GRC Overview
About 5% of the CIS-RC exam — see all 7 domains.
GRC = Governance, Risk, and Compliance, the umbrella for ServiceNow's integrated risk applications, now branded Integrated Risk Management (IRM). All applications run on the Now Platform and share the GRC common framework (Profiles, Entities, Indicators, common workflow/data model). Core apps: Policy & Compliance Management, Risk Management, Audit Management, Advanced Risk, Vendor Risk Management, Business Continuity Management, Operational Resilience, Privacy Management. Value: a single shared model so controls, risks, audits, and policies reference the same scoped entities and evidence.
Sample questions from this domain
Three of the 15 in this domain, with the reasoning. The full set is in the question bank.
In the ServiceNow GRC/IRM product family, which acronym does GRC stand for?
- A. General Risk Calculation
- B. Governance, Resilience, and Controls
- C. Global Reporting Capability
- D. Governance, Risk, and Compliance ✓
Why: GRC stands for Governance, Risk, and Compliance, the umbrella for ServiceNow's integrated risk management applications (now branded IRM). The other options are invented expansions and do not represent the product name.
Which platform capability provides the shared data model and engine that GRC applications (Policy and Compliance, Risk, Audit) are built on?
- A. The Performance Analytics engine only
- B. The Service Catalog
- C. The Knowledge Base application
- D. The Now Platform with the GRC core/framework ✓
Why: All GRC applications are built on the Now Platform and share the common GRC framework (profiles, entities, indicators, workflow). Service Catalog and Knowledge Base are separate platform capabilities, and Performance Analytics is an optional reporting layer rather than the GRC foundation.
A customer wants to manage corporate policies, map them to regulations, and monitor control effectiveness. Which GRC application is the primary fit?
- A. Audit Management
- B. Vendor Risk Management
- C. Risk Management
- D. Policy and Compliance Management ✓
Why: Policy and Compliance Management handles policies, authority documents/citations, controls, and control testing for compliance monitoring. Risk Management focuses on risk registers and assessments, Audit Management on audit engagements, and Vendor Risk on third-party risk.