---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Content pack

# AI Risk and Compliance Content Pack {#ariaid-title1}

* Release version: Australia
* 
* Updated May 19, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of AI Risk and Compliance Content Pack

The ServiceNow AI Risk and Compliance Content Pack offers foundational capabilities to help organizations efficiently manage AI-related risk and regulatory compliance.
It centralizes authoritative AI regulations and frameworks, enabling customers to link these to their internal control objectives and risk statements for ongoing assessments and compliance management.
Show full answer Show less  

## Key Features

* **Regulatory Frameworks Included:**
  * **EU AI Act:** A binding, risk-based regulatory framework with 13 chapters and 113 articles, focusing on AI system risk classification and strict controls for high-risk AI.
  * **NIST AI Risk Management Framework (AI RMF):** A voluntary U.S. framework emphasizing trustworthy AI through governance, measurement, and management lifecycle controls.
  * **California Transparency in Frontier Artificial Intelligence Act (SB 53):** State law requiring transparency, safety protocols, and public disclosures for frontier AI systems.
  * **Colorado Artificial Intelligence Act (SB 205):** State law targeting high-risk AI system developers and deployers with requirements for risk assessments and consumer transparency.
* **Comprehensive Control Objectives:** The content pack includes 300 AI control objectives covering the entire AI lifecycle, with 162 objectives mapped across all four frameworks to form a core set of universal controls. Controls are semantically aligned with regulatory provisions for audit traceability.
* **AI Risk Domains:** Seven distinct AI risk domains are defined, each with specific regulatory obligations and controls. These domains include Security and Cyber Threats, Compliance, Algorithmic Risks, Data Risks, Operational Risks, Ethical and Societal Risks, and AI Business Risks.
* **AI Control Tower:** Consolidates multiple AI regulatory frameworks into a unified source of truth for governance, reducing duplicated efforts and shadow AI through centralized inventory and aligned controls.
* **Regulatory Support:** ServiceNow commits to delivering software updates for major regulatory changes within 12 to 18 months of publication, while customers retain ultimate responsibility for compliance.

## Key Outcomes for ServiceNow Customers

* **Streamlined Compliance:** Customers can accelerate AI compliance efforts by leveraging pre-mapped controls that simultaneously satisfy multiple AI regulations and frameworks.
* **Risk Visibility and Management:** Centralized AI asset and control inventories enhance visibility, enabling effective risk assessments and mitigation across AI systems.
* **Cross-Jurisdictional Readiness:** The content pack supports compliance with major international and U.S. state AI laws, preparing organizations for evolving regulatory landscapes.
* **Reduced Operational Complexity:** By aligning controls across frameworks and automating assessments, organizations can reduce manual efforts and focus on strategic AI risk governance.

## Next Steps

ServiceNow customers can install and activate specific regulatory content modules within the AI Risk and Compliance Content Pack to begin leveraging the comprehensive AI risk and compliance capabilities aligned to the EU AI Act, NIST AI RMF, California SB 53, and Colorado AI Act.  
The ServiceNow
AI Risk and Compliance Content Pack provides foundational content to help organizations manage AI-related risk and compliance.

## Content pack overview {#airc-content-pack__section_lg3_nrz_m3c}

This application provides a centralized location to browse, search, and download AI regulations and frameworks to link to your internal control objectives or risk
statements and run assessments against them.

Currently, the application offers the following:

EU AI Act
:   The EU AI Act is a regulatory framework that sets common rules for the use of artificial intelligence in the European Union. It follows a risk-based approach, classifying AI systems into unacceptable, high, limited,
    and minimal risk categories. Higher-risk AI systems are subject to stricter requirements such as risk management, transparency, human oversight, and ongoing monitoring. Authority documents and citations for the EU AI
    Act are available in the content pack. Pre-shipped control objective and risk statement mappings are included. for the EU AI Act. The EU AI Act content is structured into 13 chapters and contains 113 articles covering risk-based regulatory requirements for AI systems.

NIST AI RMF

:   The NIST AI Risk Management Framework (AI RMF) provides voluntary guidance for managing risks associated with AI systems throughout their lifecycle. It focuses on building trustworthy AI by addressing risks related to governance, fairness, reliability, security, privacy, and transparency. The framework is organized around four core functions: Govern, Map, Measure, and Manage. Preventive controls dominate in Govern, Map, and
    Manage, as these functions focus on policies, risk identification, and mitigation planning. Detective controls are concentrated in Measure and the monitoring aspects of Manage, focusing on ongoing assessments,
    audit trails, and reporting.

    AI-specific risk libraries address both common and AI-specific risks, such as algorithmic bias, model drift, data integrity, and cybersecurity threats.

Transparency in Frontier Artificial Intelligence Act (SB 53)
:   California Senate Bill 53 establishes transparency and safety requirements for developers of frontier AI systems. It requires developers to implement safety and security protocols and publicly disclose information
    about their AI systems and safety practices. Authority documents, agency mappings, and citations for SB 53 are available in the content pack.

Colorado Artificial Intelligence Act (SB 205)
:   The Colorado Artificial Intelligence Act establishes requirements for developers and deployers of high-risk AI systems, including risk assessments, impact evaluations, and disclosure obligations to consumers affected
    by AI-driven decisions. Authority documents, agency mappings, and citations for the Colorado AI Act are available in the content pack.
{#airc-content-pack__authority_documents__entry__5}

| Category | EU AI Act | NIST AI RMF | California TFAIA (SB 53) | Colorado AI Act |
|-|-|-|-|-|
| Structure | The EU AI Act contains 13 chapters, 113 articles, 13 annexes. | 4 functions, 19 categories, 72 sub-categories. | 4 core mandates plus whistleblower and penalty provisions. | Part 17 C.R.S., 7 sections (§§ 1701-1707). |
| Type | Binding law (extraterritorial). | Voluntary framework (US). | Binding state law. | Binding state law (in transition). |
| Applies to | Providers and deployers of AI in the EU, tiered by risk. | Any organization; all AI systems and use cases. | Developers of frontier (large compute) AI models. | Developers and deployers of high-risk AI in consequential decisions. |
| Status and key dates | In force; high-risk and transparency duties apply 2 Aug 2026. | AI RMF 1.0 (2023) plus Generative AI Profile (2024). | Effective 1 Jan 2026. | SB 24-205 replaced by SB 26-189; effective 1 Jan 2027 (AG rulemaking pending). |
| Core requirements | Risk management, data governance, documentation, human oversight, conformity assessment. | Govern, Map, Measure, Manage lifecycle controls. | Public safety framework, transparency reports, critical-incident reporting, whistleblower protection. | Consumer notice and appeal rights, transparency, recordkeeping, vendor oversight. |
[Table 1. Framework structure and enforcement comparison]

{#airc-content-pack__authority_documents}

## Control objective coverage across frameworks

The AI Control Objective Universe defines 300 control objectives spanning every AI lifecycle stage. Of these, 162 objectives (54%) map to all four frameworks and form the core set of universal controls.
{#airc-content-pack__entry__32}

| Framework | Control objectives linked |
|-|-|
| NIST AI RMF | 258 |
| EU AI Act | 249 |
| Colorado AI Act | 224 |
| California AI Act | 176 |
[ ]

Each control objective is rationalized against regulation using the following approach.

1. Controls map to provisions whose intent and requirement align, not by keyword match (semantic alignment).
2. One control can satisfy multiple articles, and one article can support multiple controls (many-to-many model).
3. Original article and section IDs, for example EU Art. 9 or NIST MAP 2.3, are preserved for audit traceability (framework-native citations).
4. The coverage count signals which controls are universal, since four-framework controls form the compliance backbone (cross-jurisdictional validation).

## AI risk domains

AI risk is organized into seven domains. Each domain is a distinct category of AI-specific risk with its own drivers, regulatory obligations, and control requirements. The seven domains collectively define 28 level 2 risk
statements.
{#airc-content-pack__entry__42}

| Domain | Description |
|-|-|
| Security and Cyber | Threats that exploit AI as an attack surface, including adversarial inputs, training data poisoning, model theft, and denial-of-service attacks. Unlike traditional cybersecurity, AI attacks can remain undetected while corrupting outputs at scale. |
| Compliance | Risk of violating laws governing AI use, including data protection regulations (GDPR, CCPA), sector-specific rules (HIPAA), and emerging AI legislation (EU AI Act). The regulatory landscape evolves rapidly, so compliance today might not hold in 18 months. |
| Algorithmic | Risks inherent to algorithm design and training, including structural bias, poor generalization (overfitting), accuracy degradation over time (drift), and deep-learning opacity that makes decisions difficult to audit or explain. |
| Data | Risks tied to the data that trains and feeds AI systems, including corrupted or incomplete training inputs, mishandled personal data in pipelines, non-representative datasets that embed bias, and cyberattack exposure through large data stores. |
| Operational | Day-to-day risks of running AI in production, including model performance degrading without retraining, infrastructure that cannot scale, legacy system incompatibility, service outages, and shortages of qualified AI engineers. |
| Ethical and Societal | Broader human impact, including amplification of racial, gender, and socioeconomic bias, job displacement, erosion of accountability in high-stakes decisions, privacy intrusions, and unintended social harms. |
| AI Business Risks | Strategic and commercial consequences, including reputational damage from harmful outputs, IP theft if model weights are stolen, over-reliance on third-party AI vendors, competitive disruption, and increasing compliance costs. |
[ ]

## Key Value Benefits

AI Control Tower consolidates the EU AI Act, NIST AI RMF, California TFAIA, and Colorado AI Act into a single source of truth for AI governance.
{#airc-content-pack__entry__58}

| Capability | Description |
|-|-|
| Single source of truth | One inventory of AI assets, models, and agents across the enterprise reduces shadow AI. |
| Common controls alignment | A control mapped once satisfies EU AI Act, NIST AI RMF, California TFAIA, and Colorado AI Act requirements simultaneously, without duplicate work. |
| Speed to compliance | A pre-mapped foundation activates on day one instead of building a compliance framework from scratch. |
[ ]

## Regulatory support statement {#airc-content-pack__regulatory_support_statement}

Note:  
The ServiceNow Risk products help customers address regulatory requirements under various jurisdictions. However, we do not guarantee compliance and customers are ultimately responsible for their own compliance with
applicable regulations.

ServiceNow aims to provide software updates for new or updated major regulations and requirements within twelve to eighteen months of the regulation's publication. For regulations for which ServiceNow provides a level of
support in the base system, ServiceNow aims to provide software updates for minor regulatory changes within 12 months and for major regulatory changes within up to 18 months depending on scope and impact. We
differentiate between typical regulatory content updates, which do not require software updates or enhancements, and regulatory updates, which do require software updates or enhancements. Content updates are generally
delivered on a shorter cadence than if software update or enhancement is required for the regulatory update or change.
**Related tasks**   

* [Install AI Risk and Compliance content](https://servicenow-prod.fluidtopics.net/lNprHf9R6iwmDQhaRzY3Jw "Install the AI Risk and Compliance content application (sn_grc_ai_gov_cont) to add predefined governance content such as frameworks, authority documents, control objectives, and risk statements.")
* [Activate or update NIST Risk Management Framework](https://servicenow-prod.fluidtopics.net/hM4AT8Ocq538ogD7ufHj6g "Activate or update NIST Risk Management Framework to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.")
* [Activate or update EU Artificial Intelligence Act](https://servicenow-prod.fluidtopics.net/zK3X6oTPuQBnOhjEkeZqWw "Activate or update the EU Artificial Intelligence Act framework and select the citations relevant to your organization. The citations are installed into your instance so they can be mapped to control objectives and used in assessments.")
* [Activate or update the Colorado Artificial Intelligence Act](https://servicenow-prod.fluidtopics.net/L9vdS~Ez6jAsC_5t1ug3xQ "Activate or update the Colorado Artificial Intelligence Act (Senate Bill 24-205) to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.")
* [Activate or update the Transparency in Frontier Artificial Intelligence Act (SB 53)](https://servicenow-prod.fluidtopics.net/VTOF_aSvyj_60dRyn5Jphw "Activate or update the Transparency in Frontier Artificial Intelligence Act (SB 53) to install its citations, control objectives, and risk statements on your instance so they can be used in assessments and mapped to your AI assets.")

