framework fit & evidence
Your Frameworks, Mapped to Controls You Can Actually See
SOX, SOC 2, ISO 27001, HIPAA. Different frameworks, and often the same requirement stated in different words. Every cycle, the same manual evidence work starts over. xtype Compliance reports ServiceNow evidentiary data mapped to the frameworks Governance, Compliance and Risk teams operate against.
FRAMEWORK FIT
One product, many frameworks
Most organizations have to meet several frameworks at once, often across separate SOX, security, risk, and privacy teams, and they rebuild the same evidence for each. Segregation of Duties and Privileged Access are tested by nearly all of them. So xtype Compliance evidences the underlying activity once and maps it to every framework that asks for it.
Framework
Segregation of Duties
Privileged Access
SOX
ITGC / COSO
Change-management segregation across requestor, approver, and implementer
ITGC / COSO
Logical access to production, reviewed on cadence
SOC 2
CC5.1
Names segregation of duties explicitly
CC6.3
Names least privilege and segregation of duties together
ISO 27001
Annex A 5.3
Segregation of duties
Annex A 8.2
Privileged access rights
Full citation detail available on request. We'd rather hand your auditor the specific control reference than a broad claim.

VISIBILITY
Dashboards your team reads.
Reporting your auditor accepts.
ServiceNow holds the evidence, but not in a form a compliance team can act on. xtype Compliance gives you a live view of control status across every instance in scope, and turns the same data into reporting built for an examiner.
Control status at a glance
Every control, every instance, current state; compliant entries and exceptions side by side. No ticket, no waiting on the platform team.
Exceptions, flagged with their source
Each exception is flagged with full who/what/when detail and a link back to the source record, so your team can trace it to the ticket or approval that explains it.
Full population, not a sample
xtype Compliance evaluates every in-scope change and access event across ServiceNow and xtype; the standard an auditor expects, without the sampling argument.
Reporting on your cadence
Run control reviews monthly, quarterly, or ahead of an audit. The evidence package pairs policy definitions with full results, ready for handoff.
Every instance in scope
Dev, test, staging, production. ServiceNow's native tools are siloed by instance; one xtype Compliance report covers the environments your auditor cares about.
Mapped, not translated
Results arrive already tied to the framework reference they satisfy, so internal audit isn't reverse-engineering what a screenshot proves.
FREE EBOOK
How xtype Streamlines Audits for Your ServiceNow Environment
A practical guide for compliance, risk, and audit leaders, covering SoD enforcement, privileged access reviews, cross-instance evidence packages, and how to go from weeks of manual prep to on-demand reporting.
- How auditors test ServiceNow controls, and what they actually ask for
- SOX, SOC 2, ISO 27001, HIPAA & GDPR, mapped to xtype controls
- Evidence package templates you can hand directly to your auditor

HOW IT WORKS
From framework to evidence
The same workflow every cycle, against every framework in scope.
Set your frameworks and scope
SOX, SOC 2, ISO 27001 with a matching default policy for Segregation of Duties and Privileged Access, applied across the instances and time frame you're reporting on.
xtype Compliance runs the check
Every in-scope change and access event across ServiceNow and xtype is evaluated against your policy; full population, not a quarterly sample.
Review in the dashboard
Compliant and exception entries for each control, with full who/what/when detail and a link to the source record.
Hand over the evidence
A single package with policy definitions and full results, mapped to the framework reference it satisfies, ready for your auditor.

WHO USES IT
Built for the teams accountable for the answer
Compliance
Run control reviews on your own cadence, against every framework in scope, without opening a ticket or waiting on a custom report.
Internal audit
Test controls against full population rather than a sample, with the source record one click away from every exception.
Risk
See control status across every ServiceNow instance on your reporting cadence, so a gap surfaces in the review, not at quarter end in an audit.
Bring evidence to every audit.
Thirty minutes with a compliance specialist. Walk through the dashboards and the framework mapping against a sample ServiceNow environment.
