---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Exploring Audit Management

# Exploring Audit Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Audit Management automates the work streams of internal audit teams, optimizing resources and productivity, and eliminating recurring audit findings. Audit Management uses compliance and risk data to scope, plan, and prioritize audit engagements. The on-going review of policies and procedures, risks, and control breakdowns provide an opportunity for fixing issues before they become audit failures.

## Audit Management users {#audit-management__section_gwp_1zv_jz}

Auditors (an independent body, typically reporting to the board of directors).

## Key activities for Audit Management {#audit-management__section_j1q_bpt_3z}

Auditors are responsible for the following:

* Review policies and procedures
* Review risks
* Review control design
* Review control test design
* Review control test results
* Test controls
* Issue observations
{#audit-management__ul_xbq_shb_vy}

## Audit Management and the ServiceNow
platform

Figure 1. Audit Management and the ServiceNow AI Platform  
Note:  
For more information on the GRC application nomenclature and industry terminology, see [Governance, Risk, and Compliance application nomenclature updates and industry terminology](https://servicenow-prod.fluidtopics.net/48zTISAsMTjvYkTcnMwHug "The following terms are used within GRC applications and/or within the GRC industry.").
* **[Audit entry](https://servicenow-prod.fluidtopics.net/F5tnwOTV2T90quNZnItFeA)**   
  The audit entry field marks a record as third-line, restricting its visibility to users who hold the third-line manager role. Third-line records are excluded from the views and calculations that second-line users rely on.

