Verified User in Insurance
CI
Verified User in Insurance
Enterprise (> 1000 emp.)
"Helpful TPRM Module That Makes Due Diligence Clear and Easy to Manage"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

Risk assessment of third parties, integration with internal and external assessments. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

DORA Accelerator:

- confusing naming - e.g., column 'Legal entity' with 'Yes/No' values in the list of Legal Entities in the Operational Resilience Workspace - I believe it should be named something like 'Digital Operational Resilience Information' as it's in the list of Third Parties, as those values 'Yes' or 'No' indicate whether the core_company record has the information populated or not. Additionally, in the sn_dora_accel_entity table, there is a core_company reference field called 'Third party' - I find it confusing, as that is the list of Legal Entities (internal companies)

- company records with 'Status = Terminated' show up in the lists - in the Operational resilience Workspace, in the list of Legal entities or Third parties, there is no fixed filter which makes sure Terminated' companies are not shown there - confuses users and in when duplicates are in the system, users may create Digital Resilience Information for a wrong company records.

- missing xBRL import/export functionalities - in Europe, the Financial Market Authorities (FMA) require xBRL export format which is not in the OOTB solution of the DORA Accelerator - we had to create it from scratch, which resulted in introducing a huge technical debt. Review collected by and hosted on G2.com.

AA
Ashwin A.
Mid-Market (51-1000 emp.)
"Efficient HIPAA Compliance with Robust Workflows"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like that ServiceNow Governance, Risk, and Compliance (GRC) has good workflows and helps with Third Party Risk (TPR), which is quite beneficial, especially when it comes to RCM. Additionally, the initial setup was very easy. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

The log and Now Assist functions could be better. Review collected by and hosted on G2.com.

KR
keerthana r.
Small-Business (50 or fewer emp.)
"Robust Compliance Management, But Setup Challenges"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like ServiceNow Governance, Risk, and Compliance (GRC) because it offers out-of-the-box workflows that enhance my experience. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I have issues with the evidence management feature in ServiceNow Governance, Risk, and Compliance (GRC). It's challenging to handle multiple records efficiently and to tie multiple controls or manage ownership of multiple evidence records. Also, the initial setup wasn't easy. Review collected by and hosted on G2.com.

ER
Edxavier R.
Enterprise (> 1000 emp.)
"Effortless Setup, Comprehensive GRC Solution"
5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I find ServiceNow Governance, Risk, and Compliance (GRC) to be easy to use and it offers all the capabilities needed to go through a lifecycle policy right out of the box. This ready-to-use feature provides a starting point and a standard way to get all the work done in a straightforward process. The initial setup was super easy, and the guide was really helpful. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Nothing Review collected by and hosted on G2.com.

SR
Scott R.
Enterprise (> 1000 emp.)
"Broad Features, But Setup Challenges Persist"
2/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like the breadth of sub-products, including audit and compliance, available in ServiceNow Governance, Risk, and Compliance (GRC), although we have found some headwinds in getting those off the ground. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I find it challenging to determine how and when we can use Policy and versioning for corporate policies and how policy overlap for Standards in EA and other areas works. It also seems like ServiceNow Governance, Risk, and Compliance (GRC) isn't managing risks very well. Plus, the initial setup came with challenges. Review collected by and hosted on G2.com.

JH
Joel H.
Mid-Market (51-1000 emp.)
"Seamless Risk Management with Intuitive Interface"
4.5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like how ServiceNow Governance, Risk, and Compliance (GRC) is easily configurable and integrates with ERP systems. It also has a consistent intuitive interface for both operational and business users. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Configuring the new Workspace environment can be challenging. Review collected by and hosted on G2.com.

TH
Tongshi H.
Mid-Market (51-1000 emp.)
"Streamlined Workflow but Needs Better Documentation"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like that ServiceNow Governance, Risk, and Compliance (GRC) is a central platform that connects different data points, which helps me in managing risk and compliance needs. It really helps streamline workflow and process management. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

I think more documentation is needed in terms of how each field works and scores are being calculated. For example, there's a compliance score on the control objective form, but there's little documentation on how that score is determined. Review collected by and hosted on G2.com.

NM
Nathan M.
"A Frantic Experience"
4/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

The consolidation of key risk data into one source to enable a centralised function Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Not always as user friendly, and doesn’t always meet best practice risk processes from OOTB functions Review collected by and hosted on G2.com.

NN
Nguyen N.
"Connected, Automated and AI Enabled"
5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

The seamless connection between data in the CMDB and the different workflows in IRM provides consistent, accurate visibility into your compliance posture at any given time. Using agents also frees up your team to focus on decision-making and the more strategic elements of your program. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

Because there are so many data points and capabilities, it can be hard to find the right menu paths—especially at the beginning—so navigating the interface takes some getting used to. Review collected by and hosted on G2.com.

LG
Laxmi G.
Mid-Market (51-1000 emp.)
"Integrated Risk Management, Highly Reliable"
5/5
What do you like best about ServiceNow Governance, Risk, and Compliance (GRC)?

I like how ServiceNow Governance, Risk, and Compliance (GRC) functions like an umbrella with all pillars defined and a correct crossover entity. After understanding and taking courses, the system was easy to set up. It made sense to use it within ServiceNow as it stays in the system, integrating well with what we already use. Review collected by and hosted on G2.com.

What do you dislike about ServiceNow Governance, Risk, and Compliance (GRC)?

the entity relationship knowledge could be better documented in product information Review collected by and hosted on G2.com.