---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Manually create issues

# Manually create GRC issues {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

As a GRC user, you can manually create issues to document
policy, risk, or audit observations, or to accept any GRC problems. You can also identify
the source of the issue to help analyze and classify the issues.

## Before you begin

Role required: (per product)

* In Policy and Compliance Management: sn_grc.business_user, sn_grc.business_user_lite
* In Risk Management: sn_grc.business_user
* In Audit Management: sn_grc.business_usersn_grc.business_user_lite

{#t_CreateAnIssue__ul_tgz_zxx_rw}  
Note:  
Starting with Version 12.0.1 of the products mentioned above, the minimum role for the Assigned to user on the Issues form is GRC Business User \[sn_grc.business_user\]. The minimum role for the Issue manager is GRC User \[sn_grc._user\].

For more information on the access control limitations
to issues, see [GRC business user role to control access and track usage of compliance
tables](https://www.servicenow.com/docs/HA7ZgZQo0ip3BuoJQXoycg#policy-compliance-snc-internal-role-change__acls-issue-busin-user).

## Procedure

1. Navigate to one of the following locations:  
   * AllPolicy and ComplianceIssuesCreate New.
   * RiskIssuesCreate New.
   * AuditIssuesCreate New.

   {#t_CreateAnIssue__ul_e3m_bs3_4w}  
   Note:  
   Starting with Version 12.0.1 of the products mentioned above, the minimum role for the Assigned to user on the Issues form is GRC Business User \[sn_grc.business_user\]. The minimum role for the Issue manager is GRC User \[sn_grc._user\].
2. On the [Issue form](https://www.servicenow.com/docs/3IWshz61l6yQgD3rcuShOw "Use the Issue form to create a new issue."), fill in the fields.  
   The due date under the Dates tab is automatically calculated based on the issue rating. You can manually override the calculated due date. The Task SLAs related list creates and displays SLAs based
   on the Due date.
3. Save the issue record.  
   The tabs at the bottom of the screen enable you to perform various tasks for remediating the issue. You can add policy exceptions and create remediation tasks. Additionally, you can view other issues, indicator results, and task SLAs related to the issue.  
   Note:  
   Starting with Version 12.0.1, the Task SLA tab creates and displays SLAs based on the Due date. Notifications are sent to the issue owner and issue manager when the issue Due date reaches 50%, then 75%, then when it breaches. If the Assigned to and Due date fields are not empty and the issue is not in the New state, an SLA is created for the issue.

   If the due date for the SLA changes, a new SLA is created. The SLA is completed when the issue transitions to Closed Complete
   or Closed Incomplete. Also, the SLA is cancelled if the Due date or Assigned to fields are empty, or the state is New.

   Also starting with Version 12.0.1, remediation tasks can be created with the Assigned to user and issue manager user roles, as well as any user with the [GRC Business User role](https://www.servicenow.com/docs/w1qBQRIdXDkzFGj4Ox~F1g "Before you can successfully implement or use the Policy and Compliance Management application, you must assign roles to your users.").
* **[Group similar issues under a new parent issue](https://www.servicenow.com/docs/3Wiv2oafyqUwDP6BtSvLCA)**   
  When you are creating an issue, you have the option of grouping the issue with other similar issues.
* **[Group similar issues under an existing parent issue](https://www.servicenow.com/docs/fGxjJa~aATWVZPFBp3K1gg)**   
  When you are creating an issue, you have the option of grouping the issue with other similar issues as part of an existing parent issue group.
* **[User hierarchy access control](https://www.servicenow.com/docs/rpvVSr_MNPiYMIOe8NP1sA)**   
  If a user is assigned to an issue or a remediation task, then the manager of the user and the manager above in the hierarchy also get access to the issue or remediation task record.
* **[Report issues from the Service Portal](https://www.servicenow.com/docs/QlQZQxsU8I2EBN1qXBAfuQ)**   
  When you identify any deficiencies in the controls or improvements that can be made in the organization policies, report an issue from the ServiceNow, Inc. Service Portal.
* **[Issue assignment using the Governance, Risk, and Compliance Predictive Intelligence plugin](https://www.servicenow.com/docs/pQooy6lUPJuCKLqZ5JGVEg)**   
  Train a similarity solution model that uses machine learning so that the system can automatically suggest how to route issues to the correct assignee. Automatic routing suggestion reduces the time spent on deciding who should own the issue.

*[\>]: and then


