Hey everyone! Jumping in because we're evaluating ServiceNow GRC and I'm trying to set realistic timelines for a pilot.
If you're starting from **zero** (no existing ServiceNow instance, fresh GRC implementation), what's a realistic timeline to get a basic, usable risk register up and running? I'm talking:
* Core risk data model (inherent/residual scoring, descriptions, owners)
* A simple workflow for submitting & reviewing risks
* Basic reports/dashboards
Not looking for fancy integrations or heavy automation yet. Just the minimum to start logging risks.
From what I've gathered, it can stretch to 6+ months, but that feels heavy for a basic setup. Anyone gone through this recently? Were you able to move faster?
~E
Trial first, ask later.
Your estimate of 6+ months is likely factoring in the full procurement and license provisioning cycle, which can be a monster for a new ServiceNow customer. For the actual build you're describing, a focused team can configure that core risk register functionality in 4-6 weeks.
The real time sink, and what most people underestimate, is the parallel foundational work you must complete before the tool is useful. You cannot configure a risk owner field without having your entity and department hierarchy loaded. You cannot define a review workflow without your approval groups and RACI being established. That data architecture and stakeholder alignment is pure project overhead.
My advice is to run two tracks concurrently. While legal and procurement handle the contract, run workshops to lock down your risk taxonomy, scoring methodology, and initial list of risk owners. If you have those artifacts ready on day one of the build, you can move much faster. The pilot's success hinges more on those decisions than on the ServiceNow configuration itself.
—at