---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Configure

# Configure Digital resilience incident reporting {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Configure Digital Resilience Incident Reporting

Digital Resilience Incident Reporting in ServiceNow enables Operational Resilience administrators to automate the creation and management of incident reports related to digital resilience.
This configuration leverages Workflow Studio to auto-trigger incident reporting based on predefined conditions, integrating with the Incident Management and Security Incident Response applications.
It supports generating detailed reports in Microsoft Word format and managing regulatory mappings for compliance.
Show full answer Show less  

## Key Features

* **Workflow Automation:** Preconfigured flows in Workflow Studio automatically create and update Digital Resilience Incident (DRI) cases from incidents and security incidents, with customizable conditions such as priority, urgency, and incident duration.
* **Report Generation:** Use Word templates and template configurations to generate Digital Resilience Incident reports in Microsoft Word format, facilitating standardized and compliant documentation.
* **Regulation Mappings:** A dedicated related list within each DRI case displays connections between case entities and applicable regulations, enhancing visibility and compliance tracking.
* **Third-Party and Legal Entity Data Integration:** DRI questionnaires and reports rely on populated legal-entity and third-party tables from the Digital Resilience Third-Party Registers, which can be maintained manually or via Excel uploads.
* **Action Task Automation:** New flows manage automation of action tasks based on regulation updates, case updates, and multi-regulator triggers.
* **Customization:** Administrators can modify flow configurations to align with organizational processes and requirements.

## Prerequisites and Setup

* Populate legal-entity and third-party registers before generating Digital Resilience Incident reports.
* Configure Word templates and template configurations to enable Microsoft Word report generation.
* Understand and optionally deactivate deprecated flows if you need to use prior flow versions.

## Required and Optional Plugins

The Digital Resilience Incident Reporting application requires several plugins primarily from the Integrated Risk Management (IRM) family, including Document Designer, Digital Operational Resilience Management, GRC components, Regulatory Agency Library, and Smart Assessment modules. Optional plugins include Security Incident Response and Digital Resilience Third-Party Information Register, which enhance security incident integration and third-party data management.

## Practical Benefits for ServiceNow Customers

By configuring Digital Resilience Incident Reporting, organizations can:

* Automate detection and reporting of critical digital resilience incidents, reducing manual effort and improving response times.
* Ensure compliance with regulatory requirements through structured documentation and regulation mapping.
* Maintain accurate third-party and legal-entity data to support thorough incident analysis and reporting.
* Customize workflows to reflect unique organizational policies, enhancing operational resilience and governance.  
Digital Resilience Incident administrators can configure conditions in Workflow Studio to auto-trigger incident reporting in Digital resilience incident reporting.

## Setting up templates and modules {#workflow-confi-auto-trigger-inci-repo-cases__section_r5p_twn_3hc}

Operational Resilience administrators set up Word templates, Template configurations, and the Digital resilience incident (DRI) case type required for Digital resilience incident reporting as shown in the example.

Configure Word Templates and Template Configurations for generating reports in Microsoft Word format. For more information, see [Generating Microsoft Word reports using Document designer](https://servicenow-prod.fluidtopics.net/YfEolSFAAxvgjrCqzYfBmw "Digital resilience incident reporting administrators (sn_dri_inc_rptg.digital_resilience_incident_administrator) can now set up Microsoft Word templates and Digital resilience incident reporting managers (sn_dri_inc_rptg.digital_resilience_incident_manager) can download action task reports in Microsoft Word format​.").

The Digital Resilience Incident Case module lists all Digital Resilience Incident Cases associated with an incident or security incident. A new 'Regulation Mappings' related list is now
available in each Digital Resilience Incident Case record. It displays the relationships between entities related to the cases and their corresponding regulations.

## Prerequisite data setup for DRI questionnaires {#workflow-confi-auto-trigger-inci-repo-cases__section_yk5_qt1_gjc}

DRI report templates use legal-entity and third-party tables from Digital Resilience Third-Party Registers. Populate these tables manually or via Excel upload before generating the initial report. (sn_dora_accel_entity and
sn_dora_accel_third_party). The responder completes remaining fields.

For details, see [Maintaining Digital resilience third-party registers](https://servicenow-prod.fluidtopics.net/ZdDi7525u__D~~HlyvDkXw "The Digital resilience third-party registers application enables you to maintain contractual arrangements for Information and Communication Technology (ICT) services that support critical or important functions. You can manage contractual arrangement details through the graphical user interface or by importing or exporting Microsoft Excel files."). Also, see [Create a third party and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/U6gFD10iSgqCaCPE6jojVA "Create a third party record in Digital resilience third-party registers. Add the details of the third party company such as its name, address, phone number, vendor manager, and so on. You can then enhance its digital resilience information for compliance with DORA regulation."), and [Create a legal entity and enhance digital resilience data](https://servicenow-prod.fluidtopics.net/j6Nt1GuRKzfOW5PeLeD_bg "Create a legal entity record in Digital resilience third-party registers. You can then enhance its digital resilience information for compliance with DORA regulation.").

## Conditions for setting up the Workflow {#workflow-confi-auto-trigger-inci-repo-cases__section_adr_vpm_ydc}

Workflow Studio contains preconfigured flows and conditions for creating DRI case tasks from incidents in the Incident Management or Security Incident Response applications. Access the Digital resilience incident reporting flows by navigating to Workflow StudioFlowsFlow Designer.  
The following flows, previously used in the Digital resilience incident reporting application, have been deprecated:

1. Digital Resilience Incident Flow
2. Digital Resilience SIR Flow
3. DRI Business service Trigger
{#workflow-confi-auto-trigger-inci-repo-cases__ol_k3k_txt_khc}  
Note:  
To use the previously deployed flows, deactivate the new flows (listed in this section) and then activate the Digital Resilience Incident Flow, Digital Resilience SIR Flow, and DRI Business Service Trigger Flow.  
The following flows in Digital resilience incident reporting are still active:

1. Digital Resilience Incident Approval Flow
2. DRI case create/update on incident update
3. DRI case create/update on security incident update
4. DRI case creation on incident entity insert
5. DRI case creation on SIR entity insert
{#workflow-confi-auto-trigger-inci-repo-cases__ol_igh_sxt_khc}  
New flows have been introduced in Digital resilience incident reporting to manage action tasks, regulations, and trigger conditions for multiple regulators, as illustrated in the example:

1. Action task automation for regulation addition
2. Action task automation on action task update
3. Action task automation on DRI case updates
4. Action task automation on regulation updates
5. DRI Business Service Trigger For Multiple Regulators
{#workflow-confi-auto-trigger-inci-repo-cases__ol_w4r_sb5_khc}  
Note:  
If the Security Incident Response application is installed in your instance, flows related to the security incidents (SIR) are listed in the Flows list view.

The Digital Resilience Incident Flow and Digital Resilience SIR Flow are prebuilt into the Digital resilience incident reporting application. The flow configuration impacts all incident records in the instance. As administrators of the Operational Resilience application, you can update (customize) the flow configurations to meet your organizational requirements as shown in the example.  

Insert condition
:   Conditions such as Critical priority, High urgency, and incidents open for more than 24 hours are prebuilt in the flow. When all these conditions are met, it's automatically reported in the Digital resilience incident reporting application.

Update condition
: When an incident is reopened or updated, that classification condition is also defined in the flow. When the configured conditions are met, the incident is reported in the Digital resilience incident reporting application.  
Note:  
The Digital resilience incident reporting application is licensed under the Integrated Risk Management (IRM) application family.

## Required and optional plugins {#workflow-confi-auto-trigger-inci-repo-cases__section_yb1_3kk_12c}

The Digital resilience incident reporting application is available from the ServiceNow Store. This section details its required and optional plugins.
{#workflow-confi-auto-trigger-inci-repo-cases__table_hsy_fkn_3hc__entry__2}

| Application name | Plugin |
|-|-|
| Document designer | (com.sn_grc_doc_design) |
| Digital Operational Resilience Management | (com.sn_app_grc_digital_resilience) |
| GRC | (app-grc) |
| GRC Base Workspace | (app-grc-base-workspace) |
| GRC: Compliance Case Management | (app-grc-case-mgmt) |
| GRC Operational Resilience | app-grc-operational-resilience (com.sn_grc_oper_res) |
| GRC: Policy and Compliance Management | (com.sn_compliance) |
| Regulatory Agency Library | (com.sn_reg_body_mgmt) |
| Reusable impact framework | (sn-reusable-impact-framework) |
| Smart Assessment impact automation | (app-smart-assessment-impact-automation) |
| Smart Assessment response automation | (app-smart-assessment-response-automation) |
| Smart Assessment Core | (sn_smart_asmt) |
| Smart Assessment designer | (sn_smart_asmt_desg) |
[Table 1. List of required plugins]

{#workflow-confi-auto-trigger-inci-repo-cases__table_hsy_fkn_3hc} {#workflow-confi-auto-trigger-inci-repo-cases__table_swm_53n_3hc__entry__2}

| Application name | Plugin |
|-|-|
| Security Incident Response | (app-sir) |
| Digital Resilience Third-party Information Register | (sn_info_reg) |
[Table 2. List of optional plugins]

{#workflow-confi-auto-trigger-inci-repo-cases__table_swm_53n_3hc}

*[\>]: and then


