Audit Management Implementation
About 5% of the CIS-RC exam — see all 7 domains.
Audit Management plans and executes internal/external audits leveraging the same scoped entities and controls.
Key objects:
- Engagement — the audit project/scope (advanced planning lets you scope by entities, risks, controls).
- Audit Plan / Audit Universe — what could be audited and the planned schedule.
- Audit tasks / fieldwork — execution steps and working papers / evidence.
- Findings / Issues — results of testing, routed to remediation.
- Risk-based auditing — audits draw on the risk register and control test results so audit, risk, and compliance reuse the same data.
Exam gotcha: Audit reuses GRC controls, profiles/entities, and indicators — it does not maintain a separate parallel control universe.
Sample questions from this domain
Three of the 15 in this domain, with the reasoning. The full set is in the question bank.
What is the primary purpose of Audit Management in ServiceNow GRC?
- A. To replace the risk register
- B. To plan, scope, execute, and report on internal audit engagements ✓
- C. To configure the CMDB
- D. To store authority documents only
Why: Audit Management plans, scopes, executes, and reports on audit engagements. It does not merely store authority documents, replace the risk register, or configure the CMDB.
In Audit Management, what is an engagement?
- A. A type of authority document
- B. A risk statement
- C. A profile type
- D. A defined audit project with scope, schedule, and tasks to evaluate controls/areas ✓
Why: An engagement is a defined audit project with scope, schedule, and tasks. It is not an authority document, a risk statement, or a profile type.
How does Audit Management leverage the shared GRC framework when scoping an engagement?
- A. It can scope to entities/profiles and reference existing controls and risks rather than recreating them ✓
- B. It cannot reference profiles
- C. It only works on incidents
- D. It must create entirely new controls unrelated to Policy and Compliance
Why: Audit engagements can scope to entities/profiles and reuse existing controls and risks. They do not require recreating controls, can reference profiles, and are not limited to incidents.