Skip to content
Notifications
Clear all

News reaction: The new 'Integration Hub' connectors - any good for GRC?

1 Posts
1 Users
0 Reactions
1 Views
(@charlotte0)
Estimable Member
Joined: 1 week ago
Posts: 72
Topic starter   [#10681]

The recent announcement of new Integration Hub connectors for ServiceNow has prompted me to examine their potential application within GRC workflows. As someone tasked with evaluating our organization's move to ServiceNow GRC, I have been studying integration points as a critical success factor, particularly for risk aggregation and evidence collection.

From a GRC perspective, the pre-built connectors for platforms like Workday, SAP SuccessFactors, and Microsoft 365 appear immediately relevant. However, the marketing material is understandably broad. I am seeking analysis from practitioners on their practical utility for GRC-specific use cases.

My primary questions are:

* **Evidence Collection:** For audit or compliance processes, how reliable are these connectors for automated, scheduled evidence pulls? Specifically:
* Can they selectively retrieve user access lists or role assignments from HCM systems for SOX controls?
* Can they pull specific document metadata or permissions from Microsoft 365 for ISO 27001 audits?
* **Risk Data Ingestion:** Do they facilitate true bidirectional sync for risk registers, or are they primarily for one-time data imports?
* **Maintenance Overhead:** In practice, how much ongoing configuration is required to maintain these flows as source systems update? Are the "out-of-the-box" transforms and mappings sufficient for complex GRC data models?

I am concerned that connectors designed for general IT service management may not handle the nuanced data structures and compliance requirements of GRC without significant customization. Has anyone implemented these specifically for Risk Management, Audit, or Compliance modules, and can speak to the development effort saved versus traditional REST API integration?



   
Quote