Manage control indicators using the Compliance Workspace

  • Release version: Zurich
  • Updated July 31, 2025
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Manage control indicators using the Compliance Workspace

    The Compliance Workspace in ServiceNow's Zurich release offers compliance administrators and managers a comprehensive executive view into compliance requirements, overall compliance status, and detailed compliance breakdowns. It supports continuous monitoring by enabling the creation and management of key risk and control indicators to effectively track controls and risks within the organization.

    Show full answer Show less

    Key Features

    • Indicators: These collect data to monitor individual controls or risks and gather audit evidence. Indicator results help create issues for controls, update risk scores, and support audit and control testing activities.
    • Indicator Templates: Allow users to efficiently create multiple indicators for similar controls or risks, streamlining the monitoring process.
    • Entity Based Access: Provides granular data access management by granting users or groups access to entity-related records based on configured roles and entity user fields, ensuring secure and relevant data visibility.
    • Compliance Overview Reports: A set of interactive visualizations available to users with the appropriate roles, including:
      • Compliance Requirements Donut Chart: Focus on specific compliance areas.
      • Overall Compliance Donut Chart: Displays overall compliance status across all control requirements.
      • Entity Selector: Compare compliance across selected entities.
      • Control State Filter: Filter reports based on control states.
      • Compliance by Authority Document Bar Chart: Compare compliance levels by entity and authority document.
      • Compliance Breakdown Multi-level Pivot: Analyze compliance by authority documents and policies.
      • Non-Compliant Entities Column Chart: Shows counts of non-compliant control requirements grouped by entity.
    • Authority Documents: Define policies, risks, controls, audits, and processes to ensure adherence to regulations. These documents and their related conditions are managed and visualized within the GRC Workbench.
    • Citations: Break down authority documents into manageable provisions or themes. They can be created manually or imported from UCF authority documents, allowing detailed compliance tracking and management.
    • Content Reference Tags: Can be applied to authority documents and citations to facilitate filtering and easier identification of associated content packs, integrations, and use case accelerators.

    Practical Benefits for ServiceNow Customers

    By leveraging the Compliance Workspace and its control indicator management capabilities, customers can:

    • Continuously monitor and assess compliance posture with real-time data collection and visualization.
    • Streamline compliance workflows through automated and manual data collection tasks.
    • Gain granular control over data access aligned with organizational entities and roles.
    • Improve audit readiness by maintaining supporting evidence and up-to-date compliance status.
    • Quickly identify compliance gaps and non-compliant entities to prioritize remediation efforts.

    Continuous monitoring involves activities related to identifying and creating key risk and controls indicators. The Compliance Overview is available to compliance administrators and compliance managers, providing an executive view into compliance requirements, overall compliance, and compliance breakdowns.

    Supporting information can be collected for indicators through automatic data collection or manual tasks. Indicator results are then used to create issues for controls, update risk scores, and provide supporting information for audit activities and control testing.
    Indicators
    Indicators collect data to monitor controls and risks, and collect audit evidence. Indicators monitor a single control or risk.
    Indicator templates
    Indicator templates allow the creation of multiple indicators for similar controls or risks.
    Note:
    The Entity Based Access provides a framework for more granular approach to management of data access to objects associated with an entity. Administrators can grant access to an entity's related records by adding users or user groups, or by using entity user fields for entity-based access configuration. For more information, see Entity Based Access. When a user is qualified based on these configurations and has the minimum required roles, they will have access to the following tables:
    • Indicator
    • Indicator task
    • Indicator result

    Compliance Overview

    Table 1. Compliance Overview reports in the base system
    Name Visual Description
    Compliance Requirements Donut chart Select a wedge to focus on a specific compliance area.
    Overall Compliance Donut chart Displays the overall compliance of all the control requirements in the system. Selecting a specific wedge in the previous widget brings that area into focus.
    Entity Drop down list Select one or more entities to view and compare their compliance across multiple items.
    Control State Check list Select or clear check boxes to view filter reports by control state.
    Compliance by Authority Document Bar Chart Compare level of compliance depending on the selected entity and/or authority document.
    Compliance breakdown Multi-level Pivot View a breakdown of control compliance by related authority documents and policies.
    Non Compliant Entities Column Chart Count of non-compliant control requirements grouped by entity.

    Authority Documents

    Authority documents define policies, risks, controls, audits, and other processes to ensure adherence to the authoritative content.

    Each authority document is defined in a record and the related lists on that record contain the individual conditions of the authority document.

    The relationships of these authority document related list items are visible in the GRC Workbench in the Policy and Compliance Management application.
    Note:
    You can add content reference tags to authority documents. Content reference tags allow you to filter records in order to more easily identify the content packs, integrations, and use case accelerators associated with the authority documents.

    Citations

    Citations contain the provisions of the authority document, which can be interrelated. Citations break down an authority document into manageable themes.

    You can create citations or import them from UCF authority documents and then create any necessary relationships between the citations.
    Note:
    You can add content reference tags to citations. Content reference tags allow you to filter records in order to more easily identify the content packs, integrations, and use case accelerators associated with the citations.