
Explore ServiceNow GRC out of the box, activating plugins to manage policy, compliance, risk, and audit. Learn about vendor risk management, UCF concepts, and admin elements like workflows and ACLs.
Learn how to obtain a free personal ServiceNow developer instance, register at developer.servicenow.com, request the New York version, log in, and enable GRC plugins while understanding reset and reclaim policies.
Navigate ServiceNow with the filter navigator, favorite key GRC items, use tabbed forms, and show the update set picker and application picker in the header to streamline dev work.
Activate GRC plugins in ServiceNow, prioritizing dependencies in Madrid and New York. Install policy and compliance and related GRC components, load demo data, and verify installations.
Explore why the vendor risk management plugin may not install on a personal dev instance due to a required vendor portal purchase and high credential access; learn workarounds and expectations.
Explore how the four ServiceNow GRC applications—policy and compliance, audit, risk, and vendor risk—store policies, controls, policy exceptions, and assessments to manage compliance and audits.
Explore how ServiceNow GRC uses entities (formerly profiles) to represent items, tie them to entity types and classes, and drive audits, controls, and risk across compliance and policy.
Explore the policy and compliance module of ServiceNow, including compliance dashboards, authority documents, citations, policy life cycle, scoping, entities, controls, attestations, and indicators guiding remediation.
Create test users for each policy and compliance role to explore access limits beyond sys admin. See how inherited roles and ACLs shape who can create and manage controls.
Create groups in ServiceNow to assign roles at group level for policy and compliance. This avoids assigning roles to individuals and simplifies onboarding by using groups, compliance admins and developers.
Explore policy and compliance tables in the GRC policy and compliance management app, including many-to-many tables and acls, and learn to customize the application menu to view published policies.
Learn policy compliance administration in ServiceNow by configuring policy types, the order of choices, authority and citations, plus notifications, states, attestations, knowledge base, and remediation task closure with UCF integration.
This video explains authority documents and citations, how regulatory bodies like PCI, HIPAA, GDPR shape controls, and how UCF integration maps common controls to citations and control objectives in ServiceNow.
Explain how control objectives bridge policies and controls in ServiceNow, including auto-generated controls from entity types and additional entities, and how citations and attestations ensure regulatory compliance.
Create policies in ServiceNow, format policy text for the knowledge base, and manage the policy life cycle from draft through review and approvals to published.
Explore how ServiceNow manages controls and control objectives, conducts attestations, assigns entity ownership, and navigates the control life cycle from draft to retirement.
Explore how indicators provide a 1-to-1 attestation for controls by using templates, schedules, and manual or automated tests to generate indicator tasks and results.
Unlock user impersonation in ServiceNow by turning off the locked out flag and testing with Abel, since policy exceptions restrict admin actions without impersonation.
Learn how to create policy exceptions in the service portal and base instance, using impersonation, required fields, risk description, with SLA and audit trails, and reviewer approvals in GRC.
Master the life cycle of policy exceptions, from requesting approvals and risk assessment to approving or rejecting against policies, control objectives, and impacted controls, with extension and closure steps.
demonstrates creating and approving a policy exception in ServiceNow, linking it to a control issue, managing related risk, approval workflows, and handling extension requests within the out-of-the-box GRC process.
Explore policy and compliance management workflows in ServiceNow, view, copy, customize, and publish out-of-the-box workflows, and manage policy life cycles with related rules and scripts.
Explore how to locate and manage business rules, client scripts, UI actions, and policies in ServiceNow, and learn server-side automation, client-side validation, and script includes for reuse.
Learn how notifications work in the policy and compliance management app to support GRC accountability, including out-of-the-box alerts and dynamic recipients. Configure triggers, conditions, templates, and previews with system logs.
Build and customize dashboards and reports in the ServiceNow policy and compliance app, using out-of-the-box views and performance analytics filters to monitor compliance and non-compliant items.
Explore the ServiceNow audit application within the GRC framework, learning how engagements drive audits, audit tasks and control tests, and how issues and remediation flow from finding to administration.
Explore out-of-the-box audit management roles and groups in ServiceNow, and learn how ACLs govern table and field access, best practices for group-based permissions, and safe ACL management.
Explore the audit management app, focusing on engagement and audit task tables, and configure the application menu to separate open and closed engagements.
Explore audit templates and test plans, linking test templates to control objectives and auto-pulling questions to streamline design and operation testing across entities.
Navigate the engagement lifecycle in ServiceNow, creating Sox audits, assigning entities and controls, and generating test plans and tests; manage audit periods, task types, and approvals.
Explore the engagement lifecycle in ServiceNow GRC, managing audit tasks, control tests, and issues from fieldwork to follow-up, including impersonating a user, closures, approvals, and the workbench timeline.
Discover the out-of-the-box audit workflows in ServiceNow GRC, including audit engagement approvals, control test approvals, and audit task reassignment notifications, with how to customize approvers, states, and due-date rules.
Learn to configure and manage ServiceNow audit rules using business rules, client scripts, UI policies, and actions; control engagement workflows and ensure auditors and approvers are enforced.
Configure out-of-the-box and custom notifications in ServiceNow audit management, specifying trigger events, recipients, and message content, and preview engagement approvals to ensure accountability in GRC.
Explore out-of-the-box audit dashboards and reports in ServiceNow GRC, using premium dynamic filters to track engagements, overdue tasks, and control tasks across HR, finance, and more.
Explore the risk governance and controls in ServiceNow GRC, including risk library, frameworks, risk register, assessments, remediation tasks, and administration for a complete risk lifecycle.
Discover out-of-the-box risk management roles and how they are assigned via groups, then configure ACLs on the risk table to control create, read, write, delete access.
Navigate risk management tables and evaluate dictionary entries, fields, and ACLs. Configure the application menu to show open or retired risks, set order, and control access with roles.
Explore risk administration in ServiceNow's GRC, comparing qualitative and quantitative risk scoring, and learn how inherent and residual risks are modeled in the risk register and properties.
Explore the risk library, including risk frameworks and risk statements, and see how ServiceNow aligns with industry risk management framework concepts for risk identification and response.
Create a risk register entry, link it to a risk statement, assign an owner, and drive the risk from assessment to response using risk response tasks in the service portal.
This lecture explains four risk response tasks, focusing on creating a risk acceptance plan, navigating risk acceptance approvals, and transitioning to avoid, mitigate, or transfer strategies.
Explore the risk register lifecycle in ServiceNow, from assess to monitor, including mitigate, transfer, risk response tasks, indicators, and remediation, with risk owner, ACLs, and automatic issue creation.
Learn how risk indicators in ServiceNow auto-detect loss of integrity through daily checks of business service data and vulnerability, and customize risk assessments with the risk assessment designer.
Explore the integration of ServiceNow risk management with risk lens, using fair risk framework to add monetary, quantitative risk to risk records.
Explore the out-of-the-box risk management workflows in ServiceNow, focusing on the risk acceptance approval process, dynamic approvers, and publishing workflows after validation.
Discover how GRC risk management uses business rules, client scripts, and policies to automate risk lifecycle tasks, enforce mandatory statements, and manage UI actions and state transitions.
Explore the out of the box risk dashboards and reports in ServiceNow, including inherent risk tabs and heatmaps for risk committees. Rename tabs, add dashboards, and run reports.
Explore the vendor risk management overview in ServiceNow, including how the vendor risk application tracks vendors, vendor contacts, tiering assessments, and the assessment lifecycle to protect data and reduce risk.
Explore the out-of-the-box vendor risk management roles in ServiceNow: vendor assessment reviewer, vendor assessor, and vendor risk manager, and how ACLs govern vendor risk assessments.
Learn to add vendors and vendor contacts in ServiceNow, set statuses, assign a primary contact, and enable vendor risk assessments through the vendor portal.
Configure vendor tiering assessments in ServiceNow, tailor default scales and questionnaires, assign assessors, and auto-generate critical or high risk vendor risk assessments via the service portal.
Learn to design and deploy vendor risk assessments with assessment templates, questionnaire templates, and document request templates, tailored by risk level and supported by SIG information gathering and SOC reports.
Walk through the vendor risk assessment lifecycle in ServiceNow GRC, from creating a risk assessment and assigning owners to collecting SOC 1 and SOC 2 questionnaires and updating risk ratings.
Explore the vendor risk assessment life cycle in ServiceNow GRC: review questionnaire responses, create issues and tasks, calculate risk ratings, return to vendor, and finalize observations and resolutions.
Explore out-of-the-box vendor risk management workflows in ServiceNow, learn how the workflow editor uses timers and date fields to trigger reminder emails and assessors notifications, and publish these workflows.
Explore the vendor risk dashboard and out-of-the-box reports, track vendor risk assessment progress, and configure notifications and events to keep vendor communications accountable.
Get hands-on with ServiceNow GRC by starting a free developer instance and practicing across policy, compliance, risk, audit, and vendor risk apps. Measure progress, set goals, and keep building.
Learn to obtain and manage your ServiceNow personal developer instance (PDI), including signing up for a free ID, requesting a personal sandbox, upgrading releases, and activating plug-ins for hands-on learning.
Upgrade your ServiceNow instance by clicking your name, selecting upgrade instance, and choosing the Vancouver patch zero-click upgrade, then wait for the process to complete with an email notification.
Install plugins using the new and classic app managers in the Vancouver release of ServiceNow, updating the GRC policy and compliance management to version 17.
Upgrade the vendor risk management plugin in Vancouver to third party risk management, review release notes, check dependencies, use the app manager, and refresh the browser after activation.
Explore entities in ServiceNow GRC and how they tie applications and servers to risks. Learn to define entity types, assign owners, and use filters to create and update entities.
Explore new policy compliance features in ServiceNow, including policy types, audience definition, dynamic filters, contributors, acknowledgments, and the policy category reference field for streamlined governance.
Explore how to configure a policy workflow in a GRC environment, including assigning compliance owners, reviewers, and approvers, implementing attestations, and publishing policy text templates to the knowledge base.
Explore how to create and manage evidence requests in ServiceNow, choosing audit or compliance types, setting due dates, assigning owners, and guiding evidence through the review workflow.
Set up a policy acknowledgement audience by configuring audience filters with roles such as SNC analyst to target internal users, then stage the policy for publication and scheduled campaigns.
Learn to configure policy acknowledgement campaigns in ServiceNow GRC, including valid dates, audience, reminders, and tracking of accepted, declined, or no response with exceptions.
Welcome to the Ultimate ServiceNow GRC course! Within this course you will learn how to use and begin to configure Policy and Compliance, Audit Management, Risk Management, and Vendor Risk Management applications. You will also learn tips and tricks for implementing the GRC applications. If you do not have a ServiceNow instance to practice on then don't worry, we will walk you through the steps to get your own FREE ServiceNow Developers instance. This course was made using the New York version of ServiceNow, but a lot of the features and items we discuss are also available on Madrid and Orlando.