Book a Call

Compliance content or control evidence: build for ServiceNow GRC

Store App Planner · Updated

For compliance-content, control-testing and regulatory-intelligence vendors whose customers run ServiceNow Integrated Risk Management (GRC).

If your product supplies regulations and controls, tests controls, or tracks regulatory change, build a scoped Store app that feeds ServiceNow’s Integrated Risk Management applications. Compliance content goes in through ServiceNow’s Policy and Compliance integrator, a framework for content providers, as authority documents, citations and control objectives. Control checks run as indicators, and regulatory updates arrive through Regulatory Change Management’s framework for regulatory intelligence providers.

When this plan fits

  • You publish compliance content: regulations, standards, citations or control frameworks.
  • Or you test controls and produce evidence that a control passes or fails.
  • Or you track regulatory change and want your alerts in the customer’s regulatory workflow.
  • Your customers run ServiceNow Integrated Risk Management.

What your customers will need licensed

  • Customers need the IRM application you feed, such as Policy and Compliance Management or Regulatory Change Management; their Store listings name the ServiceNow products that include them. In the customer’s instance, Application Manager can show your app as “Not Licensed”; ServiceNow lists “A required dependency is not licensed” among the possible causes.
  • If your app is free, list it as type Integration: the Store says free apps of type Integration “are exempted from the custom table count and do not require custom table entitlement.” A free app of any other type uses each customer’s custom-table entitlement.

What you need before you start

  • Build Program membership, and vendor instances that can run the IRM applications you feed.
  • Your content mapped to ServiceNow’s model: authority documents, citations and control objectives.
  • Sample content or evidence at real volume.

The documents certification needs

Certification reviews your documents as well as your app, and in our experience it’s the part most teams miss. ServiceNow’s certification guide says “Certification has two tracks”: an app review and a listing review.

  • For the app review, ServiceNow asks for a “Design Document (for certification team only)”, a “Test Plan with results (for certification team only)” and an “Installation Guide (customer facing)”. Write the design document and test plan on ServiceNow’s templates; it provides a recommended template for the installation guide too.
  • For the listing review, your Store listing “consists of marketing documentation, demo videos, and other resources”, and the team inspects it for “Accuracy” and “Adherence to branding guidelines”.

ServiceNow lists “How well you documented your architecture in your Design Documentation” among the things that decide how long certification takes. The calendar gives the documents a week of their own.

Calendar to a Store listing

Plan on roughly 11–17 weeks (8–13 with a team that already knows the framework) from the start of design to a Store listing. The framework takes time to learn, and design is where that time goes.

PhaseWeeksNotes
Design 4–6 1–2 weeks with a team that already knows the framework
Build and test 3–5
Certification documents 1 Design document, test plan, installation guide and listing
ServiceNow certification review 3–5 ServiceNow’s typical range; no SLA is published

Not in ServiceNow’s Build Program yet? Add admission first: in our experience it takes 2–6 weeks, because ServiceNow reviews each application.

Weeks for design, build, documents and any programme steps come from our own projects. The review range is ServiceNow’s: certification “typically requires 3-5 weeks”, and no service level is published.

Certification risks on this path

  • Loading content around the Policy and Compliance integrator instead of through it, so it doesn’t link up.
  • Indicators that fail without a trace. Record results and supporting data, so auditors can see why a control passed or failed.
  • API credentials stored in properties or scripts instead of credential records.
  • Missing ACLs on custom tables, one of ServiceNow’s ten most-failed checks.

After launch

  • Maintenance is a release certification for each family release: retest on the new release and submit a revised test plan. ServiceNow’s Upgrade Policy says it “generally releases two new release families per year”. Any change to the app is a recertification, planned as new work. Retest when ServiceNow updates its IRM applications.
  • Ship content updates as data, versioned, so customers can see what changed.

What your prospect’s security reviewer will ask

  • Whose content it is, how often it updates, and what licence covers it.
  • What evidence the integration collects from their systems, and where it’s stored.
  • Which service account it runs as.

Sources

Review this plan with our team

We’ll check your plan with no commitment: the build path, what your customers will need, and a fixed-scope estimate. Personal reply within 24 business hours.

Review my plan

check_circleFounded by a former ServiceNow certification team member check_circle25+ apps taken through certification check_circleFree project scoping