---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Map regulations to the entities

# Map regulations to the entities {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Map single or multiple regulations with the entity linked to an incident or security incident.

## Before you begin

Role required: sn_oper_res.admin, sn_dri_inc_rptg.digital_resilience_incident_admin

## About this task

The Digital Resilience Incident Case module lists all DRI Cases associated with an incident or security incident. A new Regulation Mappings related list is now available in each Digital Resilience Incident Case record. It
displays the relationships between entities related to the cases and their corresponding regulations.

Each regulation mapped to an entity drives the action task workflow for that case. When a regulation is added or updated for a case, the 'Action task automation for regulation addition' and 'Action
task automation on regulation updates' flows run. These flows read the action task configuration of the matching Regulatory Body Management Agency Profile \[sn_reg_body_mgmt_agency_profile\] record. They automatically create
the required action tasks (Regulatory reporting assessment of IT incidents, DRI Initial/Intermediate/Final reports). The assignment groups, due dates, repeat intervals, and termination conditions defined in those templates
are displayed. For details on the action task templates, see [Set up action task templates in Regulatory agency profile](https://servicenow-prod.fluidtopics.net/G9qh_1zaEcc2s46fVSjiFw "Set up action task templates in the Regulatory Body Management Agency Profile [sn_reg_body_mgmt_agency_profile.list] table. Verify that the action task configurations (with Smart Assessment Smart Assessment template configurations) for the selected regulation are correctly set up.").

## Procedure

1. Navigate to AllDigital Resilience Incident ReportingDigital Resilience Incident Case Type and open the desired case record.  
   The Digital Resilience Incident Case record is displayed.  
   It contains the following tabs for the record:
   * State Model: The state model and action task state model specify the workflow states and transition conditions for a record type and an action task, respectively. A record type and an action task follow the workflow states configured in their respective state models.
   * Assessment Configuration: Assessment templates are pre-defined formats to request responses from assessors or reviewers that help to evaluate the record.
   * Template Configuration: Document templates are set up for generating word reports.
   * Inbound Email Configuration: Group email configuration is set up to inform the group members about the case record.
   {#configure-case-types-map-regu__ul_ust_xf1_khc}  
   You can configure the following related lists as outlined in the next steps.
   * Subtypes
   * View Rules
   * Assignment Rules
   * Jurisdictions
   * Record type area configs
   * Regulation Mappings
   {#configure-case-types-map-regu__ul_j5r_jg1_khc}
2. To map a regulation to an entity associated with the case, select New in the Regulation Mappings related list.  
   The Regulation Mappings New record is displayed.
   1. On the form, fill in the fields.  
      {#configure-case-types-map-regu__table_svj_5m4_3hc__entry__2}

      | Field | Description |
      |-|-|
      | Entity | Name of the entity, for example, Acer. |
      | Regulation | Regulation that is mapped to the entity associated with the case, for example, Digital Operational Resilience Act. |
      | Record type | Digital Resilience Incident Case record. This field is auto-filled. |
      [Table 1. Regulation Mappings record form]

      {#configure-case-types-map-regu__table_svj_5m4_3hc}  
      The example illustrates mapping the Acer entity to the 'Digital Operational Resilience Act' (a single regulation).

      After this mapping is saved, the regulation appears on the case and triggers the corresponding action tasks based on the regulation's action task configuration. If the same case is
      mapped to multiple regulations, a separate set of action tasks (and therefore separate Initial/Intermediate/Final reports) is generated per regulation.

      Entities can also be mapped to multiple regulations.
   {#configure-case-types-map-regu__substeps_clf_jm4_3hc}
3. To add a subtype for the case, navigate to the Subtypes related list and select New.
   1. Add the parameters such as Label, Name, Parent, Category, and Description.  
      The following example shows a Subtypes record.
   2. To mark the record as active, set the Active option.
   3. Select Submit.
   {#configure-case-types-map-regu__substeps_xk4_thl_mhc}
4. To set up rules, navigate to the View Rules related list and complete the substeps.
   1. Add Name, Table, View, Workspace type, and Execution Order number.  
      The following example shows a Rules record.
   2. Set the Active flag.
   3. Set up the roles and conditions in the Conditions tab.
   4. Select Hide details \& UI actions, Hide section navigation, and Disable section collapsing in the Form Settings tab.
   5. Set up the Default tab order and focus in Form Tabs.
   6. Select Submit.
   {#configure-case-types-map-regu__substeps_qpb_244_3hc}
5. To assign tasks to specific users and groups automatically, navigate to the Assignment Rules related list and set up the assignment rules.  
   The following example shows an Assignment rules record.
   1. Add the name of the rule and set the Active flag.  
      The name of the application is auto-filled as Digital Resilience Incident Reporting.
   2. Select a table in Applies to and specify the conditions that must be met before the task is assigned to the user or group.  
      The rule is applied only if the task isn't already assigned to another user or group.
   3. To assign a task to the users or groups, configure the users or groups in the Assign to tab.
   4. To customize the assignment rule further, enter a script in the script tab.  
      Scripts provide access to the pool of current variables.
   5. Select Submit.
   {#configure-case-types-map-regu__substeps_kxw_dp4_3hc}
6. To set up the location details and jurisdiction of the case, navigate to the Jurisdictions related list and select New.  
   The following example shows a Jurisdictions location record.
   1. Add Name, City, Zip code, State, country, Phone, Latitude, Longitude details.
   2. Select Submit.
   3. To edit an existing Jurisdictions record, select Edit.
   {#configure-case-types-map-regu__substeps_s4v_jq4_3hc}
7. To define the area type for the case and the table associated with it, navigate to the Record type area configs related list and complete the substeps.  
   The following example shows a Record type area configuration record.
   1. Set its order and Active flag.
   2. Select Submit.

   {#configure-case-types-map-regu__substeps_ky5_33l_mhc}  
   The area type can be Impacted area, Related area, Cause area. The associated table can be Entity \[sn_grc_profile\] or Citation \[sn_compliance_citation\] table.
8. Select Save.  
   The regulation mappings, subtypes, rules, and other details for the entity are saved in the case record.
**Related tasks**   

* [Complete action tasks and report incidents](https://servicenow-prod.fluidtopics.net/~kfSNgyC3LWoVrka52291w "Report incidents or security incidents associated with multiple regulations for various legal entities. The automated workflow generates regulatory reporting assessments of IT incidents, and Digital resilience incident (DRI) Initial, Intermediate, and Final reports, all within regulatory timelines. Complete the action tasks and generate reports in Microsoft Word format, as required by regulatory authorities for analysis.")

*[\>]: and then


