CIS-RC

Certified Implementation Specialist — Risk and Compliance

Study Guide

What the CIS-RC validates

The CIS-RC certification validates your ability to implement and configure ServiceNow's Governance, Risk, and Compliance (GRC) applications. This intermediate-level certification demonstrates expertise in policy and compliance management, risk assessment and management, audit management, and vendor risk management within the ServiceNow platform.

This certification is ideal for ServiceNow administrators, implementation specialists, and consultants who work with organizations implementing governance frameworks like SOX, ISO 27001, and NIST. It qualifies you to design risk registers, configure control testing workflows, manage audit engagements, and implement compliance monitoring solutions for enterprise clients.

Career impact

The CIS-RC opens doors to specialized GRC implementation roles, with certified professionals typically earning 15-25% salary premiums over non-certified peers. This certification positions you for senior implementation specialist, GRC consultant, and technical architect roles in risk and compliance.

As organizations increasingly prioritize governance and regulatory compliance, GRC expertise is in high demand. This certification complements other ServiceNow credentials and is particularly valuable for consultants working with financial services, healthcare, and public sector clients.

Exam format

  • 60 multiple-choice questions
  • 90 minutes to complete
  • 70% passing score (42 correct answers)
  • Delivered through Pearson VUE testing centers or online proctoring
  • Must wait 10 days between retake attempts
  • Exam cost: $450 USD
Free Newsletter

Enjoying this? Get one deep-dive per week.

Join 1,000+ ServiceNow pros — scripts, GlideRecord patterns, Flow Designer techniques, and career moves. Free.

No spam · Unsubscribe anytime

Prerequisites

You must hold the Certified System Administrator (CSA) certification before attempting the CIS-RC. ServiceNow also recommends 6-12 months of hands-on experience with the ServiceNow platform and familiarity with GRC concepts. While not required, experience with compliance frameworks like SOX, ISO 27001, or NIST will significantly help with contextual questions.

Sourdough
Chrome Extension

Sourdough: ServiceNow Monitoring and Analytics

A Chrome extension for ServiceNow Admins and Developers with essential tools, analytics, graphs and monitoring features.

Instance HealthGraphs & ChartsAPI HealthDeveloper ToolsQuick SearchInstance Switcher
Add to Chrome

Free to install. Pro $5/month after a 14-day no-card trial.
Pro requires the ServiceNow admin role. Upgrade inside the extension.

Overview
Tasks
CMDB
API
Metrics
Monitor
Internals
Instance:sourdoughdev·Version:Yokohama
Instance StateONLINE
System StatusFully Operational
Session Timeout90 minutes
Logged-In Sessions2 (20 active)
Build Nameyokohama-12-18-2024_p1
IP Address10.159.128.43
Instance HealthHealth Score: 90%
🔥 5dSourdough (Chrome Plugin)Dark Mode

Exam Domains

Policy and Compliance Management

25%

Covers the creation and management of policies, control objectives, controls, and control tests within the GRC hierarchy. Questions focus on configuration, workflows, and attestation processes.

Policy framework setupControl objective configurationControl test designAttestation workflows

Risk Management

25%

Focuses on risk framework implementation, risk register management, risk assessment methodologies, and risk response strategies. Includes risk scoring and matrix configuration.

Risk framework designRisk register configurationRisk assessment workflowsRisk scoring matrices

Audit Management

20%

Tests knowledge of audit engagement setup, audit task management, issue tracking, and audit workflow configuration. Emphasizes integration between audit findings and compliance.

Audit engagement setupAudit task workflowsIssue managementAudit reporting

Entity Management and Scoping

15%

Covers entity types, hierarchies, and scoping mechanisms within GRC applications. Questions test understanding of how entities relate to policies, risks, and audits.

Entity type configurationEntity hierarchiesScoping rulesEntity relationships

Content Library and Frameworks

10%

Focuses on pre-built control frameworks including SOX, ISO 27001, and NIST. Tests ability to implement and customize standard frameworks.

SOX framework implementationISO 27001 controlsNIST frameworkCustom framework creation

Integration and Vendor Risk

5%

Covers integration between GRC applications and basic vendor risk management functionality. Includes data flow between compliance failures and risk creation.

GRC application integrationVendor risk assessmentData relationshipsWorkflow automation

Study Plan

Week-by-Week Study Plan

  1. Week 1: GRC Fundamentals and Policy Management - Study the GRC hierarchy (Policy → Control Objective → Control → Test). Practice creating policies and control objectives in a developer instance. Complete the Policy and Compliance Management module in Now Learning.
  2. Week 2: Control and Test Management - Focus on control configuration, control test setup, and attestation workflows. Practice creating control tests and running attestation cycles. Study the relationship between controls and entity scoping.
  3. Week 3: Risk Management Deep Dive - Master risk framework design, risk register configuration, and risk assessment workflows. Practice setting up risk scoring matrices and understand risk response strategies. Complete hands-on labs for risk management scenarios.
  4. Week 4: Audit Management and Integration - Study audit engagement setup, audit task workflows, and issue management. Practice the integration between audit findings and compliance failures. Focus on audit reporting and dashboard configuration.
  5. Week 5: Content Library and Entity Management - Explore pre-built frameworks (SOX, ISO 27001, NIST) and their implementation. Practice entity type configuration and scoping rules. Study vendor risk management basics and GRC application integrations.
  6. Week 6: Review and Practice Exams - Complete comprehensive review of all domains. Take multiple practice tests and focus on weak areas. Practice scenario-based questions that test configuration knowledge. Schedule your exam for the end of this week.

Study Resources

Official Course
ServiceNow CIS-RC Official Course

Comprehensive official training covering all exam domains with hands-on labs and practice scenarios.

Documentation
ServiceNow GRC Documentation

Complete product documentation for Policy and Compliance Management, Risk Management, and Audit Management applications.

Practice Environment
ServiceNow Developer Instance

Free personal developer instance with GRC applications for hands-on practice and configuration testing.

Community
ServiceNow Community GRC Study Groups

Active forums and study groups where candidates share exam experiences and discuss GRC implementation challenges.

Documentation
ServiceNow GRC Implementation Guides

Step-by-step implementation guides for common GRC scenarios and framework deployments available in the knowledge base.

Practice Test
Third-Party CIS-RC Practice Tests

Commercial practice exams that simulate the real test environment and question format for the CIS-RC certification.

Exam Tips

1.The CIS-RC heavily tests the GRC hierarchy relationship - spend extra time understanding how Policy → Control Objective → Control → Test flows work in practice.
2.Many questions present implementation scenarios asking which configuration approach is correct - always read the business context before selecting technical answers.
3.Entity scoping questions are tricky - practice setting up entity hierarchies and understand how scoping affects policy and risk inheritance.
4.Risk scoring matrix configuration appears frequently - memorize the standard risk calculation methods and how to set up custom scoring.
5.Control test questions often focus on frequency, automation, and evidence collection - know the differences between manual, semi-automated, and fully automated tests.
6.Audit workflow questions test both configuration knowledge and process understanding - study the complete audit lifecycle from engagement to issue resolution.
7.Integration questions focus on data relationships between GRC apps - understand how compliance failures can automatically generate risks and audit issues.
8.Content library questions require knowledge of specific framework controls - review the key controls in SOX, ISO 27001, and NIST frameworks.
9.You can flag questions for review - use this feature for complex scenario questions and return to them after completing easier questions.
10.Vendor risk management questions are basic but important - understand the fundamental assessment workflows and risk rating processes.

Test Your Knowledge

Quick 3-question quiz — see how your ServiceNow skills stack up.

Question 1 of 3Performance

A list view on a table with millions of records is slow. Best fix?

Select an answer to continue