Internal audit asks whether entity scoping is only a compliance concept. How should the IRM lead respond?
Select an answer to reveal the explanation.
Short Explanation
Think of entities as the city’s shared map. Compliance walks it, risk marks hazards on it, and audit picks routes from it—they do not each draw a different city. One scoped population keeps the three programs talking about the same departments and systems.
Full Explanation
In ServiceNow IRM, entity framework provides the organizational objects that policy/compliance, risk, and audit reuse. Treating scoping as compliance-only forces duplicate, inconsistent populations and breaks test-once/report-many value. Audit engagements and risk assessments should reference the same governed entities where programs overlap. Shared scoping is architectural, not a documentation courtesy.