---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Scheduling an auto-update of dependencies

# Scheduling an auto-update of dependencies {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 8 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Scheduling an auto-update of dependencies

ServiceNow Business Continuity Management (BCM) enables automatic scheduling of dependency updates in Business Impact Analyses (BIAs) using Configuration Management Database (CMDB) data.
This functionality helps BCM administrators keep BIA dependencies current by pulling real-time asset relationships from the CMDB, reducing manual effort and enhancing accuracy in impact assessments.
Show full answer Show less  

## Key Features

* **Impact Analysis Dependency Update Configuration:** BCM administrators configure rules in the Impact analysis dependency update configuration module to define which BIA records are auto-updated. Multiple rules can be created and are evaluated in order to apply the first matching filter condition.
* **Scheduled Job:** The "Update BIA dependencies snapshot" scheduled job, shipped with the BCM application (inactive by default), runs regularly to check and update dependencies for BIAs based on configured rules. It creates snapshot records to track changes.
* **Notifications:** Email notifications can be sent to BIA owners when dependencies are updated, configurable via the Impact analysis dependency update configuration.
* **Manual Updates:** BCM users can manually trigger dependency updates on-demand via the "Update dependencies" UI action within a BIA, which updates dependencies and creates snapshots immediately without waiting for the scheduled job.
* **Snapshot Records:** Each BIA update creates a snapshot record showing added, updated, or deleted dependencies. Snapshots facilitate tracking and reviewing changes before they are applied. Only one active snapshot per BIA is maintained, and old snapshots are cleaned up automatically.
* **Integration with Data Relationships Framework:** BCM leverages the Data Relationships Framework (installed by default) to fetch and manage the dependency relationships efficiently from CMDB.
* **Enhanced Dependency Assessment with Xanadu Release:** Updated dependencies from the latest BIA can be used for asset-level dependency assessments, incorporating recovery objectives and tiers to support planning.

## Practical Use and Configuration

* Access the Impact analysis dependency update configuration via Business Continuity Workspace \> General Administration.
* Configure filter conditions and data sources to control which BIAs are auto-updated and when notifications are sent.
* Activate and schedule the "Update BIA dependencies snapshot" job to automate regular dependency synchronization.
* Use manual updates through the UI for immediate dependency refreshes when needed.
* Understand the 1,000 BIA record processing limit for scheduled jobs, adjustable via system properties.
* Roles: BCM administrators configure dependency update settings; BCM program managers, planners, and managers perform dependency assessments and updates.

## Benefits for ServiceNow Customers

* Streamlines dependency management in BIAs, reducing manual update overhead.
* Ensures BIAs reflect the latest asset and relationship data from CMDB, improving business continuity planning accuracy.
* Facilitates timely communication to BIA owners about dependency changes through automated notifications.
* Provides audit trail and review capability via snapshot records before applying updates.
* Supports both automated and manual update workflows to fit operational needs.
* Leverages existing ServiceNow framework capabilities for efficient dependency data handling.  
You can schedule an auto-update of the dependencies in the business impact analysis based on the source data and relationships in the CMDB. You can receive an email notification with details of the BIA dependency updates from the BCM application.

The video shows how BCM Managers can use the CMDB as a source to update dependencies in a Business Impact Analysis (BIA). The same process applies to Business Continuity Plans (BCPs) and events.

## Scheduling an auto-update of the dependencies {#update-impactanalysis-dep-based-on-cmdb-changes__id_gsb_lwf_xzb}

The BCM administrators can schedule an auto-update of the BIA dependencies in the Impact analysis dependency update configuration module, based on CMDB data and relationships. You can access the auto-update configuration module by navigating to Business Continuity WorkspaceGeneral AdministrationImpact analysis dependency update configuration.

The Impact analysis dependency update configuration module is shown in the example.

You can create multiple rules for the same record. The system evaluates configurations in ascending order and applies the first configuration whose filter condition the record satisfies. For example, you
can define another configuration rule for archived BIA records as shown in the example.

When the BCM administrators select the Auto-update dependencies option, the BCM application schedules an auto-update of the dependencies in the BIAs. Similarly, when the Send notification option is selected, the BCM application sends automated emails to the BIA owners about the dependency updates.  
The source for the BIA dependencies is CMDB.  
Note:  
The dependencies are fetched for the BIA that is listed in the Applies to field of the BIA record such as HR Application BIA, Accounts Receivable BIA.

Setting up the Impact analysis dependency update configuration module is a one-time activity. Once the sources are configured in the Impact analysis dependency update configuration module, the dependency updates
are synchronized in the BIA.

For more information on setting up the Impact analysis dependency update configuration module, see [Configuring impact analysis dependency updates](https://servicenow-prod.fluidtopics.net/fikJn_hRUJLCAVtLh1KSAA "The BCM administrators configure the Impact analysis dependency update configuration to schedule automatic BIA dependency updates based on CMDB data and relationships.").

## Using the updated dependencies with the Xanadu release {#update-impactanalysis-dep-based-on-cmdb-changes__section_ffk_1nt_bcc}

Beginning with the Xanadu release, you can use updated dependencies from the latest BIA record to conduct a dependency assessment on an asset. The Related item BIA, Recovery Time Objective (RTO), Recovery Point Objective (RPO), and
Recovery Tier columns determine required recovery timeframes and data backup needs. The details are then displayed in the Required Recovery Timeframe and Required Data Backup columns of the BIA record.

For more information on the source BIA records option in the Dependency configuration modules, see [Set up Planning dependency update configuration](https://servicenow-prod.fluidtopics.net/cWx6ZoDmXwT~Ez7wTvETUA "Configure the Planning dependency update configuration record to configure the plan record (for which the dependencies are updated), its target records, sources, and notification preferences.").

## Using the scheduled job to auto-update the dependencies {#update-impactanalysis-dep-based-on-cmdb-changes__section_mxn_ffq_hzb}

The Update BIA dependencies snapshot scheduled job is shipped as part of the base system. It runs at regular intervals and fetches the dependency updates. The scheduled job is shown in the example.

The scheduled job is not marked as Active by default. To run the scheduled job at regular intervals, the system administrators can select the Active option and select Execute now to set
up a schedule. The scheduled job then runs at regular intervals, scans the BIA records for the changes, and fetches the dependency updates for the updated BIA records. It creates a snapshot record for each BIA update.  
Note:  
The application is configured with an out-of-the-box (OOB) limit of 1000 Business Impact Analyses (BIA) records, as defined by the sn_irm_shared_cmn.config.get_gliderecord_limit system property. This means
that the system processes up to 1000 BIA records only, as it cannot exceed this threshold.

The 1,000 BIA limit applies only if you have more than 1,000 BIAs in the system and have enabled the Update BIA dependencies snapshot scheduled job. This scheduled job is inactive by
default. If you have enabled it, you must confirm that you review the note. The scheduled job processes records only up to the limit defined in the sn_irm_shared_cmn.config.get_gliderecord_limit property.

The scheduled job processes a workflow to check for the changes in the relationships and save the dependency updates automatically as shown in the example.

1. The scheduled job runs weekly, checks the dependency configuration for each BIA record, and fetches the BIA dependencies from CMDB as defined in the Sources tab of the Impact analysis dependency update configuration module. It generates a list of all active BIAs and the primary and dependent assets of each BIA. If any new dependencies are added, updated, or deleted for a BIA, the scheduled job creates a snapshot record for the BIA that displays the changes for the user.  
   Note:  
   By default, the scheduled job checks all the BIA records that are not in the Archived state for any updated dependencies.
2. The scheduled job refers to the filter condition that is set in the configuration (Impact analysis dependency update configuration module). If the condition matches the BIA record, the scheduled job fetches and stores BIA dependencies in the snapshot record based on sources defined in the configuration. If the filter condition does not match the BIA record, the application skips the record.
3. The application combines the assets list into a single list that is based on the priority defined in the Impact analysis dependency update configuration module. The application compares the asset list with the existing asset list and assigns either the Added, Updated, or Deleted state to each asset.
4. The application also compares the new assets to the assets listed in the Element definition and verifies the element definition condition. The application creates a snapshot of the asset and auto-completes the dependency updates in the Dependency snapshot record.
5. When Send notification is set to True in the Impact analysis dependency update configuration module, users of the BIA record receive notifications about dependency updates via scheduled job.
6. When the Auto-update dependencies option is set to True in the Impact analysis dependency update configuration module, the scheduled job automatically applies the dependencies snapshot to the BIA record.
7. As the final step, the scheduled job updates the BIA record according to the fields to be updated in the configuration.
{#update-impactanalysis-dep-based-on-cmdb-changes__ol_xt2_5xh_b1c}

## Updating the dependencies manually {#update-impactanalysis-dep-based-on-cmdb-changes__section_vs5_hrq_rzb}

As the BCM application user, you can update the BIA dependencies instantaneously by using the Update dependencies UI action. In this way, you can update the dependencies
manually before the scheduled job runs as per the weekly schedule. The Update dependencies UI action is listed in the Dependency assessment of the BIA. The dependencies are then updated in the sources and a
snapshot record of the BIA update is created.

See the workflow for using the Update dependencies UI action and updating the dependencies manually:

1. The BCM planner navigates to a BIA record. The application fetches the dependencies of the asset defined in the Applies to field of the BIA.
2. The BCM planner selects the Update dependencies UI action that is listed in the Dependency assessment of the BIA.
3. If the snapshot record exists for the BIA update, the system applies the dependencies through the snapshot and updates the BIA according to the Fields to be updated in the configuration. The BIA workflow
   then continues for the next steps such as requesting review and approval.

   If the snapshot record does not exist for the BIA update, the BCM planner checks if the BIA record matches any configuration filter:
   * If the BIA record matches any configuration filter, the application gets the dependencies in real time according to the sources in the configuration. Then, update the BIA record according to the Fields to be updated in the configuration. The BIA workflow then continues for the next steps.
   * If the BIA record does not match the configuration filter, the BIA workflow then continues for the next steps.
   {#update-impactanalysis-dep-based-on-cmdb-changes__ul_ihl_yg3_b1c}

{#update-impactanalysis-dep-based-on-cmdb-changes__ol_n1l_n3z_czb}

For more information on updating the dependencies manually, see [Update the BIA dependencies](https://servicenow-prod.fluidtopics.net/CVkiLlTWiIfVj8lwlo9LCg "Update the business impact analysis (BIA) dependencies manually from the snapshot if the scheduled job is not activated in the Impact analysis dependency update configuration module. You can update the dependencies in an active BIA.").  
Note:  
Note:  
The Impact analysis dependency update configuration module is used for using the scheduled job and for updating the dependencies manually (by using the Update dependencies UI action).

## Snapshot records of the BIA {#update-impactanalysis-dep-based-on-cmdb-changes__section_pqg_25l_mzb}

A snapshot record is created for each BIA update either with the scheduled job or with the Update dependencies manual UI action. If any new
dependencies are added, updated, or deleted for a BIA, the snapshot record displays the delta of the changes. The snapshot records are listed in the Pending updates module in the Business Impact Analysis list view of the Business Continuity Workspace. A snapshot record is shown in the example.

When a snapshot record gets created, the application displays a UI message in the Dependency assessment of the BIA to inform the users about the dependency updates: The dependencies have been updated in the sources. To review and apply the changes, select here - \<link\>. The UI message is shown in the example.

The snapshot records are used for record keeping purposes. The BCM application stores one active snapshot for each BIA at a time. Whenever the dependencies are updated, a snapshot is always created first. As the system processes all the records one by
one, the snapshot records are auto-committed one by one in the system.

The snapshots that are in the Completed state and that have not been updated for a few months are removed from the application
automatically.

If the BIA record does not have any changes in the dependencies, then a snapshot record is not created for that BIA record.

## Roles associated with BIA dependency updates {#update-impactanalysis-dep-based-on-cmdb-changes__section_yps_f3q_hzb}

Users with these roles check for the dependency updates in a BIA:

* The BCM program managers, BCM planners, and BCM managers can update the latest dependencies.
* BCM administrators can configure the Impact analysis dependency update configuration module.
{#update-impactanalysis-dep-based-on-cmdb-changes__ul_pdp_mnl_mzb}

A user who can update the dependency assessment can import the dependency updates for a BIA.

## Data Relationships Framework {#update-impactanalysis-dep-based-on-cmdb-changes__section_cm5_2hl_mzb}

When you perform a business impact analysis (BIA) on an asset, you must evaluate the dependencies of the BIA by performing a dependency assessment. If the dependencies in the CMDB are updated, importing them manually in a BIA can be a tedious activity. Beginning with the Australia release, the Data Relationships Framework application (com.sn_app_grc_relationship_config) supports the BCM application with the underlying framework to fetch the dependencies in the BIA. The Data Relationships Framework application is installed with the BCM application by default.

For more information on the Data Relationships Framework, see [Data Relationships Framework](https://servicenow-prod.fluidtopics.net/XY8p9NXpWII1Lr6oTtFWjQ "The Data Relationships Framework application (sn_grc_rel_config) supports the BCM application with the underlying framework to fetch the dependencies in the BIAs, plans, and events from different sources such as CMDB, BIA, and BCP. Beginning with the Australia release, the Data Relationships Framework (sn_grc_rel_config) application is installed with the BCM application by default.").
* **[Update the BIA dependencies](https://servicenow-prod.fluidtopics.net/CVkiLlTWiIfVj8lwlo9LCg)**   
  Update the business impact analysis (BIA) dependencies manually from the snapshot if the scheduled job is not activated in the Impact analysis dependency update configuration module. You can update the dependencies in an active BIA.

*[\>]: and then


