---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create an authorization package

# Create an authorization package {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you have defined the authorization boundaries for the assets or systems to send through the Authorization to Operate process, you must create an authorization package for that purpose. The package is processed through the seven steps mandated by the RMF.

## Before you begin

Role required: sn_irm_cont_auth.system_owner or sn_irm_cont_auth.admin  
Note:  
The roles are required for accessing the authorization package only after it has transitioned beyond the Prepare state.

## Procedure

1. Navigate to AllContinuous Authorization \& MonitoringAll Authorization Packages.  
2. Select New and then fill in the form.  
   The settings are described in [Fields on the Authorization Package form](https://servicenow-prod.fluidtopics.net/Kyw~qHOnYsGbUud0yPlT0g "After you have defined the authorization boundaries for the assets or systems to send through the Authorization to Operate process, you must create an authorization package for that purpose. The package is processed through the seven steps mandated by the RMF.").
3. Select the Roles and Responsibilities tab and specify the responsibilities of various stakeholders during the review and approval process.  
   The settings are described in [Fields on the Roles and Responsibilities tab](https://servicenow-prod.fluidtopics.net/G1gSkqSYTY7VPxgz9He0vg "On the Roles and Responsibilities tab, you specify the responsibilities of various stakeholders during the review and approval process.").
4. Select the PTA/PIA tab and perform the Privacy Threshold Analysis by answering the questions.  
   The PTA identifies whether various types of the Personal Identifiable Information (PII) exist in the systems being authorized.
5. If you answered No to all of the questions, you are not required to take a Privacy Impact Analysis and can select Submit.
6. If you answered Yes to any of the questions, you must take a Privacy Impact Analysis.
   1. In the Assessment respondents field, select the lock icon and select the users you want to take the assessment.
   2. When you have selected the respondents, select the lock icon again.
   3. Select Submit.  
      The assessment request notification is sent to the selected respondents.
   4. When the PIA has been completed, the assessment responses appear in a related list in the Authorization Package form.
7. Select the Notes and Comments tab to add any customer-facing notes to the package.
8. Select Categorize to transition the package to the next step

*[\>]: and then


