If you are considering implementing ServiceNow or any other system to support your GRC (Governance, Risk & Compliance) functions and processes, you should be aware of the key prerequisites for success. Some of these are obvious, while others are a little more hidden and only identified later. It is therefore important that you give careful consideration to whether you have the right foundation to build on.
It is like building a bridge. The supporting structure must be solid before building the runway. And yes – sometimes it is necessary to build the bridge while driving on it, and that can also be done, as long as you are aware that the asphalt may be a little soft in a few places.

Compelling objectives
There are many objectives in investing in a new system to support your GRC functions and processes, and some of these objectives can be so compelling that you might rush the investment and implementation and discover too late that you were not entirely ready.
Generic objectives include digitalisation, automation of manual workflows, scaling across functions, replacing legacy technology, standardisation, breaking down organisational silos, as well as complying with your overall platformization strategy.
GRC-specific objectives include increased information security and resilience, organisational robustness, and compliance with standards, external legislation, and internal policies.

These objectives, combined with more frequent and more severe threats to the company’s operations, as well as growing and stricter demands from authorities and customers, may lead decision-makers to set high demands for the implementation of new solutions. And although overly extensive preparation can get in the way of execution, it is important to find the right balance and focus on the part of the preparation that will help ensure that the execution brings you closer to your goal within the boundaries of the project.
Key components of your foundation
Many good books and articles have been written about the preparation and execution of projects in general, so I will focus here on the parts of the preparation that I believe are particularly crucial for GRC system implementations. Many pitfalls and obstacles can be foreseen and managed with good preparation.
Recommendation: Think holistically across the organisation, processes, and technology.
Consider how the new system will affect your existing processes and workflows, will replace, complement, and possibly integrate with other systems, and how the many stakeholders may have conflicting objectives and expectations. And remember that you cannot achieve security and compliance through system implementations alone.
Often, a new GRC system will replace homegrown, complicated, and advanced Excel-based systems that key stakeholders themselves have been involved in developing, have used for a long time, and are very comfortable with. It therefore requires a focused effort to carry out this transformation – not only technologically but also to a large extent organizationally, as people must get used to using a completely new system that they are not as comfortable with as the old one.
Recommendation: Anchor in the business – not in IT.
Although system implementations heavily depend on your IT organisation, GRC systems are so closely linked to critical business functions that the anchoring and ownership of the implementation should be within the business, where many of the key stakeholders are located, with IT as an important partner. And yes – IT plays a vital role in both providing large parts of the foundation and in ensuring that the GRC system fits into the overall platform strategy and enterprise architecture.
This anchoring should be applied throughout the implementation, from selecting the system and implementation partner, planning and executing the implementation, and especially during the organizational implementation.
Recommendation: Find your ‘sweet spot’.
A sweet spot is the point on a racket where the greatest effect is achieved with the least effort. In this context, it means that you must find the areas where you have the best combination of:
- Relevance – clear objectives and urgent requirements.
- Readiness – sufficient process maturity and available resources.
- Data – trustworthy data sources and sufficient data quality.

Identifying your sweet spot also means that you can think and plan strategically and long-term while executing short-term with a constant eye on the overarching and strategic objectives.
Recommendation: Build your data foundation.
One of the most important ingredients in the foundation for a GRC system is your data, and at the same time, data is an ingredient that can be very difficult to work with.
All GRC practices depend on data in your Configuration Management Database (CMDB) and typically also a number of other sources in the same or integrated systems.
So when you start implementing a new GRC system, you should include the following data perspectives in your considerations:
Format
Which format is your data in today, and can that format still be used? Especially when transforming from homegrown or Excel-based systems, it is very likely that existing data must be reformatted to continue to be used in a standard system.
Sources
How do you ensure ‘a single source of truth’? Data to support your GRC functions and processes is not necessarily already located in one single system and may need to be moved around between systems, where it becomes crucial to be in control of the true source.
Quality
How do you ensure the necessary completeness and correctness in your data? Quality is often more important than quantity, and regardless of format and source, it is crucial that you can trust your data and that it provides a correct and complete picture.
Relevance
Which data is necessary for your functions and processes to work? This depends on which GRC functions and processes you want to support. This could, for example, be your control library, risk scenarios, policies, standards and legislation, organisational structure, suppliers and contracts, as well as technical components and assets such as business applications, systems, platforms, locations, etc.
Governance
Is your current data governance appropriate and sufficient? A decisive factor for your data quality and trust in your ‘single source of truth’ is that your master data management and governance is suitable for the purpose, including ownership, management, classification, access and rights management, as well as change management and versioning.
Conclusion
Well begun is half done! And the balance between preparation, planning, and execution is crucial. You should avoid letting overly thorough preparation become an obstacle to execution and the realisation of your objectives, and at the same time, you should avoid starting execution too quickly without having the prerequisites in place, or at least be explicit about which part of your foundation needs to be established as part of the execution itself.
And if it seems a bit overwhelming, uncertain, or difficult to find the right balance or to build your master data foundation, it is a good idea to talk to someone who has tried it before, knows the pitfalls, and knows how to achieve your objectives. Maybe Devoteam could be a good place to start?

