Verified User in Consulting
CC
Verified User in Consulting
Small-Business (50 or fewer emp.)
"Comprehensive GRC Management on a Unified Platform"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

ServiceNow GRC's greatest strength is its ability to provide a single source of truth for governance, risk, and compliance activities. The platform links risks, controls, assessments, issues, and remediation actions together, improving visibility and accountability across the organisation. I also value its workflow automation, configurable framework, and executive reporting capabilities, which help clients reduce manual effort and gain real-time insights into their risk and compliance posture. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

While ServiceNow GRC is highly capable, it can be complex to implement and configure, particularly for organisations that are new to GRC technology. The platform has a steep learning curve for administrators, and advanced reporting or dashboard development often requires specialised expertise. Additionally, implementation and licensing costs may be challenging for smaller organisations, and some administrative screens could be more intuitive for non-technical users. Review collected by and hosted on G2.com.

Verified User in Banking
CB
Verified User in Banking
Enterprise (> 1000 emp.)
"Single platform for enterprise-wide risk visibility"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

The standout strength is consolidation: policies, controls, risk assessments, audits, and incidents all live in one platform, giving real-time visibility across the entire GRC program. For anyone already in the ServiceNow ecosystem, the UI feels familiar and intuitive, making it easy to navigate and track issues across teams. Integrations are a genuine highlight, especially the deep CMDB connection that lets you trace risk directly back to specific assets and incidents, with heat maps, risk scoring, and rich reporting built in. Performance impresses when it comes to real-time monitoring - the platform automatically detects policy non-compliance as issues emerge rather than after the fact. Using multiple modules together (IRM, CAM, etc.) delivers strong ROI, turning fragmented GRC processes into a single auditable workflow. On AI, Now Assist for IRM and auto-generation rules for third-party assessments are genuinely useful, cutting out repetitive manual work and making risk calculations more consistent and transparent. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

The UI has a steep learning curve for first-time users, with no built-in onboarding guide to ease the start. While integrations are powerful, the initial configuration, particularly CMDB, demands significant time and internal expertise. Pricing is subscription-based per user and can be hard to justify as a standalone tool without broader ServiceNow investment. Support is the most inconsistent area, with documentation tending to cover menu structure rather than function, and vendor support tickets can take weeks to resolve, often leaving teams to problem-solve independently. AI features, while promising, are still maturing and not yet consistently reliable across all modules. Review collected by and hosted on G2.com.

DP
dinakar p.
Enterprise (> 1000 emp.)
"Useful but Limited GRC Capabilities with Integration Ease"
2.5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like that ServiceNow Governance, Risk, and Compliance (GRC) is integrated with all the data in ServiceNow. It is easy to code and integrate, especially with its low-code/no-code capabilities, which help in reducing the time to market. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

There are several things that I find challenging with ServiceNow Governance, Risk, and Compliance (GRC). It doesn't solve all the problems, and I feel like it lacks some major components of GRC. While it helps with model risk, policy management, and compliance, there are still areas where it's lacking. The control testing and handling of cyber vulnerabilities are only dealt with to some extent, which is a bit disappointing. I also have issues with the licensing model, specifically that read licenses should be free if users login once a month or year. Additionally, the initial setup was not easy for us because we have a lot of solutions, making it too complicated to migrate. Review collected by and hosted on G2.com.

MA
Michael A.
Enterprise (> 1000 emp.)
"Robust Traceability, Needs Better Workspace Functionality"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like the traceability between records in ServiceNow Governance, Risk, and Compliance (GRC). It's great to know what citations relate to each control and how those controls target risks. This makes it easy to govern. Also, it helps us understand how our company's controls are covering regulatory requirements and industry frameworks. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Workspace views don't have the same functionality as default/native views. For example, in the risks workspace, you can't select multiple risk responses during a risk assessment, whereas you can select multiple if operating in the native view. The initial setup was challenging, requiring us to redesign some processes to conform with ServiceNow functionality due to our reluctance to customize ServiceNow. Review collected by and hosted on G2.com.

MT
Mira T.
"GRC for External Connections Cyber Security Assessment"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

Great to have our External Connections Cyber Security Assessment scoped app that relates to Policy and Compliance (P&C) in the same platform as our ITSM (to leverage order guide, service request, change, etc), CMDB (device inventory), Knowledge Management (KB Articles), Now Assist (AI Assistance), Platform Analytics (dashboard and reporting), and future possibilities such as OT Visibility, Vulnerability Response, AI Agents/Specialists, etc. P&C allows for auto-instantiation of controls per the entity type, auto-instantiation of issues for failed attestations, recurring attestations to confirm controls are still in affect, compliance status/score, as well as lifecycle status of the policy/entity:control/issue. We’re also able to leverage platform capabilities like scheduled job, email with email template, business rules, flow, etc in this low code application used enterprise wide. Enhancements are added to continue to improve our process and user experience. Lastly, the support and partnership from ServiceNow ensures our success. Thank you ServiceNow. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Currently no functionality to sync-up attestation of a new control (of an existing entity already in review/monitor state) with the rest of the controls’ attestation cycle. Review collected by and hosted on G2.com.

DS
donna s.
Enterprise (> 1000 emp.)
"Centralized Policy Management with Room for User-Friendliness"
3.5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like how ServiceNow Governance, Risk, and Compliance (GRC) keeps all the rules in one place for everyone to use as a source of truth. I also appreciate that with this tool, I only need to teach one platform, which simplifies the training process. The approvals feature is valuable as it eliminates the hassle of having to chase them down. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

One area where I find ServiceNow Governance, Risk, and Compliance (GRC) could improve is its appeal to a very broad audience of users, many of whom are not tech-savvy. It would be beneficial to have a feature that walks them through the process, similar to how a survey does. Review collected by and hosted on G2.com.

CB
carsten b.
Small-Business (50 or fewer emp.)
"Streamlined Risk Management"
5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I use ServiceNow Governance, Risk, and Compliance (GRC) to centralize risk and compliance management across my organization on a single platform, which is really helpful. It makes identifying, assessing, and tracking risks with scoring and ownership straightforward. I really like how it allows me to monitor third-party risk posture throughout the lifecycle of my projects. The integration with HRSD to secure some of my most sensitive data is also something I value. Additionally, I found the initial setup very easy to provision. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Screen density and form layouts can feel sort of busy, at least for non-technical users. Review collected by and hosted on G2.com.

Dr. Atul G.
DG
Dr. Atul G.
Enterprise (> 1000 emp.)
"Integrated Control and Risk Management, but Setup Needs Improvement"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I use ServiceNow Governance, Risk, and Compliance (GRC) to set up control and minimize risk. I like its interconnection with control, policy, and risk. Seeing these three elements in one place in the workspace gives a clear picture to stakeholders, helping them make decisions before time. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I think UCF should come out of the box so users can build the controls quickly. Also, the initial setup wasn't that easy since it requires understanding the process first and foundational data. Review collected by and hosted on G2.com.

Chandra Udhaya K.
CK
Chandra Udhaya K.
Mid-Market (51-1000 emp.)
"Efficient Tool with Room for Policy Automation Improvement"
3.5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like the metrics feature in ServiceNow Governance, Risk, and Compliance (GRC) as it provides actionable insights that help create a roadmap and improve decision-making. The dashboarding and reporting functions are also great as they contribute to saving time and costs. The initial setup was smooth, which is always a plus. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I find the automation of government policies in ServiceNow Governance, Risk, and Compliance (GRC) doesn't work as well as it could. We don't need to spend time reviewing and implementing the changes, but it seems like there's a gap in automation that could be improved. Review collected by and hosted on G2.com.

IM
Ivan M.
SOAR engineer
Enterprise (> 1000 emp.)
"Improved Compliance Management with Integration Challenges"
4.5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like that ServiceNow Governance, Risk, and Compliance (GRC) offers visibility into the controls to ensure they meet enterprise security standards. It also helps identify gaps that exist in our environment and allows us to implement controls quickly. The integration with vulnerabilities is another aspect I find enjoyable. Additionally, the initial setup was easy. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I feel there are not enough integrations with other technologies and there is a lack of data visibility in ServiceNow Governance, Risk, and Compliance (GRC). Review collected by and hosted on G2.com.