Combined Policy and Compliance Management release notes for upgrades from Zurich to Australia

  • Release version: Australia
  • Updated August 11, 2026
  • 11 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Policy and Compliance Management Release Notes for Upgrades from Zurich to Australia

    This consolidated release note provides a comprehensive guide for ServiceNow customers upgrading Policy and Compliance Management from the Zurich to the Australia release version. It highlights key new features, changes, and important upgrade tasks to support a smooth transition and leverage enhanced compliance capabilities.

    Show full answer Show less

    New Features

    • Association of Citations to Controls: Enables direct linking of controls with multiple citations across standards to avoid duplication and improve compliance reporting accuracy. Compliance scores dynamically update based on active associated controls.
    • Control Objectives Rationalization Enhancements: Automates rationalization initiation, simplifies recommendations into a two-step workflow, allows skipped approvals for owner-reviewers, and supports commenting on recommendations with an improved user interface.
    • Now Assist for IRM Citation Impact Analysis: Uses AI to identify and suggest updates to control objectives affected by changes in citation descriptions or guidance, streamlining review and approval within the Now Assist panel.
    • Enhanced Control Objectives and Controls: Introduces granular control objective requirements for individual statements, automatic generation of control requirements per entity, and attestation capabilities at the control requirement level.
    • Policy Exception and Extension Request Improvements: Approvers can view key details in pop-ups before decision-making, indicator tasks are suppressed for exempt controls, requesters can provide additional information via a "Send Information" button, and linking requirements for issue-based exceptions are expanded.
    • GRC Approval Configurator Upgrades: Supports multi-level, multi-user group approvals for policy exceptions and extensions with flexible rule definitions based on states and sub-states.
    • Common Control Objective Creation with Generative AI: Merges similar control objectives automatically, populating fields from accepted duplicates to streamline consolidation.
    • Entity-Based Record Access Rules: New controls, attestations, indicators, and tasks inherit access restrictions automatically based on linked entity settings, reducing manual updates and ensuring consistent security.
    • Australia-Specific Features:
      • Personal Authentication for Policy Authoring: Enables document operations in SharePoint and Google Drive under individual user credentials for improved audit traceability while maintaining consistent access management via a service account.
      • Dashboard Access from Compliance Workspace: Policy and Compliance dashboards are accessible directly from Compliance Workspace, enhancing user experience without requiring the Platform Analytics app.
      • Assessment Template Versioning: Supports version control for CRI tiering questionnaires, profiles, and control assessments, ensuring assessments use the latest published templates.
      • Role-Based Workspace Redirection: Email notification links direct users to the workspace aligned with their roles, improving navigation and task handling.
      • Control Objective Workflow: Introduces a structured lifecycle with states such as Draft, Review, Approved, and Retired, enabling controlled editing and revision of published control objectives.
      • Rationalization of UCF and non-UCF Control Objectives: Supports combined rationalization with clear handling of Unified Compliance Framework control objectives, ensuring consistent retention and dismissal rules.

    Changes

    • Rationalization Process UI Improvements: Redesigned interface with reordered layout, primary action highlights, validations for inactive controls, and options to restart analysis for recommendations.
    • AI Platform Updates: Introduction of ServiceNow Otto®—the new name for the integrated conversational AI platform delivering agentic, multimodal, and autonomous workflow capabilities.
    • Large Language Models: Default AI model selection updated to a third-party large language model for new or inactive AI assets, with manual selection of the Now LLM Service still available.
    • ServiceNow AI Licensing Tiers: Introduction of Foundation, Advanced, and Prime tiers providing different levels of AI functionality and access across applications and workflows.

    Activation and Requirements

    • Policy and Compliance Management installation remains available via the ServiceNow Store request process for both Zurich and Australia releases.
    • Browser support continues for the latest public release and two preceding versions of Chrome, Firefox (including ESR), Edge Chromium, and Safari (12.0+).

    Key Outcomes for ServiceNow Customers

    • Improved compliance accuracy and efficiency through direct citation-to-control associations and AI-assisted impact analysis.
    • Streamlined control objective management with automated rationalization and structured workflows supporting better governance.
    • Enhanced policy exception handling and approval flexibility, enabling faster and clearer decision processes.
    • Stronger security and access control via entity-based rules and personal authentication in policy authoring.
    • Better user experience with role-aware workspace access and consolidated dashboard availability.
    • Advanced AI capabilities through ServiceNow Otto® and tailored licensing tiers, empowering more intelligent and autonomous compliance operations.

    Consolidated page of all release notes for Policy and Compliance Management from Zurich to Australia.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Policy and Compliance Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Zurich to Australia.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Policy and Compliance Management to Australia

    Before you upgrade to Australia, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    New features

    Between your current release family and Australia, new features were introduced for Policy and Compliance Management.

    Release Release notes

    Zurich

    Association of citations to controls
    In many compliance frameworks, a single control objective may be referenced by multiple citations across different standards, regulations, or policy requirements. Without proper association management, organizations risk duplicating controls, misinterpreting coverage, or inaccurately reporting compliance. The association of citations to controls feature addresses this challenge by enabling users to associate controls with citations directly. When this feature is enabled, compliance scores update dynamically based on the status of directly associated active controls.
    Enhancements to control objectives rationalization process
    The following enhancements have been introduced to the rationalization process of control objectives:
    • Rationalization process is now automatically created when selecting the Rationalize button in the control objective page.

    • The recommendation workflow has been simplified into a two-step process: Step 1 identifies duplicates by accepting or dismissing recommendations; Step 2 finalizes by retaining one recommendation or creating a new common control objective.
    • Approvals for the rationalization process are skipped for owners who are reviewers, and levels where all reviewers are owners are automatically approved.

    • Owners and approvers can add comments and justifications directly on recommendation cards and reply to existing comments.

    • The user interface has been updated with better navigation, quick summaries, visual improvements, and clear error messages.
    Citation impact analysis and updates with Now Assist for IRM
    When a citation’s description or supplemental guidance is updated, Now Assist identifies related control objectives that might be affected. It reviews these control objectives to determine whether the descriptions or guidance need changes and provides suggested updates. Users can review, provide feedback, and approve these updates directly in the Now Assist panel, ensuring that citation changes are reflected in associated control objectives.
    Enhancements to control objectives and controls
    The following enhancements have been introduced to control objectives and controls:
    • The Control objective requirements option provides a granular layer under a control objective. When each control objective has multiple statements, each statement becomes a control objective requirement.
    • The Create control requirements option generates control requirements automatically for every control generated under an entity type.
    • The Attestation at control requirement level enables attestation at a granular level for individual control requirements within a control.
    Enhancements to policy exception and extension requests
    The following enhancements have been introduced:
    • For policy exception and extension requests, approvers can now view key details, such as justification, reason, and validity period, within a pop-up before approving or rejecting a policy exception or policy exception extension.
    • For manual indicators, if the associated control is marked as exempt, no indicator task is generated.
    • When a policy exception is in the Analyze state and the Awaiting Requested Information sub-state, the interface now includes a Send Information button that allows the requester to provide additional details or clarifications requested by the approver.
    • Previously, an issue-based exception required a linked policy or control objective for additional approvals. Now, it requires any one of the following: a linked policy, control objective, or control. The control must be linked to the policy exception itself, not just to the issue.
    GRC Approval Configurator

    The GRC Approval Configurator can now be used to manage both policy exception and extension approvals. It allows verification, approval, and extension rules to be defined based on state, sub-state, and other filter conditions, with support for multiple user groups and multi-level approvals. This enhancement provides greater flexibility in assigning appropriate approvers at each level based on defined conditions, facilitating structured and collaborative reviews. For extension approvals, users can now configure multiple approvers, overcoming the previous limitation of a single default approver (Compliance Manager).

    Common Control Objective Creation
    Use Generative AI to merge similar control objectives into a single, consolidated common control objective. The system automatically populates the name, description, and guidance fields from the accepted duplicates, eliminating the need to manually select a primary control objective.
    Entity based record access rules to secure new records

    When entity based record access rules are enabled on the Entity Based Access Configuration Properties page, any newly created controls, control attestations, indicators, and indicator tasks associated with a configured entity will automatically inherit the entity-based access (EBA) value from that entity. Previously, users had to run bulk access updates to apply EBA restrictions whenever new objects were created.

    Additionally, when a standard control is converted to a common control, the Entity based access restriction option is inactive by default. Users can manually enable the EBA option for common controls directly from the Access Settings section in the Details tab of the respective control.

    Australia

    Personal authentication and document access permissions in policy authoring
    After upgrading Policy and Compliance Management to 22.3.2, you can enable personal authentication for policy authoring in Microsoft SharePoint and Google Drive. When enabled, policy authoring uses a hybrid authentication model. Create, connect, and upload operations run under the logged-in user's personal credentials, while document access permission grants and content sync always run under the shared service account. This approach supports audit traceability at the individual user level for document operations and keeps access management and sync consistent regardless of who initiates them.
    Dashboard access from Compliance Workspace
    After upgrading to 22.3.2, you can access Policy and Compliance Management dashboards directly from the Compliance Workspace.
    The following dashboards are available:
    • Compliance Overview
    • Policy Acknowledgement
    • Policy Exception Overview
    • Policy Overview
    These dashboards are also accessible from the Platform Analytics application.
    Assessment template versioning
    After upgrading Policy and Compliance Management to 22.3.2, CRI tiering questionnaire, CRI profile assessment, and control assessment templates support versioning. Template managers can create and publish new versions of these templates over time. When a CRI tiering questionnaire, CRI profile assessment, or control assessment is initiated, the assessment is generated using the latest published version of the template.
    Role-based workspace redirection for email notification links
    After upgrading Policy and Compliance Management to 22.3.2, email notification links for Policy and Compliance Management records redirect users to their appropriate workspace based on their assigned roles. Users without a workspace role are redirected to the GRC Task Page, or to the classic UI if the common workspace is not installed. The following record types support workspace redirection: Controls, Evidence, Control risk indicators, Indicator task, Policy acknowledgments, and Policy exceptions.
    Control objective workflow
    After upgrading Policy and Compliance Management to 22.0.1, the new Control objective workflow feature introduces a structured lifecycle for managing control objective records. Enable this feature using the Enable Control Objective Workflow property under Policy and Compliance > All > Properties and is disabled by default.
    • When disabled, only the State field is added to control objective records. Active records show Published, inactive records show Retired, and new records default to Draft.
    • When enabled, control objectives move through: Draft, Review, Approved, Current version, and Retired. The following new fields are also introduced: State, Effective date, Revision type, and Record nature.
    • Editing a published control objective creates a working draft, keeping the published record active until approved changes are published.
    • Users must select a revision type: Major or Minor. A Major revision moves associated controls back to Draft. A Minor revision applies updates without moving controls back to Draft.
    • The Owner and Owning Group fields control who can edit the control objective and perform workflow actions.
    Rationalizing control objectives
    After upgrading Policy and Compliance Management to 22.0.1, both Unified Compliance Framework (UCF) control objectives and non-UCF control objectives can be rationalized together.
    • Recommendation cards show a Source field to indicate whether it originates from UCF or a non-UCF source.
    • As UCF control objectives cannot be deactivated, the Identify Duplicates and Finalize sub-states guide the users to retain the UCF control objective. Any UCF recommendations that are not retained are automatically dismissed when the user requests review.
    • Only one UCF control objective can be retained at a time. If you retain a different UCF control objective, the previously retained one is automatically dismissed.
    • When rationalization is complete, the retained UCF control objective stays active, accepted non-UCF recommendations are deactivated, and any dismissed UCF control objectives remain active and unchanged.

    Changes

    Between your current release family and Australia, some changes were made to existing Policy and Compliance Management features.

    Release Release notes

    Zurich

    Improvements to the rationalization process of control objectives
    Several enhancements have been made to the rationalization process:
    • Redesigned the rationalization UI with a reordered layout and highlighted primary actions.
    • Validations added for deactivated and deleted control objectives. Introduced the “Restart Analyze” option to support reevaluation of recommendations.
    • Introduced support for Azure OpenAI, Amazon Bedrock, and Google Gemini for recommendations of control objectives.
    • Updated the Consolidate state UI to show the recommendation panel with retained and accepted control objectives and their associated items.

    Australia

    Australia Patch 5
    ServiceNow Otto® name announcement
    Now Assist introduced AI on the platform. As that experience has evolved, there's a new name for the experience. ServiceNow Otto® is the conversational AI platform integrated into ServiceNow workflows. It provides agentic capabilities, supports multimodal interactions across web, mobile, and messaging channels, and enables autonomous orchestration for cross-system workflows.
    The Now Assist for IRM (sn_irm_gen_ai) plugin, which provides generative AI capabilities for RCM, has been renamed to ServiceNow Otto for IRM.
    Australia Patch 4
    Large language models on the ServiceNow AI Platform
    The Now LLM Service is no longer the default model provider for new or inactive AI assets. A third-party LLM is now selected by default, while existing configurations using the Now LLM Service continue unchanged. The Now LLM Service is still available for manual selection.
    Australia Patch 1
    ServiceNow product tiers
    The ServiceNow AI Platform now brings you a new AI experience with three licensing tiers available:
    • Foundation: AI basics to deliver insights
    • Advanced: AI to boost productivity across relevant use cases
    • Prime: Act autonomously with all AI assets, and create your own

    Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents.

    Removed

    Between your current release family and Australia, some Policy and Compliance Management features or functionality were removed.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Deprecations

    Between your current release family and Australia, some Policy and Compliance Management features or functionality were deprecated.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Activation information

    Review information on how to activate Policy and Compliance Management.

    Release Release notes

    Zurich

    Install Policy and Compliance Management by requesting it from the ServiceNow Store.

    Australia

    Install Policy and Compliance Management by requesting it from the ServiceNow Store.

    Additional requirements

    If any additional requirements were introduced or changed for Policy and Compliance Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Policy and Compliance Management we have noted them here.

    Release Release notes

    Zurich

    Policy and Compliance Management supports the latest public release and the two preceding versions of the following web browsers:
    • Google Chrome
    • Firefox and Firefox Extended Support Release (ESR)
    • Microsoft Edge Chromium
    • Safari 12.0 and later versions

    Australia

    Policy and Compliance Management supports the latest public release and the two preceding versions of the following web browsers:
    • Google Chrome
    • Firefox and Firefox Extended Support Release (ESR)
    • Microsoft Edge Chromium
    • Safari 12.0 and later versions

    Accessibility information

    Review details on accessibility information for Policy and Compliance Management, such as specific requirements or compliance levels.

    Release Release notes

    Zurich

    Australia

    No updates for this release.

    Localization information

    If there are specific localization considerations for Policy and Compliance Management we have noted them here.

    Release Release notes

    Zurich

    No updates for this release.

    Australia

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Policy and Compliance Management we have noted them here.

    Release Release notes

    Zurich

    • Association of citations to controls feature enables users to associate controls with citations directly to avoid duplicated controls and ensure accurate compliance reporting.
    • Multiple enhancements to control objectives rationalization process, including improvements including automatic rationalization process creation, simplified two-step workflow for recommendations, skipped approvals for owner-reviewers, comment capabilities, and improved UI.
    • Now Assist for IRM includes skills and AI agent to identify affected control objectives when citation descriptions change and to provide suggested updates for review and approval.
    • Enhancements to control objectives and controls, including control objective requirements for granular statements, automatic control requirement generation, and attestation at control requirement level.
    • Enhancements to policy exception and extension requests, including approver pop-ups with key details, no indicator tasks for exempt controls, Send Information button for requesters, and expanded linking requirements for issue-based policy exceptions.

    See Privacy Management for more information.

    Australia

    • ServiceNow Otto is the new name for the Now Assist experience, delivering agentic AI, multimodal interactions, and autonomous cross-system workflow orchestration.
    • Enable personal authentication for policy authoring in Microsoft SharePoint and Google Drive to register policy documents under the logged-in user's identity instead of a shared service account.
    • Access Policy and Compliance Management dashboards directly from the Compliance Workspace, without installing Platform Analytics application.
    • Manage control objective changes through a structured workflow without affecting the active published record.
    • Rationalize UCF and non-UCF control objectives together in a single rationalization process.
    • Email notification links redirect users to their appropriate workspace based on their assigned roles.

    See Policy and Compliance Management for more information.