We're evaluating ServiceNow GRC to centralize our risk register, and the biggest unresolved question is cross-functional risk ownership. In theory, a platform should solve this, but in practice, we see the same gaps.
Our current process (spreadsheets and emails) fails because a risk like "supply chain disruption for critical component" touches Procurement, Manufacturing, and IT. Each unit assigns it a low-to-medium rating locally, but the aggregate enterprise impact is critical. Nobody truly owns the mitigation across the boundary.
For those using ServiceNow GRC in production:
* How do you technically assign ownership for risks that inherently span multiple business units? Is it a single owner with "contributors," or a committee model tracked within the system?
* What's the workflow when a mitigation action assigned to Unit A is dependent on a control from Unit B? Does the platform help surface and track those dependencies, or does it just create another silo of tasks?
* How do you handle the reporting and accountability? If the risk isn't mitigated, who gets the escalation – the highest-ranking owner, or all of them?
I'm specifically looking for implementation details, not sales features. How is this configured, and what are the practical pitfalls? Our procurement team needs to know if the tool enforces collaboration or just gives us a new place to argue over who's responsible.