---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Manage information objects

# Manage the Privacy Management library {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Privacy Management library consists of authority documents, citations, control objectives, policies, and \[PI\] Information objects that help to manage the privacy content.

## Authority documents {#privacy-library-setup__section_rtj_nfw_gqb}

Authority documents are the principles, guidelines, regulations, standards, and frameworks that organizations must comply with. Some examples of authority documents are:

* Statutes (Bills or Acts)
* Regulations
* Audit Guidelines

{#privacy-library-setup__ul_p44_cfw_gqb}Organizations can either create the authority documents, citations, and control objectives or they can download and import them from a third-party provider such as the Network Frontiers Unified Compliance Framework (UCF). You can create and manage authority documents from LibraryAuthority documents in the List view of the Privacy Workspace.

## Citations {#privacy-library-setup__section_xgt_4fw_gqb}

Citations are records with the specific requirements cited by an authority document. A citation relates authority documents to its applicable controls. Each citation has control objectives. You can add citations to the Library
from the List view of the Privacy Workspace.

## Policies {#privacy-library-setup__section_ywx_sfw_gqb}

Policies include control objectives. Policies can also be associated to authority documents. Policies are published and regularly updated with incremented versions. You can add policies to the Library from the List view of the
Privacy Workspace.

## Risk statements {#privacy-library-setup__section_pm4_qtk_ctb}

Using risk statements you can create a central risk register to manage potential privacy risks that may occur any time and any where in an organization. You can add risk statements to the Library from the List view of the
Privacy Workspace.

## Privacy assessments {#privacy-library-setup__section_ov3_stk_ctb}

Privacy assessments are used to collect information from business owners. This information helps the privacy teams to understand how personal information (PI) is being used or stored in a processing activity.

## Risk assessments {#privacy-library-setup__section_jr5_stk_ctb}

The risk assessments capability enables you to determine the organizational privacy risk posture using criticality and privacy risk assessments.

## PI Information objects {#privacy-library-setup__section_vm5_cgb_sqb}

\[PI\] Information objects refer to information objects that are of type Personal information. To understand the benefit of using information objects in the Privacy Management solution, refer to [Information objects in Privacy Management](https://servicenow-prod.fluidtopics.net/ntmK4EHhvet~BBW4DuiH7A "The purpose of an information object is to logically describe the type of data that is exchanged between an application and a database."). Maintaining a library of \[PI\] Information objects and associating them with the processing activities helps the privacy teams to understand what personal information
(PI) is being processed by the processing activity.

Only the information objects that are tagged with the Personal information tag are available to be added to a processing activity. For more information on how to tag information objects see, [Classify information objects as personal information](https://servicenow-prod.fluidtopics.net/DL4O5gU1scbyF4XE3ZqI~g "Categorize information objects as personal information. Only information objects classified as personal information can be associated with the processing activities.").
* **[Create an information object](https://servicenow-prod.fluidtopics.net/BuNxt_5vAmsxQpQvCIQAcQ)**   
  Create information objects manually to associate the right data subject types with business processes or applications.
* **[Configure information object categories](https://servicenow-prod.fluidtopics.net/3VhjcH9bV92Nv97a~mw94w)**   
  Configure information object categories to classify information objects effectively. For example, attributes like iris scans and fingerprints are often referred to as biometric data, or email addresses and phone numbers can be grouped as contact information. Information object categories enable you to categorize these information objects under these broader classifications.
* **[Classify information objects as personal information](https://servicenow-prod.fluidtopics.net/DL4O5gU1scbyF4XE3ZqI~g)**   
  Categorize information objects as personal information. Only information objects classified as personal information can be associated with the processing activities.

**Related tasks**   

* [Create a privacy assessment](https://servicenow-prod.fluidtopics.net/f2ranjOqv08w5N2yRz_nVQ "Create various types of assessments and send those assessments to the business process or business application owners to collect their responses. The responses help you to understand how personal information (PI) is being used or stored in a processing activity.")
* [Create a Risk Assessment Methodology](https://servicenow-prod.fluidtopics.net/1eHuVwOde5~BR~7H2Mox_A "Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.")

*[\>]: and then


