---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Implement setup checklist for the GRC: Policy and Compliance Management application

# Implement setup checklist for the GRC: Policy and Compliance Management application {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

This checklist includes the setup tasks that you are required to complete in your ServiceNow AI Platform® instance. When you have completed these tasks, the base
system is ready for operation. Optional setup procedures are also included to enhance GRC: Policy and Compliance Management functionality.

## Before you begin

Role required: sn_compliance.admin, sn_compliance.manager

Consider creating and
printing a PDF of this checklist topic. You can then check off tasks as you complete
them.

## Procedure

To generate a PDF, click the Save As PDF icon (![Save as PDF icon]()) at the top of the topic and click Selected topic.  
{#policy-compliance-impl-checklist__table_lqq_1qt_rhb__entry__2}

| Item | Description |
|-|-|
| ![check box.]() | As a user with the Compliance Administrator or Compliance Manager role, verify that you have the GRC core applications installed on a ServiceNow AI Platform instance. Note: The GRC core applications and the ServiceNow AI Platform instance should be from the same family release. 1. To verify the GRC: GRC Profile Dependencies core application is installed on your instance, navigate to Plugins and search for GRC Profile. 2. If the GRC Profile core application is not already installed, click Install to install it. 3. After the GRC Profile application is installed, install the Policy and Compliance Management core application. {#policy-compliance-impl-checklist__ol_s3w_qyz_c3b} If Policy and Compliance Management is not visible in your instance, all of the GRC core applications are available from the ServiceNow Store. For more information about getting entitlement, downloading, and installing the GRC core applications, see [GRC and the ServiceNow Store](https://servicenow-prod.fluidtopics.net/QUIvx1Dk9V7333VQqcErUA "All GRC applications are available from the ServiceNow Store, allowing you to obtain new and updated features more rapidly. Before you can use any GRC applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them). Then, you can download them from the ServiceNow Store and activate them."). |
| ![check box.]() | As a user with the Compliance Administrator role, in your ServiceNow AI Platform instance, verify that you have assigned users with the required ServiceNow AI Platform roles. For detailed instructions and a list of Policy and Compliance Management roles, see [Assign Policy and Compliance Management roles to your users](https://servicenow-prod.fluidtopics.net/QsDrNCbpWHtTF5fClm1WHQ "Before you can successfully implement or use the Policy and Compliance Management application, you must assign roles to your users."). |
| ![check box.]() | As a user with the Compliance Administrator role, set Policy and Compliance Management properties to control various behaviors in the system. For example, you can define states for which a control is active or inactive. For detailed instructions, see [Set Policy and Compliance Management properties](https://servicenow-prod.fluidtopics.net/KsSEIFhZl~Emri9Zl78PwA "Set properties to control various aspects and behaviors in the software."). |
| ![check box.]() | As a user with the Compliance Administrator or Compliance Manager role, create policies. A policy is a document that defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates. For detailed instructions, see [Create a policy](https://servicenow-prod.fluidtopics.net/vqncqI2kfHgB2xPtK9_qFA "A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates."). |
| ![check box.]() | As a user with the Compliance Administrator or Compliance Manager role, create control objectives. A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. They can be categorized, classified, and related to policies. For detailed instructions, see [Create a control objective](https://servicenow-prod.fluidtopics.net/gIblu0oyLt7qED_NffDD7w "A control objective is an objective, direction, or standard that acts as guidance for company interactions and operations. Control objectives can be categorized, classified, and related to policies."). |
| ![check box.]() | As a user with the Compliance Administrator or Compliance Manager role, relate control objectives to policies. You can associate control objectives to a policy individually when the policy is in the Review or Draft state. For detailed instructions, see [Relate a control objective to a policy](https://servicenow-prod.fluidtopics.net/AFgWMJh0l0tXVh1Ou9zoVg "Associate the control objective to a policy individually when the policy is in the review or draft state by clicking the edit button in the Control Objective related list."). |
| ![check box.]() | As a user with the Compliance Administrator, Compliance Manager, or Attestation Creator role, create an attestation. The Attestation Designer allows you to create and edit metric types, as well as define different metric types for different controls. For detailed instructions, see [Create a control attestation using the Attestation Designer](https://servicenow-prod.fluidtopics.net/aN_ZEYxMGlDZjbsgO3Td3A#create-attestation-using-attestation-designer "Use the Attestation Designer to create and edit metric types. Use different metric types for different controls. Select multiple respondents for an attestation, as well as change scoring parameters."). |
| ![check box.]() | As a user with the Compliance Administrator or Compliance Manager role, create control indicators. Indicator data for controls, risk, and audit evidence are measured differently depending on the GRC application. For detailed instructions, see [Create a control indicator](https://servicenow-prod.fluidtopics.net/Ef~dnYBfbij_K3k~M5J9rQ#create-control-indicator "Indicator data for controls, risk, and audit evidence are measured differently depending on the GRC application."). |
[Table 1. GRC: Policy and Compliance Management application checklist]

{#policy-compliance-impl-checklist__table_lqq_1qt_rhb}

Congratulations! You have successfully set up the GRC: Policy and Compliance Management base system. Depending on the needs of
your organization, optional setup procedures are available. For example, if
you integrate with Network Frontiers Unified Compliance Framework (UCF),
procedures for managing the integration are here. Or if you want to set up
the mobile experience for GRC: Policy and Compliance Management, those
procedures are also here.

For detailed instructions for optional features, see [Policy and Compliance Management enhancement steps](https://servicenow-prod.fluidtopics.net/NILNi55ZfEVVMaWMgzUP7w "After you have set up the Policy and Compliance Management base system, you can perform the procedures listed in the following sections to enhance the functionality of the application.").

