Combined AI Risk and Compliance release notes for upgrades from Yokohama to Zurich

  • Release version: Zurich
  • Updated August 11, 2026
  • 12 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined AI Risk and Compliance Release Notes for Upgrades from Yokohama to Zurich

    This consolidated release summary guides ServiceNow customers through the AI Risk and Compliance upgrades from the Yokohama to Zurich release versions. It highlights new features, changes, and essential upgrade tasks to help organizations enhance governance, risk management, and compliance of AI assets including systems, models, and datasets.

    Show full answer Show less

    Key Features

    • AI Asset Lifecycle Management: Manage AI assets end-to-end, supporting centralized inventory, governance consistency, and traceability throughout development, deployment, monitoring, and retirement phases.
    • Impact and Risk Assessments: Perform detailed impact assessments to identify fundamental rights risks (e.g., bias, privacy, misinformation) and conduct risk assessments on individual AI asset risks to improve oversight and mitigation.
    • AI Case Management: Structure and track AI-related cases and incidents with clear documentation and resolution workflows to ensure accountability.
    • AI Framework Content Pack: Use pre-configured regulatory mappings (e.g., EU AI Act, NIST AI RMF) to build a compliance-ready AI asset inventory aligned with major AI governance frameworks.
    • AI Risk and Compliance Workspace: Access a comprehensive dashboard showing AI asset risks, compliance status, controls, assessments, and case activity to support informed decision-making and reporting.
    • 360° Relationship Visualization: Explore interdependencies among AI assets, controls, risks, and issues through interactive visualizations.
    • Collaborative Discussions: Facilitate internal collaboration on ethical, transparency, and accountability considerations throughout the AI asset lifecycle.
    • Role-Based Access Control and Data Segregation: Enforce security by restricting access to sensitive AI asset data based on roles and entity-based permissions while maintaining core entity visibility.
    • Bulk Risk Assessment Projects: Assess multiple risks and controls for AI assets simultaneously within single projects to improve efficiency and consistency.
    • Content Accelerator: Quickly activate and manage regulatory content packs from a unified hub, streamlining framework adoption and compliance management.
    • Email-Driven Case and Inquiry Creation: Automatically generate AI cases and inquiries by emailing a dedicated address, eliminating manual reporting gaps.
    • AI Asset Offboarding Workflow: Govern AI asset retirement with structured workflows ensuring compliance, impact tracking, and audit trail maintenance.
    • Risk Score Aggregation and Visualization: Aggregate and visualize system-level AI risk scores using heatmaps and widgets for comprehensive risk posture monitoring.
    • Enhanced AI Risk and Compliance Views: Access updated, detailed views tailored for AI models and datasets that include refreshed questionnaires and templates aligned to current governance standards.
    • AI Cases Tab: Centralize monitoring and management of AI cases with filtering and sorting capabilities to prioritize investigations and actions efficiently.
    • Risk Heatmap Filtering: Customize risk visualizations by specific risk assessment methodologies to align with organizational or regulatory evaluation frameworks.
    • Grouped Control Attestations: Organize attestations by objectives or frameworks to reduce redundancy and improve compliance visibility.
    • Regulatory Update Scanning: Stay informed about global regulatory changes through automated scanning and interpretation features that help assess impact timely.
    • Compliance Posture Reporting Controls: Tailor reporting of compliance insights related to regulations and internal policies with configurable detail and cadence.

    Key Outcomes for ServiceNow Customers

    • Achieve comprehensive governance and lifecycle management of AI assets with improved traceability and control.
    • Identify and mitigate AI-related risks more efficiently through bulk risk assessments and detailed impact analyses.
    • Enhance compliance readiness by leveraging up-to-date regulatory content packs and structured case management.
    • Improve security and data access control with entity-based permissions and role-based access enforcement.
    • Streamline collaboration and communication among stakeholders via integrated worknotes, comments, and chat discussions.
    • Maintain continuous visibility into AI risk and compliance posture with dashboards, heatmaps, and risk score visualizations.
    • Automate case creation from email to ensure consistent tracking and faster response to AI-related incidents and inquiries.
    • Support structured offboarding of AI assets to reduce compliance gaps and operational risks during retirement or replacement.

    Upgrade Considerations

    Before upgrading to Zurich, customers should review and complete recommended pre- and post-upgrade tasks to ensure a smooth transition. The Zurich release introduces no removals or deprecations but includes significant feature enhancements and improved usability.

    Activation and Requirements

    AI Risk and Compliance can be installed via the ServiceNow Store. There are no new browser, localization, or accessibility requirements noted for the Zurich release. Customers should refer to the ServiceNow Store for installation requests and version history.

    Consolidated page of all release notes for AI Risk and Compliance from Yokohama to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family AI Risk and Compliance release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading AI Risk and Compliance to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for AI Risk and Compliance.

    Release Release notes

    Yokohama

    AI asset lifecycle management
    Manage the complete life-cycle of AI assets, from selecting appropriate AI systems to developing, deploying, and monitoring AI models and datasets. This feature helps maintain a centralized inventory, confirms consistent governance practices, and improves traceability and oversight across all stages of AI development and usage.
    Perform impact assessment on an AI use case
    Perform impact assessments to identify how AI systems, models, and datasets affect fundamental rights. This feature detects potential risks, such as copyright issues, algorithmic bias, privacy breaches, misinformation, and surveillance concerns, to support better oversight and risk management.
    AI asset inventory risk management
    Identify individual and specific risks associated with AI assets, such as AI systems, models, and datasets. Perform risk assessments on each identified risk separately.
    AI case management
    Manage and track cases or incidents related to AI use cases across the organization. This feature provides a structured approach to documenting, investigating, and resolving AI-related issues and cases, supporting consistent oversight and accountability.
    AI framework content pack
    Use the default AI framework content pack to prepare a compliance-ready inventory of AI assets. The content pack provides mappings to key AI regulations and standards, such as the European Union AI Act and the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF). This feature helps organizations to align AI governance activities with regulatory requirements.
    AI Risk and Compliance workspace
    See a comprehensive overview of all your AI inventory-related information in the AI Risk and Compliance workspace. The AI Risk and Compliance workspace enables you to:
    • Identify the risk classification of AI asset inventory.
    • Identify the compliant and noncompliant controls for authority documents and policies.
    • View AI systems based on state and department.
    • View the AI assessments and risk assessments information.
    • View information related to the control attestation, indicators, AI issues, AI cases, and policy exceptions.
    • Generate report to help leaders identify, assess, and mitigate risks.
    360° Relationship Visualization of AI assets
    Explore the relationships between critical AI assets that impact your business, including controls, risks, and issues.
    Collaborate with internal users
    Collaborate with internal users by starting chats focused on the ethical, transparency, and accountability aspects of AI assets. Use discussions to document considerations, share feedback, and drive informed decision-making throughout the AI asset life-cycle.
    Roles installed
    The following roles related to AI Risk and Compliance for managing AI systems across the enterprise were added:
    • AI Risk and Compliance Admin [sn_grc_ai_gov.ai_risk_and_compliance_admin]: Configure AI Risk and Compliance and delete AI systems.
    • AI Risk and Compliance Manager [sn_grc_ai_gov.ai_risk_and_compliance_manager]: Initiate impact assessment, risk assessment, and control attestations. Manage the life cycle of the AI system.
    • AI Risk and Compliance Analyst [sn_grc_ai_gov.ai_risk_and_compliance_analyst]: Initiate impact assessment, risk assessment, and control attestations. Manage the life cycle of the AI system.
      Note:
      AI Risk and Compliance Analyst can perform these actions only on the records assigned to them.
    • AI Risk and Compliance User [sn_grc_ai_gov.ai_risk_and_compliance_business_user]: Create an AI case on the Employee Center and work on the assigned tasks. Perform control attestations.
    • AI Risk and Compliance Reader [sn_grc_ai_gov.ai_risk_and_compliance_reader]: Read the AI systems and AI impact assessments.

    Zurich

    Assess multiple risks and controls for AI assets simultaneously
    Create a risk assessment project to perform bulk assessments on multiple risks for an AI asset, enabling assessors to evaluate them in a single project. This approach reduces time and effort, confirms consistency across multiple assessments, and provides a more comprehensive view of risks and controls within the same project. You can scope multiple risks related to the assessable entity within the project and perform assessments.

    AI Risk and Compliance team can determine inherent risks, control effectiveness, residual risks, and target risks in the risk assessment project. They can also reassess completed assessments or reassign in-progress assessment projects to another assessor.

    AI asset data segregation with entity based access
    Enhance data segregation and security to ensure that only authorized users can access sensitive AI Risk and Compliance data while maintaining visibility into core entities. AI Risk and Compliance managers can control access risks, controls, related entities, issues, indicators, AI asset tasks, risk assessments, attestations, and AI assets data through entity-based access. Entities themselves stay visible to all users, while visibility of linked records is limited to authorized users.
    AI Risk and Compliance content accelerator
    Use the AI Risk and Compliance content accelerator icon on the AI Risk and Compliance workspace to activate the pre-configured content packs. Content Accelerator includes regulatory packs such as the EU Artificial Intelligence Act and NIST AI Risk Management Framework, offering citations, control objectives, and risk statements. The unified content hub helps to streamline scoping, reduce manual navigation between frameworks, and promote consistent use of regulatory content accelerator packs. This feature supports AI Risk and Compliance team in meeting relevant business requirements, maintaining team consistency, and speeding up the activation and management of global regulatory frameworks.
    Automatic AI case and inquiry creation from emails
    Report AI cases or raise AI inquiries by sending an email to a dedicated email address. Your email automatically creates a new AI Case or AI Inquiry record in the system. This feature remove manual work and scattered reporting methods, ensuring every case or inquiry is automatically captured, categorized, and tracked.
    360° AI asset view
    Use the 360° AI asset view in the AI Control Tower to explore the relationship between your AI assets and all its associated records in a distinctive visualization. This visualization provides valuable insights into how these objects interact and relate to each other within the AI asset. You can view related records such as, datasets, AI model, risks, controls, and assessments.
    AI asset offboarding workflow
    Manage AI asset changes and retirements through structured workflows that ensure compliance and reduce operational risk. Track and approve modifications to models, datasets, and systems while automatically identifying impacts on dependent assets. Initiate formal offboarding processes that remove access, close documentation, and update related controls when retiring underperforming or deprecated AI assets. Maintain complete audit trails integrated with your policy and risk frameworks to demonstrate governance continuity during lifecycle transitions.
    Deliver system-level AI risk score aggregation and visualization
    Aggregate AI system-level risk scores by integrating heatmaps and residual risk score widgets directly within your AI asset overview records. These visual tools help you to see the cumulative risk exposure and track the residual risks across the entire AI asset inventory. With this feature, you get clear, data-driven insights into the overall AI system risk posture.
    Enable AI risk and compliance views with updated content packs
    Get the dedicated AI risk and compliance views for your AI models and dataset records. With these views, you get a structured and comprehensive overview of the related risks, controls, and compliance obligations, including the refreshed content packs that feature the updated assessment questionnaires and templates that align with the latest governance frameworks and regulatory standards. Your organization can perform accurate and timely risk assessments while maintaining compliance with evolving AI governance requirements.
    Implement robust access control and AI asset management capabilities
    Apply role-based access controls across AI assets and dashboards to ensure that data access is based on user roles. You can enable employees to request access to AI assets through a governed process and enforce consistent tracking of life-cycle states (such as development, deployment, monitoring, and retirement) across all AI assets.
    Use the AI cases tab to monitor and manage AI case activity
    Gain a centralized overview of all your AI asset cases and inquiries by using the AI cases tab in the AI Risk and Compliance workspace. On this tab, you see a list of records that include the case details such as the status, priority, owner, and timeline of your AI cases. You can monitor the progression of a case, stay informed about ongoing investigations, follow up on pending actions, and ensure timely resolutions. On the tab, you can also find filtering and sorting options that help you to prioritize cases that require immediate attention.
    Filter the risk heatmap by Risk Assessment Methodology for targeted risk analysis
    Apply the Risk Assessment Methodology filter to customize the display of the risk heatmap that is based on the specific risk evaluation frameworks from the AI risk and compliance home page. You can segment and analyze the AI risks according to the risk assessment models that your organization adopts, such as the internal standards, regulatory frameworks, or industry benchmarks, so that you can understand how different risk factors are identified, scored, and distributed.
    Group control attestations
    Group control attestations by such predefined criteria as the control objectives, frameworks, or assessment cycles so that you can more efficiently manage and review attestations, reduce redundancy, and improve your visibility into the compliance status across related controls for the AI Risk and Compliance team.
    Scan and analyze updates from global regulators
    Enable the AI Risk and Compliance team to scan and interpret regulatory updates that are issued by global authorities. Your organization can stay informed about emerging compliance requirements, assess their potential impact, and take timely action.
    Manage reporting compliance posture insights on key regulations or policies
    Control the reporting of compliance posture insights that are related to key regulations and internal policies by using a setting to determine which insights are shared, their level of detail, and the reporting cadence. Your organization can align reporting outputs with regulatory obligations and internal governance requirements.

    Changes

    Between your current release family and Zurich, some changes were made to existing AI Risk and Compliance features.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    AI risk and compliance home page

    The Risk and compliance tab now features dedicated Risk overview and Compliance overview sections that enable you to continuously monitor the risk and compliance posture of your AI assets.

    The Risk overview section is a filtered view of your AI assets that are based on inherent and residual risk levels so that you can make informed risk evaluations. The Compliance overview section displays the regulatory risk classification of AI systems, models, and datasets through donut charts. Additionally, you can see the compliance status of your AI assets in relation to applicable authority documents and internal policies.

    Worknotes and comments in AI system records
    The AI system record now supports worknotes and comments. You can now document decisions, share updates, and provide context throughout the AI risk and compliance life-cycle. Worknotes and comments help improve the communication among stakeholders and ensure a comprehensive audit trail.

    Removed

    Between your current release family and Zurich, some AI Risk and Compliance features or functionality were removed.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some AI Risk and Compliance features or functionality were deprecated.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate AI Risk and Compliance.

    Release Release notes

    Yokohama

    Install AI Risk and Compliance by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Zurich

    Install AI Risk and Compliance by requesting it from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for AI Risk and Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for AI Risk and Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for AI Risk and Compliance, such as specific requirements or compliance levels.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    Localization information

    If there are specific localization considerations for AI Risk and Compliance we have noted them here.

    Release Release notes

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for AI Risk and Compliance we have noted them here.

    Release Release notes

    Yokohama

    • Manage AI systems, models, and datasets across their entire life-cycle with consistent governance for better visibility, control, and compliance.
    • Perform impact assessments for AI systems, models, and datasets to identify high-risk AI assets.
    • Perform risk assessments on individual risks associated with an AI asset based on additional information and testing.
    • Manage and oversee AI-related cases and incidents through a structured case management process.
    • Build a compliance-ready AI asset inventory aligned with regulatory requirements using the AI framework content pack.

    See AI Risk and Compliance for more information.

    Zurich

    • Use entity-based access to limit AI asset data access to authorized users, maintaining core entity visibility.
    • Perform assessment on multiple risks for an AI asset by creating a risk assessment project.
    • Activate and manage pre-configured content packs using the unified content hub.
    • Report AI cases or raise AI inquiries by emailing a dedicated address, which automatically creates a new, trackable record in the system.
    • Retire and replace AI assets with structured workflows that prevent compliance gaps and security risks.
    • Aggregate system-level AI risk scores by embedding heatmaps and residual score widgets within your AI asset overview records. You get visibility into your cumulative risk across the AI inventory and support for continuous risk monitoring.
    • Get the dedicated AI risk and compliance views for your AI models and dataset records. With these views, you have a centralized interface where you can assess, monitor, and manage the risk and compliance attributes that are specific to your AI assets.
    • Enforce role-based access controls, enable employee-initiated AI asset requests, and maintain consistent life-cycle state tracking across all your AI assets and dashboards. This capability helps you to ensure security, transparency, and governance throughout the asset life-cycle.
    • View and manage your AI asset's risk and compliance cases more efficiently by accessing the new AI cases tab on the AI Risk and Compliance home page.
    • Monitor and track the risk and compliance posture of your AI assets to ensure that your organization aligns with organizational and regulatory standards. You can also gain real-time insights into the emerging risks and compliance gaps across your AI portfolio.

    See AI Risk and Compliance for more information.