Filter Ratings and Reviews
Filter 34 vetted ServiceNow Governance, Risk, and Compliance reviews and ratings
Reviews (1-6 of 6)
Companies can't remove reviews or game the system. Here's why.
ServiceNow Governance, Risk, and Compliance is our central request management system along with tools to generate value out of the data. It helps to keep track of requests within a huge organization and has options to archive them. Dashboards are very intuitive in nature and add value.
- Central Request Management System
- Intuitive Dashboards
- Safe and Secure
- Not User Friendly
- Not easily Deployable
- Too many permissions required
As our company looked to assess and document our Internal Controls Environment and management, we looked to ServiceNow and other vendors to provide us with a framework/baseline starting point. We carefully compared features/capabilities of ServiceNow, Metric Stream, Modulo, and others and really benefited from the software demos offered by each company. We chose ServiceNow because of our already positive experience with their IT helpdesk software (was already used in our company) and how intuitively the GRC software appeared to operate. We understood that some customization was necessary, but felt it would more easily be adapted to our business versus the other options. Our experience, so far, has been positive; however, we feel we are still in the configuration/expansion phase. The challenges we are still overcoming are in our understanding of GRC attributes of our Oracle EBS R12 system, Active Directory access controls, and change control over these and other IT systems.
Our experience has been positive, and we appreciate the level of reporting and insight we gained by selecting a software like ServiceNow GRC instead of trying to handle this ourselves with documents and spreadsheets. As with most implementations, the costs occur up front, but we do expect an ROI in the next few years as we establish processes of administration, assessment, and remediation.
Our experience has been positive, and we appreciate the level of reporting and insight we gained by selecting a software like ServiceNow GRC instead of trying to handle this ourselves with documents and spreadsheets. As with most implementations, the costs occur up front, but we do expect an ROI in the next few years as we establish processes of administration, assessment, and remediation.
- Easily configurable and potentially customizable where needed
- Handle multiple user inputs and change management
- Good dashboard reporting and visibility for executive team
- Dashboard reporting takes some configuration to show KPIs needed
- Cost may increase as we add more users/expand its scope internationally
- Needs better templates to help our team configure and deploy effectively
Being used in one of our departments to manage the GRC needs related to incident management of IT and non-IT applications and devices. SN BCM is being used to automate and manage the disaster recovery planning for critical IT applications serving the healthcare needs. This helped us lower the administration cost and also ensure the consistent uptime of applications helping us deliver patient care. Also, bringing everything in one place and automating helped us maintain a single source of truth to be leveraged across other enterprise applications.
- Ease of use
- Configuration options available.
- Integrations with standard products.
- Reporting can further be improved to allow for customizations.
- End user configurable options.
September 15, 2020

I was on the team that implemented this at my former company and we are implementing this at my current company. On the security and risk teams, it is an absolute must to have a simple, repeatable way of mapping, tracking, and resolving security and risk issues. This is extremely valuable for us when we have our audits and need to provide evidence that we are adhering to what we say we do. ServiceNow GRC is very scalable and customizable which helped us meet both industry-standards and internal classification requirements in our organization.
- Finding reported by the auditor. GRC helps us identify, assign, and track the resolution of this.
- Exception to information security policy. These require quarterly reviews and setting up reminders to revisit these.
- Building out new projects and baking security and compliance into the project and tracking it in GRC to ensure we deliver a compliant product on day one
- Like all ServiceNow, there is a learning curve, but with custom forms, this is easier that it was 5 years ago.
ServiceNow was already a product being used by my company. Within Information Security, we had a need for a GRC platform. It came to our attention ServiceNow offered this. Out of the box there was very little that could be leveraged to support a robust GRC platform. However, all the functionality was there to be used after extensive configuration, etc. Some custom code was required although we tried to limit wherever possible. After approximately 8 - 10 months of designing and developing our requirements into the tool, we had a program that could be supported by a GRC tool, that was largely built in a way that would fit our needs and current processes. The only cost was the additional license. The only frustration that comes from choosing ServiceNow, is that it took several months to get what other GRC tools (e.g. Modulo, MetricStream, etc) offer out of the box. However, that comes at a much higher cost. I would recommend ServiceNow Governance, Risk and Compliance (GRC) to anyone already using ServiceNow for Service Management and has a limited security budget. The other benefit is the integration with an existing CMDB or asset inventory where ServiceNow is the record of reference.
- ServiceNow GRC is easily configurable. It does not require an extremely large team to support a decent size company.
- While out of the box it does not deliver functionality offered by other GRC competitors, it can easily be designed. And by giving you the ability to design, you can make it fit your program with relative ease.
- Cost benefit if ServiceNow is already leveraged within the environment. Deploying GRC capabilities comes at the cost of extra licenses.
- Delivering more out of the box functionality that rivals other GRC platforms. The bare bones approach may not help companies that do not have expertise or capabilities to build effective GRC processes.
- Easier way to implement workflow.
- Offering better metrics without buying add-on tools.
August 21, 2018

This is a tool that's being used by the entire company. It has helped the entire company understand and have knowledge about incidents, problems, as well as other stuff that is happening in the different areas of the company. All in a single web interface, easy to use and for all users.
- Integrate teams of your company. Ticket information is spread quickly
- Web interface is quick and has all the information needed. You define it
- You have free and paid user options.
- You need to have a ServiceNow partner to work with you
- The free option for users doesn't require payment, but depends on the partners.
ServiceNow Governance, Risk, and Compliance Scorecard Summary
Feature Scorecard Summary
What is ServiceNow Governance, Risk, and Compliance?
ServiceNow Governance, Risk, and Compliance provides the tools businesses use to proactively manage risk by measuring, testing and auditing internal processes. This solution helps business users ensure compliance to regulations, policies, standards and frameworks. It is available via the Standard, Professional, and Enterprise editions, the latter two supporting GRC and internal auditing processes.
ServiceNow Governance, Risk, and Compliance Technical Details
Operating Systems: | Unspecified |
---|---|
Mobile Application: | No |
Frequently Asked Questions
What is ServiceNow Governance, Risk, and Compliance?
ServiceNow Governance, Risk, and Compliance provides the tools businesses use to proactively manage risk by measuring, testing and auditing internal processes. This solution helps business users ensure compliance to regulations, policies, standards and frameworks. It is available via the Standard, Professional, and Enterprise editions, the latter two supporting GRC and internal auditing processes.
What are ServiceNow Governance, Risk, and Compliance's top competitors?
RSA Archer, MetricStream M7, and BMC Helix ITSM (Remedy) are common alternatives for ServiceNow Governance, Risk, and Compliance.
What is ServiceNow Governance, Risk, and Compliance's best feature?
Reviewers rate Integration with Corporate Performance Management (CPM) systems highest, with a score of 7.7.
Who uses ServiceNow Governance, Risk, and Compliance?
The most common users of ServiceNow Governance, Risk, and Compliance are Enterprises from the Unknown industry.