A law firm focused on employment and labor law since 1958, with more than 1,100 attorneys in major cities nationwide engaged CoreX to implement ServiceNow Integrated Risk Management on a time and materials basis, establishing a governed platform for risk, policy, compliance, third-party risk, and audit activity.
Risk and compliance work at a national law firm spans many moving parts: enterprise and IT risks that need consistent assessment, policies and controls that must be mapped to authoritative sources and tested on a schedule, and a vendor population whose due diligence has to be repeatable rather than ad hoc.
Managing those processes without a common platform makes it difficult to see exposure in one place, to prove that controls were tested, or to hold vendor assessments to a single standard.
The engagement also carried real execution complexity. Existing GRC content lived in ZenGRC and had to be migrated, which required custom API development rather than a standard import. A competing internal initiative at the firm disrupted the planned timeline mid-flight, and parts of the scope depended on newly released ServiceNow functionality the delivery team had to ramp up on while building.
CoreX implemented ServiceNow IRM across four areas: Risk Management, Policy and Compliance Management, Third-Party Risk Management, and Audit Management. Delivery followed a workshop-led pattern, beginning with sessions to review out-of-the-box process and application functionality, followed by requirements workshops that documented functional and technical specifications, prototype reviews, and configuration against the agreed design.
The build covered the working parts of an operating GRC program:
Migration of ZenGRC content was handled through custom API development built for the firm's data. When the competing internal initiative shifted the schedule, CoreX adjusted resourcing quickly to keep the engagement moving, and the team absorbed the newly released platform functionality as it built.
Throughout, proactive communication and best-practice guidance kept scope tightly controlled, and hands-on QA support and role-based training prepared firm staff to own the platform after go-live.
The engagement delivered successfully despite the migration complexity, the timeline disruption, and the new platform functionality in scope. The firm now runs risk, policy and compliance, third-party risk, and audit on a single ServiceNow foundation, with controls mapped to authoritative sources, scheduled testing and approval workflows in place, and vendor due diligence standardized through a common portal, rating scale, and question bank.
GRC content previously held in ZenGRC was carried onto the platform through purpose-built integration work, and the firm's staff were trained and supported through QA to operate and extend what was built.
What began as separate risk, compliance, and vendor processes now operates as one governed program on ServiceNow, with the reporting and analytics to show where exposure sits. Tight discipline, fast resourcing decisions, and knowledge transfer to firm staff mean the platform is positioned to keep serving the firm well beyond the initial implementation.