---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Reporting incidents or security incidents for multiple regulations

# Reporting incidents for multiple regulations {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Reporting incidents for multiple regulations

ServiceNow's Digital Resilience Incident Reporting application enables customers to report incidents and security incidents across multiple regulations and legal entities efficiently.
It automates workflows to streamline compliance with regulatory timelines, ensures accurate data migration, helps prevent duplicate reports, and supports generation of reports in Microsoft Word format as required by authorities.
Show full answer Show less  

## Key Features

* **Automated Reporting Workflow:** The application supports a structured reporting process for IT incidents, including Initial Reports (within 24 hours), Intermediate Reports (every three days until resolution), and Final Reports. This automation ensures timely compliance with regulatory deadlines.
* **Multi-Entity Case Creation:** You can associate multiple legal entities with a single incident. When an entity is linked, a Digital Resilience Incident Reporting case is automatically created via prebuilt flows, simplifying management across jurisdictions.
* **Action Task Sequencing and Automation:** Action tasks are automatically generated and sequenced based on configurable templates. For example, closing the Initial Report task triggers creation of the Intermediate Report task, which recurs every three days until resolution. Final Report tasks are generated upon incident closure with a 30-day due date.
* **Customizable Templates and Workflows:** Administrators can tailor action task templates, their sequencing, due dates, and termination conditions to align with specific organizational needs and regulatory requirements. This flexibility supports diverse compliance frameworks.

## Practical Benefits for ServiceNow Customers

* Automates and accelerates compliance with multiple regulatory incident reporting requirements, reducing manual effort and errors.
* Ensures accurate and timely reporting for multiple legal entities from a single incident record, improving data consistency and audit readiness.
* Provides a clear, repeatable sequence of action tasks that guide incident assessment and reporting stages, enhancing process visibility and control.
* Supports regulatory reporting in the mandated Microsoft Word format, facilitating submission to authorities without additional formatting work.
* Enables customization and extension by administrators to meet evolving regulatory demands and internal policies.

## Next Steps for Implementation

To fully leverage this capability, administrators should configure entities and regulatory mappings, set up and customize action task templates, and familiarize themselves with completing action tasks as defined by their organizational processes. Reference ServiceNow documentation on configuring Digital Resilience Incident Reporting and regulatory agency profiles for detailed setup guidance.  
You can now report incidents or security incidents for multiple regulations for various legal entities in Digital resilience incident reporting. The application streamlines operations by automating tasks, migrating data, helping to prevent duplicates, and verifying accurate reporting.

## Automated reporting workflow {#reporting-for-multiple-regulations__section_wtp_5gn_3hc}

Starting with Digital resilience incident reporting, release 21.1.1, the application uses an automated reporting workflow to generate reports within regulatory reporting timelines:

* Regulatory reporting assessment of IT incidents
* Initial Report (within 24 hours)
* Intermediate Report (every three days until resolved)
* Final Report
{#reporting-for-multiple-regulations__dri-module-in-ws_ul_mh2_kpr_12c}

You can complete these tasks and generate reports in Microsoft Word format, as required by regulatory authorities for analysis.

## Case creation by adding entities {#reporting-for-multiple-regulations__section_icd_qdn_3hc}

Digital resilience incident reporting is used for incident reporting and assessment for legal entities or other objectives according to regulations. You can now add entities to an incident, which automatically
create a Digital resilience incident reporting case.  
Note:  
When an entity is mapped to an incident or security incident, the 'DRI case creation on incident entity insert' or 'DRI case creation on SIR entity insert' flow runs and a Digital Resilience Incident Reporting case is created automatically in the Digital Resilience Incident Reporting module with the prebuilt flow. For information on the flows, see [Configure Digital resilience incident reporting](https://servicenow-prod.fluidtopics.net/RN3eLbCJuQadHsL738147g "Digital Resilience Incident administrators can configure conditions in Workflow Studio to auto-trigger incident reporting in Digital resilience incident reporting.").

For information on setting up the entities, see [Set up entities for the targets](https://servicenow-prod.fluidtopics.net/XjOr3de0hDHXPw8~0o6qUw "Set up an entity record in the instance and map it to an incident or security incident. You can map one or multiple entities to the selected incident.").

## Sequence of action tasks {#reporting-for-multiple-regulations__section_udn_1fp_3hc}

The sequence of action tasks in the DIR process is outlined in the document "Digital resilience incident reporting for multiple regulations." It is primarily driven by template configurations. Here's an overview of how action tasks
are created and sequenced:

Action task creation and sequence are explained.

1. Initial action task creation: When a DIR case is created (triggered by sources like incidents), the system automatically generates action tasks. For example, the template shown creates the 'Regulatory reporting assessment of IT incidents' action task.
2. Template configuration: Templates are configured to create specific action tasks. For example, the 'DRI Initial report' template runs only once. It automatically creates the 'DRI Initial report' action task when the regulation's reporting status changes to 'Reportable.' Administrators can then update its name, due date, and termination conditions.
3. Closure of action tasks: When the 'DRI Initial report' is closed, the 'DRI Intermediate report' action task is created. If the 'DRI Initial report' task remains open, the 'DRI Intermediate report' action task is created every
   three days until the DIR case or source incident is closed.

   Note:  
   It is not mandatory to close every intermediate report assessment that was generated during the lifecycle of the incident. The Final report action task is created automatically when the source incident is closed, independent of the open intermediate assessments. Any intermediate assessments that remain open after the source incident is closed are no longer required - the periodic generation stops as soon as the termination conditions configured on the DRI Intermediate report template are met (typically when the source incident state is 'Closed' or the DRI case state is 'Closed'/'Canceled').
4. Closure of incident: When the source incident or security incident is closed, the "DRI Final report" action task is created, with a due date of 30 days.
5. Automated action task generation: These template configurations enable automatic creation of action tasks, as previously demonstrated. as administrators, you can create multiple action tasks and tailor their sequence to meet your organizational requirements and applicable regulations.
6. Completion of action tasks: Action tasks are completed according to the conditions defined in their templates, promoting efficient process management and required task completion.  
   Note:  
   As administrators, you can customize the configurations available with the base version or add additional action tasks as needed.

{#reporting-for-multiple-regulations__ol_n4r_1fp_3hc}

For information on mapping regulations and setting up action task templates, see [Map regulations to the entities](https://servicenow-prod.fluidtopics.net/soJ~svrHRT2EeCFnViVIZQ "Map single or multiple regulations with the entity linked to an incident or security incident.") and [Set up action task templates in Regulatory agency profile](https://servicenow-prod.fluidtopics.net/G9qh_1zaEcc2s46fVSjiFw "Set up action task templates in the Regulatory Body Management Agency Profile [sn_reg_body_mgmt_agency_profile.list] table. Verify that the action task configurations (with Smart Assessment Smart Assessment template configurations) for the selected regulation are correctly set up.").

For information on completing action tasks, refer to [Complete action tasks and report incidents](https://servicenow-prod.fluidtopics.net/~kfSNgyC3LWoVrka52291w "Report incidents or security incidents associated with multiple regulations for various legal entities. The automated workflow generates regulatory reporting assessments of IT incidents, and Digital resilience incident (DRI) Initial, Intermediate, and Final reports, all within regulatory timelines. Complete the action tasks and generate reports in Microsoft Word format, as required by regulatory authorities for analysis.").

