Great software for GRC
September 17, 2020
Great software for GRC

Score 5 out of 10
Vetted Review
Verified User
Software Version
IRM Enterprise
Overall Satisfaction with ServiceNow Governance, Risk, and Compliance
As our company looked to assess and document our Internal Controls Environment and management, we looked to ServiceNow and other vendors to provide us with a framework/baseline starting point. We carefully compared features/capabilities of ServiceNow, Metric Stream, Modulo, and others and really benefited from the software demos offered by each company. We chose ServiceNow because of our already positive experience with their IT helpdesk software (was already used in our company) and how intuitively the GRC software appeared to operate. We understood that some customization was necessary, but felt it would more easily be adapted to our business versus the other options. Our experience, so far, has been positive; however, we feel we are still in the configuration/expansion phase. The challenges we are still overcoming are in our understanding of GRC attributes of our Oracle EBS R12 system, Active Directory access controls, and change control over these and other IT systems.
Our experience has been positive, and we appreciate the level of reporting and insight we gained by selecting a software like ServiceNow GRC instead of trying to handle this ourselves with documents and spreadsheets. As with most implementations, the costs occur up front, but we do expect an ROI in the next few years as we establish processes of administration, assessment, and remediation.
Our experience has been positive, and we appreciate the level of reporting and insight we gained by selecting a software like ServiceNow GRC instead of trying to handle this ourselves with documents and spreadsheets. As with most implementations, the costs occur up front, but we do expect an ROI in the next few years as we establish processes of administration, assessment, and remediation.
Pros
- Easily configurable and potentially customizable where needed
- Handle multiple user inputs and change management
- Good dashboard reporting and visibility for executive team
Cons
- Dashboard reporting takes some configuration to show KPIs needed
- Cost may increase as we add more users/expand its scope internationally
- Needs better templates to help our team configure and deploy effectively
- Great ROI in time savings
- Scalable
- Executive and Internal Audit visibility of Risks and Compliance
We performed these assessments manually for years before selecting ServiceNow GRC. Other companies we assessed were Modulo and Metric Stream. Our takeaway from the other companies was that they seemed too simplistic to handle the needs of an Oracle EBS R12 ERP and our other systems. Further, we liked the reporting elements that came out of the box from ServiceNow.
Do you think ServiceNow Governance, Risk, and Compliance delivers good value for the price?
Yes
Are you happy with ServiceNow Governance, Risk, and Compliance's feature set?
Yes
Did ServiceNow Governance, Risk, and Compliance live up to sales and marketing promises?
Yes
Did implementation of ServiceNow Governance, Risk, and Compliance go as expected?
Yes
Would you buy ServiceNow Governance, Risk, and Compliance again?
Yes
Comments
Please log in to join the conversation