---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Explore

# Exploring Regulatory Change Management {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring Regulatory Change Management

The Regulatory Change Management (RCM) application in ServiceNow provides a structured framework to help organizations efficiently manage regulatory changes by integrating with third-party regulatory intelligence providers.
This integration enables continuous monitoring of regulatory alerts, assessment of their applicability and impact, and the implementation of necessary compliance and risk-related changes.
Show full answer Show less  
RCM supports organizations in maintaining regulatory compliance through a workflow that includes taxonomy management, regulatory alert integration, event triage, impact assessment, change management, and compliance reporting.

## Key Features

* **Integration with Regulatory Intelligence Providers:** Connect your ServiceNow instance to external sources like Thomson Reuters Regulatory Intelligence to consume regulatory alerts automatically.
* **Internal Regulatory Taxonomy:** Create and map internal classification elements (Content Type, Jurisdiction, Regulatory Body, Sector, Theme) to standardize and organize regulatory content in alignment with external taxonomies.
* **Regulatory Alert Management and Triage:** Users with specific roles (RCM manager and RCM user) review and assign regulatory alerts, determining their relevance and need for impact assessments.
* **Impact Assessment:** Subject matter experts assess the impact of regulatory changes using configurable methodologies, with AI-powered recommendations available to support decision-making.
* **Change Management and Action Plans:** Coordinators devise and assign action tasks to relevant teams, track progress, and seek approvals from managers to ensure regulatory compliance steps are implemented effectively.
* **Reporting and Dashboards:** Monitor compliance status, maintain audit trails, and generate reports to assess organizational readiness and regulatory adherence.
* **Compliance Workspace Integration:** RCM is accessible via the Compliance Workspace, offering a centralized view to monitor regulatory activities and manage tasks efficiently.
* **Advanced AI Capabilities:** Leverage Now Assist for agentic workflows and generative AI to streamline analysis, summarization, and impact assessment of regulatory alerts, enhancing compliance team responsiveness.

## Practical Workflow

* Set up integration with regulatory content providers to receive alerts.
* Establish an internal taxonomy to classify and organize regulatory information.
* Review and triage incoming alerts to identify relevant regulatory events.
* Perform impact assessments with subject matter experts, utilizing AI recommendations if available.
* Create regulatory change tasks and develop detailed action plans for compliance updates.
* Assign and track action tasks through completion, with managerial oversight and approval.
* Close regulatory alerts and tasks once compliance activities are completed successfully.

## Benefits for ServiceNow Customers

By using the Regulatory Change Management application, ServiceNow customers can:

* Stay proactively informed about regulatory changes through integrated, automated alert consumption.
* Standardize regulatory content classification to improve clarity and consistency.
* Streamline regulatory impact assessments and compliance workflows, reducing manual effort.
* Improve collaboration among regulatory, risk, and compliance teams with defined roles and task management.
* Utilize AI-powered insights to accelerate and enhance decision-making processes.
* Maintain comprehensive audit trails and reporting for regulatory compliance verification.
* Access a unified workspace to monitor and manage all regulatory change activities efficiently.  
The Regulatory Change Management application provides a framework that your organization can use to integrate with third-party regulatory intelligence providers to keep up with the regulatory changes and external
regulations.

## Regulatory Change Management overview {#what-is-rcm__section_es4_l3d_wmb}

The Regulatory Change Management application enables you to manage your upcoming regulatory changes efficiently. The application provides the structured workflows that help your organization to assess the applicability
of the regulatory changes, assess their impact, and implement risk and compliance-related changes.

The following infographic shows the process flow of the Regulatory Change Management application.  
Figure 1. Process flow of the Regulatory Change Management application

The Regulatory Change Management application works with the following types of components:

* Integration component: The regulatory intelligence partners typically provide the integration component. Through this integration, you can consume regulatory alerts into your instance.
* Application framework component: The Regulatory Change Management application has an application framework component. This component provides the structured workflows that you can use to analyze and process the regulatory alerts that are received in the regulatory alerts table.

{#what-is-rcm__ul_w2j_qkb_hnb}  
The Regulatory Change Management application consists of the following workflow:

1. Manage regulatory taxonomy: Create an internal regulatory taxonomy that is specific to the ServiceNow AI Platform. You can map the taxonomy with the external taxonomies that are provided by the third-party regulatory intelligence providers for standardization. The internal taxonomy contains the following design elements:
   * Content Type
   * Jurisdiction
   * Regulatory Body
   * Sector
   * Theme

   {#what-is-rcm__ul_ckg_xsv_jnb}

   You can create and map these elements with the external taxonomy during the setup process.
2. Integrate for regulatory intelligence: Integrate with the third-party regulatory intelligence providers and consume the alerts into your instance at regular intervals. You can monitor regulatory data in a rapidly changing environment.
3. Triage regulatory events: Analyze the regulatory alerts and identify the regulatory events that are relevant to your organization.
4. Assess impact: Assess the impact of regulatory events by using configurable impact assessment methodologies.
5. Manage changes: Identify changes that should be done. These changes are implemented through the following action tasks:
   * Update the underlying GRC objects, such as the policies, processes, risks, and controls in the regulatory library.
   * Update the existing citations or import the new citations from the providers in the regulatory library.
   {#what-is-rcm__ul_jfk_l4r_fnb}
6. View reports and dashboards: Assess the state of the regulatory compliance by using reports and dashboards. You can maintain an audit trail of the compliance activities.
{#what-is-rcm__ol_erz_vp2_wmb}

The following diagram shows the workflow of the Regulatory Change Management application.  
Figure 2. Workflow of the Regulatory Change Management application

## Key product innovations {#what-is-rcm__section_ah1_dgf_4cc}

The following infographic shows the process for making innovations for the key products of the Regulatory Change Management application.
Figure 3. Process for innovating key products  
The steps to complete the Regulatory Change Management process flow to innovate key products are:

1. Set up the integration. Your customers can subscribe to a public RSS feed for the regulatory bodies or a subscription provider such as Thomson Reuters Regulatory Intelligence (TRRI) that is a curated intelligence provider. A subscription provider can aggregate the regulatory changes from different sources and provide the collective changes as feeds.
2. Set up an internal taxonomy. The taxonomy elements are different classifiers that an organization can apply to its regulatory content to categorize it. You can use the taxonomy elements to create a hierarchical structure of the different classifications for setting up the regulatory content for an organization.
3. Review a regulatory alert. A user with the sn_grc_reg_change.manager role (RCM manager) reviews a regulatory alert and assigns it to a coordinator or a user with the sn_grc_reg_change.user role (RCM user). The user with the sn_grc_reg_change.user role reviews the alert. If the regulatory change requires an impact assessment, the RCM user sends it to a subject matter expert (SME) with a business user role.

   A user with sn_grc_reg_change.user and sn_grc_comp_genai.reg_change_ai_user roles can generate
   AI-powered recommendations for a regulatory alert for the impacted citations, control objectives, and controls.
4. Assess the impact. The subject matter expert (SME) with a business user role assesses the impact of the regulatory change and sends the score of the impact assessment to the Regulatory Change Management application. If the alert is not applicable to the organization, the RCM user closes the alert. If the alert is applicable to the organization, the RCM user creates a new regulatory change task and assigns it to the same coordinator or to a new coordinator.
5. Devise an action plan. The coordinator identifies the steps to comply with the regulatory change, devises an action plan, and creates the action tasks for the different teams that must complete the identified action items. The coordinator then creates the action tasks that are associated with the regulatory change task. After the action plan is created, it's sent to the RCM manager for an approval. The manager reviews the action plan and confirms if more action tasks must be created or if some of the action tasks aren't necessary.
6. Complete the action tasks and send them for review to a user with the sn_grc_reg_change.manager role (RCM manager). If the action plan is rejected, the coordinator goes through the action plan, updates the actual tasks, and sends the action plan back for an approval. The compliance manager can see all compliance-based action tasks and the risk manager can see all risk-based action tasks. After the tasks are assigned to the risk and compliance users, the action tasks are tracked until they're completed. A due date is marked and tracked for the action tasks. When the tasks are completed, the regulatory alert and the parent regulatory change tasks are closed and the change process flow is completed.
{#what-is-rcm__ol_j1d_drv_nqb}

## A day in the life of a regulatory change manager {#what-is-rcm__section_psq_qjp_ddc}

A user with the sn_grc_reg_change.manager role (RCM manager) monitors, manages, decides, and verifies the regulatory changes on a daily basis.

The following infographic depicts a typical day for a regulatory change management.  
Figure 4. Typical day of a regulatory change manager
* **[Regulatory Change Management application landing page](https://servicenow-prod.fluidtopics.net/E~0_CAc63YSMYDrjoZhF7A)**   
  The Regulatory Change Management application landing page view provides the overview of the regulatory activities in your organization. Users with the sn_grc_reg_change.manager roles only can view the Regulatory Change Management landing page in the primary navigation in the Compliance Workspace.
* **[Tasks page in the Compliance Workspace](https://servicenow-prod.fluidtopics.net/0uZJDwJzEQNKMMsxpHB3FQ)**   
  The Tasks page within the Compliance Workspace provides a centralized, task-centric interface for managing all activities related to regulatory events, source documents, and compliance workflows. It helps you stay organized, ensures timely and accountable action, and promotes overall regulatory readiness.
* **[Source document import tasks](https://servicenow-prod.fluidtopics.net/ylE4TdF14ymeU4oK~wlOwg)**   
  The Regulatory Change Management application processes external alerts that may include citation titles, citation numbers, and references to legislative or regulatory materials relevant to compliance.
* **[Regulatory process flow and tasks](https://servicenow-prod.fluidtopics.net/2QkEZKYrKHfCxf2t~Ey4rg)**   
  The Regulatory Change Management process flow includes the tasks that different users can perform to help your organization manage and comply with regulatory changes.
* **[RSS feeds overview](https://servicenow-prod.fluidtopics.net/9lnEl~Kxw~wJJ9XpWWoqIw)**   
  A Really simple syndication (RSS) feed in Regulatory Change Management is like a subscription service for updates about new or changed rules and regulations. Instead of visiting multiple websites to check for updates, you can subscribe to feeds from regulatory bodies or industry news.
* **[Impact assessments for the regulatory alerts](https://servicenow-prod.fluidtopics.net/wEfYcMNZSIAk92vuljb4lA)**   
  A regulatory event alert may result in a regulatory change to an organization. You can evaluate the impact of the regulatory change on your organization by performing impact assessments.
* **[Regulatory assessment for a regulatory alert](https://servicenow-prod.fluidtopics.net/GMH4yLzn_kcxxZ41LGyoig)**   
  Utilize the Smart Assessment Engine to perform smart assessments on regulatory alerts. This ability enhances regulatory decision-making by enabling impact assessments directly at the regulatory alert level, streamlining processes through a unified core assessment framework, and assigning analysis to multiple stakeholders for improved collaboration and efficiency.
* **[Next Experience Discuss and Chat Collaboration](https://servicenow-prod.fluidtopics.net/aQcU7xu5_1a_XzFnTCEaxg)**   
  On a regulatory change management case, select Discuss from other options. Collaborate with virtual agents by using Next Experience Chat Collaboration and Discuss.
* **[Regulatory Change Management application in the Compliance Workspace](https://servicenow-prod.fluidtopics.net/lxW4gcNtqIwoAMFxYcU39A)**   
  Starting with GRC: Regulatory Change Management, version 13.0.1, the Regulatory Change Management application is available in Compliance Workspace. Compliance Workspace provides your users with a single-pane view so that they can check upcoming regulatory changes, assess their impact, and implement risk and compliance-related changes for the organization.
* **[Exploring Now Assist in Regulatory Change Management (RCM)](https://servicenow-prod.fluidtopics.net/8QK3VpRq6YAxfbtxpqVmDQ)**   
  With Now Assist in Regulatory Change Management, part of the ServiceNow Otto for Integrated Risk Management (IRM) application, you can use agentic workflows and generative AI skills that streamline the analysis, summarization, and impact assessment of regulatory alerts. These capabilities empower compliance teams to act swiftly and accurately on regulatory changes.

