People reviewing and signing documents at a table
ServiceNow IRM

The ServiceNow IRM license model. How to scope GRC risk packs to the people who use them.

How ServiceNow prices its risk and compliance packs, how legacy GRC terms map to current packaging, and how to measure and cut IRM scope before renewal.

Contact Us ServiceNow Advisory
500+Enterprise clients
$2B+Under advisory
PublishedSeptember 16, 2025UpdatedSeptember 23, 2026
ContentsKey takeawaysHow IRM is licensedGRC versus IRMWho needs a licenseWhat overscoping costsMeasuring usageWhat we have seenNegotiating the renewalWhat to do nextFAQ

ServiceNow sells risk and compliance as product packs on top of the Now Platform, priced on metrics that differ from the core subscription. Programs overpay when the whole organization is licensed for modules only the risk team opens.

Key takeaways
  • The packs have their own meters. IRM packs sit above the fulfiller subscription and are priced on product metrics, so a per user assumption from the platform can be wrong in either direction.
  • Scope is where the money goes. Across our reviews, 25 to 40 percent of licensed risk module access sat with people who never opened the module.
  • Bundles carry unused applications. Most programs had modules they never deployed, and 10 to 20 percent of pack value was recoverable at renewal once deployment was measured.
  • Old GRC terms need mapping. Contracts from the GRC era carry module names and metrics the current price book no longer sells, and whoever maps them sets the new price.
  • Attesters rarely need a full seat. Control owners who only attest and approve belong on the lightest construct your terms allow, and the wider workforce belongs off the risk entitlement.
  • Measure before the meeting. Join risk module activity to the entitlement over four quarters and bring the result to the platform renewal, since mid term reductions return nothing.

How is ServiceNow IRM licensed?

ServiceNow licenses Integrated Risk Management as product packs on top of the Now Platform subscription you already pay for. You pay for the platform, then separately for the risk capability, and each pack is priced on its own product metric. That metric is often a different unit from the one your fulfiller subscription counts.

The practical consequence is that the risk quote is incremental to the platform conversation. It covers policy and compliance, risk management, audit management, vendor risk and their sibling applications, and every one of those lines should be scoped to the people who work risk, whatever the platform population looks like.

The layers of a ServiceNow risk and compliance contract
LayerWhat it coversHow to scope it
Now Platform baseThe fulfiller subscription the risk packs sit onAlready owned. The risk quote adds to it and should not resize it.
IRM packsPolicy and compliance, risk management, audit management, vendor risk and sibling applicationsEach pack on its product metric, sized to the population that works risk
Legacy GRC termsModule definitions and metrics from older contractsMapped explicitly at renewal, by you, before the account team does it for you
Bundled extrasCapabilities packaged into risk bundles that the program never deployedMeasured against usage and recovered at the next renewal

Why doesn't the platform user count carry over to the risk packs?

Because the risk modules meter on their own definitions. A program that scopes IRM as if it were another fulfiller pack inherits the platform's population, which can be thousands of people, when the product metric only needs the risk team, its assessors and the control owners who attest.

The error runs in both directions. Carry a per user assumption from the platform into a pack that counts something else and the number can come out far too high, or shaped wrongly for how the program works. Either way you end up paying for a count no one checked against the contract wording.

The first question on every risk quote

Ask for the exact unit of each risk metric, in the contract's own words, and apply it to the people who do the work. Settle the count before you discuss the discount, because a 30 percent discount on a count that is twice too large still costs more than list price on the right one.

Which applications sit inside the risk packs?

ServiceNow's product pages list Policy and Compliance Management, Risk Management, Audit Management, Third Party Risk Management, Business Continuity Management, Privacy Management and Operational Resilience Management in the risk and compliance family. Packs bundle several of these together, and in most programs we reviewed part of the bundle never reached production.

That gap between what is bundled and what is deployed is the second source of recoverable spend. List the applications named on your order form next to the applications with live records in your instance, and the unused lines show themselves.

Watch the briefingResearch briefing · 4:08

How do GRC and IRM differ in a ServiceNow contract?

IRM, Integrated Risk Management, is the product family name most current order forms carry. GRC, Governance, Risk, and Compliance, is the earlier name, and contracts written in that era still hold GRC module names, metrics and definitions that the current price book no longer sells.

The labels have moved again since. ServiceNow's website and documentation now use Governance, Risk, and Compliance as the umbrella, with Integrated Risk Management as one application inside it. Your contract, the next quote and the documentation may each use different names, and every mismatch is a place where scope can change unannounced.

What happens when the account team maps the old terms for you?

The renewal maps GRC era terms to current packaging one way or another. Left to the account team, the mapping lands on the current bundles at current scope. That is a repricing presented as modernization, and it adds every application in the new bundle whether or not you ran its predecessor.

When you run the mapping, you start from what the program deployed under the old terms and price only that under the new ones. The difference, everything bundled in but never used, becomes your negotiating position instead of being absorbed as the cost of upgrading.

Why we would not treat the new packaging as a like for like upgrade

The usual advice is to let ServiceNow convert legacy GRC entitlements to the nearest current bundle, since the conversion is framed as a technical necessity and the account team has the SKU tables. We disagree, because that conversion is the one decision that sets your price for the next term.

Build the mapping as a four column schedule: the old line item, what it covered, whether it holds live records in your instance, and the current SKU you accept for it. Rows with no live records get no current SKU. Send the schedule with your renewal request so the quote starts from it.

Free white paper

ServiceNow 10 Step Renewal Toolkit

The renewal sequence, the risk pack reconciliation and the order form wording in one download.

Get the white paper →

Who actually needs an IRM license?

Only a small group needs one. The working population of a risk program is the risk and compliance team that authors policies and runs assessments, plus control owners who attest on a set cadence. Everyone else receives a policy, reads it, or completes an occasional task.

The licensing failure maps that wide population onto the entitlement. The correction maps roles: authors and assessors on the pack, attesters at the lightest construct your terms allow, and the occasional population off the risk entitlement entirely. It is the same role discipline the fulfiller versus requester line applies on the platform underneath.

Mapping risk program roles to license constructs
RoleWhat they do in the toolWhere they belong
Risk and compliance teamAuthor policies, build controls, run risk assessments and auditsFull pack entitlement
Assessors and auditorsPerform assessments, document findings, raise issuesFull pack entitlement, counted by name
Control and risk ownersAttest to controls, approve assessments, complete response tasksThe lightest construct the contract allows
Employees at largeRead and acknowledge policies, report an issueOff the risk entitlement, through the portal where the terms permit

What is the lightest construct for attesters?

It depends on your contract generation, so read the order form before you assume anything. ServiceNow's current GRC documentation lists a GRC Business User Lite role that performs a subset of business user tasks, including policy acknowledgment, attestation and issue management. It also lists a read only GRC Reader role.

A separate GRC Employee role allows employees to acknowledge policies, report risk events and issues, and request policy exceptions. If your terms price the lite construct, most control owners belong there. If they do not, put it on the list of terms to ask for at renewal, with a stated unit price.

What does overscoping cost on an IRM contract?

On a typical overscoped line, correcting scope and constructs can cut the annual cost by about two thirds. The numbers below are hypothetical.

Say your order form covers 400 risk users at $1,200 per user per year, a $480,000 annual line. Your activity records show 60 authors and assessors, 200 control owners who attest each quarter, and 140 licensed users with no module activity in four quarters.

Hypothetical IRM scope correction, annual cost
StepCalculationAnnual costChange
Current scope400 users x $1,200$480,000None
Remove inactive access260 users x $1,200$312,000$168,000 lower (35 percent)
Move attesters to a lite construct60 x $1,200 plus 200 x $450$162,000A further $150,000 lower

The second row needs nothing from the vendor except your records. The third depends on a lite construct existing in your terms, so treat the $450 as a placeholder for your order form's price.

On top of scope, bundled modules you never deployed are priced into the pack. At a 15 percent bundle share, a $312,000 pack line carries $46,800 of applications you pay for without running.

How do you measure IRM usage before the renewal?

Join module activity per licensed user, per quarter, to the entitlement. The failure is measurable well before renewal, and the evidence turns the scope conversation from a negotiation about intentions into a reconciliation of records, which is a conversation buyers win.

  1. Pull the entitlement. In Subscription Management, list the users and groups allocated to each risk subscription. Users allocated by group membership often include whole departments.
  2. Pull role assignments. Export the sys_user_has_role table filtered to the GRC and IRM roles, so you know who holds full, lite and reader access.
  3. Pull activity from the risk tables. Count records each user created, updated or attested in the policy, control, risk, issue and audit tables, quarter by quarter.
  4. Join and classify. Mark every licensed user as author, assessor, attester or inactive, using at least four quarters so annual attestation cycles are not missed.
  5. Price the result. Apply the contract's unit to each class and compare the total with your current line.
Analytics dashboard open on a laptop screen
Platform login data overstates risk module use. A control owner who logs in every week to work incidents looks active on the platform while never opening a control record, so filter activity to the risk tables.

What should the evidence pack contain?

  • Entitlement by subscription. Licensed counts per risk pack, taken from the order form and from Subscription Management.
  • Activity by role class. The author, assessor, attester and inactive counts, with the date range used.
  • Deployed applications. Which bundled applications hold live records and which were never configured.
  • Legacy mapping. Each GRC era line on the old contract, what it covered and what you ran under it.

What have we seen in ServiceNow risk module reviews?

Across roughly 20 to 30 ServiceNow risk and compliance reviews Morten Andersen led between 2024 and 2026, the recurring finding was IRM scope set to the whole organization when only a risk team used it. The working population was usually counted in dozens.

  • Access that never opened the module. Across those reviews, 25 to 40 percent of licensed risk module access sat with people whose activity records showed no module use at all.
  • Recoverable bundle weight. Most programs we reviewed had bundled modules they never deployed, and 10 to 20 percent of pack value was recovered at renewal once deployment was measured against entitlement.
  • Metric mismatch. Programs were scoped on the platform's assumptions instead of the product metric, and the inflated counts were never rechecked after the original deal.
Measure usage before the renewal meeting. Evidence brought after the quote arrives is only an argument.

The correction for all three is the same discipline we apply across a ServiceNow contract: usage joined to entitlement every quarter, with a named owner, and taken into the renewal alongside the wider platform negotiation, where the risk line can be traded against the rest of the spend.

How should you negotiate the IRM line at renewal?

Renegotiate IRM scope at the platform renewal, with the evidence assembled beforehand. Mid term reductions return nothing under standard ServiceNow terms, so the renewal is where the corrected scope lands, and it lands best as one line inside the larger platform deal.

What will the account team say, and how should you answer?

  • "Enterprise wide licensing gives you room to grow the program." Ask for the growth plan in writing and a price hold on additional users. Buying headroom now means paying for it every year before you use it.
  • "The legacy GRC SKUs are retired, so we have to move you to the current bundle." Agree to the new SKU names and refuse the new scope. Price only the applications you ran under the old terms.
  • "Control owners need full licenses to attest." Ask which role the attestation task requires in current documentation, and point to the attestation tasks listed for the GRC Business User Lite role.
  • "Third party risk is included in the pack anyway." Ask for the line value of each bundled application and remove the ones with no live records.

Which contract terms should you ask for?

  • A written definition of each risk metric. It stops the unit from shifting when packaging changes again.
  • A lite or attester construct at a stated price. Control owners are the largest group, so their unit price drives the total.
  • A legacy mapping schedule. Attach old line, new line and scope to the order form, so the conversion cannot widen later.
  • Price holds on additional users for the full term. You can then buy for current use and add seats as the program grows.
  • A reduction right at renewal for individual packs. You can then drop an application that never went live without reopening the whole deal.

How does this change for a small program versus a large one?

A risk team of a dozen people at a 2,000 employee company mostly faces the bundle problem. Its user count is small, so the saving comes from applications it never deployed. A global bank with thousands of control owners faces the construct problem, because the attester price multiplied by thousands of people outweighs every other line.

First purchases differ from renewals too. On a first purchase you can set the metric definitions and constructs before any count exists. On a renewal you are correcting a count, and the rightsizing tool gives you a starting reconciliation to test against the vendor's number.

What to do next

  1. 12 months out, read the metric. Find the exact unit for each risk pack in the contract wording, and price the packs on it instead of the platform's assumption.
  2. 9 months out, measure activity. Join module activity per licensed user to the entitlement over four quarters, and reconcile the inactive access out of scope.
  3. 6 months out, map roles. Classify every licensed user with the role table above and price each class on the construct your terms allow.
  4. 6 months out, run the GRC to IRM mapping yourself. Complete the four column schedule and price only the rows with live records.
  5. 3 months out, send your scope first. Give the account team your corrected count and application list before they issue the renewal quote.
  6. At renewal, trade the risk line inside the platform deal. The ServiceNow practice runs the reconciliation with you and carries the corrected scope into the order form.
When to bring in help

Want a second opinion on your ServiceNow licensing? Our ServiceNow licensing consultants work only for buyers, with no partner income.

Frequently asked questions

How is ServiceNow GRC and IRM licensed?

As product packs added to the Now Platform, separate from the base fulfiller subscription, with each pack priced on its own product metric. Pricing is not published, so the unit and price come from your order form and quote. Ask for the metric definition in writing, so the unit cannot shift when ServiceNow repackages the product again.

Does everyone in the organization need IRM licensing?

Almost never. Employees who read and acknowledge policies or report an issue can usually do so through the portal without a risk seat, if your terms permit it. Paid access belongs with the risk and compliance team, assessors and auditors, with control owners on a lighter construct where one exists. Programs licensed for the whole company were the most overscoped we saw.

What is the difference between GRC and IRM in ServiceNow contracts?

IRM, Integrated Risk Management, is the name most current order forms use, and GRC is the earlier name whose module definitions and metrics survive in older contracts. ServiceNow's site now uses Governance, Risk, and Compliance as the umbrella label again, so check every line by what it covers, never by its name.

Why is the risk module metric different from the platform's?

Because the packs meter on product specific definitions, while the platform counts fulfillers and requesters. A per user assumption carried over from the platform inflates or misshapes the count. Reread the contract's exact unit before every renewal and apply it only to people who do risk work.

How much IRM spend is typically recoverable?

Two corrections add up: removing licensed access with no module activity, and removing bundled applications you never deployed. The first usually saves more on a large program, the second on a small one. Both land at renewal, and both depend on having the usage measurement finished before the renewal meeting.

When should the IRM scope be renegotiated?

At the platform renewal, with the evidence prepared six to twelve months ahead: activity joined to entitlement, roles mapped to constructs, and the legacy GRC mapping done by your team. Negotiated inside the wider ServiceNow deal, the corrected risk line can be traded against platform terms you care about.

Do control owners need a full IRM license to attest?

Usually not. ServiceNow documents a GRC Business User Lite role that covers attestation, policy acknowledgment and issue management without full authoring access. Whether you can use it depends on your contract generation, so check the order form. If the construct is missing, ask for it at renewal with a stated price.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the ServiceNow 10 step renewal toolkit.

The ten step renewal sequence, the risk pack scope reconciliation, the GRC to IRM mapping and the order form language that holds the corrected scope.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

ServiceNow licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.