---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Use

# Using Regulatory Change Management {#ariaid-title1}

* Release version: Australia
* 
* Updated August 11, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Regulatory Change Management

Regulatory Change Management (RCM) in ServiceNow enables organizations to systematically track, assess, and respond to regulatory changes that impact their business operations.
The application supports capturing issues, monitoring tasks, and managing regulatory alerts through a workflow, primarily accessed via the Workspace view starting from version 18.1.2.
Show full answer Show less  

## Key Features

* **Role-based Access:** RCM managers (with the `sngrcregchange.manager` role) can assign alerts, create action tasks, and monitor progress. Business users and RCM users collaborate on reviewing alerts and conducting impact assessments.
* **Playbook Configuration:** Organizations can configure an RCM playbook to define teams, user entitlements, customers, and providers for regulatory content access.
* **Internal Taxonomy:** Classify and organize regulatory content using customizable taxonomy elements to create a hierarchical structure tailored to the organization.
* **Regulatory Monitoring:** Integrate with external regulatory intelligence providers (e.g., Thomson Reuters, LexisNexis) and subscribe to industry updates for real-time regulatory changes.
* **Assessment and Impact Analysis:** Conduct impact assessments and gap analyses to evaluate and prioritize regulatory changes based on risk and compliance impact.
* **Action Plan Development:** Create detailed remediation plans, define responsibilities, timelines, and resources, and assign tasks to relevant teams for compliance.
* **Communication and Documentation:** Inform stakeholders, provide training, update policies and procedures, and document findings to maintain compliance transparency.
* **Monitoring and Continuous Improvement:** Track implementation progress, conduct post-implementation reviews, close completed tasks, and update the playbook based on feedback and lessons learned.

## What Customers Can Expect

With ServiceNow's Regulatory Change Management, customers can efficiently manage the end-to-end lifecycle of regulatory changes. This includes capturing regulatory alerts, assessing their impact, executing remediation plans, and ensuring organizational compliance. The solution facilitates collaboration among legal, compliance, risk, and operational teams, providing clear workflows and visibility into task progress. By implementing this framework, organizations reduce compliance risks, streamline regulatory updates, and maintain up-to-date policies and controls aligned with evolving regulations.  
You can use the classic environment to perform all Regulatory Change Management application activities.

As an RCM manager with the sn_grc_reg_change.manager role, you can capture any problems or exceptions that are observed during the workflow by assigning regulatory alerts or
creating an action task or issue that is related to the regulatory change tasks and source document tasks. You can also monitor the regulatory change tasks and action tasks.

You can also use a [setup checklist](https://servicenow-prod.fluidtopics.net/BZt5EbSTUVV45AMIrmaRFA "Complete the tasks that are required to set up the Regulatory Change Management application. When you have completed these tasks, the base system is ready for operation. Optional setup procedures are also included to enhance Regulatory Change Management application functionality.") that can help you to get your base system ready for operation.

Starting with version 18.1.2, all the new features and enhancements are available only in the Workspace view.

## Regulatory Change Management Playbook {#using-rcm__section_wy2_5md_scc}

Configure a Regulatory Change Management RCM playbook for your organization or business by following this process:

1. Manage your user entitlements, include the customers and providers that read and access the regulatory content, and establish a regulatory team:
   * Designate a team of subject matter experts, legal counsel, or compliance professionals that can track regulatory changes.
   * Include the representatives from legal, audit, compliance, risk management, and operational departments.
   * Include your customers and providers. You include the customers who subscribe to a public RSS feed for the regulatory bodies or a subscription provider, such as Thomson Reuters Regulatory Intelligence (TRRI). You also include the providers, such as Thomson Reuters Regulatory Intelligence (TRRI), that aggregate the regulatory changes from different sources and provide the collective changes as feeds.
   * Set up an internal taxonomy. The taxonomy elements are different classifiers that an organization can apply to its regulatory content to categorize it. You can use taxonomy elements to create a hierarchical structure of the different classifications for setting up the regulatory content for an organization.
   {#using-rcm__ul_qjj_g3h_qcc}
2. Monitor the regulatory changes:
   * Stay informed about the new and updated regulations that could affect your organization or business.
   * Subscribe to industry newsletters, updates for the regulatory bodies, and relevant legal databases that are made publicly available and accessible via RSS.
   * Integrate with regulatory intelligence providers such as Thomson Reuters or LexisNexis, to monitor changes in real time.
   {#using-rcm__ul_jdl_53h_qcc}
3. Assess the impact:
   * Evaluate the implications of regulatory changes on your organization or business.
   * Analyze regulatory changes:
     1. If you have the sn_grc.business_user role (Business User), review the regulatory alerts and assign them to a user with the sn_grc_reg_change.user role (RCM user) for review. If the regulatory change requires an impact assessment, the RCM user sends it to a subject matter expert (SME) with a business user role.
     2. Review the new regulations and draft new requirements, policies, or control measures.
     3. Determine the scope of the impact on your various business units including the functions, departments, and processes.
     {#using-rcm__ol_wdg_bjh_qcc}
   {#using-rcm__ul_x32_1jh_qcc}
4. Conduct an impact assessment:
   1. Perform a risk assessment or gap analysis to evaluate the potential impact on the operations, finances, and compliance of your organization or business.
   2. Assess the impact of the regulatory change and send the impact assessment score to the Regulatory Change Management application. If the alert is not applicable, close the alert. If the alert is applicable, create a new regulatory change task and assign it to the same or a new coordinator.
   3. Engage stakeholders from affected departments to gather insights.
   {#using-rcm__ol_uwq_kjh_qcc}
5. Perform a gap analysis:
   1. Identify your current state. Assess your existing inventory of policies, citations, and controls in relation to the new regulations.
   2. Identify gaps. Compare the current state with the new regulatory requirements (draft, final rules, or enforcement actions) to identify any discrepancies.
   3. Prioritize gaps. Evaluate the significance (high, medium, or low) of each gap by the potential risk and impact to your organization or business.
   4. Develop a gap remediation plan. Create a plan to address the identified gaps, and specify the actions, timelines, and responsibilities for your organization or business.
   {#using-rcm__ol_srg_pjh_qcc}
6. Document your findings:
   1. Prepare a detailed report that outlines the regulatory changes, their implications, and recommended actions.
   2. Report the regulatory findings, compliance deviations, or non-material outcomes that are due to the regulatory change.
   {#using-rcm__ol_b3w_xjh_qcc}
7. Manage the regulatory changes and strategies:
   * Implement strategies to address the regulatory changes.
   * Develop an implementation plan:
     1. Identify the steps to take to comply with the regulatory change, devise an action plan, and create the action tasks for different teams. After the action plan is created, send it to the RCM manager for approval and to confirm that all the action tasks are sufficient or if any aren't necessary.
     2. Create a clear action plan that details the actions required to comply with the new regulations. The action plans could be legal review, business change, policy updates, control revisions, or training.
     3. Define the timelines, resources or watch list teams, and responsibilities.
     {#using-rcm__ol_sxk_2kh_qcc}
   {#using-rcm__ul_zm1_ckh_qcc}
8. Communicate changes:
   1. Inform all relevant stakeholders about the regulatory changes and the planned actions.
   2. Provide the training and resources to help employees understand and adapt to the new requirements.
   {#using-rcm__ol_sgb_mkh_qcc}
9. Update your policies and procedures:
   1. Revise your existing policies, procedures, or controls to align with the new regulations.
   2. Confirm that your documentation reflects the changes and is easily accessible.
   {#using-rcm__ol_sjg_4kh_qcc}
10. Monitor your implementation plan:
    1. Track the progress against the implementation plan.
    2. Address any challenges or issues that arise during the process.
    {#using-rcm__ol_s5z_wkh_qcc}
11. Review your plan and identify ways to keep improving it:
    * Evaluate how effective the regulatory change management process is and make improvements where needed.
    * Conduct post-implementation reviews:
      1. If the action plan is rejected, assign the same coordinators to go through the action plan, update the actual tasks, and send the action plan for an approval. All compliance-based action tasks are visible to the compliance manager and risk managers can see the Risk-based action tasks. After the tasks are assigned to the risk and compliance users, track the action tasks through completion. Select a due date and track the action tasks. After the actual tasks are completed, close the regulatory alert and the parent regulatory change tasks.
      2. Assess the effectiveness of the implemented changes and compliance status.
      3. Gather feedback from your stakeholders to identify the areas for improvement.
      {#using-rcm__ol_w3k_1lh_qcc}
    {#using-rcm__ul_hdj_zkh_qcc}
12. Update the playbook:
    1. Revise the playbook based on the lessons learned and evolving usage guidelines.
    2. Incorporate the feedback to enhance the monitoring and management processes.
    {#using-rcm__ol_sky_2lh_qcc}
{#using-rcm__ol_vlp_23h_qcc}

