatory alerts, assessing their relevance and impact, and managing compliance and risk-related changes through defined workflows.
It enables organizations to stay current with evolving regulations and maintain compliance effectively.
Show full answer Show less  

## Key Features

* **Integration with Regulatory Intelligence Providers:** Connects with external partners like Thomson Reuters Regulatory Intelligence to consume regulatory alerts directly into your ServiceNow instance.
* **Regulatory Taxonomy Management:** Allows creation of an internal taxonomy aligned with external taxonomies, categorizing regulatory content by content type, jurisdiction, regulatory body, sector, and theme for standardized processing.
* **Triage and Impact Assessment:** Enables users to review incoming regulatory alerts, determine their applicability, and assess impact using configurable methodologies supported by AI-powered recommendations.
* **Change Management and Task Tracking:** Facilitates creating action plans and tasks to update GRC components such as policies, processes, risks, controls, and citations. Tracks due dates and task completion for compliance assurance.
* **Role-Based Workflow:** Supports roles such as Regulatory Change Manager (RCM manager), Regulatory Change User (RCM user), subject matter experts, and coordinators for efficient collaboration and approval processes.
* **Compliance Workspace Integration:** Available from version 13.0.1, offering a unified interface to monitor regulatory changes, impact assessments, and compliance actions.
* **Collaboration Tools:** Includes Next Experience Chat and Discuss features to enable real-time collaboration and support on regulatory change cases.

## Practical Process Flow

The typical regulatory change management lifecycle includes:

* Setting up integration with regulatory intelligence feeds.
* Establishing and mapping an internal regulatory taxonomy.
* Reviewing and triaging regulatory alerts by RCM managers and users.
* Conducting impact assessments by subject matter experts.
* Creating and approving action plans with assigned tasks for risk and compliance teams.
* Tracking task completion, closing alerts, and maintaining audit trails.

## Why It Matters for ServiceNow Customers

This application empowers your organization to proactively manage regulatory changes, reduce compliance risks, and streamline collaboration across risk, compliance, and business stakeholders. By leveraging automation, integration, and AI-driven insights, you can maintain up-to-date regulatory compliance efficiently and ensure that all necessary changes are implemented and tracked within your ServiceNow environment.  
The Regulatory Change Management application provides a framework that your organization can use to integrate with third-party regulatory intelligence providers to keep up with the regulatory changes and external
regulations.

## Regulatory Change Management overview {#what-is-rcm__section_es4_l3d_wmb}

The Regulatory Change Management application enables you to manage your upcoming regulatory changes efficiently. The application provides the structured workflows that help your organization to assess the applicability
of the regulatory changes, assess their impact, and implement risk and compliance-related changes.

The following infographic shows the process flow of the Regulatory Change Management application.  
Figure 1. Process flow of the Regulatory Change Management application

The Regulatory Change Management application works with the following types of components:

* Integration component: The regulatory intelligence partners typically provide the integration component. Through this integration, you can consume regulatory alerts into your instance.
* Application framework component: The Regulatory Change Management application has an application framework component. This component provides the structured workflows that you can use to analyze and process the regulatory alerts that are received in the regulatory alerts table.

{#what-is-rcm__ul_w2j_qkb_hnb}  
The Regulatory Change Management application consists of the following workflow:

1. Manage regulatory taxonomy: Create an internal regulatory taxonomy that is specific to the ServiceNow AI Platform. You can map the taxonomy with the external taxonomies that are provided by the third-party regulatory intelligence providers for standardization. The internal taxonomy contains the following design elements:
   * Content Type
   * Jurisdiction
   * Regulatory Body
   * Sector
   * Theme

   {#what-is-rcm__ul_ckg_xsv_jnb}

   You can create and map these elements with the external taxonomy during the setup process.
2. Integrate for regulatory intelligence: Integrate with the third-party regulatory intelligence providers and consume the alerts into your instance at regular intervals. You can monitor regulatory data in a rapidly changing environment.
3. Triage regulatory events: Analyze the regulatory alerts and identify the regulatory events that are relevant to your organization.
4. Assess impact: Assess the impact of regulatory events by using configurable impact assessment methodologies.
5. Manage changes: Identify changes that should be done. These changes are implemented through the following action tasks:
   * Update the underlying GRC objects, such as the policies, processes, risks, and controls in the regulatory library.
   * Update the existing citations or import the new citations from the providers in the regulatory library.
   {#what-is-rcm__ul_jfk_l4r_fnb}
6. View reports and dashboards: Assess the state of the regulatory compliance by using reports and dashboards. You can maintain an audit trail of the compliance activities.
{#what-is-rcm__ol_erz_vp2_wmb}

The following diagram shows the workflow of the Regulatory Change Management application.  
Figure 2. Workflow of the Regulatory Change Management application

## Key product innovations {#what-is-rcm__section_ah1_dgf_4cc}

The following infographic shows the process for making innovations for the key products of the Regulatory Change Management application.
Figure 3. Process for innovating key products  
The steps to complete the Regulatory Change Management process flow to innovate key products are:

1. Set up the integration. Your customers can subscribe to a public RSS feed for the regulatory bodies or a subscription provider such as Thomson Reuters Regulatory Intelligence (TRRI) that is a curated intelligence provider. A subscription provider can aggregate the regulatory changes from different sources and provide the collective changes as feeds.
2. Set up an internal taxonomy. The taxonomy elements are different classifiers that an organization can apply to its regulatory content to categorize it. You can use the taxonomy elements to create a hierarchical structure of the different classifications for setting up the regulatory content for an organization.
3. Review a regulatory alert. A user with the sn_grc_reg_change.manager role (RCM manager) reviews a regulatory alert and assigns it to a coordinator or a user with the sn_grc_reg_change.user role (RCM user). The user with the sn_grc_reg_change.user role reviews the alert. If the regulatory change requires an impact assessment, the RCM user sends it to a subject matter expert (SME) with a business user role.

   A user with sn_grc_reg_change.user and sn_grc_comp_genai.reg_change_ai_user roles can generate
   AI-powered recommendations for a regulatory alert for the impacted citations, control objectives, and controls.
4. Assess the impact. The subject matter expert (SME) with a business user role assesses the impact of the regulatory change and sends the score of the impact assessment to the Regulatory Change Management application. If the alert is not applicable to the organization, the RCM user closes the alert. If the alert is applicable to the organization, the RCM user creates a new regulatory change task and assigns it to the same coordinator or to a new coordinator.
5. Devise an action plan. The coordinator identifies the steps to comply with the regulatory change, devises an action plan, and creates the action tasks for the different teams that must complete the identified action items. The coordinator then creates the action tasks that are associated with the regulatory change task. After the action plan is created, it's sent to the RCM manager for an approval. The manager reviews the action plan and confirms if more action tasks must be created or if some of the action tasks aren't necessary.
6. Complete the action tasks and send them for review to a user with the sn_grc_reg_change.manager role (RCM manager). If the action plan is rejected, the coordinator goes through the action plan, updates the actual tasks, and sends the action plan back for an approval. The compliance manager can see all compliance-based action tasks and the risk manager can see all risk-based action tasks. After the tasks are assigned to the risk and compliance users, the action tasks are tracked until they're completed. A due date is marked and tracked for the action tasks. When the tasks are completed, the regulatory alert and the parent regulatory change tasks are closed and the change process flow is completed.
{#what-is-rcm__ol_j1d_drv_nqb}

## A day in the life of a regulatory change manager {#what-is-rcm__section_psq_qjp_ddc}

A user with the sn_grc_reg_change.manager role (RCM manager) monitors, manages, decides, and verifies the regulatory changes on a daily basis.

The following infographic depicts a typical day for a regulatory change management.  
Figure 4. Typical day of a regulatory change manager
* **[Regulatory Change Management application in the Compliance Workspace](https://www.servicenow.com/docs/~0ueKeuRNjHLte~noqpT0w)**   
  Starting with GRC: Regulatory Change Management, version 13.0.1, the Regulatory Change Management application is available in Compliance Workspace. Compliance Workspace provides your users with a single-pane view so that they can check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes for the organization.
* **[Differences between regulatory event alert and source document alert](https://www.servicenow.com/docs/qQIecsMzG6JT2CvEm9PZaQ)**   
  A regulatory event alert informs you of a regulatory change, while a source document alert signals the release or update of the related official document.
* **[Regulatory process flow and tasks](https://www.servicenow.com/docs/OqTe6MRU08a5OXPfoG8hKQ)**   
  The Regulatory Change Management process flow includes the tasks that different users can perform to help your organization manage and comply with regulatory changes.
* **[Next Experience Discuss and Chat Collaboration](https://www.servicenow.com/docs/K20gU6goSbSsY910OXto0Q)**   
  On a regulatory change management case, select Discuss from other options. Collaborate with virtual agents by using Next Experience Chat Collaboration and Discuss.

