Own the risk process
For risk, compliance, audit, privacy and resilience professionals moving beyond spreadsheets and disconnected evidence.
Learn ServiceNow Integrated Risk Management on the Australia release. Build policy, risk, audit, third-party risk, privacy, resilience and AI-governance workflows that stand up to real review.
The common core creates one vocabulary. Role-specific activities then separate process design from platform configuration.
For risk, compliance, audit, privacy and resilience professionals moving beyond spreadsheets and disconnected evidence.
For ServiceNow administrators and developers who want to implement IRM data, access, workspaces and integrations.
For consultants, pre-sales specialists and delivery leads who need release, entitlement and upgrade awareness.
For learners preparing for ServiceNow risk-and-compliance credentials who want hands-on evidence behind the terminology.
No prior GRC experience is required for the practitioner path. The implementer activities assume working familiarity with ServiceNow administration. An advisor can help map the right entry point.
Modules 1–5 establish the shared model. Modules 6–11 apply a practitioner and implementer lens. Module 12 joins both paths in a capstone.
Portfolio, entity model, policy, risk and assessments.
Practitioner artefacts paired with configured platform evidence.
Define, build, test and present an IRM operating model.
Map the applications, roles, product tiers and ServiceNow Otto terminology that shape an implementation.
Evidence: an accurate platform-estate map.Model organisations, processes, assets, controls and scope without creating an audit-maintenance problem.
Evidence: a three-level entity hierarchy with scoped controls.Connect authority documents, policies, control objectives, controls, attestations and issues through a reviewable lifecycle.
Evidence: an end-to-end compliance cycle.Design risk statements, methodologies, assessments, indicators and response workflows with human review around AI-assisted suggestions.
Evidence: a defensible risk register and assessment method.Author, version, delegate and review assessment templates while testing roles, access and in-flight change behavior.
Evidence: a versioned assessment with an access test pack.Plan engagements, test controls, capture findings and separate third-line audit records from second-line operational records.
Evidence: an audit workspace with record-segregation checks.Configure third-party and engagement workflows, current questionnaires, SBOM intake and Smart Assessment patterns—plus the Australia upgrade changes.
Evidence: a TPRM workflow and upgrade-impact register.Turn a regulatory alert or report into triage, ownership, control change, approval and traceable closure.
Evidence: a closed-loop regulatory-change case.Model processing activities, assessments, obligations and issues across representative multi-jurisdiction scenarios.
Evidence: a privacy control and assessment pack.Connect business services, impact analysis, continuity plans, exercises, dependencies and reporting.
Evidence: a resilience programme with test results.Use AI Control Tower and risk-and-compliance patterns to inventory, classify, monitor and contain AI use.
Evidence: an AI-system intake, risk classification and control set.Scope a multi-entity scenario, configure the operating model, test access and workflows, and present decisions to a mock steering committee.
Evidence: a demo-ready IRM programme and upgrade plan.The exact applications available in a practice instance depend on ServiceNow access and entitlement. The curriculum connects each surface to a clear governance outcome.
Projects are threaded through the curriculum so each configuration decision has a business owner, a test case and a reviewable artefact.
Design and configure an operating model spanning policy, risk, audit, third parties, privacy, resilience and AI governance.
Entity and control architecture with scoped ownership and traceability.
Assessment and issue workflows with review and exception paths.
Access and regression evidence for practitioner and implementer roles.
Australia upgrade-impact plan with entitlement dependencies.
Trace an authority requirement through policy, control objective, control, attestation, evidence and remediation.
Build a third-party engagement, assessment, review and issue flow using current Smart Assessment patterns.
Inventory an AI use case, classify risk, assign controls, record review decisions and define containment actions.
Each outcome is tied to an artefact that can be reviewed in class and explained in an interview or project discussion.
Design entities, control objectives, controls, evidence and ownership so the structure remains usable at scale.
Build policy, risk, audit, assessment and issue lifecycles with clear states, roles and audit trails.
Identify entitlement, data-model and removed-feature impacts before an upgrade reaches production.
Inventory AI systems, classify risk, define controls and preserve human escalation for consequential decisions.
Validate practitioner, implementer, second-line, third-line and third-party views with evidence—not assumptions.
Explain scope, trade-offs, gaps, rollout controls and next steps to technical and non-technical stakeholders.
Release-specific material is reviewed against official ServiceNow documentation and taught with entitlement and upgrade caveats.
Understand the relationship between ServiceNow Otto, AI experiences and the Foundation, Advanced and Prime product tiers.
Assessments using entities are no longer supported in Australia. Labs use current third-party and engagement assessment patterns.
Use the audit-entry field to distinguish third-line records from the records used by second-line teams.
Capabilities vary by product tier, application version and customer entitlement. Designs document dependencies explicitly.
ServiceNow products, certification requirements and release behavior change. Digital Edify reviews the curriculum monthly; customers should confirm production entitlements with their ServiceNow account team.
Shared teaching keeps the operating model coherent; role-based lab evidence keeps the work relevant.
| Focus | Practitioner evidence | Implementer evidence |
|---|---|---|
| Entities and controls | Scope, ownership and control rationale | Hierarchy, mappings, roles and access tests |
| Risk and assessments | Methodology, questions and decision criteria | Configured templates, workflow and regression evidence |
| Audit and issues | Plan, independence rules and finding quality | Workspace, audit-entry behavior and issue routing |
| Third-party risk | Due-diligence design and review decisions | Engagement workflow, assessment engine and integrations |
| AI governance | Classification, policy and risk acceptance | Inventory, monitoring, controls and containment workflow |
Join from the Hitech City campus or a live online class. Current schedules and seat availability are confirmed by an advisor.
Build representative configurations in a practice environment and document the difference between lab evidence and production readiness.
Receive guidance on presenting artefacts, refining a role-focused resume and preparing to defend implementation choices.
Career support does not guarantee employment, interviews, placement or salary. Outcomes depend on the learner, employer decisions, experience, location, role fit and market conditions.
Explain the operating-model choice, demonstrate the configuration and show the evidence.
Design review. Explain scope, ownership, data relationships and the reason behind each control choice.
Configuration review. Demonstrate workflow behavior, roles, access boundaries, approvals and exception handling.
Evidence review. Show test results, audit history, traceability and the changes made after feedback.
Organise the entity model, control lifecycle, assessments, test evidence and capstone decisions into a reviewable portfolio.
Translate modules into practitioner or implementer responsibilities without overstating production experience.
Practise scenarios around scope, access, evidence, upgrades, exceptions and stakeholder communication.
Current schedules, delivery options, fees and seat availability are confirmed by admissions.
For current schedules, fees, exact certification requirements and enrolment terms, speak with an advisor.
The practitioner path does not require prior GRC experience. Implementer activities assume working ServiceNow administration knowledge; an advisor can recommend preparation based on your background.
Yes. Release-specific labs and upgrade notes use the Australia documentation baseline, including current TPRM assessment behavior, audit-entry separation and ServiceNow AI product tiers.
The curriculum develops practical risk-and-compliance competencies relevant to ServiceNow certification paths. Exam names, prerequisites and blueprints can change, so confirm the current official requirements in ServiceNow University before booking an exam.
The learning plan includes guided configuration work in a Personal Developer Instance or equivalent practice environment, subject to ServiceNow availability and product access.
Schedules, fees and enrolment terms can change and are confirmed directly by an advisor. The website does not publish a fixed duration or fee.
No. Career support can include portfolio, resume and interview preparation, but Digital Edify does not guarantee employment, interviews, placement, salary or any other outcome.
Book a 20-minute advisor call. We will map your risk or ServiceNow background to the right entry point and show you a representative project.