---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create a compliance evaluation configuration

# Create a compliance evaluation configuration {#ariaid-title1}

* Release version: Australia
* 
* Updated July 25, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Create a compliance evaluation configuration that defines which AI systems, control objectives, metrics, and schedule a compliance evaluation applies to.

## Before you begin

Role required: sn_grc_ai_gov.ai_risk_and_compliance_manager

## About this task

A compliance evaluation configuration monitors AI systems for compliance and updates evaluation scores on an ongoing basis. Use evaluation frameworks from ServiceNow and Traceloop to produce trace, session, or span records
for your AI
systems.
These frameworks help you derive a comprehensive evaluation of your AI systems.

## Procedure

1. Navigate to AllAI Risk and ComplianceAI Risk and Compliance Workspace.
2. Select the list icon ![]().
3. From the Controls monitoring module, select the Compliance evaluation configurations and select New.
4. Define the evaluation details and data scope details.  
   {#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__2}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__3}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__4}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__6}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__8}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__9}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__11}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__13}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__15}{#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc__entry__17}

   | Field | Description |
   | Basic details ||
   | Evaluation name | A unique, descriptive name for this evaluation, using specific terms that identify the AI system, assessment scope, or version being evaluated (for example, *Monitoring AI Toxicity*). |
   | Description | The purpose and scope of this evaluation, including what is being assessed, why it matters, and any key constraints or context users should know. |
   | Data scope details ||
   | Authority documents | The authority documents that govern this evaluation. The following options are provided: * NIST AI Risk Management Framework * EU Artificial Intelligence Act * AI Content Safety \& Toxicity Standard {#airc-compliance-evaluation-configuration__ul_q4b_cwk_bkc} |
   | Policies | The policies that this evaluation aligns with or enforces. The following options are provided: * Artificial Intelligence Software Development Lifecycle Policy * Enterprise Artificial Intelligence Governance Policy * Internal use of AI Systems {#airc-compliance-evaluation-configuration__ul_r4b_cwk_bkc} |
   | AI system type | The category of AI system being evaluated. The following options are provided: * Agentic AI * Generative AI {#airc-compliance-evaluation-configuration__ul_s4b_cwk_bkc} |
   | Provider | The provider. The following options are provided: * ServiceNow * Others {#airc-compliance-evaluation-configuration__ul_t4b_cwk_bkc} |
   | Metric category | The metric category used in this evaluation: * Safety * Security * Quality {#airc-compliance-evaluation-configuration__ul_u4b_cwk_bkc} |
   |-|-|
   [Table 1. Evaluation details and data scope fields]

   {#airc-compliance-evaluation-configuration__table_p4b_cwk_bkc}
5. Select Next.
6. Select Add control objectives to add control objectives to the scope.
7. Map control objectives from the filtered list by selecting the check box of each desired control objective.
8. Select Add to complete the control objective mapping, and then select Next.  
9. Define the evaluation criteria and frequency in the Evaluation criteria and frequency section.  
   {#airc-compliance-evaluation-configuration__table_kx1_2dj_bkc__entry__2}{#airc-compliance-evaluation-configuration__table_kx1_2dj_bkc__entry__3}{#airc-compliance-evaluation-configuration__table_kx1_2dj_bkc__entry__5}

   | Field | Description |
   | Frequency | The frequency at which evaluations are conducted. The following options are provided: * Daily * Weekly * Monthly {#airc-compliance-evaluation-configuration__ul_lx1_2dj_bkc} For example, for AI toxicity, a monthly evaluation monitors control drift. |
   | Success condition result | The result, Passed or Failed, assigned to an AI system when the evaluation criteria is met. |
   |-|-|
   [Table 2. Evaluation criteria and frequency fields]

   {#airc-compliance-evaluation-configuration__table_kx1_2dj_bkc}
10. In the All Evaluations section, define the conditions and the metrics under which the configuration is applicable.  
    If multiple conditions are specified, they are evaluated in the order listed to determine applicability.  
    {#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc__entry__2}{#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc__entry__3}{#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc__entry__5}{#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc__entry__7}{#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc__entry__8}

    | Field | Description |
    | Name | A name for the evaluation. |
    | Conditions | The field, operator, and value that filter which records this configuration applies to, for example, \[Risk classification\] \[is\] \[High\]. Select "and" or "or" to combine multiple conditions, and select New condition set to add a condition set that is evaluated independently of other condition sets. |
    | Metric thresholds ||
    | Metric | The metric, operator, and threshold value that determine when a control is evaluated as compliant or non-compliant, for example, \[Toxicity\] \[is\] \[True\]. Select Add metric to define additional metric thresholds for this configuration. |
    |-|-|
    [Table 3. Conditions and metric thresholds fields]

    {#airc-compliance-evaluation-configuration__table_tt5_cdj_bkc}
11. Select Submit.
{#airc-compliance-evaluation-configuration__steps_zrr_5tl_1kc}

## What to do next

The compliance evaluation configuration is ready to be mapped to one or more AI systems. For information on mapping an evaluation configuration to AI systems, see [Use a compliance evaluation on an AI system record](https://servicenow-prod.fluidtopics.net/rmCX9_V8TMpLa~BIWomc1g "Map a control objective to an AI system, run its compliance evaluation, and review evaluation results, supporting data, and automatically created issues.").

*[\>]: and then


