Certified Implementation Specialist - Risk and Compliance (CIS-RC) Mainline Exam Blueprint


ServiceNow Logo.png
 
Updated January 2026

Introduction

The ServiceNow Certified Implementation Specialist – Risk and Compliance Exam Specification document defines the purpose, audience, testing options, exam content coverage, test framework, and prerequisites for earning the Certified Implementation Specialist – Risk and Compliance certification.

Exam Purpose

The Certified Implementation Specialist – Risk and Compliance exam confirms you have the knowledge and skills to configure, implement, and maintain ServiceNow Risk, Policy & Compliance, and Audit Management applications. This certification validates their ability to manage entity frameworks, configure compliance processes, and support audits, enhancing governance and risk operations. 

Exam Audience

The ServiceNow Certified Implementation Specialist – Risk and Compliance exam is available to ServiceNow customers, partners, employees, and others interested in becoming a ServiceNow Risk and Compliance Implementer. Here is the recommended experience: 

    • Six months of field experience participating in at least two ServiceNow deployment projects or maintaining ServiceNow instances

 

Exam Preparation

Exam questions are based on official ServiceNow training materials, the ServiceNow Product documentation site, and the ServiceNow developer site. Study materials posted elsewhere online are not official and should not be used to prepare for the examination.

ServiceNow recommends completing these training course(s) in preparation for the Certified Implementation Specialist – Risk and Compliance exam. 
 

    • Welcome to ServiceNow
    • ServiceNow Administration Fundamentals
    • UI Builder Essentials
    • Flow Designer Essentials
    • Get Started with Now Create
    • ServiceNow Platform Implementation
    • CMDB Fundamentals
    • GRC: Integrated Risk Management (IRM) Fundamentals
    • GRC: Integrated Risk Management (IRM) Implementation
    • GRC: Classic Risk Assessment Fundamentals
    • GRC: Audit Management Essentials
    • GRC: Regulatory Change Management Essentials
    • GRC: Integrated Risk Management (IRM) Simulator 
    • Official practice exams are available through our trusted partner, MeasureUp — please refer to Knowledge Article KB0013408 for more information on how to access them.

 

Additional Resources

In addition to the above, these additional resources are valuable in preparation for the exam. 

 

Exam scope

This table shows the exam domains, weightings, sub-topics, and the percentage of questions represented in each domain. The listed sub-skills should NOT be considered an all-inclusive list of the exam content.  

Number of Domains

Exam Domain

Percent of Exam

1

GRC Overview

  • GRC Positioning and Framework
  • Key Terminology
  • Technical Details

11.67%

2

Implementation Planning

  • Use Cases
  • Implementation Team and Checklist
  • Risk and Compliance Personas, Groups and Roles

5%

3

Entity Framework

  • Entity Scoping Overview
  • Entity Type Approach
  • Entity Class Approach
  • Entity Architecture

20%

4

Policy and Compliance

  • Policy and Compliance Record Lifecycles
  • Policy and Compliance Architecture
  • Policy and Compliance Configuration
  • Compliance Supporting Processes

25%

5

Risk and Advanced Risk

  • Risk and Advanced Risk Record Lifecycles
  • Risk and Advanced Risk Architecture
  • Risk and Advanced Risk Configuration

25%

6

Common Elements and Extended Capabilities

  • Integrations
  • Content Packs
  • Other Platform Capabilities
  • Regulatory Change Management
  • Common Elements
  • Continuous Monitoring

8.33%

7

Audit and Advanced Audit

  • Audit and Advanced Audit Lifecycles
  • Audit and Advanced Audit Architecture
  • Audit and Advanced Audit Personas, Groups, and Roles

5%

Total

100%

 

Exam Registration

Step 1: Register for your exam 

  • Registration = payment. This step secures your exam attempt. Learning credits and credit card payments are accepted. Instructor-led training completion includes one free exam attempt. Discounted exam pricing may be available through associated company benefits.  
  • You can register at any time. Once registered, you have 90 days to schedule and complete your exam. 
  • Exam fees are non-refundable. Register only when you are prepared to schedule your exam. 

Step 2: Schedule your exam 

  • Click here to schedule the CIS – RC exam. Note: ServiceNow provides reasonable accommodation to individuals with disabilities or English as a Second Language (ESL) while taking the certification exam. 
  • Schedule within 90 days. After registration, you must schedule your exam appointment and complete your exam within 90 days. 

Step 3: Choose your exam delivery method 

  • From the My Exams page, you will be directed to Pearson
  • Choose to take your exam at a Pearson test center or online with OnVUE, where proctors observe via a webcam. 

Step 4: Complete your exam  

  • If you do not complete your exam within 90 days, your registration will expire, and you will need to register and pay the full exam fee again (start at step 1 again). 

 

 

Exam Structure

Exam Duration

The exam duration is 90 minutes.

Number of Items

The exam consists of 60 questions.

 

Multiple Choice (single answer)

For each multiple-choice question on the exam, there are at least three possible responses. Select the correct response. 

Multiple Select (select all that apply)

There are at least four possible responses for each multiple-select question on the exam. The question will state how many responses should be selected. Select ALL correct responses. Partial credit is not provided. 

Exam Result

An exam result notification is immediately displayed as a *conditional pass or fail after completing and submitting the exam.  

In addition, an exam result report is available and shows your exam result and the percentage of items in each section you answered correctly. Your exam result is conditional, meaning your results are preliminary and may be updated upon final review.  

*A conditional result means the exam can be audited and reviewed at any time, and the certification may be revoked after investigation if it is found that the ServiceNow Test Security Policies have been violated.   

 

 Understanding Your Results: 

 
Each question on the exam is worth one point. Your total score is compared to a predetermined cut score - this score is not publicly shared and is not always 70%  - to determine a pass or fail outcome. The section percentages on the exam result notification show how you performed in each domain, but they do not determine your overall result, should not be averaged, and do not indicate expertise. 

If You Pass: 

  • You will earn the Certified Implementation Specialist – Risk and Compliance certification and receive a Credly digital badge to showcase your achievement. 
  • To maintain your certification, complete annual maintenance exams (deltas) and pay the yearly Certification Maintenance Program (CMP) fee. 

 

If You Do Not Pass: 

  • Review the exam blueprint and the recommended training before retaking the exam. 
  • The retake policy requires a waiting period between attempts and payment of the exam fee for each attempt. 

 

 

 

Sample Questions

Sample Item #1:

What are scoped applications in GRC? (choose two)

A. GRC: Profiles 

B. GRC: Risk Management 

C. GRC: Compliance and Audit Management 

D. Global 

Answer: A, B 

 

Sample Item #2:

Who should be on the core implementation team for a GRC implementation? (choose two)

A. Risk and compliance experts  

B. ServiceNow developer team 

C. External audit team 

D. Risk assessors 

Answer: A, B 

 

Sample Item #3:

What mandatory field is required on the Entity Filter record?

A. Filter date  

B. Filter name 

C. Conditions 

D. Source table 

Answer: D 

 

Sample Item #4:

What tables are in the GRC: Policy and Compliance scope? (choose two)

A. Issue  

B. Control 

C. Risk 

D. Citation 

Answer: B, D 

 

Sample Item #5:

What tables are in the Risk scope? (choose two)

A. Issue  

B. Risk Framework 

C. Risk Statement 

D. Citation 

Answer: B, C 

 

Sample Item #6:

Unified Compliance Framework (UCF) Control documents import into which ServiceNow table with the UCF integration?

A. Citation table 

B. Control Objectives table 

C. Authority Documents table 

D. Policy table 

Answer: B 

 

Sample Item #7:

Which roles are inherited when a user is given the sn_audit.user role? (choose three) 

A. sn_grc.reader 

B. sn_compliance.reader 

C. sn_risk.reader 

D. sn_audit.external_auditor 

Answer: A, B, C 


Back to Top