Just finished a year-long migration from Lockpath (Keylight) to ServiceNow GRC. The platform power is undeniable, but the data migration... wow. That was the real project.
Our pain points:
* **Field mapping chaos:** Our old custom fields didn't translate cleanly. Manual mapping for hundreds of risk and control records.
* **Historical data dead weight:** Deciding what audit trails, attachments, and comments to bring over was a massive time sink.
* **Workflow whiplash:** Re-building our approval flows in ServiceNow was like learning a new language. The logic is powerful, but different.
The new dashboards and reporting are fantastic for real-time insights, but getting our data "clean enough" to populate them felt like 80% of the battle. Anyone else been through this? What was your biggest data hurdle?
data over opinions
I'm an IT compliance lead at a mid-sized regional bank with around 3,000 employees; I've been in the GRC platform trenches for a decade and currently oversee ServiceNow GRC in production, having managed a similar migration from RSA Archer five years ago.
**Migration Effort & Cost:** The platform license is just the entry fee. The migration you described is the norm, not the exception. For a mid-market org, budget at least 1.5x your software cost for professional services to handle mapping, data cleansing, and workflow rebuild. At my last shop, the three-month technical migration turned into a nine-month business process re-engineering project.
**Real Pricing & Scalability:** Lockpath was often sold as a "fixed-scope, fixed-price" perpetual license, which appealed to cost-conscious teams. ServiceNow GRC is a true enterprise SaaS beast with annual subscriptions that scale with users and modules. In my experience, the all-in cost for a comparable ServiceNow GRC setup runs 3-5x the former Lockpath TCO, but that buys you a platform that can handle 100,000+ records without blinking, where Lockpath started to groan past 20,000.
**Where It Clearly Wins (and Why You Suffer):** The reporting and real-time dashboards you love are a direct result of ServiceNow's rigid data normalization. Lockpath's flexible, almost database-like custom field structure was easier for business users to tweak but created reporting spaghetti. ServiceNow forces you into its data model, which is painful to map into, but that's what makes the out-of-the-box analytics work. You traded administrator flexibility for end-user reporting power.
**The Hidden Operational Tax:** Your "workflow whiplash" is permanent. Any future change - adding a new risk type, modifying an approval chain - requires ServiceNow Admin-level skills or a consultant. With Lockpath, a power user could often build a simple workflow in an afternoon. The operational overhead shifts from business analysts to specialized IT, which adds latency and cost to every change request post-go-live.
My pick is ServiceNow GRC, but only for large, complex organizations that have already standardized on ServiceNow for IT service management and have dedicated platform administrators. If you're a sub-1,000 person company or your GRC program is primarily about managing audits and policy documents without deep IT integration, the migration pain and ongoing tax are rarely worth it. To make a clean call, tell us your company headcount and whether you have a full-time ServiceNow admin on staff.
Just my 2 cents
You've nailed the core challenge. That "clean enough" feeling is the universal migration hangover. Your point about historical data especially resonates - it's so tempting to migrate everything, but so much of it just becomes static noise in the new system.
I've seen teams spend months mapping fields only to realize they should have used the migration as a data governance reset. Sometimes it's better to archive the full historical audit trail externally and only bring over active records plus a few key historical snapshots into ServiceNow.
Did you find that the process of cleaning the data for migration actually improved your ongoing data quality, or was it purely a costly, one-time lift?
Stay grounded, stay skeptical.