---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Governance, Risk, and Compliance

# Governance, Risk, and Compliance {#ariaid-title1}

* Release version: Yokohama
* 
* Updated December 8, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 5 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Governance, Risk, and Compliance

ServiceNow Governance, Risk, and Compliance (GRC) provides an integrated risk program that connects business, security, and IT functions on a single platform.
It enables real-time response to business risks through continuous monitoring, automation, and unified risk management.
The solution transforms manual, siloed processes into streamlined, transparent, and efficient workflows that improve decision-making and organizational performance.
Show full answer Show less  

## Key Features

* **AI Risk and Compliance:** Manage AI capabilities ethically by mitigating AI risks and ensuring compliance.
* **Audit Management:** Use risk data to scope, prioritize, and automate audit plans, reducing costs and improving audit effectiveness.
* **Business Continuity Management:** Plan and execute disaster recovery and continuity efforts effectively, including during emergencies like pandemics.
* **Compliance Case Management:** Report, investigate, analyze, and resolve compliance issues efficiently.
* **Continuous Authorization and Monitoring:** Accelerate IT system onboarding with ongoing compliance monitoring.
* **Model Risk Management:** Identify and manage risks associated with models across their lifecycle.
* **Operational Resilience:** Gain real-time visibility into the resilience of technology, processes, people, and facilities.
* **Policy and Compliance Management:** Automate policy lifecycle management with continuous compliance monitoring and cross-mapping to regulations.
* **Privacy Management:** Manage enterprise-wide privacy risks and compliance in real time.
* **Regulatory Change Management:** Stay current with regulatory changes through integrations with leading content providers.
* **Risk Management:** Conduct detailed business impact analyses to prioritize and respond to enterprise and IT risks.
* **Smart Assessment Engine:** Automate risk assessment processes to reduce manual efforts and costs.
* **Third-party Risk Management:** Continuously monitor and mitigate risks in vendor ecosystems with automated assessments and reporting.

## Benefits and Practical Use

ServiceNow GRC helps organizations:

* Unify risk and compliance management across extended enterprises and vendors.
* Streamline and automate emergency response and business continuity efforts.
* Improve audit efficiency by leveraging risk data for audit planning and execution.
* Enhance vendor risk management through continuous monitoring and standardized remediation workflows.
* Maintain regulatory compliance by automating policy management and adapting to regulatory changes.
* Achieve better visibility and control over operational resilience and privacy risks.

## Getting Started

ServiceNow customers can work with implementation specialists to tailor GRC solutions to their needs and accelerate value realization. Additional expertise can be gained through ServiceNow training and certification programs. Customers can also explore and request GRC applications via the ServiceNow Store to extend their risk and compliance capabilities.  
Respond to business risks in real time. Connect security and IT with an integrated risk
program offering continuous monitoring, prioritization, and automation.

## Governance, Risk, and Compliance applications {#r_WhatIsGRC__section_xxs_dj1_pjb}

|-|-|-|
| [AI Risk and ComplianceLearn how you can use the AI Risk and Compliance application to manage your artificial intelligence (AI) capabilities ethically, mitigate AI risks, and ensure compliance.](https://servicenow-prod.fluidtopics.net/Jk9rrmY54ahd45G~K_yF9w "The ServiceNow AI Risk and Compliance application, along with the ServiceNow AI Control Tower, enables the risk and compliance managers to ensure that the organizations comply with the regulations and policies with respect to their AI systems.") | [Audit Management Use risk data to scope and prioritize audit plans and automate cross-functional processes.](https://servicenow-prod.fluidtopics.net/FUVVUveHilSQk4Ow~YCMyQ "The ServiceNow Audit Management application involves a set of activities related to planning audit engagements, executing engagements, and reporting findings to the audit committee and executive board. Engagement reporting assures key stakeholders that the organization's risk and compliance management strategy is effective.") | [Business Continuity Management Plan, exercise, and recover from disasters effectively and efficiently.](https://servicenow-prod.fluidtopics.net/fufvIpb1A5123LVHe2QoWQ "ServiceNow Business Continuity Management application gives your organization the capability to continue to deliver products and services at an acceptable level when a disruptive incident occurs. The ongoing activities of this application are aimed to reduce the operational risks and improve your organizational ability to respond, react, and recover from issues and disruptions.") |
| [Compliance Case Management Report, investigate, analyze, and resolve compliance cases.](https://servicenow-prod.fluidtopics.net/QGbsCHFmmeWVWOhdf5Jmtw "Report, investigate, analyze, and resolve a compliance case or raise a compliance request by using the ServiceNow GRC: Compliance Case Management application.") | [Continuous Authorization and Monitoring Accelerate the process of bringing IT systems online and continuously monitoring them.](https://servicenow-prod.fluidtopics.net/s5uGqPgL9j543l_fdj99WQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.") | [Model Risk Management![]()Learn how you can use the Model Risk Management application to identify, assess, validate, and address risks associated with a model throughout their life-cycle.](hWSrMO21WhniM0NCYtwV4A "The ServiceNow Model Risk Management application enables you to identify, assess, validate, and address risks associated with a model throughout their life cycle.") |
| [Operational Resilience Gain real-time visibility into the resilience of your technology, people, processes, and facilities.](https://servicenow-prod.fluidtopics.net/_vXQtg01J3xdS0BWteHdJQ "Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.") | [Policy and Compliance Management Automate and manage policy life-cycles and continuously monitor for compliance.](https://servicenow-prod.fluidtopics.net/R76eUDFdwZNZaPnjB33vhg "The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.") | [Privacy Management Manage privacy risk and compliance across the enterprise in real time.](https://servicenow-prod.fluidtopics.net/jdKTQVNge4MJ1AjtxyzNVw "Use the Governance, Risk, and Compliance: Privacy Management application to help protect your customers, employees, and suppliers with integrated data privacy risk and compliance management solutions and privacy by design concepts​.") |
| [Regulatory Change Management Keep pace with today's complex regulatory landscape with integration to leading content providers.](https://servicenow-prod.fluidtopics.net/6calg1ciPHXvMjAd4_IK7w "The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application verifies the overall regulatory compliance for your organization.") | [Risk Management Enable fine-grained business impact analysis to appropriately prioritize and respond to risks.](https://servicenow-prod.fluidtopics.net/OaXBo9RlzLQBW9S8XV1rwQ "Use the Governance, Risk, and Compliance: Risk Management application to continuously monitor to identify high-impact risks, improve your risk-based decision-making, and reduce reaction time effectively. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.") | [Smart Assessment EngineReduce the manual burden and costs of your risk assessment processes through automation.](https://servicenow-prod.fluidtopics.net/SPXuZ6CpdMRckr9i3A89eA "The ServiceNow Smart Assessment Engine (SAE) application helps you to reduce the manual burden and costs of your assessment processes through automation.") |
| [Third-party Risk Management Continuously monitor, detect, assess, mitigate, and remediate risks in third-party ecosystems.](https://servicenow-prod.fluidtopics.net/Xh9_5RKfLpV9sXlwyJ3Gzg "The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.") | Common GRC features[Leverage the power of entities, 360 degree views, the tasks landing page, and security features across GRC products.](https://servicenow-prod.fluidtopics.net/NyyXoC4sI0DGVkS7SYkfJQ "Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.") |   |
[ ]

{#r_WhatIsGRC__table_iwv_lpv_klb}

## Request apps on the Store {#r_WhatIsGRC__section_tcm_hsr_ckb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#r_WhatIsGRC__inline-send-to-store}

## Respond to business risks in real time with ServiceNow
GRC {#r_WhatIsGRC__section_kys_xfv_rjb}

ServiceNow
Governance, Risk, and Compliance (GRC) helps transform inefficient processes
across your extended enterprise into an integrated risk program. Through continuous
monitoring and automation, the GRC applications deliver a real time
view of compliance and risk, improve decision making, and increase performance across your
organization and with vendors.

Only ServiceNow applications can connect the business, security, and
IT with an integrated risk framework that transforms manual, siloed, and inefficient
processes into a unified program that is built on a single platform.

[View and download the full info card](https://downloads.docs.servicenow.com/resource/enus/infocard/grc_statcard_infographic.pdf) for a highlight
of GRC features.

|-|-|
| ![Emergency Response Management]() | Streamline and automate activities in the face of an emergency :   Mobilize your business continuity efforts during natural disasters and pandemics like COVID-19. |
| ![Automate and manage]() | Automate and manage policy life cycles and continuously monitor for compliance. :   It makes perfect sense to embrace a single platform that can make all compliance efforts more organized, simpler, more transparent, and highly reliable. |
| ![Risk Management]() | Enable fine-grained business impact analysis to appropriately prioritize and respond to risks. :   Respond to business risks in real-time with integrated risk management. |
| ![Audit Management]() | Use risk data to scope and prioritize audit plans and automate cross-functional processes. :   Reduce audit costs, improve efficiency, and minimize risk. |
| ![Vendor Risk Management]() | Continuously monitor, detect, assess, mitigate, and remediate risk in vendor ecosystems. :   As your vendors become privy to more of your sensitive systems and data, their risk and compliance posture becomes even more important to your security. It's important to assess your vendors regularly and proactively mitigate any issues that arise. |
[ ]

{#r_WhatIsGRC__table_uw5_lxw_sjb}

## Automate and manage policy life cycles and continuously monitor for compliance {#r_WhatIsGRC__section_tzz_1kr_qjb}

The ServiceNow® Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures. The process automatically cross-maps the procedures to external regulations. Also, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.{#r_WhatIsGRC__ph_PCMgmtDescrip}

## Enable fine-grained business impact analysis to appropriately prioritize and respond to risks {#r_WhatIsGRC__section_jzr_jmr_qjb}

The ServiceNow
Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides
structured workflows for the management of risk assessments, risk indicators, and risk issues.

## Use risk data to scope and prioritize audit plans and automate cross-functional processes {#r_WhatIsGRC__section_z1v_jkr_qjb}

The ServiceNow
Audit Management product automates the work streams of internal audits teams, optimizing resources and productivity, and eliminating recurring audit findings. Audit Management uses compliance and risk data to scope, plan, and prioritize audit engagements. The ongoing review of policies and procedures, risks, and control breakdowns provide an opportunity for fixing issues
before they become audit failures.

The ServiceNow
Regulatory Change Management application empowers the customers to check upcoming regulatory changes, assess their impact, and implement risk and compliance related changes, ensuring overall regulatory
compliance.

## Continuously monitor, detect, assess, mitigate, and remediate risk in vendor ecosystems {#r_WhatIsGRC__section_v2b_jy1_yjb}

As your vendors become privy to more of your sensitive systems and data, their risk and compliance posture becomes even more important to your security. It's important to assess your vendors regularly, but until now, it has been
a time-consuming and error-prone exercise comprised of spreadsheets, email, and rudimentary legacy risk management tools.

The Vendor Risk Management application transforms the way you manage vendor risk through vital reporting of vendor risk and issues, a consistent assessment and remediation process, and automated assessment procedures. It
provides a means to facilitate stakeholder interactions, drive transparency and accountability, and effectively monitor vendor-related risks.

By aligning Vendor Risk Management with overall enterprise risk management priorities, you can create an essential integrated view of risk and a stronger extended enterprise risk posture.

## Learn {#r_WhatIsGRC__section_nkg_gl3_5rb}

* [What is a business continuity plan?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-business-continuity-plan.html)
* [What is business resilience?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-business-resilience.html)
* [What is Compliance Management?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-compliance-management.html)
* [What is GRC?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-grc.html)
* [What is operational resilience?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-operational-resilience.html)
* [What is operational risk management?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-operational-risk-management.html)
* [What is ransomware?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-ransomware.html)
* [What is third party risk management (TPRM)?](https://www.servicenow.com/products/governance-risk-and-compliance/what-is-third-party-risk-management.html)
{#r_WhatIsGRC__ul_q4v_hl3_5rb}

## Get started {#r_WhatIsGRC__section_pqm_vfr_qjb}

* Work with an implementation specialist to achieve your desired business outcomes. To learn more, visit the [Customer Success Center](https://www.servicenow.com/success.html).
* Take a Governance, Risk, and Compliance course to build expertise and realize ROI faster. To sign up, see [ServiceNow training and certification](https://www.servicenow.com/services/training-and-certification.html).
{#r_WhatIsGRC__ul_bpv_zmr_sjb}

## Applications and features {#r_WhatIsGRC__section_vpq_1j1_pjb}

* [AI Risk and Compliance](https://servicenow-prod.fluidtopics.net/Jk9rrmY54ahd45G~K_yF9w "The ServiceNow AI Risk and Compliance application, along with the ServiceNow AI Control Tower, enables the risk and compliance managers to ensure that the organizations comply with the regulations and policies with respect to their AI systems.")
* [Audit Management](https://servicenow-prod.fluidtopics.net/FUVVUveHilSQk4Ow~YCMyQ "The ServiceNow Audit Management application involves a set of activities related to planning audit engagements, executing engagements, and reporting findings to the audit committee and executive board. Engagement reporting assures key stakeholders that the organization's risk and compliance management strategy is effective.")
* [Business Continuity
  Management](https://servicenow-prod.fluidtopics.net/fufvIpb1A5123LVHe2QoWQ "ServiceNow Business Continuity Management application gives your organization the capability to continue to deliver products and services at an acceptable level when a disruptive incident occurs. The ongoing activities of this application are aimed to reduce the operational risks and improve your organizational ability to respond, react, and recover from issues and disruptions.")
* [Compliance Case Management](https://servicenow-prod.fluidtopics.net/QGbsCHFmmeWVWOhdf5Jmtw "Report, investigate, analyze, and resolve a compliance case or raise a compliance request by using the ServiceNow GRC: Compliance Case Management application.")
* [Continuous Authorization and Monitoring](https://servicenow-prod.fluidtopics.net/s5uGqPgL9j543l_fdj99WQ "Continuous Authorization and Monitoring (CAM) employs the seven steps defined by the NIST Risk Management Framework (RMF) to allow you to make better-informed decisions about your security posture.")
* [Model Risk Management](https://servicenow-prod.fluidtopics.net/hWSrMO21WhniM0NCYtwV4A "The ServiceNow Model Risk Management application enables you to identify, assess, validate, and address risks associated with a model throughout their life cycle.")
* [Operational Resilience](https://servicenow-prod.fluidtopics.net/_vXQtg01J3xdS0BWteHdJQ "Operational Resilience is the ability of an organization to respond to the adverse operational events by anticipating, preventing, recovering from, and adapting to such events.")
* [Policy and Compliance
  Management](https://servicenow-prod.fluidtopics.net/R76eUDFdwZNZaPnjB33vhg "The ServiceNow Policy and Compliance Management product provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and benchmarks. Additionally, the application provides structured workflows for the identification, assessment, and continuous monitoring of control activities.")
* [Privacy Management](https://servicenow-prod.fluidtopics.net/jdKTQVNge4MJ1AjtxyzNVw "Use the Governance, Risk, and Compliance: Privacy Management application to help protect your customers, employees, and suppliers with integrated data privacy risk and compliance management solutions and privacy by design concepts​.")
* [Regulatory Change
  Management](https://servicenow-prod.fluidtopics.net/6calg1ciPHXvMjAd4_IK7w "The ServiceNow Regulatory Change Management application enables you to check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes. The application verifies the overall regulatory compliance for your organization.")
* [Risk Management](https://servicenow-prod.fluidtopics.net/OaXBo9RlzLQBW9S8XV1rwQ "Use the Governance, Risk, and Compliance: Risk Management application to continuously monitor to identify high-impact risks, improve your risk-based decision-making, and reduce reaction time effectively. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.")
* [Smart Assessment Engine](https://servicenow-prod.fluidtopics.net/SPXuZ6CpdMRckr9i3A89eA "The ServiceNow Smart Assessment Engine (SAE) application helps you to reduce the manual burden and costs of your assessment processes through automation.")
* [Third-party Risk Management](https://servicenow-prod.fluidtopics.net/Xh9_5RKfLpV9sXlwyJ3Gzg "The ServiceNow GRC: Third-party Risk Management (TPRM) application enables you to proactively identify, assess, and mitigate risks that are associated with your third-party relationships. TPRM provides a centralized process for managing your portfolio of third parties, assessing and scoring risk, and performing remediation.")
* [GRC and the ServiceNow
  Store](https://servicenow-prod.fluidtopics.net/QUIvx1Dk9V7333VQqcErUA "All GRC applications are available from the ServiceNow Store, allowing you to obtain new and updated features more rapidly. Before you can use any GRC applications, you must verify that you have entitlement to them (that is, you have valid licenses to use them). Then, you can download them from the ServiceNow Store and activate them.")
* [Common GRC Features](https://servicenow-prod.fluidtopics.net/NyyXoC4sI0DGVkS7SYkfJQ "Each Governance, Risk, and Compliance application has unique features and capabilities. Additionally, there are many features that are common to all GRC applications.")
{#r_WhatIsGRC__ul_od3_cj1_pjb}

