Combined Policy and Compliance Management release notes for upgrades from Xanadu to Zurich
Summarize
Summary of Combined Policy and Compliance Management Release Notes for Upgrades from Xanadu to Zurich
This consolidated release notes document guides ServiceNow customers through the key updates and enhancements in Policy and Compliance Management from the Xanadu release family through to Zurich. It highlights new features, important upgrade tasks, changes, deprecations, activation instructions, browser requirements, and additional considerations to help customers effectively plan and execute their upgrade to Zurich.
Show less
New Features
- Document Management Integration: Customers can now upload policy documents from local machines to Microsoft OneDrive, Google Drive, and Microsoft SharePoint, enabling collaborative policy authoring, version control, and easier access across devices.
- Policy Authoring Enhancements: Integration with Microsoft SharePoint supports policy drafting, redlining, revision, and history retention, streamlining collaboration among policy owners, reviewers, and approvers.
- Cyber Risk Institute (CRI) Assessments: Perform CRI tiering and entity assessments to determine compliance status and calculate overall compliance scores based on questionnaire responses.
- User Role Improvements: Employee Center portal users with the employee operator role can respond to policy acknowledgments and request policy exceptions directly, simplifying employee interactions.
- Entity-Level Compliance Scoring: View rolled-up compliance scores at the entity level, incorporating child entities and direct controls for comprehensive visibility.
- Duplicate Citation Management: Eliminate duplicate citations in UCF content downloads by consolidating citations and updating related records to ensure data accuracy.
- Performance Improvements: Compliance Workspace performance is enhanced by removing the Issues widget while maintaining access to issue details.
- Entity-Based Access Control: Enables granular data access control for controls, attestations, and policy exceptions, configurable by administrators for improved security and data segregation.
- Generative AI for Control Objectives: Use AI to identify, recommend, and merge duplicate control objectives, ensuring consolidated and accurate compliance information.
- Zurich-Specific Enhancements:
- Associate multiple citations with controls to prevent duplication and improve compliance reporting accuracy.
- Streamlined control objective rationalization with automated workflows, simplified steps, enhanced UI, and integrated commenting.
- Now Assist for IRM uses AI to identify control objectives impacted by citation updates and suggests changes for approval.
- Granular control objective requirements and automated generation of control requirements, with attestation capabilities at detailed levels.
- Improved policy exception and extension request workflows, including detailed approver views, indicator task optimizations, and enhanced linking requirements.
- Enhanced GRC Approval Configurator supports multi-level, multi-user group approvals for policy exceptions and extensions, increasing approval process flexibility.
- Automatic application of entity-based access rules to new records improves security compliance and reduces manual updates.
Changes
- Expanded roles authorized to initiate CRI tiering and profile assessments, including corporate compliance managers and analysts.
- Domain separation is enforced across all Policy and Compliance Management records, ensuring proper data segmentation.
- Now Assist skills are enabled by default for new installations and unconfigured existing installations starting from Yokohama Patch 11.
- Rationalization process UI redesigned with new options including the ability to restart analyses and support for multiple AI platforms (Azure OpenAI, Amazon Bedrock, Google Gemini).
Deprecations and Removals
- The GRC DevOps Accelerator has been deprecated as of Yokohama and is no longer supported or available for new activation.
- No other feature removals or deprecations are noted between Xanadu and Zurich.
Activation and Installation
Policy and Compliance Management continues to be installed by requesting it from the ServiceNow Store for all release families. Customers should verify installation via the store and review cumulative release notes for app versions.
Additional Requirements and Browser Support
- No new additional requirements were introduced between Xanadu and Zurich.
- Supported browsers include the latest public release and two prior versions of Google Chrome, Firefox (including ESR), Microsoft Edge Chromium, and Safari 12.0 or later.
Practical Benefits for ServiceNow Customers
- Enhanced policy document management and collaborative authoring streamline policy lifecycle management.
- Improved compliance scoring and reporting provide comprehensive entity-level visibility and reduce data duplication risks.
- AI-driven features automate control objective rationalization and citation impact analysis, increasing efficiency and accuracy.
- Granular access controls and robust approval workflows enhance security and governance around compliance processes.
- Performance optimizations and UI improvements contribute to a smoother user experience within the compliance workspace.
Consolidated page of all release notes for Policy and Compliance Management from Xanadu to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Policy and Compliance Management release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.
Important information for upgrading Policy and Compliance Management to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Policy and Compliance Management.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Policy and Compliance Management features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Policy and Compliance Management features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Policy and Compliance Management features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
GRC DevOps Accelerator is now deprecated and no longer supported or available for new activation. For details, see the Deprecation process [KB0867184] article in the Now Support Knowledge Base. |
Zurich |
No updates for this release. |
Activation information
Review information on how to activate Policy and Compliance Management.
| Release | Release notes |
|---|---|
Xanadu |
Install Policy and Compliance Management by requesting it from the ServiceNow Store. Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes. |
Yokohama |
Install Policy and Compliance Management by requesting it from the ServiceNow Store. |
Zurich |
Install Policy and Compliance Management by requesting it from the ServiceNow Store. |
Additional requirements
If any additional requirements were introduced or changed for Policy and Compliance Management we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Policy and Compliance Management we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
GRC: Policy and Compliance Management requires the latest public release and two previous release versions of the following browsers:
|
Yokohama |
GRC: Policy and Compliance Management requires the latest public release and two previous release versions of the following browsers:
|
Zurich |
Policy and Compliance Management supports the latest public release and the two preceding versions of the following web browsers:
|
Accessibility information
Review details on accessibility information for Policy and Compliance Management, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
Localization information
If there are specific localization considerations for Policy and Compliance Management we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Policy and Compliance Management we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Policy and Compliance Management for more information. |
Yokohama |
See Policy and Compliance Management for more information. |
Zurich |
See Privacy Management for more information. |