---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Explore Digital resilience incident reporting {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Digital resilience incident reporting

The Digital resilience incident reporting module, part of the Operational Resilience Workspace, enables ServiceNow customers to log and report incident data to regulatory authorities efficiently.
It automates the creation and tracking of reporting cases from major incidents detected in Incident Management or Security Incident Response applications, helping organizations comply with regulatory requirements on incident reporting timelines.
Show full answer Show less  

## Key Features

* **Automatic Case Creation:** Reporting cases are automatically generated for critical incidents based on classification criteria such as incident severity, duration, and impact on critical business services.
* **Structured Assessment Process:** Initiates regulatory reporting assessments to classify incidents as reportable, potentially reportable, or not reportable.
* **Regulatory Reporting Workflow:** Supports the generation of initial reports (within 24 hours), intermediate reports (every three days until resolution), and final reports (within 30 days of incident closure) to meet regulatory timelines.
* **Integration:** Seamlessly integrates with Incident Management and Security Incident Response applications to import critical incident data automatically.
* **Assessment Workspace Automation:** Uses smart assessments to auto-populate responses, streamlining the reporting process for Digital Resilience Incident Reporting (DIR) users.
* **Incident Classification:** Classifies incidents based on business service criticality, incident duration, and stage to determine reporting requirements.
* **Export Capability:** Users can export incident reports in formats specified by regulatory authorities for further analysis.

## Incident Reporting Workflow and Case Management

* **Case Task States:** DIR case tasks progress through stages: Draft (creation and assignment), In Progress (assessment and classification), Pending Approval, and Approved (completion and closure).
* **Regulatory Reporting Status:** The status field indicates if an incident is reportable, potentially reportable, or not reportable, and is visible on the case form's details panel.
* **Repeated Assessments:** Potentially reportable cases may trigger additional assessments if incident details change.
* **Automated Reporting Tasks:** Upon classification as reportable, action tasks for initial, intermediate, and final reports are generated with defined due dates to ensure timely submission.
* **Final Report Generation:** Automatically triggered upon incident closure, with intermediate reports ceasing as configured.

## Data Access and User Experience

* The module displays comprehensive views such as all incident reporting cases, user-specific cases, unassigned cases, and assigned tasks.
* The "My Tasks" page consolidates pending tasks, user items, and watchlist entries, improving user productivity and task management.

## Additional Information

Details on roles, scripts, and tables used within the Digital resilience incident reporting module are available in the Digital resilience incident reporting reference, helping administrators manage permissions and customize workflows.  
The Digital resilience incident reporting module in the Operational Resilience Workspace is used to log and report incidents data to the regulators.

## Key features of Digital resilience incident reporting {#dri-module-in-ws__section_a53_t3k_12c}

The Digital resilience incident reporting application module in the Operational Resilience Workspace offers the following key features.

* Creates reporting cases automatically from major incidents reported in the Incident Management and Security Incident Response applications.
* Initiates a structured assessment process, including Regulatory reporting assessment to determine if the incident is reportable.
* Tracks the status of reports and assessments, ensuring timely submission and compliance with regulatory timelines.
* Uses automated reporting workflow to generate reports within regulatory reporting timelines:
  * Regulatory reporting assessment of IT incidents
  * Initial Report (within 24 hours)
  * Intermediate Report (every three days until resolved)
  * Final Report
  {#dri-module-in-ws__dri-module-in-ws_ul_mh2_kpr_12c}
* Allows users to export incident reports for further analysis in the format specified by regulatory authorities.
{#dri-module-in-ws__ul_lss_1pr_12c}

## Integration with Incident Management or Security Incident Response {#dri-module-in-ws__section_bd5_b2m_ydc}

The Digital resilience incident reporting module is available in the Operational Resilience Workspace by default. If you are using the Incident Management or Security Incident Response applications, you can report critical incidents from these Workspaces into the Digital resilience incident reporting module.

## Auto-populating the responses in the Assessment Workspace {#dri-module-in-ws__section_tq4_1fm_ydc}

For the reported DIR case task, an assessment action task is created and assigned to a DIR user. Smart assessment in the Assessment Workspace is used for auto-populating the responses to the assessment. The Assessment Workspace is available to the Digital resilience incident reporting users by default.

## Incident classification {#dri-module-in-ws__section_gdn_x3m_ydc}

When an incident is detected, it is determined whether critical business services are affected. The following approach is followed to classify the incident.

## Digital resilience incident reporting workflow {#dri-module-in-ws__section_ayx_1qk_sdc}

To classify major incidents, the Digital resilience incident reporting (sn_dri_inc_rptg) automatically initiates reporting cases.  
Reporting cases are triggered and reported in Digital resilience incident reporting by using one of the following conditions:

1. Incident Management
   * The incident is classified as critical in the Service Operations Workspace.
   * Incident duration: The incident has been open for more than 24 hours and it is still in the Work in progress or Analysis stage.
   * The incident involves a critical business service where the business criticality value is 1.
   {#dri-module-in-ws__ul_f15_fgl_ydc}
2. Security Incident Response:
   * The incident is classified as critical in the SIR workspace.
   * Incident duration: The incident has been open for more than 24 hours and it is still in the Work in progress or Analysis stage.
   {#dri-module-in-ws__ul_frc_yfl_ydc}
3. Manual: The incident has been reported manually in the Digital resilience incident reporting module.
{#dri-module-in-ws__ol_y4y_5gk_ydc}

## States of the case task {#dri-module-in-ws__section_inz_tgl_ydc}

1. Draft: Any DIR user can create a DIR case task and assign it to the DIR managers group. A notification is sent to the managers group to assign it to one of the managers. DIR case task can also be created automatically from the IM incidents or SIR incidents if they meet the criteria defined in the creation flow.
2. In progress:
   1. An action task is created for the DIR case task and assigned to a DIR user. The Regulatory reporting status field (sn_grc_inc_rptg_case_task.breach, shown on the Details panel of the case form) is updated based on the response.

   2. The DIR case task is classified as Potentially reportable, Not reportable, or Reportable based on the assessment response. This classification is stored in the Regulatory reporting status field (sn_grc_inc_rptg_case_task.breach) on the Digital Resilience Incident Reporting case form and on each Regulation Mapping record in the Regulation Mappings related list. If a case is initially marked as Potentially reportable, further updates on the source incident can lead to additional assessments.  
      Note:  
      The "Regulatory reporting status" field is now shown on the Details panel of the case form (or in the Regulation Mappings related list) and not in a separate "Reporting status" section in the Workspace view of the case.
   3. If the DIR case task is identified as Reportable, a new action task is created for the initial report assessment with a due date of 24 hrs. It is assigned to any DIR user by the DIR manager handling the case.
   4. After the initial report action task is completed and submitted, a new action task for the intermediate report is created with a due date as three days.
   5. Intermediate report assessments are generated every three days until the source incident is closed (Incident Management or Security Incident Response).  
      Note:  
      It is not mandatory to close every intermediate report assessment that was generated during the lifecycle of the incident. The Final report action task is created automatically when the source incident is closed, independent of the open intermediate assessments. Any intermediate assessments that remain open after the source incident is closed are no longer required - the periodic generation stops as soon as the termination conditions configured on the DRI Intermediate report template are met (typically when the source incident state is 'Closed' or the DRI case state is 'Closed'/'Canceled').
   6. A final report action task is created with a due date of 30 days from the closing date of the source incident.
   {#dri-module-in-ws__ol_l51_bhl_ydc}
3. Pending approval and Approved: Once the reports are completed, the DIR case task is approved and closed.
{#dri-module-in-ws__ol_crr_vgl_ydc}

## Data displayed in Digital resilience incident reporting {#dri-module-in-ws__section_tv3_qsl_ydc}

The Digital resilience incident reporting modules display the following data on the reporting cases:

* All incident reporting cases
* My incident reporting cases
* Unassigned incident reporting cases
{#dri-module-in-ws__ul_fq5_g14_scc}

## My tasks {#dri-module-in-ws__section_o41_rdx_pvb}

The My tasks page in the Operational Resilience Workspace displays all the reporting cases and action tasks that have been assigned to the signed-in user. This section includes the following information for the signed-in user:

* My pending tasks
* My items
* Watchlist
{#dri-module-in-ws__ul_o3n_qwl_qvb}

## Roles, Scripts, and Tables used for reporting {#dri-module-in-ws__section_h4y_hnh_ydc}

For information on the roles, scripts, and tables used in [Roles installed with Digital resilience incident reporting](https://servicenow-prod.fluidtopics.net/dIbA2PpBKh7LBY_e5JPrgg "Certain roles are installed with the Digital resilience incident reporting functionality."), see [Digital resilience incident reporting reference](https://servicenow-prod.fluidtopics.net/Bxp2VDQcEY~3hPfgVScGRw "Reference topics provide additional information about the Digital resilience incident reporting application, including the associated tables and roles.").

