---
sourceDocument: Xanadu Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/governance-risk-compliance

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Setup checklist for the GRC Audit Management application

# Setup checklist for the GRC
Audit Management application {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This checklist includes the setup tasks that you are required to complete in your ServiceNow AI Platform® instance. When you have completed these tasks, the base
system is ready for operation. Optional setup procedures are also included to enhance Audit Management functionality.

## Before you begin

Role required: admin

Consider creating and printing a PDF of this checklist topic. You can then check off tasks as you complete them.

To generate a PDF, click the save as PDF icon () at the top of the topic.

## Procedure

Click the Selected topic.  
{#setup-checklist-audit__table_lqq_1qt_rhb__entry__2}

| Item | Description |
|-|-|
| ![check box.]() | As an audit administrator or audit manager, create engagements to manage audit information and include entities, controls, and control tests that are relevant to the audit. For details, see [Create an engagement](https://www.servicenow.com/docs/Jobls28BXMe8FXQzKkf3yQ "Audit managers create engagements to manage audit information and collect entities, controls, and control tests that are relevant to the audit."). |
| ![check box.]() | As an audit administrator or audit manager, after you have created engagements, define which entities are scoped in the audit engagement. For details, see [Add entities to an engagement scope](https://www.servicenow.com/docs/Dny0_KKPL_b1zTDCygtP~A "Audit managers can define which entities are involved in the audit engagement. When you add an entity to an engagement, the corresponding risks, controls, test plans, and indicator results of the entity are also added to the engagement."). |
| ![check box.]() | After defining a control, audit managers create control tests that run periodically and provide documented evidence of whether the associated control is operating correctly. For details, see [Create a control test from an engagement](https://www.servicenow.com/docs/RJ6OMXlA0djXYzfvWDFsbQ "After defining a control, audit managers create control tests that run periodically and provide documented evidence of whether the associated control is operating correctly."). You can also generate control tests automatically. For details, see [Automatically generate control tests from an engagement](https://www.servicenow.com/docs/l0PJGAEr8bdeXTTtyEEhiQ "After adding an entity to an engagement, you can automatically generate control tests.") |
| ![check box.]() | After defining a control, audit managers create activities that explore and provide documented evidence of whether the associated control is operating correctly. For details, see [Create an audit task activity](https://www.servicenow.com/docs/0RGcZ1L46F~FvIiVCFc2LA "After defining a control, audit managers create activities that explore and provide documented evidence of whether the associated control is operating correctly."). |
| ![check box.]() | After defining a control, audit managers create interviews with control owners to discuss and provide documented evidence of whether the associated control is operating correctly. For details, see [Create an interview](https://www.servicenow.com/docs/eBSTovnG0FJa9s3JUh07cg "After defining a control, audit managers create interviews with control owners to discuss and provide documented evidence of whether the associated control is operating correctly.") |
| ![check box.]() | After defining a control, audit managers create walkthroughs that will be conducted to observe and provide documented evidence of whether the associated control is operating correctly. For details, see [Create a walkthrough](https://www.servicenow.com/docs/YmSmueO7A6nAJRI_sHr05Q "After defining a control, audit managers create walk throughs that will be conducted to observe and provide documented evidence of whether the associated control is operating correctly."). |
| ![check box.]() | As an audit manager, generate an audit report that summarizes the findings of an engagement so report findings can be communicated to executives. For details, see [Generate an audit report from an engagement](https://www.servicenow.com/docs/XZVZcsgB0_14ux9z47dv8w "Generate an audit report and maintain different versions of audit reports from an engagement in Follow up state.") |
[Table 1. Audit Management application checklist]

{#setup-checklist-audit__table_lqq_1qt_rhb}

