logo

NJP

Manage and Report on Corporate Compliance

Import · Jun 02, 2022 · video

hello today we are going to discuss at a high level how to manage and report on corporate compliance so let's take a look how to monitor compliance control assurance activity and overdue regulatory changes how to track high priority issues and tasks assigned to you and groups you're a member of and how to define control objectives and see how their compliance scores roll up to the policy score the servicenow risk and compliance solution portfolio is powered by and built on the servicenow cloud platform in addition to the policy and compliance applications that we'll discuss today the servicenow irm suite of offerings also includes digital technology enterprise and operational risk management operational resilience audit as well as third party and vendor risk management business continuity management esg and privacy these applications sit on top of the now platform which includes powerful workflow and orchestration functionality the service now service portal knowledge base as well as artificial intelligence capabilities let's take a look today i've logged in as jacob williams our corporate compliance manager jacobs has complete insight into the organization's compliance structure through his role-based workspace as you can see jacob can see which authority documents are aligned against the organization as well as which high priority issues are being tracked against each as well as the computed compliance score going down jacob can also see which policies are least compliant within the organization as well as high priority issues tracked against them their compliance score and any high risk policy exceptions finally jacob can see which entities are least compliant within the organization their high priority issues compliance scores as well as their risk rating which is derived from entity level risk assessments jacob also has an overview into the control assurances across the organization including ongoing and overdue control tests open indicators as well as active and overdue control attestations jacob can also see trending metric data for each of these finally jacob can track open and overdue issues policy acknowledgement campaigns open and overdue policy exceptions as well as any active and overdue regulatory changes if we go into one of the policies that jacob is tracking we can see additional information we'll go into the change management standard a standard and a policy within servicenow are essentially the same thing you can have any number of standards checklists procedures uh policies and they can all be related to one another here we can see a description of the change management standard as well as the current workflow state we can see this standards overall computed compliance score as well as any non-compliant entities and control objectives that may contribute to that score we can also see which controls are compliant non-compliant and not applicable and as we could for the organization we can track policy acknowledgements exceptions as well as issues at the individual policy level we see that this one policy is addressing 11 corporate control objectives we can see the category classification as well as the type of these control objectives if we click into one of the control objectives we can see the same compliance numbers that we've seen at the policy level as well as the organizational level now just at the individual control objective level again we can see that overall compliance score non-compliant entities as well as detailed control attestation information active indicators and ongoing and overdue control tests finally we can track active and non-compliant controls policy exceptions and issues as they pertain to this individual control objective you may have also seen that this control objective addresses not only one but five citations spanning a multitude of authority documents including sock 2 iso 27001 and nist 853 we can see a description of the citation as well as the compliance score for each individual citation finally clicking into one of the citations were presented with the same compliance information including the compliance score the breakdown of compliant versus non-compliant controls non-compliant entities as well as the ability to track issues and policy exceptions at the individual citation level so we've seen how to track corporate compliance from the organization down to the authority document the policy the control objective and then at the individual citation within the authority document and that's great but what happens if these citations change we know that authority documents and regulatory frameworks are updated from time to time and there should be a way to automatically capture those changes and determine if they are or are not applicable that's where the regulatory change management functionality comes into play thank you so much for your time today and for additional information please visit the product page at www.servicenow.com forward slash risk

View original source

https://www.youtube.com/watch?v=xYteuPZKoLA