---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Entity scoping

# Entity scoping in GRC {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Entity scoping is permitted in each of the core GRC applications. Scoping provides a way to allocate risks and controls at different levels. Dependencies are created using the dependency map in the GRC Workbench.

## Entity scoping overview {#c_Scoping__section_c1b_tbh_f3b}

Note:  
Starting with the New York release, the term profile was replaced with the term entity. See [Governance, Risk, and Compliance application nomenclature updates and industry terminology](https://servicenow-prod.fluidtopics.net/0r2UK1No2RWQxJX6dLKYUg "The following terms are used within GRC applications and/or within the GRC industry.") for more information about all updated GRC application terms.

Organizations have various control owners maintaining individual files and spreadsheets for tracking the compliance of different systems, projects, organizations, etc. In this environment, risk managers cannot prevent or even be
aware of the duplicate risks and controls created on shared entities. The entire purpose of entity scoping is to provide a top-down approach for maintaining your risk universe, which is the hierarchical library of both risks and controls. Mature organizations with a healthy risk posture find that most risks are standard and recurring. Entity scoping helps you catalog and visualize upstream and downstream risks and controls based on
the roll up of the related entities.  
Figure 1. From an organic approach to a structured system

1. Create or edit Entity Types and map them using the Entity Filter to existing ServiceNow® tables.
2. Map these entity types to external regulations and internal policies using control objectives and risk statements.
3. Generate risk and control instances on related entities.
4. Maintain your risk appetite and scoring results by the aggregated calculation for entities; all combos for risk scores on risk roll up.

{#c_Scoping__ol_rlz_fch_f3b} Figure 2. Scoping process
* **[Generate risks and controls from entity types](https://servicenow-prod.fluidtopics.net/aHJ8w8VQ4cz5hLB27D02eg)**   
  Create and edit entity types and map them to existing ServiceNow® tables for which you must track compliance (applications, departments, regions, processes, systems, etc.). Entities are assigned to control objectives and risk statements, which generate controls and risks for every entity type.
* **[Create independent entities](https://servicenow-prod.fluidtopics.net/QnD2Lg17fPaZCCSMOGxjhw)**   
  Entities can be created manually, rather than generating them from the entity types. Entities can also be created without needing to refer to an existing ServiceNow® table, like assets, applications, business services, or processes.
* **[Relate entities to each other](https://servicenow-prod.fluidtopics.net/zLFcrSod72j595F~ARRF1w)**   
  Create relationships between entities to understand how controls and risks affect each other and how they affect the enterprise.

