Home / AI Programs / ServiceNow IRM & GRC
Enterprise AI · ServiceNow · Integrated Risk Management

Govern risk at the speed of AI.

Learn ServiceNow Integrated Risk Management on the Australia release. Build policy, risk, audit, third-party risk, privacy, resilience and AI-governance workflows that stand up to real review.

12-module curriculum Australia release Practitioner + implementer paths Personal Developer Instance
Explore the curriculum →
Est. 2016Digital Edify
100K+alumni community
1,000+hiring partners
4.8/5average class rating
01 · Who this is for

Four seats at the table. One platform model.

The common core creates one vocabulary. Role-specific activities then separate process design from platform configuration.

Risk practitioner

Own the risk process

For risk, compliance, audit, privacy and resilience professionals moving beyond spreadsheets and disconnected evidence.

Platform implementer

Configure the operating model

For ServiceNow administrators and developers who want to implement IRM data, access, workspaces and integrations.

Practice builder

Scope credible programmes

For consultants, pre-sales specialists and delivery leads who need release, entitlement and upgrade awareness.

Certification candidate

Connect concepts to practice

For learners preparing for ServiceNow risk-and-compliance credentials who want hands-on evidence behind the terminology.

No prior GRC experience is required for the practitioner path. The implementer activities assume working familiarity with ServiceNow administration. An advisor can help map the right entry point.

02 · Curriculum

Twelve modules. One connected IRM programme.

Modules 1–5 establish the shared model. Modules 6–11 apply a practitioner and implementer lens. Module 12 joins both paths in a capstone.

Common coreModules 1–5

Portfolio, entity model, policy, risk and assessments.

Dual lensModules 6–11

Practitioner artefacts paired with configured platform evidence.

Joint capstoneModule 12

Define, build, test and present an IRM operating model.

01

IRM portfolio on the Australia release

Map the applications, roles, product tiers and ServiceNow Otto terminology that shape an implementation.

Evidence: an accurate platform-estate map.
02

Entity framework and content model

Model organisations, processes, assets, controls and scope without creating an audit-maintenance problem.

Evidence: a three-level entity hierarchy with scoped controls.
03

Policy and Compliance Management

Connect authority documents, policies, control objectives, controls, attestations and issues through a reviewable lifecycle.

Evidence: an end-to-end compliance cycle.
04

Risk Management and Advanced Risk

Design risk statements, methodologies, assessments, indicators and response workflows with human review around AI-assisted suggestions.

Evidence: a defensible risk register and assessment method.
05

Smart Assessment Engine

Author, version, delegate and review assessment templates while testing roles, access and in-flight change behavior.

Evidence: a versioned assessment with an access test pack.
06

Audit Management and audit entry

Plan engagements, test controls, capture findings and separate third-line audit records from second-line operational records.

Evidence: an audit workspace with record-segregation checks.
07

Third-Party Risk Management

Configure third-party and engagement workflows, current questionnaires, SBOM intake and Smart Assessment patterns—plus the Australia upgrade changes.

Evidence: a TPRM workflow and upgrade-impact register.
08

Regulatory change and compliance cases

Turn a regulatory alert or report into triage, ownership, control change, approval and traceable closure.

Evidence: a closed-loop regulatory-change case.
09

Privacy Management

Model processing activities, assessments, obligations and issues across representative multi-jurisdiction scenarios.

Evidence: a privacy control and assessment pack.
10

Business continuity and operational resilience

Connect business services, impact analysis, continuity plans, exercises, dependencies and reporting.

Evidence: a resilience programme with test results.
11

Governing AI systems and agents

Use AI Control Tower and risk-and-compliance patterns to inventory, classify, monitor and contain AI use.

Evidence: an AI-system intake, risk classification and control set.
12

Capstone: deliver an IRM programme

Scope a multi-entity scenario, configure the operating model, test access and workflows, and present decisions to a mock steering committee.

Evidence: a demo-ready IRM programme and upgrade plan.
03 · Platform stack

The IRM surfaces you will work across.

The exact applications available in a practice instance depend on ServiceNow access and entitlement. The curriculum connects each surface to a clear governance outcome.

PC
Policy & Compliance
RM
Risk Management
AM
Audit Management
TP
Third-Party Risk
SAE
Smart Assessments
PM
Privacy Management
BC
Business Continuity
OR
Operational Resilience
AI
AI Control Tower
FD
Flow Designer
IH
Integration Hub
ATF
Automated Test Framework
PA
Performance Analytics
OT
ServiceNow Otto
04 · Project studio

Do the work. Keep the evidence.

Projects are threaded through the curriculum so each configuration decision has a business owner, a test case and a reviewable artefact.

Joint capstone

Multi-entity IRM programme

Design and configure an operating model spanning policy, risk, audit, third parties, privacy, resilience and AI governance.

01

Entity and control architecture with scoped ownership and traceability.

02

Assessment and issue workflows with review and exception paths.

03

Access and regression evidence for practitioner and implementer roles.

04

Australia upgrade-impact plan with entitlement dependencies.

IRMPolicyRiskAuditTPRM
Control design

Policy-to-control lifecycle

Trace an authority requirement through policy, control objective, control, attestation, evidence and remediation.

PolicyControlsEvidence
Third-party risk

Due-diligence workflow

Build a third-party engagement, assessment, review and issue flow using current Smart Assessment patterns.

TPRMAssessmentsIssues
AI governance

AI-system intake and controls

Inventory an AI use case, classify risk, assign controls, record review decisions and define containment actions.

AI Control TowerRisk classificationHuman review
05 · Outcomes

Leave with evidence, not notes.

Each outcome is tied to an artefact that can be reviewed in class and explained in an interview or project discussion.

Model risk and controls

Design entities, control objectives, controls, evidence and ownership so the structure remains usable at scale.

Configure reviewable workflows

Build policy, risk, audit, assessment and issue lifecycles with clear states, roles and audit trails.

Handle release change

Identify entitlement, data-model and removed-feature impacts before an upgrade reaches production.

Govern AI use

Inventory AI systems, classify risk, define controls and preserve human escalation for consequential decisions.

Test access boundaries

Validate practitioner, implementer, second-line, third-line and third-party views with evidence—not assumptions.

Present programme decisions

Explain scope, trade-offs, gaps, rollout controls and next steps to technical and non-technical stakeholders.

06 · Current-release focus

Teach what changed—including removals.

Release-specific material is reviewed against official ServiceNow documentation and taught with entitlement and upgrade caveats.

Australia-native terminology

Understand the relationship between ServiceNow Otto, AI experiences and the Foundation, Advanced and Prime product tiers.

TPRM upgrade awareness

Assessments using entities are no longer supported in Australia. Labs use current third-party and engagement assessment patterns.

Audit record separation

Use the audit-entry field to distinguish third-line records from the records used by second-line teams.

Entitlements before architecture

Capabilities vary by product tier, application version and customer entitlement. Designs document dependencies explicitly.

ServiceNow products, certification requirements and release behavior change. Digital Edify reviews the curriculum monthly; customers should confirm production entitlements with their ServiceNow account team.

07 · Learning experience

Practitioners define. Implementers configure.

Shared teaching keeps the operating model coherent; role-based lab evidence keeps the work relevant.

FocusPractitioner evidenceImplementer evidence
Entities and controlsScope, ownership and control rationaleHierarchy, mappings, roles and access tests
Risk and assessmentsMethodology, questions and decision criteriaConfigured templates, workflow and regression evidence
Audit and issuesPlan, independence rules and finding qualityWorkspace, audit-entry behavior and issue routing
Third-party riskDue-diligence design and review decisionsEngagement workflow, assessment engine and integrations
AI governanceClassification, policy and risk acceptanceInventory, monitoring, controls and containment workflow
Delivery

Campus and live online

Join from the Hitech City campus or a live online class. Current schedules and seat availability are confirmed by an advisor.

Environment

Personal Developer Instance

Build representative configurations in a practice environment and document the difference between lab evidence and production readiness.

Career support

Portfolio and interview preparation

Receive guidance on presenting artefacts, refining a role-focused resume and preparing to defend implementation choices.

Career support does not guarantee employment, interviews, placement or salary. Outcomes depend on the learner, employer decisions, experience, location, role fit and market conditions.

08 · Your instructor

Learn from practitioners. Defend every decision.

Explain the operating-model choice, demonstrate the configuration and show the evidence.

MK
Manikanta Kona
Founder, Digital Edify · Enterprise platform architect
ServiceNow · IRM · Enterprise governance
“A GRC implementation is credible only when the control model, access decisions and audit evidence tell the same story.”
01
DESIGN REVIEW
02
CONFIG REVIEW
03
EVIDENCE REVIEW

Design review. Explain scope, ownership, data relationships and the reason behind each control choice.

Configuration review. Demonstrate workflow behavior, roles, access boundaries, approvals and exception handling.

Evidence review. Show test results, audit history, traceability and the changes made after feedback.

09 · Career support

Turn the capstone into a credible story.

Career preparation helps you explain your role, decisions and evidence clearly. It does not guarantee an interview, placement, job or salary.
01 / PORTFOLIO

Show the operating model.

Organise the entity model, control lifecycle, assessments, test evidence and capstone decisions into a reviewable portfolio.

02 / RESUME

Describe what you owned.

Translate modules into practitioner or implementer responsibilities without overstating production experience.

03 / INTERVIEW

Defend the trade-offs.

Practise scenarios around scope, access, evidence, upgrades, exceptions and stakeholder communication.

See career support →
10 · Campus and online

Join in Hyderabad. Or learn live online.

Current schedules, delivery options, fees and seat availability are confirmed by admissions.

Flagship campus
Hyderabad
2nd Floor, Hitech City Road · Above Domino's · Opp. Cyber Towers, Jai Hind Enclave · Hyderabad, Telangana
India desk
Hours
Mon–Sun · 7 AM–9 PM
Online class
Global
Join mentor-led sessions remotely and complete the same IRM curriculum, role-based activities and capstone review.
Format
Live online
11 · FAQ

Straight answers before you enrol.

For current schedules, fees, exact certification requirements and enrolment terms, speak with an advisor.

Do I need prior GRC or ServiceNow experience?

The practitioner path does not require prior GRC experience. Implementer activities assume working ServiceNow administration knowledge; an advisor can recommend preparation based on your background.

Is the curriculum based on the Australia release?

Yes. Release-specific labs and upgrade notes use the Australia documentation baseline, including current TPRM assessment behavior, audit-entry separation and ServiceNow AI product tiers.

Will this prepare me for a ServiceNow certification?

The curriculum develops practical risk-and-compliance competencies relevant to ServiceNow certification paths. Exam names, prerequisites and blueprints can change, so confirm the current official requirements in ServiceNow University before booking an exam.

Will I work on a ServiceNow instance?

The learning plan includes guided configuration work in a Personal Developer Instance or equivalent practice environment, subject to ServiceNow availability and product access.

What is the programme duration or current fee?

Schedules, fees and enrolment terms can change and are confirmed directly by an advisor. The website does not publish a fixed duration or fee.

Does career support guarantee a job?

No. Career support can include portfolio, resume and interview preparation, but Digital Edify does not guarantee employment, interviews, placement, salary or any other outcome.

Build an IRM programme you can defend.

Book a 20-minute advisor call. We will map your risk or ServiceNow background to the right entry point and show you a representative project.