Combined Common Governance, Risk, and Compliance feature release notes for upgrades from Xanadu to Zurich

  • Release version: Zurich
  • Updated July 20, 2026
  • 7 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Combined Common Governance, Risk, and Compliance Feature Release Notes for Upgrades from Xanadu to Zurich

    This consolidated release notes document provides ServiceNow customers with a comprehensive view of all updates, new features, and enhancements to the Common Governance, Risk, and Compliance (GRC) feature from the Xanadu release through to Zurich. It is designed to assist customers in preparing for upgrades by detailing important pre- and post-upgrade tasks, as well as highlighting new capabilities and improvements relevant to GRC management across these release families.

    Show full answer Show less

    Key Features

    • Issue Grouping Management Method (Xanadu): Enables grouping and managing issues either from a parent issue or independently as child issues. New fields such as Group level and Management method help clarify issue relationships and management approaches, facilitating better issue tracking and resolution.
    • Confidentiality and Inheritance Enhancements: Improves confidentiality controls within issue grouping by controlling how confidential child issues relate to parent issues. Changes to confidentiality status appropriately unlink or reassign child issues, ensuring compliance and data security.
    • GRC Licensing Overview Dashboard: Provides a self-service dashboard to monitor license usage trends and projections across Integrated Risk Management, Business Continuity Management, and Privacy Management. Infrastructure enhancements include longer data retention (up to five years) and expanded capacity for unique user usage data.
    • Introduction of GRC Employee Role: A new role available through the GRC Employee User application allows employees to acknowledge policies, report risk events and compliance cases, request policy exceptions, and interact with the Compliance team directly via the Employee Center. This role supports broader organizational engagement in GRC processes.
    • Lite Operator Role Enhancements: Addition of audit reader and approver roles as Lite Operator roles, with reclassification of several operator roles when GRC Employee User and GRC Business User Lite applications are installed. This provides more granular audit permissions to applicable users.
    • Entity Filter Modification Warning: A warning system alerts users attempting to delete or modify entity filters, including an impact analysis on related entities, risks, and controls to prevent unintended data issues.
    • Document Designer Integration: Integration with Microsoft 365 allows users to update and add content to ServiceNow Reporting through the Document Designer application, enabling insertion of data and reports into Word documents for enhanced reporting capabilities.
    • Role Attribution to Licensing Mapping: A dedicated tab on the GRC Licensing Overview dashboard helps customers understand how licensing applies to various roles and users, including default GRC roles and specific role combinations.
    • Stakeholder Mapping in Entities: Allows definition of stakeholders with customizable roles for single and composite entities, improving team coordination in risk assessments and projects.

    Upgrade and Activation Notes

    Customers are advised to review and complete pre- and post-upgrade tasks specific to the Common GRC feature before upgrading to Zurich. Activation of the GRC feature requires installation through the ServiceNow Store. Customers should verify entitlement for the GRC Employee User application to utilize related features.

    Additional Information

    • No changes, removals, or deprecations were noted across the Xanadu, Yokohama, and Zurich releases for the Common GRC feature.
    • There are no new browser, localization, accessibility, or highlight considerations introduced in these releases.

    Practical Benefits for ServiceNow Customers

    • Enhanced issue grouping and confidentiality management streamline GRC workflows and compliance adherence.
    • Improved visibility into license usage and role-based licensing impacts aids in optimizing resource allocation and compliance with licensing terms.
    • Expanded user roles, including the GRC Employee and Lite Operator roles, enable broader organizational participation and more efficient audit processes.
    • Integration with Microsoft 365 Document Designer enhances reporting flexibility and document management within ServiceNow.
    • Stakeholder management features support effective collaboration in risk assessment activities.

    Consolidated page of all release notes for Common Governance, Risk, and Compliance feature from Xanadu to Zurich.

    How to use this page

    To help you prepare for your upgrade, we have combined the cross-family Common Governance, Risk, and Compliance feature release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.

    Tip:
    If there were no updates for a release notes section in a certain family release, we included a short note for your reference. For example, if a product did not have any updates in Tokyo, the row says "No updates for this release."

    Important information for upgrading Common Governance, Risk, and Compliance feature to Zurich

    Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    New features

    Between your current release family and Zurich, new features were introduced for Common Governance, Risk, and Compliance feature.

    Release Release notes

    Xanadu

    Management method in issue grouping
    Group and manage issues from a parent issue, or manage child issues independently using the group issue management method. When you select the Management method as Manage parent, the child issues inherit the values of the State, Response, and Explanation fields from the parent issue. When Manage child is selected, the child issue maintains its own State, Response, and Explanation fields individually.
    As a part of this feature, the following two new fields were added on the issue record in the Issue grouping section:
    • Group level: Identifies whether an issue is a child, parent, or a standalone issue.
    • Management method: Indicates whether the issue is managed from a parent issue or as an individual child issue.
    Confidentiality and inheritance enhancements in issue grouping
    Streamline the issue grouping process with the following enhancements:
    • Add confidential child issues only under a confidential parent issue.
    • Add nonconfidential child issues under a confidential or nonconfidential parent issue.
    • Change a confidential parent issue to nonconfidential. This action will remove all confidential child issues under the parent issue, making them standalone issues after you save the record.
      Note:
      When you change a nonconfidential child issue to confidential, which is under a nonconfidential parent issue, this action removes the child issue from the nonconfidential parent issue. The child issue becomes a standalone issue and no longer linked to the parent issue.
    GRC Licensing Overview dashboard
    Use the self-service GRC Licensing Overview dashboard to track license usage trends and next month's projected usage based on role allocation. You can see the monthly aggregated counts of license consumption across different product families including Integrated Risk Management, Business Continuity Management, and Privacy Management. The following infrastructure enhancements were made:
    • Expanded the unique user usage table capacity from 9 months to 12 months.
    • License consumption details are archived for five years.
    • Aggregated monthly counts of license usage are stored.
    Introducing GRC Employee role
    Install the new GRC Employee User application and assign the GRC Employee role to your employees. The users with the GRC Employee role can perform the following activities from the Employee Center:
    • Read and acknowledge organizational policies.
    • Report risk events and issues.
    • Request policy exceptions.
    • Report a compliance case to the Compliance team.
    • Raise inquiries and requests to the Compliance team.
    Note:
    This update is only applicable to customers who are entitled to and have installed the GRC Employee User application. For more details, review the entitlement on the subscription dashboard or contact ServiceNow.
    Lite operator role enhancements
    The sn_audit.reader and sn_audit.approver roles were added as Lite Operator roles. These new roles are available to all customers.
    The following Operator roles are reclassified as Lite Operator roles when GRC Employee User application and GRC Business User Lite applications are installed:
    • sn_grc.business_user
    • sn_risk_advanced.ara_assessor
    • sn_irm_cont_auth.authorization_official
    • sn_irm_cont_auth.reader
    • sn_irm_cont_auth.executive_read
    Note:
    This reclassification is only applicable to customers who are entitled to and have installed the GRC Employee User application. For more details, review the entitlement on the subscription dashboard or contact ServiceNow.
    Entity filter deletion or modification warning
    Avoid the unintended consequences of deleting or modifying an entity filter with a warning message. This message includes an impact analysis of the affected entity, risk, and control records.
    Document designer integration
    You can update and add content using Microsoft 365 for ServiceNow Reporting now integrated with the Document designer application to insert data and reports into a Microsoft Word document.
    Role attribution to licensing mapping tab
    Use the Role attribution to licensing mapping tab on the GRC Licensing Overview dashboard to understand how licensing applies to roles and users. This tab helps you with the following:
    • Identify the license treatment for all the default GRC roles.
    • Determine the license treatment of a specific user based on their assigned roles.
    • Determine the license treatment for a specific combination of roles.
    Map stakeholders in entity
    Use the Stakeholders related list in the entity form to define stakeholders with customizable roles relevant to single and composite entities. This feature enables effective team involvement in risk assessments and risk assessment projects. You can add persona, group, and users in the stakeholder list.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Changes

    Between your current release family and Zurich, some changes were made to existing Common Governance, Risk, and Compliance feature features.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Removed

    Between your current release family and Zurich, some Common Governance, Risk, and Compliance feature features or functionality were removed.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Deprecations

    Between your current release family and Zurich, some Common Governance, Risk, and Compliance feature features or functionality were deprecated.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Activation information

    Review information on how to activate Common Governance, Risk, and Compliance feature.

    Release Release notes

    Xanadu

    Install GRC by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Additional requirements

    If any additional requirements were introduced or changed for Common Governance, Risk, and Compliance feature we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Browser requirements

    If any specific browser requirements were introduced or changed for Common Governance, Risk, and Compliance feature we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Accessibility information

    Review details on accessibility information for Common Governance, Risk, and Compliance feature, such as specific requirements or compliance levels.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Localization information

    If there are specific localization considerations for Common Governance, Risk, and Compliance feature we have noted them here.

    Release Release notes

    Xanadu

    No updates for this release.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.

    Highlight information

    If there are specific highlight considerations for Common Governance, Risk, and Compliance feature we have noted them here.

    Release Release notes

    Xanadu

    • Group issues within your workspaces to organize and manage related issues, and streamline the issue grouping process with the confidentiality and inheritance enhancements.
    • Select an existing standalone issue to serve as the parent for other related issues during issue grouping.
    • Track license consumption across different product families using the GRC Licensing Overview dashboard.
    • Use the new GRC Employee role to report or request GRC workflows, and read and acknowledge policies from the Employee Center (Only applicable to customers who are entitled to and have installed the GRC Employee User application).
    • Read and approve audits, and read audit related tables with the enhanced Lite Operator changes.
    • Update and add content using Microsoft 365 for ServiceNow Reporting now integrated with the Document designer application.

    See Governance, Risk, and Compliance for more information.

    Yokohama

    No updates for this release.

    Zurich

    No updates for this release.