Ellipse Gradient for Header
ServiceNow Integrated Risk Management logo

ServiceNow Integrated Risk Management Integration Guide

Integrate ServiceNow Integrated Risk Management with enterprise systems through ServiceNow REST APIs, configured outbound callbacks, staged imports, attachments, and secure workflows.

ServiceNow Integrated Risk Management integration options at a glance

ServiceNow Integrated Risk Management primarily integrates through the ServiceNow REST API framework, including the Table API, product-specific APIs, Import Set API, Attachment API, batch requests, and applicable asynchronous REST operations. ServiceNow also supports legacy SOAP web services and configured outbound REST messages, flows, business rules, notifications, or callbacks for selected event-driven scenarios. OAuth 2.0 and Basic Authentication are commonly available subject to instance policy, roles, ACLs, scopes, and integration-user permissions. Martini can consume these APIs, receive configured callbacks, upload evidence files, schedule incremental synchronization, transform IRM objects, and expose APIs for downstream systems.

Integration pointSupported by ServiceNow Integrated Risk Management?Common use casesHow Martini supports it
REST APIsYesUse the Table API, Import Set API, Attachment API, Aggregate API, batch requests, asynchronous operations, and product-specific APIs to read and update IRM data.Martini can consume ServiceNow REST APIs, transform payloads, apply business rules, paginate results, and expose reusable APIs or workflows.
SOAP APIsLegacySupport older integrations or enterprise systems that require WSDL-based ServiceNow web services.Martini can consume SOAP services where legacy compatibility is required, while REST remains the preferred design for new integrations.
Webhooks / outbound callbacksLimitedOutbound REST messages, flows, business rules, notifications, or scripted actions can invoke external endpoints for selected records and events.Martini can expose an API or workflow endpoint to receive configured callbacks and safely process event payloads with duplicate protection.
Bulk, asynchronous, and batch APIsYesUse Import Set processing, batch requests, asynchronous REST operations, scheduled imports, and pagination for larger or staged transfers.Martini can orchestrate staged loads, checkpoint progress, control concurrency, and reconcile partial failures.
File / attachment APIsYesUpload, download, and associate evidence, assessment documentation, remediation artifacts, and other files with IRM records.Martini can handle binary content separately from JSON metadata, map parent record identifiers, and apply checksum or duplicate controls.
AuthenticationYesOAuth 2.0 and Basic Authentication are commonly available, subject to instance policy, roles, ACLs, scopes, and integration-user permissions.Martini can use environment-specific secrets and configured authentication while handling token expiry, authorization failures, and ServiceNow response payloads.
Database accessNoDirect database connectivity to the ServiceNow SaaS database should not be assumed or used for IRM integration.Martini should use ServiceNow APIs, exports, reporting interfaces, or approved replication products instead of direct database access.

How ServiceNow Integrated Risk Management exposes data and business events

ServiceNow REST APIs

ServiceNow provides a REST API framework that includes the Table API and additional platform, IRM, import, attachment, aggregate, batch, and asynchronous APIs where applicable. Exact tables, fields, roles, and product-specific APIs depend on the instance configuration and release.

Martini implementation pattern

Martini implementation pattern: a workflow authenticates to ServiceNow, retrieves or submits the required resource, transforms the payload into a canonical model, applies business rules, and writes to the target system. The workflow records pagination state, identifiers, response details, and reconciliation outcomes.

Implementation sequence

Authenticate with an environment-specific ServiceNow credential
Build a bounded query for the required IRM table or product API
Retrieve pages of Risks, Controls, Issues, or related objects
Map and validate fields and ServiceNow reference identifiers
Apply ownership, status, and duplicate-prevention rules
Write the result to the target system or ServiceNow API

Outbound callbacks

ServiceNow can invoke external endpoints through outbound REST messages, flows, business rules, notifications, or scripted actions. Callback coverage is configured for selected tables and events; it is not a universal webhook stream for every IRM change.

Martini implementation pattern

Martini implementation pattern: Martini exposes an API endpoint, validates the callback contract and authentication, uses the supplied sys_id and event information to retrieve current ServiceNow data when needed, then orchestrates downstream processing. Duplicate callbacks are handled through correlation and idempotency checks.

Implementation sequence

Receive the configured ServiceNow callback
Authenticate and validate the event contract
Check the correlation identifier and event replay status
Retrieve the current ServiceNow resource when the callback is partial
Apply mappings and downstream business rules
Acknowledge or record the result and route failures for retry

Bulk and asynchronous processing

ServiceNow supports Import Set processing, REST batch requests, applicable asynchronous REST operations, scheduled imports, and paginated reads. These mechanisms support staged or higher-volume movement when the selected API and workload permit them.

Martini implementation pattern

Martini implementation pattern: a scheduled or triggered workflow partitions the workload, submits or retrieves batches, stores checkpoints, and reconciles accepted, rejected, and pending items. The design avoids treating a large Table API read as one unbounded transaction.

Implementation sequence

Start a scheduled or controlled batch workflow
Determine the source watermark and bounded page or batch
Submit or retrieve the batch through the applicable ServiceNow API
Persist accepted, rejected, and pending identifiers
Retry transient failures with controlled backoff
Complete reconciliation and advance the checkpoint

File and attachment APIs

The ServiceNow Attachment API supports binary files associated with records, including evidence, assessment documentation, and remediation artifacts. Attachment permissions, size policies, content types, and parent-record access must be verified.

Martini implementation pattern

Martini implementation pattern: a workflow first resolves the parent IRM record, then transfers binary content separately from JSON metadata, associates the attachment, and records the result. Checksums or external references can help prevent duplicate files.

Implementation sequence

Resolve and authorize the parent IRM record
Retrieve or receive the evidence file and metadata
Validate content type, size, and duplicate indicators
Upload the binary content through the Attachment API
Associate the attachment with the parent record
Record the attachment identifier and processing outcome

SOAP web services

ServiceNow supports SOAP-based web-service interfaces for compatible integrations, although REST is generally preferred for new work. SOAP remains relevant where an existing enterprise contract requires WSDL-based communication.

Martini implementation pattern

Martini implementation pattern: Martini consumes the required SOAP operation, maps XML request and response structures into the integration model, applies validation and business rules, and routes SOAP faults or transport failures through workflow error handling.

Implementation sequence

Authenticate to the configured ServiceNow SOAP service
Submit the WSDL-defined request
Parse the XML response or SOAP fault
Map the response into the canonical model
Apply validation and target-system rules
Persist the result and retry only eligible transient failures

Common ServiceNow Integrated Risk Management integration patterns

Pattern 1: Synchronize Risks and Issues with remediation systems

When to use this pattern

Use this pattern when governance teams manage Risks or Issues in ServiceNow IRM while remediation teams work in ServiceNow ITSM, Jira, or another case-management platform. Scheduled incremental polling is suitable when callback coverage is incomplete.

Integration direction
ServiceNow Integrated Risk Management
Martini
Jira
Example Mapping
ServiceNow Integrated Risk Management FieldCanonical FieldTarget Field
sys_idsourceRecordIdexternalReference
numberissueNumbersummaryOrExternalKey
statestatusstatus
assigned_toownerassignee
Martini implementation pattern

A Martini workflow queries changed records using sys_updated_on with a tie-breaker or overlap window, paginates results, maps ownership and status values, and applies create-versus-update rules. It stores source and target identifiers, handles missing references as exceptions, retries transient failures, and reconciles rejected items.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination and checkpoints
  • data mapping
  • business rules
  • error handling

Pattern 2: Process control evidence and assessment attachments

When to use this pattern

Use this pattern when evidence originates in a document or business system and must be associated with a ServiceNow Control, Assessment, or Issue. It separates binary transfer from record metadata and status updates.

Integration direction
Workday
Martini
ServiceNow Integrated Risk Management
Example Mapping
ServiceNow Integrated Risk Management FieldCanonical FieldTarget Field
externalDocumentIdevidenceReferenceattachment metadata
contentTypefileTypeattachment content type
controlIdparentRecordIdparent sys_id
processingStatusevidenceStatusControl or Issue status
Martini implementation pattern

Martini validates the source metadata, resolves the parent ServiceNow record, checks size and duplicate indicators, uploads the binary through the Attachment API, and updates the related control or issue only after successful association. Failed transfers are retained for replay without creating duplicate attachments.

Martini capabilities used
  • workflow orchestration
  • file handling
  • API consumption
  • data validation
  • mapping
  • retry and reconciliation

Pattern 3: Synchronize organizational ownership from Workday

When to use this pattern

Use this pattern when Workday or another authoritative organizational system owns worker, manager, department, or hierarchy data used by IRM Entities, profiles, and assignment fields.

Integration direction
Workday
Martini
ServiceNow Integrated Risk Management
Example Mapping
ServiceNow Integrated Risk Management FieldCanonical FieldTarget Field
workerIdpersonExternalIduser reference
departmentCodeorganizationCodeEntity reference
managerIdmanagerExternalIdowner or approver
employmentStatusactiveStatusassignment eligibility
Martini implementation pattern

A scheduled Martini workflow retrieves changed organizational data, validates that referenced ServiceNow users and groups exist, maps entities and ownership, and updates only approved fields. Records with unresolved references are quarantined, while successful updates retain source watermarks and ServiceNow identifiers.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • reference resolution
  • data transformation
  • validation
  • error handling

Pattern 4: Trigger remediation from selected ServiceNow events

When to use this pattern

Use this pattern when a configured outbound REST message, flow, business rule, or notification should initiate action when an Issue or control deficiency reaches a selected state.

Integration direction
ServiceNow Integrated Risk Management
Martini
Jira
Example Mapping
ServiceNow Integrated Risk Management FieldCanonical FieldTarget Field
sys_idsourceRecordIdexternalReference
tablesourceTablesourceType
eventTypelifecycleEventworkflow action
stateremediationStatusJira status
Martini implementation pattern

ServiceNow invokes a Martini API with the event contract. Martini authenticates and validates the payload, retrieves current data when needed, enriches it from the target system, applies routing rules, and writes the remediation result. Correlation IDs, idempotency checks, and controlled retries protect against duplicate callbacks.

Martini capabilities used
  • API exposure
  • webhook and callback handling
  • workflow orchestration
  • data enrichment
  • business rules
  • idempotency and retries

Applications commonly integrated with ServiceNow Integrated Risk Management

ServiceNow IRM commonly participates in enterprise workflows that connect governance data with operational, identity, organizational, and remediation systems. Martini can orchestrate these relationships through documented APIs and configured callbacks without requiring a dedicated native connector.

Application Scenario Direction Martini Pattern
ServiceNow ITSM Link IRM Issues and remediation activities to Incidents, Problems, Changes, and Tasks managed by ITSM. ServiceNow Integrated Risk Management → Martini → ServiceNow ITSM Use ServiceNow REST APIs to retrieve or receive selected IRM Issues, map identifiers and status values, and update the corresponding ITSM records. Store correlation identifiers and apply idempotent update rules.
ServiceNow CMDB Associate risks, controls, and compliance scope with configuration items, services, and business applications. ServiceNow CMDB → Martini → ServiceNow Integrated Risk Management Retrieve approved CMDB reference data, resolve ServiceNow sys_id values, and update IRM relationships through controlled REST workflows. Validate permissions and reference-field behavior before production writes.
Salesforce Exchange ownership, operational context, or selected risk and compliance findings associated with Salesforce processes. Salesforce → Martini → ServiceNow Integrated Risk Management Consume Salesforce and ServiceNow APIs, normalize ownership and external identifiers, apply field-level business rules, and synchronize only the approved IRM fields with retry and reconciliation handling.
Jira Create and track remediation work for IRM Issues or control deficiencies in development and project teams. ServiceNow Integrated Risk Management → Martini → Jira Trigger from configured ServiceNow callbacks or scheduled polling, create or update Jira work items, retain the Jira key and ServiceNow sys_id, and return status or resolution changes to IRM.
Microsoft Entra ID Synchronize users, groups, and organizational ownership used for risk, control, and remediation assignments. Microsoft Entra ID → Martini → ServiceNow Integrated Risk Management Retrieve approved identity and group data, validate matching ServiceNow users and groups, then update ownership or assignment fields while applying least-privilege and duplicate-prevention rules.
Workday Supply worker, department, manager, and organizational hierarchy data for IRM ownership and entity structures. Workday → Martini → ServiceNow Integrated Risk Management Schedule incremental retrieval, transform organizational data into ServiceNow Entities, profiles, or ownership references, resolve reference fields, and quarantine records with missing owners.
SAP S/4HANA Provide business-process, organizational, financial, or supplier information for risk and control scope. SAP S/4HANA → Martini → ServiceNow Integrated Risk Management Orchestrate API-based extraction from SAP and ServiceNow, map business keys into IRM scope data, enforce validation rules, and retain checkpoints for repeatable reconciliation.
RSA Archer Exchange risk, compliance, control, or issue information during GRC platform coexistence, migration, or consolidation. RSA Archer → Martini → ServiceNow Integrated Risk Management Use staged extraction and transformation workflows, map legacy identifiers to ServiceNow sys_id or approved alternate keys, validate relationships, and produce exception results for reconciliation.

How to build a ServiceNow Integrated Risk Management integration in Martini

Objective

Establish environment-specific access to the ServiceNow instance using an approved authentication method and a least-privileged integration user.

Instructions in Martini

  • Configure the ServiceNow base URL and applicable REST or SOAP API
  • Use OAuth 2.0 where approved, or Basic Authentication where permitted
  • Store client secrets and credentials in Martini secrets
  • Confirm roles, ACLs, scopes, domain rules, and attachment permissions

Objective

Select a trigger that matches the required timeliness and ServiceNow event coverage.

Instructions in Martini

  • Use a configured ServiceNow callback for selected events
  • Use a scheduled Martini workflow for incremental synchronization
  • Use a manual or API trigger for controlled remediation or migration operations
  • Define the tables, event types, and source watermark

Objective

Read the current ServiceNow resource or accept the callback payload needed for processing.

Instructions in Martini

  • Use the Table API or product-specific API where appropriate
  • Bound queries and paginate Table API reads
  • Retrieve the current record when a callback contains only identifiers
  • Use the Import Set, batch, asynchronous, or Attachment API for applicable workloads

Objective

Coordinate retrieval, enrichment, validation, target writes, and reconciliation as a maintainable Martini workflow.

Instructions in Martini

  • Separate transport, transformation, business rules, and persistence logic
  • Resolve ServiceNow reference fields explicitly
  • Retain sys_id, external identifiers, correlation IDs, and checkpoints
  • Route validation failures and unresolved references to an exception path

Objective

Convert ServiceNow IRM structures and choice values into the target system's canonical model.

Instructions in Martini

  • Map Risks, Controls, Issues, Indicators, Policies, Entities, and profiles explicitly
  • Avoid writing calculated, derived, journal, or read-only fields without confirmation
  • Normalize dates, statuses, ownership, and priority values
  • Handle binary attachments separately from JSON metadata

Objective

Enforce ownership, routing, idempotency, and source-of-truth decisions before writing changes.

Instructions in Martini

  • Distinguish create, update, replay, and delete behavior
  • Prevent duplicate records using sys_id or an approved alternate key
  • Validate target references and required fields
  • Account for ServiceNow business rules, flows, notifications, approvals, and audit side effects

Common ServiceNow Integrated Risk Management data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
RisksSynchronize identified risks, assessment results, ownership, status, scoring, and treatment information.ServiceNow ITSM, Jira, GRC platforms, data warehousesMartini reads or writes approved risk fields through REST APIs, retains sys_id or an alternate key, resolves references, and applies idempotent upsert rules.
ControlsExchange control definitions, owners, effectiveness assessments, test results, and risk or policy relationships.GRC platforms, Jira, document systems, reporting storesMartini maps control fields and relationships, validates required references, and separates calculated or read-only fields from writable fields.
Policies and policy statementsSynchronize governance requirements, obligations, and mappings to controls or compliance activities.Document platforms, GRC platforms, reporting storesMartini transforms policy structures, preserves ServiceNow identifiers, and routes validation failures for review before updates.
IndicatorsExchange measurements for control, risk, or compliance performance, including applicable key indicators.Analytics platforms, data warehouses, GRC platformsMartini retrieves bounded datasets or aggregates where permitted, normalizes measurements, and records the source timestamp and scope.
IssuesCreate and track control deficiencies, assessment findings, remediation items, and exceptions.ServiceNow ITSM, Jira, case-management systemsMartini can trigger from configured callbacks or poll incrementally, map ownership and status, retain correlation IDs, and retry only transient failures.
Entities and profilesRepresent organizational units, services, applications, processes, locations, and assessment context.Workday, Microsoft Entra ID, SAP S/4HANA, CMDBMartini validates reference data and synchronizes owners, scopes, and profiles using stable identifiers and explicit reference resolution.

Authentication and security considerations

Authentication and authorization

ServiceNow commonly supports OAuth 2.0 and Basic Authentication for REST integrations, subject to instance policy. Mutual TLS and certificate-based controls may also be available in selected configurations.

  • Use a dedicated integration user with only the roles, scopes, table permissions, and field ACL access required by the workflow.
  • Store ServiceNow credentials, OAuth client details, and certificates as environment-specific Martini secrets.
  • Confirm application scopes, domain separation, IP restrictions, API access policies, and attachment permissions.
  • Prefer OAuth 2.0 for managed production integrations when approved by the ServiceNow security team.

Operational considerations for ServiceNow Integrated Risk Management integrations

Design for controlled synchronization

ServiceNow API limits depend on instance configuration, user, API, licensing, and platform load. Use bounded queries, pagination, controlled concurrency, response-aware throttling, and retry backoff.

  • Use sys_updated_on with a tie-breaker, an overlap window, or an approved synchronization watermark for incremental processing.
  • Retain sys_id or a stable alternate key to support idempotent creates and updates.
  • Distinguish ACL failures, validation errors, missing references, rate limits, conflicts, and transient 5xx responses.
  • Test against a representative sub-production instance because releases, scoped applications, custom fields, business rules, and APIs can vary.
  • Handle attachments separately and account for binary size, content type, parent-record access, and duplicate files.

Why use Martini instead of scripts or point-to-point integrations?

Integration control and reuse

Point-to-point scripts often combine authentication, API calls, mappings, retries, and business rules in code that is difficult to govern as requirements change. Martini provides a workflow-based structure for these concerns while preserving the option to add custom logic when required.

  • Centralize ServiceNow API consumption, callback handling, transformations, and target-system orchestration.
  • Reuse mappings, validation rules, authentication configuration, and error-handling patterns across IRM workflows.
  • Support scheduled, event-driven, API-led, staged, and attachment-processing designs in one integration runtime.
  • Expose controlled Martini APIs for ServiceNow callbacks or downstream consumers.
  • Provide workflow logging, troubleshooting, retries, and reconciliation paths for operational support.

Frequently asked questions

How can ServiceNow Integrated Risk Management be integrated with enterprise systems?

ServiceNow IRM can be integrated primarily through the ServiceNow REST API framework, including the Table API, product-specific APIs, Import Set API, Attachment API, batch operations, and applicable asynchronous REST APIs. SOAP web services support legacy scenarios, while configured outbound REST messages, flows, business rules, or notifications can support selected callback-driven processes.

Can Martini integrate with ServiceNow Integrated Risk Management?

Yes. Martini can integrate with ServiceNow IRM by consuming its REST APIs, using SOAP where legacy compatibility requires it, receiving configured outbound callbacks, processing attachments, scheduling incremental synchronization, and exposing APIs for downstream systems. No native Martini ServiceNow connector is verified in the supplied context.

Do I need a connector to integrate ServiceNow Integrated Risk Management with Martini?

No. A dedicated ServiceNow IRM connector is not required. Martini can use ServiceNow's confirmed native integration mechanisms, including REST APIs, configured callbacks, SOAP services for legacy use cases, Attachment API operations, and supported authentication methods.

Is there any extra Lonti cost to integrate ServiceNow Integrated Risk Management with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate ServiceNow IRM. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from ServiceNow, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.

Which ServiceNow integration methods should be used for new work?

REST is generally the preferred approach. Use the Table API for controlled table access, product-specific APIs where available, the Import Set API for staged ingestion, and the Attachment API for evidence files. Use SOAP mainly for existing integrations that require WSDL-based compatibility.

Are ServiceNow IRM events or webhooks available?

ServiceNow can invoke Martini through configured outbound REST messages, flows, business rules, notifications, or scripted actions for selected tables and events. This is not a universal webhook feed for every IRM object. Scheduled incremental polling is an alternative when callback coverage is incomplete.

How does Martini synchronize ServiceNow IRM data reliably?

Martini can use bounded queries, pagination, sys_updated_on or another approved change field, overlap windows, and stable identifiers such as sys_id. Workflows map fields into a canonical model, apply source-of-truth rules, retain checkpoints, prevent duplicates, and reconcile rejected or partially processed items.

How are errors, retries, and duplicate callbacks handled?

Martini workflows can distinguish authentication, authorization, validation, reference, rate-limit, conflict, and transient server failures. Retry policies should target only eligible transient failures, with backoff and controlled concurrency. Correlation IDs, sys_id values, alternate keys, and persisted processing state support idempotency and duplicate prevention.