ServiceNow CIS-GRC - Risk and Compliance Implementation

By IAmtheCheese · Updated Jun 9, 2026

CertificationCIS – Risk and Compliance (CIS-RC)
Questions160
Passing Score75%
Format100% Multiple Choice
Sessions Logged523
Your progressLog in / Register to track times taken, best score, questions mastered, and coverage on this quiz.
Rating
Log in to rate

Certification Summary

The ServiceNow Certified Implementation Specialist - Risk and Compliance exam targets consultants tasked with building and configuring the GRC suite, rather than those who simply navigate the interface. Most people take this because a partner status requires a specific number of certified bodies, so expect questions that assume you know how to map control objectives to entities without breaking the underlying table structure.

Expect the exam to focus on Entity Scoping, Policy and Compliance, and Risk Implementation, which account for 75 percent of the content. The remaining sections cover GRC Overview, Implementation Planning, Audit Management, and Extended Capabilities. You will need to demonstrate how to configure the relationship between control tests and audit engagements within the GRC module.

Topics covered

This quiz

GRC Overview20 (12.5%)
Implementation Planning5 (3.1%)
Entity Framework31 (19.4%)
Policy and Compliance43 (26.9%)
Risk and Advanced Risk36 (22.5%)
Common Elements and Extended Capabilities16 (10%)
Audit and Advanced Audit9 (5.6%)

Exam blueprint

Official domain weights for this certification.

GRC Overview10%
Implementation Planning5%
Entity Scoping25%
Policy and Compliance Implementation Approach25%
Risk Implementation Approach25%
Extended Capabilities5%
Audit Management Implementation5%
GRC Overview20 questions
  • GRC Positioning and Framework4 q
  • Key Terminology4 q
  • Technical Details12 q
Implementation Planning5 questions
  • Use Cases2 q
  • Implementation Team and Checklist1 q
  • Risk and Compliance Personas, Groups and Roles2 q
Entity Framework31 questions
  • Entity Scoping Overview7 q
  • Entity Type Approach6 q
  • Entity Class Approach6 q
  • Entity Architecture12 q
Policy and Compliance43 questions
  • Policy and Compliance Record Lifecycles7 q
  • Policy and Compliance Architecture8 q
  • Policy and Compliance Configuration15 q
  • Compliance Supporting Processes13 q
Risk and Advanced Risk36 questions
  • Risk and Advanced Risk Record Lifecycles9 q
  • Risk and Advanced Risk Architecture10 q
  • Risk and Advanced Risk Configuration17 q
Common Elements and Extended Capabilities16 questions
  • Integrations6 q
  • Content Packs2 q
  • Other Platform Capabilities2 q
  • Regulatory Change Management2 q
  • Common Elements2 q
  • Continuous Monitoring2 q
Audit and Advanced Audit9 questions
  • Audit and Advanced Audit Lifecycles3 q
  • Audit and Advanced Audit Architecture3 q
  • Audit and Advanced Audit Personas, Groups, and Roles3 q
Question catalog for this preview

Catalog listing of the 5 preview questions for this quiz.

Question 1

When planning a GRC implementation checklist, what should be true about activities?

Answer choices

  • A. Checklists are optional because GRC configures itself

  • B. Checklists should follow phased delivery: scope, entitlements, foundation data, application configuration, adoption, and operationalization (Correct)

  • C. Only the Service Portal theme must be configured

  • D. Only hardware discovery must be completed first

Explanation

Implementation guidance emphasizes phased readiness: entitlements/plugins, foundational GRC data model (entities), then application-specific configuration and operating cadence.

Question 2

In which state of the Control record do Administrators schedule indicators?

Answer choices

  • A. Retired

  • B. Attest

  • C. Monitor (Correct)

  • D. Review

Explanation

Administrators schedule indicators in the Monitor state of a Control record. During the Monitor state, controls are generally not edited and updated only based on indicator activity. For instance, if the indicator result is Passed, the Control record could be updated to a Compliant status. Administrators do not schedule indicators in the Attest state. During the attest state, control owners are assigned to attest that a control is implemented. Only after executing an attestation, Administrators can measure (monitor) if the control is working as intended. Administrators do not schedule indicators in the Review state of a Control record. The Review state is used to review the evidence and attestation for a control. The Compliance Manager persona can then decide whether the Control can moved to Monitor, or they can move it back to Draft if the attestation and evidence was not sufficient.…

Question 3

Indicator scheduled runs should align to which control lifecycle state?

Answer choices

  • A. Draft

  • B. Monitor (Correct)

  • C. Retired only

  • D. Attest only

Explanation

Operational measurement happens after control passes review into monitoring.

Question 4

How does ServiceNow release new versions of the ServiceNow Governance, Risk and Compliance (GRC) application?

Answer choices

  • A. Via the ServiceNow Store. (Correct)

  • B. Via an application in ServiceNow Studio

  • C. Via ServiceNow family releases

  • D. Via unscoped Update Sets pushed between subproduction instances

Explanation

All Governance, Risk and Compliance (GRC) applications are available from the ServiceNow Store, allowing you to obtain new and updated features more rapidly. Before you can use any GRC applications, you must verify that you have entitlement to them, that is; you have valid licenses to use them. Then, you can download them from the ServiceNow Store and activate them. Some ServiceNow modules, like ITSM Asset Management, only receive updates via Family releases, but that does not apply to GRC. Family releases are the major ServiceNow upgrades that happen two times per year. Custom ServiceNow applications are built as a best practice in ServiceNow studio and released/deployed from there.

Question 5

Which statement describes an Authority Document in ServiceNow Governance, Risk and Compliance (GRC)?

Answer choices

  • A. Authority Documents serve to monitor controls and risks, and collect audit evidence.

  • B. Authority Documents describe an internal practice that processes must follow.

  • C. Authority Documents manage processes and citations are created to manage the process. (Correct)

  • D. Authority Documents are interchangeable with Knowledge article templates for HR policies

Explanation

Authority Documents manage processes and citations are created within them to manage points of the process. For example, the process named Building Security contains a citation for Entry Control. Authority Documents do not describe an internal practice that processes must follow. A policy defines an internal practice that processes must follow. Policies are defined as policies, procedures, standards, plans, checklists, frameworks, and templates. While a Policy is used to describe internal processes, an Authority Document is often an external document and contains laws and regulations about processes. Authority Documents do not serve to monitor controls and risks, and collect audit evidence. Indicators collect data to monitor controls and risks, and collect audit evidence. Indicators monitor a single control or risk.