---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Regulatory process flow and tasks

# Regulatory process flow and tasks {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Regulatory process flow and tasks

The Regulatory Change Management (RCM) process flow enables organizations to effectively manage and comply with regulatory changes by coordinating tasks across different user roles.
Regulatory alerts are sourced from external providers such as RSS feeds or subscription services like Thomson Reuters Regulatory Intelligence (TRRI), which aggregate relevant regulatory updates applicable to the organization.
Show full answer Show less  

## Key Features

* **User Roles:** The application defines specific roles including RCM Administrator, RCM Manager, RCM User/Coordinator, Business User, Risk Manager, and Compliance Manager, each with distinct responsibilities in managing regulatory changes.
* **Integration Setup:** Organizations can subscribe to public regulatory RSS feeds or curated intelligence providers to receive regulatory alerts.
* **Taxonomy Configuration:** Internal taxonomy elements allow organizations to classify regulatory content hierarchically for better categorization and management.
* **Review and Assignment:** RCM Managers review regulatory alerts and assign them to coordinators (RCM Users) who further assess applicability and impact.
* **Impact Assessment:** Subject Matter Experts with business user roles assess the impact of regulatory changes and provide scores to the RCM application.
* **Action Plan Development:** Coordinators devise compliance action plans, create related tasks for various teams, and submit for managerial approval.
* **Task Completion and Tracking:** Compliance and risk managers oversee the approval and completion of action tasks. Tasks are tracked with due dates until closure.

## Key Outcomes

* Streamlined process for receiving, assessing, and responding to regulatory changes ensuring timely compliance.
* Clear role-based task assignments that improve accountability and coordination within regulatory change management.
* Effective impact assessment and classification of regulatory updates tailored to organizational needs.
* Robust tracking of compliance action tasks with visibility for risk and compliance managers, facilitating closure of regulatory changes once completed.  
The Regulatory Change Management process flow includes the tasks that different users can perform to help your organization manage and comply with regulatory changes.

Regulatory alerts are sourced from the external providers that provide the data as regulatory alerts. The alert may be received as Really Simple Syndication (RSS) feeds or from an external provider such as the Thomson Reuters Regulatory Intelligence (TRRI). The Regulatory Change Management application receives the new regulatory changes that are applicable to an organization.

The Regulatory Change Management application has the following user roles:  
* RCM administrator: A user who has the sn_grc_reg_change.admin role.
* RCM Manager: A user who has the sn_grc_reg_change.manager role.
* RCM User or coordinator: A user who has the sn_grc_reg_change.use role. This user ensures that the regulatory changes are assigned to the correct teams and that the changes are completed in time.
* Business user role: A user who has the sn_grc.business_user role.
* Risk or Compliance manager: A user who has the sn_risk.manager or sn_compliance.manager role. This user would perform the changes as part of the Regulatory Change Management application.

{#reg-change-workflow-swimlane__ul_m35_q4v_nqb}For more information about the roles, see [User roles in Regulatory Change Management](https://servicenow-prod.fluidtopics.net/TTkuVqn3N9CrWiXQlLE~PA "Stakeholders in the Regulatory Change Management (RCM) application have different roles and responsibilities.").

## Regulatory Change Management process flow {#reg-change-workflow-swimlane__section_vkl_svc_d2c}

The following infographic shows the Regulatory Change Management process flow.  
Figure 1. Regulatory Change Management process flow and tasks performed by different users

The steps to complete the Regulatory Change Management process flow are:

1. Set up the integration. Your customers can subscribe to a public RSS feed for the regulatory bodies or they can subscribe to a subscription provider such as TRRI that is a curated intelligence provider. A subscription provider can aggregate the regulatory changes from different sources and provide the collective changes as feeds.
2. Set up an internal taxonomy. The taxonomy elements are the different classifiers that an organization can apply to its regulatory content to categorize it. You can use taxonomy elements to create a hierarchical structure of different classifications for setting up the regulatory content for an organization.
3. Review a regulatory alert. A user with the sn_grc_reg_change.manager role (RCM manager) reviews a regulatory alert and assigns it to a coordinator or a user with the sn_grc_reg_change.user role (RCM user). The user with the sn_grc_reg_change.user role reviews the alert. If the regulatory change requires an impact assessment, the RCM user sends it to a subject matter expert (SME) with a business user role.
4. Assess the impact. The subject matter expert (SME) with a business user role assesses the impact of the regulatory change and sends the score of the impact assessment to the Regulatory Change Management application. If the alert is not applicable to the organization, the RCM user closes the alert. If the alert is applicable to the organization, the RCM user creates a new regulatory change task and assigns it to the same or a new coordinator.
5. Devise an action plan. The coordinator identifies the steps to comply with the regulatory change, devises an action plan, and creates the action tasks for the different teams that need to complete the identified action items. The coordinator then creates the action tasks that are associated with the regulatory change task. After the action plan is created, it's sent to the RCM manager for an approval. The manager reviews the action plan and confirms if more action tasks need to be created or if some of the action tasks aren't necessary.
6. Complete the action tasks. The compliance analyst sends the actions for approval to a user with the sn_grc_reg_change.manager role (RCM manager). If the action plan is rejected, the coordinator goes through the action plan, updates the actual tasks, and sends the action plan back for an approval. The compliance manager can see all compliance-based action tasks and the risk manager can see all the risk-based action tasks. After the tasks are assigned to the risk and compliance users, the action tasks are tracked until they are completed. A due date is marked and tracked for the action tasks. When the tasks are completed, the regulatory alert and the parent regulatory change tasks are closed and the change process flow is completed.
{#reg-change-workflow-swimlane__ol_j1d_drv_nqb}
**Related concepts**   

* [Regulatory Change Management application landing page](https://servicenow-prod.fluidtopics.net/E~0_CAc63YSMYDrjoZhF7A "The Regulatory Change Management application landing page view provides the overview of the regulatory activities in your organization. Users with the sn_grc_reg_change.manager roles only can view the Regulatory Change Management landing page in the primary navigation in the Compliance Workspace.")
* [Tasks page in the Compliance Workspace](https://servicenow-prod.fluidtopics.net/0uZJDwJzEQNKMMsxpHB3FQ "The Tasks page within the Compliance Workspace provides a centralized, task-centric interface for managing all activities related to regulatory events, source documents, and compliance workflows. It helps you stay organized, ensures timely and accountable action, and promotes overall regulatory readiness.")
* [Source document import tasks](https://servicenow-prod.fluidtopics.net/ylE4TdF14ymeU4oK~wlOwg "The Regulatory Change Management application processes external alerts that may include citation titles, citation numbers, and references to legislative or regulatory materials relevant to compliance.")
* [RSS feeds overview](https://servicenow-prod.fluidtopics.net/9lnEl~Kxw~wJJ9XpWWoqIw "A Really simple syndication (RSS) feed in Regulatory Change Management is like a subscription service for updates about new or changed rules and regulations. Instead of visiting multiple websites to check for updates, you can subscribe to feeds from regulatory bodies or industry news.")
* [Impact assessments for the regulatory alerts](https://servicenow-prod.fluidtopics.net/wEfYcMNZSIAk92vuljb4lA "A regulatory event alert may result in a regulatory change to an organization. You can evaluate the impact of the regulatory change on your organization by performing impact assessments.")
* [Regulatory assessment for a regulatory alert](https://servicenow-prod.fluidtopics.net/GMH4yLzn_kcxxZ41LGyoig "Utilize the Smart Assessment Engine to perform smart assessments on regulatory alerts. This ability enhances regulatory decision-making by enabling impact assessments directly at the regulatory alert level, streamlining processes through a unified core assessment framework, and assigning analysis to multiple stakeholders for improved collaboration and efficiency.")
* [Next Experience Discuss and Chat Collaboration](https://servicenow-prod.fluidtopics.net/aQcU7xu5_1a_XzFnTCEaxg "On a regulatory change management case, select Discuss from other options. Collaborate with virtual agents by using Next Experience Chat Collaboration and Discuss.")
* [Regulatory Change Management application in the Compliance Workspace](https://servicenow-prod.fluidtopics.net/lxW4gcNtqIwoAMFxYcU39A "Starting with GRC: Regulatory Change Management, version 13.0.1, the Regulatory Change Management application is available in Compliance Workspace. Compliance Workspace provides your users with a single-pane view so that they can check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes for the organization.")
* [Exploring Now Assist in Regulatory Change Management (RCM)](https://servicenow-prod.fluidtopics.net/8QK3VpRq6YAxfbtxpqVmDQ "With Now Assist in Regulatory Change Management, part of the ServiceNow Otto for Integrated Risk Management (IRM) application, you can use agentic workflows and generative AI skills that streamline the analysis, summarization, and impact assessment of regulatory alerts. These capabilities empower compliance teams to act swiftly and accurately on regulatory changes.")

