---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Act on recommendations for control objectives

# Accept or dismiss recommendations for regulatory alert impacted control objectives {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Accept recommendations to mark specific business areas as impacted, helping compliance practitioners capture and address relevant regulatory alerts for control objectives. Dismiss recommendations to filter out irrelevant or
unnecessary information.

## Before you begin

Important:  
This Now Assist skill is turned on by default. The skill will be automatically available to appropriate role users for the application. For more information, see [Now Assist skills, agents, and agentic workflows on by default](https://www.servicenow.com/docs/access?context=now-assist-skills-on-by-default&version=yokohama&pubname=yokohama-intelligent-experiences&ft:locale=en-US).

Role required: To view your assigned regulatory alerts, you need the sn_grc_reg_change.user and sn_grc_comp_genai.reg_change_ai_user roles.

For more information on related roles and regulatory alerts, see [Types of alerts, user roles, and states of regulatory alerts](https://servicenow-prod.fluidtopics.net/69by3_lO3WwRzqaHxVX58Q "Different users perform various actions on the alert records based on the type of the alert.").  
Important:  
Be sure to check AI-generated recommendations for accuracy. If no information is available, the generated recommendations display "No recommendations available", "None", "No records to display", and so on.

## Procedure

1. Navigate to one of the following locations:  
   * WorkspacesCompliance Workspace, select the list icon ![]() and then navigate to Regulatory alerts.
   * WorkspacesCompliance Workspace select the Regulatory Change Management dashboard icon ![]() and then in the Activity overview, Tracking, or Trends section, select any segment or value in an Alerts related widget to open the list of regulatory alerts with that state.
   {#manage-recommend-co-reg-alert__ul_zck_crf_c2c}
2. Select the regulatory alert that you want and review the recommendations by selecting the Recommendations tab.  
   Note:  
   If recommendations haven't already been generated, you can generate recommendations for a regulatory alert in any state except Closed or Cancelled by completing one of the following.
   * On the Overview tab, select Recommend.
   * On the Recommendations tab, select Show recommendations.

   {#manage-recommend-co-reg-alert__ul_qqn_dnm_tgc}For more information, see [Generate recommendations for regulatory alert impacted citations, control objectives, controls, and policies](https://servicenow-prod.fluidtopics.net/UVan7RzyA2s4VylOo~EpmQ "Generate recommendations to identify and mark potential impact areas, such as citations, control objectives, controls, and policies for regulatory alerts using the corresponding regulatory alert impacted skill. Recommendations simplify the process of associating impacts and creating action tasks.").
3. Review potential impact areas by selecting the Control objectives tab in the Recommended areas of the impact section.  
   The recommended control objectives only include control objectives that are part of the existing inventory.

   Note:  
   The `Suggest business operations affected by regulatory alert recommendation context` provides the recommendations that you see here. For more information, see [Recommendation contexts and templates](https://servicenow-prod.fluidtopics.net/thMvPjB8pIt83g4xnyqyYQ "By using the Governance, Risk, and Compliance recommendations framework, you can use recommendation contexts and templates to deliver AI-driven insights directly to your users within the user interface. With these insights, your users can make informed decisions and take prompt actions.").  
   If recommendations are available, you can scroll through the generated list of control objectives recommendation cards and review the information about each control, such as its name and compliance status.
4. Select the control objectives recommendation card that you want and review the following sections:  
   {#manage-recommend-co-reg-alert__id_o2v_k4c_cfc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the control objective. |
   | Category | Business or technical domain for the control objective. |
   | Classification | Functional intent of the control objective. |
   | Type | Operational nature or domain of the control objective. |
   | Description | Description and summary of the control objective. |
   | Supplemental Guidance | Additional guidance on how to address the control objective. |
   | Evaluate Affected Associations ||
   | Child Control Objectives | Specific goal or requirement that is tied to this recommended parent control objective. For each child control objective, the following information is provided if available. * Reference * Name of the control objective * Category that the control objective is associated with * Classification for the control objective {#manage-recommend-co-reg-alert__ul_ehn_b4s_vgc} |
   | Policies | Related policies that can be associated with the control objective. For each policy, the following information is provided if available. * Number assigned to the policy * Name of the policy * Type of policy * State of the policy {#manage-recommend-co-reg-alert__ul_ycq_b4s_vgc} |
   | Controls | Related controls that can be associated with the control objective. For each control, the following information is provided if available. * Name of the control * Number assigned to the control * Entity that the control is associated with * Function of the control {#manage-recommend-co-reg-alert__ul_els_b4s_vgc} |
   | Risk Statements | Related risk statements that can be associated with the control objective. For each risk statement, the following information is provided if available. * Name of the risk statement * Framework that the risk is associated with * Risk statement category * Description of the risk statement. {#manage-recommend-co-reg-alert__ul_igx_b4s_vgc} |
   [ ]

   {#manage-recommend-co-reg-alert__id_o2v_k4c_cfc}

   For full descriptions of these fields, see [Create a control objective](https://servicenow-prod.fluidtopics.net/gIblu0oyLt7qED_NffDD7w "A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies."), [Create a policy](https://servicenow-prod.fluidtopics.net/vqncqI2kfHgB2xPtK9_qFA "A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates."), [Create a control](https://servicenow-prod.fluidtopics.net/kZOFgQ18ZccGuuES_xPulg "Controls are automatically generated when you associate a policy with an entity type or an entity type with a control objective. A control is created for each entity listed in the entity type for the control objective. Controls can also be manually created."), and [Create a risk manually](https://servicenow-prod.fluidtopics.net/fpj5Y~dr5GuZBA3J9K0mhg "Risk administrators can create risk records when they see a potential for a gain or loss of value.").
5. To associate child control objectives, policies, controls, or risk statements with your recommendation, navigate to the corresponding tab and select the check box for each record you want to include as part of the impacted areas.  
   Each selected record will be added as an impacted area after you accept the recommendation.  
   Note:  
   The control objective that you're reviewing may not have anything associated with it. Child control objectives, policies, controls, or risk statements must be mapped to control objectives in the inventory for them to appear.

6. **Optional:** View the record for a control objective, refresh your recommendations, or review related activity for each recommendation.

   | Option | Description |
   | Select the details icon ![](). | View the record for a control objective. |
   | Select the refresh icon ![](). | Refresh the recommendations to reflect the latest data. |
   | Select the summary icon ![](). | Open the Feedback trail side-panel to review the related activity for the recommendation. |
   |-|-|

   {#manage-recommend-co-reg-alert__choicetable_zwf_rnd_ngc}
7. Accept or dismiss the recommendations and their associations.
   * Select Accept and then Confirm to accept a recommendation as an impacted area.
   * Select Dismiss and then Confirm to avoid a recommendation from being shown again.

   {#manage-recommend-co-reg-alert__choices_p24_zqm_tgc}  
   Before you act on a recommendation, you see a summary of the impact areas and associations that you're accepting or dismissing.  
   If you accept the recommendation, it's marked as an impacted area and is added to the list of impacts. If you dismiss the recommendation, it's marked as dismissed and isn't shown again for that specific regulatory
   alert.

## What to do next

If you accepted any recommendations, confirm the creation of an impacted area by navigating to the Impacted areas tab. If you dismissed all recommendations or must add more impacted areas, you can manually add impacted areas.
For more information, see [Add impacted areas manually to a regulatory alert](https://servicenow-prod.fluidtopics.net/ZLHahiees6UEw0C57mARKA "Add impacted areas such as citations, control objectives, policies, and more to your regulatory alerts. Adding impacted areas to a regulatory alert captures additional impacts that you identified and impacts that weren’t initially recommended.").

*[\>]: and then


