ServiceNow® Partner & first UK VORTIQ-X Implementation PartnerLearn more →
✦ Client Work

Case Studies — Real Outcomes

GRC, resilience and AI governance programmes delivered on ServiceNow, with regulatory alignment and evidence your auditors can rely on. Outcomes are described qualitatively; no numeric metrics are claimed without validation.

🔍
Insurance

TPRM Programme Build for a UK Insurance Group

Vendor inventory and risk tiering established, risk-based due diligence workflows configured, regulatory-ready evidence pack produced automatically, and fourth-party mapping introduced for critical suppliers.· DORA & FCA Aligned
Challenge

No formal third-party risk programme existed. Vendors were managed across spreadsheets with no tiering, no due diligence process, and no regulatory evidence trail.

Business & Governance Risk

Without a formal TPRM programme, the insurer could not evidence oversight of its ICT third parties to the FCA or demonstrate DORA compliance. A material vendor failure would have been undetectable until it caused disruption.

Approach

Built a full TPRM programme on ServiceNow IRM, starting with a CMDB-linked vendor inventory and risk tiering, then layering due diligence workflows and continuous monitoring on top.

ServiceNow Capabilities
ServiceNow IRMVendor Risk ManagementCMDB integrationContinuous monitoring dashboards
Authority Requirements

Not applicable. This engagement predated the AI authority programme.

Solution

Configured vendor inventory on the CMDB, risk-based tiering (critical, important, standard), tiered due diligence workflows, automated reassessment triggers, and a continuous monitoring dashboard aligned to DORA and FCA requirements.

Outcome

Vendor inventory and risk tiering established, risk-based due diligence workflows configured, regulatory-ready evidence pack produced automatically, and fourth-party mapping introduced for critical suppliers.

Evidence

Every vendor assessment, risk score and reassessment is recorded in ServiceNow with full audit trail. The evidence pack is produced automatically from live records rather than compiled manually.

What this demonstrates: That a ServiceNow TPRM programme replaces spreadsheet-based vendor management with a governed, evidenced system that regulators can rely on.
ServiceNow TPRM →
⚠️
Legal Services

Business Continuity Programme for a Global Law Firm

Continuity plans migrated with assigned owners, quarterly test cycle automated and evidenced, client-facing resilience reporting enabled, and ISO 22301 alignment documented.· Test Evidence Produced
Challenge

BCM plans were stored in static Word documents with no ownership, no testing cadence, and no way to demonstrate resilience to regulators or clients.

Business & Governance Risk

Static continuity plans go stale within months. Without ownership and testing, the firm could not demonstrate to clients or regulators that it could remain within impact tolerances during disruption.

Approach

Migrated all continuity plans into ServiceNow BCM, established ownership workflows, automated testing schedules, and built a real-time resilience dashboard.

ServiceNow Capabilities
ServiceNow BCMContinuity plan authoringAutomated testing schedulesResilience dashboards
Authority Requirements

Not applicable. This engagement focused on business continuity, not AI agent authority.

Solution

Migrated continuity plans into ServiceNow BCM with assigned owners, configured quarterly test cycles with automated evidence capture, enabled client-facing resilience reporting, and documented ISO 22301 alignment.

Outcome

Continuity plans migrated with assigned owners, quarterly test cycle automated and evidenced, client-facing resilience reporting enabled, and ISO 22301 alignment documented.

Evidence

Test results, ownership attestations and continuity plan reviews are all recorded in ServiceNow with timestamps and owner sign-off.

What this demonstrates: That ServiceNow BCM replaces static documents with a live, owned, tested and evidenced resilience programme.
Operational Resilience →
🏛️
Banking

Operational Resilience for a Tier 1 UK Bank

Important business services identified and mapped, impact tolerances set and evidenced, scenario testing framework built and first exercises run, and regulator-ready evidence pack delivered.· FCA PS21/3 Aligned
Challenge

The bank had not completed its important business service mapping or set impact tolerances ahead of FCA's compliance deadline.

Business & Governance Risk

Failure to identify important business services and set impact tolerances would have constituted a breach of FCA PS21/3 rules, with potential supervisory action and reputational damage.

Approach

Delivered a structured mapping exercise, configured ServiceNow to capture IBS, impact tolerances, and scenario testing evidence, producing a complete FCA evidence pack.

ServiceNow Capabilities
ServiceNow GRCImportant Business Service mappingImpact tolerance configurationScenario testing framework
Authority Requirements

Not applicable. This engagement focused on operational resilience, not AI agent authority.

Solution

Identified and mapped important business services in ServiceNow, set and evidenced impact tolerances for all services, built a scenario testing framework and ran the first exercises, and delivered a regulator-ready evidence pack.

Outcome

Important business services identified and mapped, impact tolerances set and evidenced, scenario testing framework built and first exercises run, and regulator-ready evidence pack delivered.

Evidence

IBS mapping, impact tolerances and scenario test results are all maintained as live records in ServiceNow, not static documents.

What this demonstrates: That operational resilience on ServiceNow provides live, evidenced mapping that satisfies FCA PS21/3 requirements.
Operational Resilience →
🤖
Financial Services

AI Control Tower for a Financial Services Group

AI models classified and registered in ServiceNow, EU AI Act risk classification framework embedded, board-level AI risk dashboard configured, and model approval workflows established.· EU AI Act Aligned
Challenge

Rapid AI adoption across business units with no central governance. Regulators demanding model explainability, risk classification, and audit trails.

Business & Governance Risk

Without central AI governance, the group could not answer the fundamental regulator question: what AI systems do we have, and what risk category does each fall into? Shadow AI deployed outside procurement compounded the exposure.

Approach

Built an AI Control Tower on ServiceNow, starting with AI asset discovery to establish inventory, then layering risk classification, approval workflows and continuous monitoring.

ServiceNow Capabilities
ServiceNow IRMAI Control TowerAI DiscoveryRisk classification workflows
Authority Requirements

AI use cases were inventoried and risk-classified. Runtime authority boundaries were identified as a Phase 2 requirement, to be implemented with VORTIQ-X when use cases move toward production.

Solution

Built an AI Control Tower on ServiceNow with model inventory, risk classification aligned to EU AI Act, approval workflows, and a continuous monitoring dashboard.

Outcome

AI models classified and registered in ServiceNow, EU AI Act risk classification framework embedded, board-level AI risk dashboard configured, and model approval workflows established.

Evidence

AI inventory, risk classifications, approval decisions and monitoring alerts are all recorded in ServiceNow with full audit trail. A regulatory audit pack can be produced from live records.

What this demonstrates: That ServiceNow AI Control Tower provides the inventory, classification and governance foundation that AI authority extends into runtime controls.
ServiceNow AI Governance →

Want to See What We Can Do for You?

Every engagement starts with a conversation about where you are and what you need to achieve. No obligation.

Get in Touch →