Case Studies — Real Outcomes
GRC, resilience and AI governance programmes delivered on ServiceNow, with regulatory alignment and evidence your auditors can rely on. Outcomes are described qualitatively; no numeric metrics are claimed without validation.
TPRM Programme Build for a UK Insurance Group
No formal third-party risk programme existed. Vendors were managed across spreadsheets with no tiering, no due diligence process, and no regulatory evidence trail.
Without a formal TPRM programme, the insurer could not evidence oversight of its ICT third parties to the FCA or demonstrate DORA compliance. A material vendor failure would have been undetectable until it caused disruption.
Built a full TPRM programme on ServiceNow IRM, starting with a CMDB-linked vendor inventory and risk tiering, then layering due diligence workflows and continuous monitoring on top.
Not applicable. This engagement predated the AI authority programme.
Configured vendor inventory on the CMDB, risk-based tiering (critical, important, standard), tiered due diligence workflows, automated reassessment triggers, and a continuous monitoring dashboard aligned to DORA and FCA requirements.
Vendor inventory and risk tiering established, risk-based due diligence workflows configured, regulatory-ready evidence pack produced automatically, and fourth-party mapping introduced for critical suppliers.
Every vendor assessment, risk score and reassessment is recorded in ServiceNow with full audit trail. The evidence pack is produced automatically from live records rather than compiled manually.
Business Continuity Programme for a Global Law Firm
BCM plans were stored in static Word documents with no ownership, no testing cadence, and no way to demonstrate resilience to regulators or clients.
Static continuity plans go stale within months. Without ownership and testing, the firm could not demonstrate to clients or regulators that it could remain within impact tolerances during disruption.
Migrated all continuity plans into ServiceNow BCM, established ownership workflows, automated testing schedules, and built a real-time resilience dashboard.
Not applicable. This engagement focused on business continuity, not AI agent authority.
Migrated continuity plans into ServiceNow BCM with assigned owners, configured quarterly test cycles with automated evidence capture, enabled client-facing resilience reporting, and documented ISO 22301 alignment.
Continuity plans migrated with assigned owners, quarterly test cycle automated and evidenced, client-facing resilience reporting enabled, and ISO 22301 alignment documented.
Test results, ownership attestations and continuity plan reviews are all recorded in ServiceNow with timestamps and owner sign-off.
Operational Resilience for a Tier 1 UK Bank
The bank had not completed its important business service mapping or set impact tolerances ahead of FCA's compliance deadline.
Failure to identify important business services and set impact tolerances would have constituted a breach of FCA PS21/3 rules, with potential supervisory action and reputational damage.
Delivered a structured mapping exercise, configured ServiceNow to capture IBS, impact tolerances, and scenario testing evidence, producing a complete FCA evidence pack.
Not applicable. This engagement focused on operational resilience, not AI agent authority.
Identified and mapped important business services in ServiceNow, set and evidenced impact tolerances for all services, built a scenario testing framework and ran the first exercises, and delivered a regulator-ready evidence pack.
Important business services identified and mapped, impact tolerances set and evidenced, scenario testing framework built and first exercises run, and regulator-ready evidence pack delivered.
IBS mapping, impact tolerances and scenario test results are all maintained as live records in ServiceNow, not static documents.
AI Control Tower for a Financial Services Group
Rapid AI adoption across business units with no central governance. Regulators demanding model explainability, risk classification, and audit trails.
Without central AI governance, the group could not answer the fundamental regulator question: what AI systems do we have, and what risk category does each fall into? Shadow AI deployed outside procurement compounded the exposure.
Built an AI Control Tower on ServiceNow, starting with AI asset discovery to establish inventory, then layering risk classification, approval workflows and continuous monitoring.
AI use cases were inventoried and risk-classified. Runtime authority boundaries were identified as a Phase 2 requirement, to be implemented with VORTIQ-X when use cases move toward production.
Built an AI Control Tower on ServiceNow with model inventory, risk classification aligned to EU AI Act, approval workflows, and a continuous monitoring dashboard.
AI models classified and registered in ServiceNow, EU AI Act risk classification framework embedded, board-level AI risk dashboard configured, and model approval workflows established.
AI inventory, risk classifications, approval decisions and monitoring alerts are all recorded in ServiceNow with full audit trail. A regulatory audit pack can be produced from live records.
Want to See What We Can Do for You?
Every engagement starts with a conversation about where you are and what you need to achieve. No obligation.
Get in Touch →