Control tests, risk responses, and audit fieldwork all surface remediation work for the same utility. How should the IRM design treat those remediation items?
Select an answer to reveal the explanation.
Short Explanation
Picture one city work-order desk for potholes, whether a citizen, inspector, or auditor reported them. IRM’s shared issue process is that desk—one remediation lifecycle no matter if the gap came from a control test, a risk, or an audit finding. Separate tables just make the same leak look like three different problems.
Full Explanation
Common elements in ServiceNow IRM include shared issue management so remediation is consistent across Policy and Compliance, Risk, and Audit. A single issue process lets owners track, remediate, and close gaps with one workflow regardless of originating source. Siloing by app, forcing everything into ITSM Incident, or burying notes on a risk statement alone breaks that common remediation model.