ServiceNow GRC Training
Manage risk and compliance on ServiceNow. Policy and compliance, risk management, controls, audit and continuous monitoring, the Integrated Risk Management suite.
ServiceNow GRC/IRM (Governance, Risk and Compliance, Now Integrated Risk Management) training teaches you to manage policy and compliance, risk, controls, audits and continuous monitoring on the Now Platform, aligned to the CIS-Risk and Compliance certification.
Who this course is for
Prerequisite: Basic administration. GRC and IRM concepts are introduced, so a risk or audit background helps but is not required.
What makes this different
You build, not just watch
From the first session you are on your own developer instance, configuring, scripting and breaking things safely. That is what makes it stick.
Taught on the current release
No outdated screenshots. Everything maps to the release ServiceNow runs today, including current AI and platform features.
One trainer who still implements
One working consultant for the whole batch, no rotation, so the teaching is consistent and grounded in real projects.
Support continues to the offer
Resume review, mock interviews on real scenario questions, and referrals. Support does not stop when the last class ends.

Curriculum
7 modules and 3 projects, updated to the current release. Every module maps to real GRC work and expands into its full topic list, practised on a live developer instance.
ServiceNow GRC Training module list: 7 modules, what each one covers, and how many topics it expands into. Full topic lists are in the accordions below.
| # | Module | What you configure | Topics |
|---|---|---|---|
| 01 | GRC and IRM foundations5 hours | Explain the ServiceNow IRM architecture and configure the entities, profiles and roles the rest of the suite depends on. | 4 |
| 02 | Policy and the common control framework6 hours | Build a common control framework by loading authority documents and citations and mapping them to policies and control objectives. | 4 |
| 03 | Controls, testing and attestation6 hours | Configure controls, control tests and attestation campaigns and evaluate the results they produce. | 4 |
| 04 | Risk management6 hours | Configure the risk framework, register and scoring model and run a risk assessment from creation to response. | 4 |
| 05 | Issues, remediation and audit management6 hours | Manage issues and remediation tasks and plan, scope and execute an audit engagement. | 4 |
| 06 | Continuous monitoring and indicators5.5 hours | Configure indicators and continuous monitoring so that control failures are detected and raised automatically. | 4 |
| 07 | Delivery, reporting and certification readiness5.5 hours | Deliver IRM reporting and integrations, apply implementation practices and prepare for the CIS-Risk and Compliance exam. | 4 |
1GRC and IRM foundationsModule 1 of 7 · 5 hours
Explain the ServiceNow IRM architecture and configure the entities, profiles and roles the rest of the suite depends on.
- GRC to IRM overview
- GRC to IRM product evolution
- IRM application families and plugins
- advanced risk and advanced compliance packages
- shared services on the Now Platform
- Entities and profiles
- entity and entity class records
- profile types and profile generation
- filters and scripted profile population
- linking profiles to controls and risks
- Roles
- IRM administrator and manager roles
- risk manager and compliance manager separation
- reader and end user roles
- role assignment through groups
- IRM data model and scoping
- core IRM tables and their relationships
- scoped application boundaries
- domain separation considerations
- record ownership and delegation
2Policy and the common control frameworkModule 2 of 7 · 6 hours
Build a common control framework by loading authority documents and citations and mapping them to policies and control objectives.
- The common control framework
- authority documents and content packs
- control objectives and control statements
- framework hierarchy and inheritance
- mapping citations to control objectives
- Policies and citations
- policy records and policy statements
- citation import and manual authoring
- policy lifecycle and review cycles
- policy acknowledgement campaigns
- Compliance workflows
- policy and control approval flows
- state models and lifecycle transitions
- Flow Designer in IRM
- notifications and task routing
- Policy exceptions and waivers
- exception request intake
- risk acceptance and approval chains
- expiry and review dates
- reporting on open exceptions
3Controls, testing and attestationModule 3 of 7 · 6 hours
Configure controls, control tests and attestation campaigns and evaluate the results they produce.
- Controls and control tests
- control records and control instances
- manual and automated control tests
- test plans and test schedules
- control effectiveness states
- Attestations
- attestation designer and templates
- questionnaires and question sets
- campaign scheduling and target selection
- response review and follow up
- Control ownership and delegation
- control owner assignment
- delegation and out of office handling
- escalation for overdue tests
- ownership coverage reporting
- Evidence and documentation
- evidence requests and attachments
- document repositories for control artefacts
- retention of test results
- audit trail of control changes
4Risk managementModule 4 of 7 · 6 hours
Configure the risk framework, register and scoring model and run a risk assessment from creation to response.
- Risk framework and register
- risk statements and risk records
- risk register structure
- risk categories and taxonomies
- inherent and residual risk
- Risk assessments
- assessment methodologies
- risk assessment questionnaires
- assessment scheduling and reminders
- qualitative and quantitative approaches
- Risk scoring
- scoring criteria and calculators
- likelihood and impact scales
- score aggregation to profiles
- risk appetite and thresholds
- Risk response and treatment
- accept, avoid, mitigate and transfer options
- risk response tasks
- linking responses to controls
- monitoring residual risk over time
5Issues, remediation and audit managementModule 5 of 7 · 6 hours
Manage issues and remediation tasks and plan, scope and execute an audit engagement.
- Issues and remediation
- issue creation from failed control tests
- issue states and ownership
- remediation tasks and due dates
- closure and verification
- Audit management
- audit engagements and scoping
- audit tasks and workpapers
- audit universe and annual planning
- audit report generation
- Findings
- findings raised from audit tasks
- severity and classification
- corrective action plans
- follow up and retest
- Audit evidence and sampling
- evidence requests to control owners
- sampling approaches for testing
- workpaper review and sign off
- record retention for engagements
6Continuous monitoring and indicatorsModule 6 of 7 · 5.5 hours
Configure indicators and continuous monitoring so that control failures are detected and raised automatically.
- Continuous monitoring
- continuous monitoring architecture
- automated test scheduling
- failure handling and issue generation
- monitoring coverage across profiles
- Indicators and evidence
- indicator templates and indicator records
- data collection methods and scripts
- indicator results and thresholds
- evidence captured by indicator runs
- Indicator sources and integrations
- table based indicators
- external data sources
- MID Server considerations
- scheduled data collection jobs
- Monitoring exceptions and tuning
- false positive review
- threshold tuning
- suppression of known issues
- trend review of indicator results
7Delivery, reporting and certification readinessModule 7 of 7 · 5.5 hours
Deliver IRM reporting and integrations, apply implementation practices and prepare for the CIS-Risk and Compliance exam.
- Dashboards and reporting
- risk and compliance dashboards
- Performance Analytics for IRM
- executive risk posture views
- scheduled reports and distribution
- Integrations
- CMDB and asset data as entity sources
- vendor risk data exchange
- IntegrationHub spokes and REST
- import sets for authority content
- Best practices
- phased implementation approach
- data model hygiene
- upgrade and update set considerations
- stakeholder engagement and adoption
- CIS prep
- exam domain review
- hands on revision on a developer instance
- practice question strategy
- certification roadmap after CIS-Risk and Compliance
Implement a full IRM slice for one entity class: a common control framework with mapped policies, a scored risk with a completed assessment, an automated indicator, and an audit engagement that drives an issue to closure.
How this course covers the CIS-Risk and Compliance exam blueprint.
| Exam area | Weight | Covered in |
|---|---|---|
| IRM foundations and architecture | - | Module 1 |
| Policy and compliance management | - | Module 2, Module 3 |
| Risk management | - | Module 4 |
| Audit management and issues | - | Module 5 |
| Continuous monitoring and indicators | - | Module 6 |
| Reporting and integrations | - | Module 7 |
Not covered: ServiceNow platform administration fundamentals, which are covered by the CSA level course; Legal or regulatory interpretation of the frameworks loaded into the instance; Custom scoped application development outside the IRM applications.
Curriculum version 2026-09-01 · approved by mohsin
What you'll be able to do
Real projects you'll build
Interview-ready scenarios on a live instance, not toy demos.
Control framework
Build a common control framework mapped to entities and run a control test cycle.
Risk assessment
Create a risk, assess and score it, and drive an issue to remediation.
Continuous monitoring
Set up an indicator that automatically tests a control and raises a finding on failure.
Certification and hands-on
Every session runs on a real ServiceNow developer instance, so you configure and build rather than watch. The course maps to the CIS-Risk and Compliance exam and finishes with an IT Canvass certificate plus a certification roadmap. The CIS-Risk and Compliance exam costs US$300 (ServiceNow University, 2026). IT Canvass does not issue the official ServiceNow credential.
ServiceNow has an official certification catalog with four tiers: Expert (Certified Technical Architect, Certified Master Architect), Mainline (Certified System Administrator, Certified Application Developer, Certified Application Specialist and the Certified Implementation Specialist product tracks), Micro-Certifications (focused product skills such as Now Assist, Flow Designer and CMDB), and Suite Certifications (bundled credentials such as the ITSM and CSM Professional suites).
Certification facts. Vendor figures change, so confirm against the official ServiceNow catalogue before booking.
| Exam code | CIS-Risk |
|---|---|
| Credential | ServiceNow CIS-Risk and Compliance |
| Issued by | ServiceNow, Inc. (not by IT Canvass) |
| Exam duration | 90 minutes |
| Exam cost | US$300 per exam attempt, plus the mandatory training where required |
| Prerequisite | CSA is the prerequisite for every CIS exam. Mandatory paid training applies to most CIS tracks. |
| What IT Canvass issues | An IT Canvass course completion certificate and a certification roadmap |
Your GRC career roadmap
The security and risk path from admin to security architect, with indicative 2026 bands.
Salary snapshot: GRC / IRM Consultant
Indicative ranges aggregated from public salary data. Actual pay varies by location, employer and experience.
How IT Canvass compares
Against a typical training provider, this GRC course is taught on the current ServiceNow release, gives you your own developer instance from day one, and keeps one working consultant for the whole batch instead of rotating trainers. Every module is mapped to the CIS-Risk and Compliance exam, sessions are recorded with lifetime access, and job support (resume review, mock interviews and referrals) is included in one transparent fee. Most providers still teach older release material, run slide-first sessions with limited lab time, and bill support and recordings as add-ons.
Fees and training modes
Choose how you want to learn GRC. No-cost EMI available on all modes.
Interactive live batches, weekday or weekend, with the full cohort and lifetime recordings.
Private one-on-one coaching at your pace, whether you need interview-ready fast or hands-on help with your current project.
Learn on your own time with recorded sessions, labs and Q&A doubt support.
Train your team on Servicenow GRC IRM Training
Tailored curriculum, flexible scheduling, a dedicated ServiceNow architect, and progress reporting for your managers. Delivered live online or on-site for cohorts of any size.
Your trainer
Neelima, ServiceNow Architect, 12+ years
I still deliver ITSM, ITOM and HRSD implementations for enterprise clients, so I teach from what is breaking in production this quarter, not from a slide deck. In class I show the patterns that scale and the mistakes that cost teams days.
Learner reviews
The common control framework is the backbone and the course built it correctly before anything else.
Continuous monitoring is what turns GRC from paperwork into something useful. Great practical treatment.
Cleared CIS-Risk and Compliance and, more usefully, implemented the framework at work.
Fees, batches and policies
The questions people actually ask before enrolling, answered plainly.