Case Studies | CoreX

Standing Up Integrated Risk Management for a National Employment and Labor Law Firm

Written by CoreX Editorial Team | 8/5/26

A law firm focused on employment and labor law since 1958, with more than 1,100 attorneys in major cities nationwide engaged CoreX to implement ServiceNow Integrated Risk Management on a time and materials basis, establishing a governed platform for risk, policy, compliance, third-party risk, and audit activity.

Challenge

Risk and compliance work at a national law firm spans many moving parts: enterprise and IT risks that need consistent assessment, policies and controls that must be mapped to authoritative sources and tested on a schedule, and a vendor population whose due diligence has to be repeatable rather than ad hoc.

Managing those processes without a common platform makes it difficult to see exposure in one place, to prove that controls were tested, or to hold vendor assessments to a single standard.

The engagement also carried real execution complexity. Existing GRC content lived in ZenGRC and had to be migrated, which required custom API development rather than a standard import. A competing internal initiative at the firm disrupted the planned timeline mid-flight, and parts of the scope depended on newly released ServiceNow functionality the delivery team had to ramp up on while building.

Solution

CoreX implemented ServiceNow IRM across four areas: Risk Management, Policy and Compliance Management, Third-Party Risk Management, and Audit Management. Delivery followed a workshop-led pattern, beginning with sessions to review out-of-the-box process and application functionality, followed by requirements workshops that documented functional and technical specifications, prototype reviews, and configuration against the agreed design.

The build covered the working parts of an operating GRC program:

  • Risk Management, including risk frameworks and statements, risk calculations, entity types and classes, catalog-driven risk entry, and risk overview and heatmap reporting.
  • Policy and Compliance Management, including the compliance framework of policies, controls, and authoritative sources, entity relationships and hierarchies, control test definitions with assigned tasks, review and approval workflows, control testing schedules, test plan and indicator templates, SLAs for past-due issues, and data imports for authoritative sources and firm policies.
  • Third-Party Risk Management, including the third-party risk portal, vendor and contact loading, risk engagements, rating scales and scoring, vendor assessments and question banks, and vendor risk score integration.
  • Audit Management, added to the original scope, alongside the Performance Analytics content pack for the Third-Party Risk Management workspace.

Migration of ZenGRC content was handled through custom API development built for the firm's data. When the competing internal initiative shifted the schedule, CoreX adjusted resourcing quickly to keep the engagement moving, and the team absorbed the newly released platform functionality as it built.

Throughout, proactive communication and best-practice guidance kept scope tightly controlled, and hands-on QA support and role-based training prepared firm staff to own the platform after go-live.

Results

The engagement delivered successfully despite the migration complexity, the timeline disruption, and the new platform functionality in scope. The firm now runs risk, policy and compliance, third-party risk, and audit on a single ServiceNow foundation, with controls mapped to authoritative sources, scheduled testing and approval workflows in place, and vendor due diligence standardized through a common portal, rating scale, and question bank.

GRC content previously held in ZenGRC was carried onto the platform through purpose-built integration work, and the firm's staff were trained and supported through QA to operate and extend what was built.

Summary

What began as separate risk, compliance, and vendor processes now operates as one governed program on ServiceNow, with the reporting and analytics to show where exposure sits. Tight discipline, fast resourcing decisions, and knowledge transfer to firm staff mean the platform is positioned to keep serving the firm well beyond the initial implementation.