
Explore governance, risk, and compliance in ServiceNow GRC by learning policy compliance management, entities and risk management, authority documents and citations, policies, controls, and policy lifecycles in a scoped app.
Explore governance, risk, and compliance (GRC) in ServiceNow and how linked tables and processes support it. Learn how a GRC platform helps organizations govern objectives, ensure compliance, and mitigate risks.
Activate the key GRC plugins in ServiceNow—GRC profiles, policy and compliance management, risk management—and the Compliance UCF plugin; install dependencies and reveal policy, compliance, and risk modules in Quebec.
Explore the key changes in ServiceNow GRC from Orlando onward, including naming shifts from profiles to entities, policy statements to control objectives, indicators from item to control/risk, and scoping updates.
Governance defines organizational objectives and authority policies, encoding regulations like NIST, HIPAA, and SOX as authority documents and citations in ServiceNow.
Learn how authority documents and citations drive the GRC process by grouping citations into policies and linking each citation to a control objective, with examples like HIPAA and GDPR.
Explore how ServiceNow GRC links authority docs, citations, and control objectives to policies and controls, with a data privacy policy example illustrating lifecycle from creation to publication and knowledge articles.
Explore how authority documents, policies, citations, and control objectives connect through independent tables and m2m links. Note that policy_statement equals control objective, and see how sn_compliance tables drive the structure.
Explore how GRC choices drive incident, policy, and risk data by configuring category, type, and classification options, editing control objectives, and applying scope-aware updates across policy and risk tables.
Create and manage audiences for policy acknowledgements, assigning finance users and groups via user filters, then launch acknowledgement campaigns to notify recipients and log responses.
Explore how ServiceNow GRC manages policy acknowledgements through campaigns, audience targeting, and user responses—accept, decline, or exception requests—tracked in the portal and backend UI with a 60-day due date.
Explore the life cycle of policy exceptions in ServiceNow GRC, from creating an exception, triggering analysis and review, to multi-stage approvals, manager handoffs, and final exemption status.
Configure policy exception duration in the admin settings by increasing the default maximum to 90 days, while ensuring the exception's valid to date does not exceed the campaign validity.
Entity scoping defines at which level to verify policy controls—from whole organization to country, city, or branch—covering data privacy and monitoring by examining entities, classes, and types.
Explore how to create and manage entities in ServiceNow GRC, linking them to departments, locations, and other classes, and attach controls to track compliance and attestations.
Select a control objective for an entity, enable automatic control creation, and apply the resulting draft control to multiple locations through downstream controls.
Discover how entity types group multiple entities, automatically generate controls from linked policies and control objectives, and use entity filters to scale compliance across locations in ServiceNow GRC.
Explore how the GRC module controls derive from control objectives, linking authority documents and citations to policies, and see how attaching entities creates per-entity controls for each objective.
Explore the life cycle of a control in ServiceNow GRC, from draft through attestation, review, and monitor to retirement, including ownership, key controls, and compliance status.
Explore how end users submit attestations through the service portal, impersonate a user, attach evidence, and mark controls as implemented, triggering monitoring and compliant status in the GRC module.
Risk in GRC is a possible event that could harm or derail controls and compliance, linking threats like fire, earthquake, or storms to data center entities and backup objectives.
Explore how risks and controls run in parallel, attach entities to control objectives and risk statements, link controls to risks, and organize policies in ServiceNow GRC.
Explore how ServiceNow GRC organizes and uses risk statements within risk frameworks to capture, categorize, and assess risks, with examples, categories, and default scoring.
Create and link risks in ServiceNow GRC by attaching risk statements to risks and entities, auto populating fields, and generating controls, risks, and assessments for comprehensive risk management.
Explore the life cycle of risk from draft to retired, including assessments, responses, and monitoring. See how risk assessment respondents, risk response tasks, and transfers move a risk through stages.
Examine how response tasks like transfer, acceptance, mitigation, and avoidance drive risk remediation in ServiceNow GRC, including approvals, justifications, end dates, and lifecycle steps.
Explore risk assessments in the grc module, customize assessments by editing inherent and residual risk questions, and create copies to add new questions with field validations.
Explore qualitative and quantitative risk scoring in ServiceNow GRC, including SLE, ARO, and ALE, and the difference between inherent and residual risk, with risk criteria shaping scores.
Learn the ServiceNow table structure that links control objectives, entities, and risk statements to risks, using M2M connections to relate controls and risks, and upstream downstream risk links.
Identify the key roles in the GRC module for policy and compliance and risk management, including reader, user, manager, admin, editor, and developer, plus role inheritance and UI action visibility.
Learn how GRC modules in ServiceNow run in three application scopes: policy and compliance management, profiles, and risk management, and how to switch scopes to edit risks, entities, and controls.
Explore key ServiceNow GRC properties in the risk module, including qualitative impact, likelihood, and active risk states. Learn how policy, knowledge bases, and notifications drive risk scoring and governance.
Explore troubleshooting in scoped ServiceNow GRC apps by comparing global and application scopes, using gs.log, gs.info, or gs.debug, and adjusting gs.now to GlideDate when needed.
Understand how to customize script includes in ServiceNow GRC by using inheritance, copying and editing the assess item function, and avoiding changes to base script includes for safe, maintainable updates.
Explore the three core GRC workflows—policy approval, policy review, and policy exceptions—and learn how approvals, reviews, and 80 percent validity triggers automate notifications and control exemptions.
This is course deals with the GRC - Governance, Risk, and Compliance module in ServiceNow. Key topics covered are - Entities, Policies, Risks, Controls, Policy Exceptions, Policy Acknowledgement Campaigns.
Application modules covered in this course - Policy and Compliance Management, Risk Management.
It would be an advantage if you already have basic process knowledge on what GRC - Governance, Risk, and Compliance is. Even if you are totally new, this course covers the basic introduction of the key topics.
Once you successfully complete this course, you should be able to:
Activate required plugins for GRC - Governance, Risk, and Compliance module
Load Authority Documents, Citations, and Control Objectives
Create and Publish a Policy in ServiceNow
Understand the links between Authority Documents and Policies in the Governance part
Understand the key roles in the GRC - Governance, Risk, and Compliance process
Trigger Acknowledgement Campaign requests from ServiceNow
Configure audience for Campaigns
Understand the full Life cycle of Risks Management in ServiceNow
Understand basics of Entities and Entities in the Policy Compliance process
Create Controls and complete attestations
Configure Assessments for Risk
Learn tips when working with the scoped application of GRC - Governance, Risk, and Compliance module in ServiceNow
This course do not cover Audit Management and Vendor Risk Management
Feel free to post your Question in the Q&A section if you have any question on GRC - Governance, Risk, and Compliance module in ServiceNow