Looking for good ServiceNow GRC/IRM learning resources
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 hours ago
Hi everyone,
I’m currently learning ServiceNow GRC/IRM and looking to build a strong understanding of the modules, starting from the fundamentals and progressing to more advanced, real-world scenarios.
Could anyone recommend good learning resources for ServiceNow GRC/IRM, such as:
- 📚 ServiceNow documentation or learning paths
- 🎥 Good YouTube videos or training series
- 🧪 Hands-on PDI exercises or real-world scenarios
- 📝 Blogs, community posts, or implementation guides
- 💡 Any recommended order/roadmap for learning GRC/IRM
I’m particularly interested in understanding areas like Policy & Compliance Management, Risk Management, Controls, Test Plans, Evidence, Issues, and IRM processes from both a functional and technical perspective.
Any recommendations, tips, or learning paths that have worked well for you would be greatly appreciated.
Thanks in advance! 🙏
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
Hi @Aparna45
There are dedicated IRM learning paths on SN University. Just do a search.
In terms of order I'd recommend starting with Risk Management (because the whole point or IRM is to manage risk), then Policy and Compliance, followed by Audit Management then branch out into whatever subjects you like, such as TPRM, BCM, Privacy Management or Operational Resilience. Many of these paths will have a lab instance or simulation.
AI Control Tower has a strong Risk and Compliance element as well, and is very much en vogue so worth looking at (but get a good grounding in Risk and Compliance first as otherwise AI Risk and Compliance Workspace won't make much sense).
A big part of IRM is understanding Entities and Entity scoping. This goes right across the product so something to think about as you progress through the products. Quick hint, they're usually people, places, or things that you are applying the product to (Risks, Controls, Audit Engagements, Privacy Screening Assessments etc).
There are many non-ServiceNow elements to IRM that you can only really gain from industry experience, so expect your learning to take you only so far. To truly understand it you need to work on actual engagements.
Best of luck and I hope this helps!
Mat