---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Exploring Policy and Compliance Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The ServiceNow
Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the
application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.

## Policy and Compliance Management overview {#policy-compliance__section_k1r_bgw_jz}

A comprehensive integrated risk management (IRM) program is defined by the requirements established by an organization's policies. For instance, controls may mitigate risk, but they are primarily implemented to enforce policies.
Therefore, the normalization and consolidation of policies is an integral step in an organization's strategy to manage risk and meet compliance requirements across an ever-growing regulatory landscape. For more information, see [Structural overview of Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/fpMe_3JmkpZgylMb8Z_dhw "The structural overview of Policy and Compliance Management enables you to understand how the different modules that make up the Policy and Compliance Management application of ServiceNow integrate and interact with one another.")  
The scope of Policy and Compliance Management includes:

* Process to create policies and controls.
* Control risk exposure by continuously monitoring risks and control or configuration changes.
* Reduce manual burden and cost through automation.
{#policy-compliance__ul_eln_4l1_nwb}  
The process objectives of Policy and Compliance Management are:

* Create a centralized platform for creating policies, control objectives, and controls, and map them to regulations and industry guidelines.
* Manage the life cycle of the policies with a consistent process. For a graphical representation of a policy's life cycle, see [An overview of policy life cycle in Policy and Compliance Management](https://servicenow-prod.fluidtopics.net/L8qt9jHA5pGHIH_2LkbNIA "Policies ensure compliance and reduce exposure to risks. A policy can be of any type – it can be a policy, procedure, standard, plan, checklist, framework, or template. Publishing a policy is within its approval process.").
* Communicate policies across the organization using a tool.
* Assess the state of compliance.
* Provide a systematic and consistent approach to managing the life cycle of controls.
{#policy-compliance__ul_lrn_z41_nwb}  
Policy and Compliance Management centralizes the following activities:

* Establish controls and control owners
* Define control tests and expected results
* Establish test and control frequencies
* Identify risks: impact and likelihood
* Prepare attestations
* Map authoritative sources to policies, procedures, controls, and risks
{#policy-compliance__ul_owr_jgw_jz}

## Policy and Compliance Management users

Policy and Compliance activities involve all levels of management. A key function of good governance involves the establishment of a strong organization structure.

* Board of directors
* IT steering committee
* Audit committee
* All levels of management
{#policy-compliance__ul_inl_51b_vy}

## Policy and Compliance Management and the ServiceNow AI Platform


