Updated January 2026
IntroductionThe ServiceNow Certified Implementation Specialist – Risk and Compliance Exam Specification document defines the purpose, audience, testing options, exam content coverage, test framework, and prerequisites for earning the Certified Implementation Specialist – Risk and Compliance certification. Exam PurposeThe Certified Implementation Specialist – Risk and Compliance exam confirms you have the knowledge and skills to configure, implement, and maintain ServiceNow Risk, Policy & Compliance, and Audit Management applications. This certification validates their ability to manage entity frameworks, configure compliance processes, and support audits, enhancing governance and risk operations. Exam AudienceThe ServiceNow Certified Implementation Specialist – Risk and Compliance exam is available to ServiceNow customers, partners, employees, and others interested in becoming a ServiceNow Risk and Compliance Implementer. Here is the recommended experience:
Exam PreparationExam questions are based on official ServiceNow training materials, the ServiceNow Product documentation site, and the ServiceNow developer site. Study materials posted elsewhere online are not official and should not be used to prepare for the examination. ServiceNow recommends completing these training course(s) in preparation for the Certified Implementation Specialist – Risk and Compliance exam.
Additional ResourcesIn addition to the above, these additional resources are valuable in preparation for the exam.
Exam scopeThis table shows the exam domains, weightings, sub-topics, and the percentage of questions represented in each domain. The listed sub-skills should NOT be considered an all-inclusive list of the exam content.
Exam Registration
Step 1: Register for your exam
Step 2: Schedule your exam
Step 3: Choose your exam delivery method
Step 4: Complete your exam
Exam StructureExam DurationThe exam duration is 90 minutes. Number of ItemsThe exam consists of 60 questions.
Multiple Choice (single answer)For each multiple-choice question on the exam, there are at least three possible responses. Select the correct response. Multiple Select (select all that apply)There are at least four possible responses for each multiple-select question on the exam. The question will state how many responses should be selected. Select ALL correct responses. Partial credit is not provided. Exam ResultAn exam result notification is immediately displayed as a *conditional pass or fail after completing and submitting the exam. In addition, an exam result report is available and shows your exam result and the percentage of items in each section you answered correctly. Your exam result is conditional, meaning your results are preliminary and may be updated upon final review. *A conditional result means the exam can be audited and reviewed at any time, and the certification may be revoked after investigation if it is found that the ServiceNow Test Security Policies have been violated. Understanding Your Results: If You Pass:
If You Do Not Pass:
Sample QuestionsSample Item #1:What are scoped applications in GRC? (choose two) A. GRC: Profiles B. GRC: Risk Management C. GRC: Compliance and Audit Management D. Global Answer: A, B
Sample Item #2:Who should be on the core implementation team for a GRC implementation? (choose two) A. Risk and compliance experts B. ServiceNow developer team C. External audit team D. Risk assessors Answer: A, B
Sample Item #3:What mandatory field is required on the Entity Filter record? A. Filter date B. Filter name C. Conditions D. Source table Answer: D
Sample Item #4:What tables are in the GRC: Policy and Compliance scope? (choose two) A. Issue B. Control C. Risk D. Citation Answer: B, D
Sample Item #5:What tables are in the Risk scope? (choose two) A. Issue B. Risk Framework C. Risk Statement D. Citation Answer: B, C
Sample Item #6:Unified Compliance Framework (UCF) Control documents import into which ServiceNow table with the UCF integration? A. Citation table B. Control Objectives table C. Authority Documents table D. Policy table Answer: B
Sample Item #7:Which roles are inherited when a user is given the sn_audit.user role? (choose three) A. sn_grc.reader B. sn_compliance.reader C. sn_risk.reader D. sn_audit.external_auditor Answer: A, B, C | |||||||||||||||||||||||||||