.png)

ServiceNow Integrated Risk Management Integration Guide
Integrate ServiceNow Integrated Risk Management with enterprise systems through ServiceNow REST APIs, configured outbound callbacks, staged imports, attachments, and secure workflows.
ServiceNow Integrated Risk Management integration options at a glance
ServiceNow Integrated Risk Management primarily integrates through the ServiceNow REST API framework, including the Table API, product-specific APIs, Import Set API, Attachment API, batch requests, and applicable asynchronous REST operations. ServiceNow also supports legacy SOAP web services and configured outbound REST messages, flows, business rules, notifications, or callbacks for selected event-driven scenarios. OAuth 2.0 and Basic Authentication are commonly available subject to instance policy, roles, ACLs, scopes, and integration-user permissions. Martini can consume these APIs, receive configured callbacks, upload evidence files, schedule incremental synchronization, transform IRM objects, and expose APIs for downstream systems.
| Integration point | Supported by ServiceNow Integrated Risk Management? | Common use cases | How Martini supports it |
|---|---|---|---|
| REST APIs | Yes | Use the Table API, Import Set API, Attachment API, Aggregate API, batch requests, asynchronous operations, and product-specific APIs to read and update IRM data. | Martini can consume ServiceNow REST APIs, transform payloads, apply business rules, paginate results, and expose reusable APIs or workflows. |
| SOAP APIs | Legacy | Support older integrations or enterprise systems that require WSDL-based ServiceNow web services. | Martini can consume SOAP services where legacy compatibility is required, while REST remains the preferred design for new integrations. |
| Webhooks / outbound callbacks | Limited | Outbound REST messages, flows, business rules, notifications, or scripted actions can invoke external endpoints for selected records and events. | Martini can expose an API or workflow endpoint to receive configured callbacks and safely process event payloads with duplicate protection. |
| Bulk, asynchronous, and batch APIs | Yes | Use Import Set processing, batch requests, asynchronous REST operations, scheduled imports, and pagination for larger or staged transfers. | Martini can orchestrate staged loads, checkpoint progress, control concurrency, and reconcile partial failures. |
| File / attachment APIs | Yes | Upload, download, and associate evidence, assessment documentation, remediation artifacts, and other files with IRM records. | Martini can handle binary content separately from JSON metadata, map parent record identifiers, and apply checksum or duplicate controls. |
| Authentication | Yes | OAuth 2.0 and Basic Authentication are commonly available, subject to instance policy, roles, ACLs, scopes, and integration-user permissions. | Martini can use environment-specific secrets and configured authentication while handling token expiry, authorization failures, and ServiceNow response payloads. |
| Database access | No | Direct database connectivity to the ServiceNow SaaS database should not be assumed or used for IRM integration. | Martini should use ServiceNow APIs, exports, reporting interfaces, or approved replication products instead of direct database access. |
How ServiceNow Integrated Risk Management exposes data and business events
ServiceNow REST APIs
ServiceNow provides a REST API framework that includes the Table API and additional platform, IRM, import, attachment, aggregate, batch, and asynchronous APIs where applicable. Exact tables, fields, roles, and product-specific APIs depend on the instance configuration and release.
Martini implementation pattern
Martini implementation pattern: a workflow authenticates to ServiceNow, retrieves or submits the required resource, transforms the payload into a canonical model, applies business rules, and writes to the target system. The workflow records pagination state, identifiers, response details, and reconciliation outcomes.
Implementation sequence
Outbound callbacks
ServiceNow can invoke external endpoints through outbound REST messages, flows, business rules, notifications, or scripted actions. Callback coverage is configured for selected tables and events; it is not a universal webhook stream for every IRM change.
Martini implementation pattern
Martini implementation pattern: Martini exposes an API endpoint, validates the callback contract and authentication, uses the supplied sys_id and event information to retrieve current ServiceNow data when needed, then orchestrates downstream processing. Duplicate callbacks are handled through correlation and idempotency checks.
Implementation sequence
Bulk and asynchronous processing
ServiceNow supports Import Set processing, REST batch requests, applicable asynchronous REST operations, scheduled imports, and paginated reads. These mechanisms support staged or higher-volume movement when the selected API and workload permit them.
Martini implementation pattern
Martini implementation pattern: a scheduled or triggered workflow partitions the workload, submits or retrieves batches, stores checkpoints, and reconciles accepted, rejected, and pending items. The design avoids treating a large Table API read as one unbounded transaction.
Implementation sequence
File and attachment APIs
The ServiceNow Attachment API supports binary files associated with records, including evidence, assessment documentation, and remediation artifacts. Attachment permissions, size policies, content types, and parent-record access must be verified.
Martini implementation pattern
Martini implementation pattern: a workflow first resolves the parent IRM record, then transfers binary content separately from JSON metadata, associates the attachment, and records the result. Checksums or external references can help prevent duplicate files.
Implementation sequence
SOAP web services
ServiceNow supports SOAP-based web-service interfaces for compatible integrations, although REST is generally preferred for new work. SOAP remains relevant where an existing enterprise contract requires WSDL-based communication.
Martini implementation pattern
Martini implementation pattern: Martini consumes the required SOAP operation, maps XML request and response structures into the integration model, applies validation and business rules, and routes SOAP faults or transport failures through workflow error handling.
Implementation sequence
Common ServiceNow Integrated Risk Management integration patterns
Pattern 1: Synchronize Risks and Issues with remediation systems
When to use this pattern
Use this pattern when governance teams manage Risks or Issues in ServiceNow IRM while remediation teams work in ServiceNow ITSM, Jira, or another case-management platform. Scheduled incremental polling is suitable when callback coverage is incomplete.
Integration direction
Example Mapping
| ServiceNow Integrated Risk Management Field | Canonical Field | Target Field |
|---|---|---|
| sys_id | sourceRecordId | externalReference |
| number | issueNumber | summaryOrExternalKey |
| state | status | status |
| assigned_to | owner | assignee |
Martini implementation pattern
A Martini workflow queries changed records using sys_updated_on with a tie-breaker or overlap window, paginates results, maps ownership and status values, and applies create-versus-update rules. It stores source and target identifiers, handles missing references as exceptions, retries transient failures, and reconciles rejected items.
Martini capabilities used
- scheduled workflows
- API consumption
- pagination and checkpoints
- data mapping
- business rules
- error handling
Pattern 2: Process control evidence and assessment attachments
When to use this pattern
Use this pattern when evidence originates in a document or business system and must be associated with a ServiceNow Control, Assessment, or Issue. It separates binary transfer from record metadata and status updates.
Integration direction
Example Mapping
| ServiceNow Integrated Risk Management Field | Canonical Field | Target Field |
|---|---|---|
| externalDocumentId | evidenceReference | attachment metadata |
| contentType | fileType | attachment content type |
| controlId | parentRecordId | parent sys_id |
| processingStatus | evidenceStatus | Control or Issue status |
Martini implementation pattern
Martini validates the source metadata, resolves the parent ServiceNow record, checks size and duplicate indicators, uploads the binary through the Attachment API, and updates the related control or issue only after successful association. Failed transfers are retained for replay without creating duplicate attachments.
Martini capabilities used
- workflow orchestration
- file handling
- API consumption
- data validation
- mapping
- retry and reconciliation
Pattern 3: Synchronize organizational ownership from Workday
When to use this pattern
Use this pattern when Workday or another authoritative organizational system owns worker, manager, department, or hierarchy data used by IRM Entities, profiles, and assignment fields.
Integration direction
Example Mapping
| ServiceNow Integrated Risk Management Field | Canonical Field | Target Field |
|---|---|---|
| workerId | personExternalId | user reference |
| departmentCode | organizationCode | Entity reference |
| managerId | managerExternalId | owner or approver |
| employmentStatus | activeStatus | assignment eligibility |
Martini implementation pattern
A scheduled Martini workflow retrieves changed organizational data, validates that referenced ServiceNow users and groups exist, maps entities and ownership, and updates only approved fields. Records with unresolved references are quarantined, while successful updates retain source watermarks and ServiceNow identifiers.
Martini capabilities used
- scheduled workflows
- API consumption
- reference resolution
- data transformation
- validation
- error handling
Pattern 4: Trigger remediation from selected ServiceNow events
When to use this pattern
Use this pattern when a configured outbound REST message, flow, business rule, or notification should initiate action when an Issue or control deficiency reaches a selected state.
Integration direction
Example Mapping
| ServiceNow Integrated Risk Management Field | Canonical Field | Target Field |
|---|---|---|
| sys_id | sourceRecordId | externalReference |
| table | sourceTable | sourceType |
| eventType | lifecycleEvent | workflow action |
| state | remediationStatus | Jira status |
Martini implementation pattern
ServiceNow invokes a Martini API with the event contract. Martini authenticates and validates the payload, retrieves current data when needed, enriches it from the target system, applies routing rules, and writes the remediation result. Correlation IDs, idempotency checks, and controlled retries protect against duplicate callbacks.
Martini capabilities used
- API exposure
- webhook and callback handling
- workflow orchestration
- data enrichment
- business rules
- idempotency and retries
Applications commonly integrated with ServiceNow Integrated Risk Management
ServiceNow IRM commonly participates in enterprise workflows that connect governance data with operational, identity, organizational, and remediation systems. Martini can orchestrate these relationships through documented APIs and configured callbacks without requiring a dedicated native connector.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| ServiceNow ITSM | Link IRM Issues and remediation activities to Incidents, Problems, Changes, and Tasks managed by ITSM. | ServiceNow Integrated Risk Management → Martini → ServiceNow ITSM | Use ServiceNow REST APIs to retrieve or receive selected IRM Issues, map identifiers and status values, and update the corresponding ITSM records. Store correlation identifiers and apply idempotent update rules. |
| ServiceNow CMDB | Associate risks, controls, and compliance scope with configuration items, services, and business applications. | ServiceNow CMDB → Martini → ServiceNow Integrated Risk Management | Retrieve approved CMDB reference data, resolve ServiceNow sys_id values, and update IRM relationships through controlled REST workflows. Validate permissions and reference-field behavior before production writes. |
| Salesforce | Exchange ownership, operational context, or selected risk and compliance findings associated with Salesforce processes. | Salesforce → Martini → ServiceNow Integrated Risk Management | Consume Salesforce and ServiceNow APIs, normalize ownership and external identifiers, apply field-level business rules, and synchronize only the approved IRM fields with retry and reconciliation handling. |
| Jira | Create and track remediation work for IRM Issues or control deficiencies in development and project teams. | ServiceNow Integrated Risk Management → Martini → Jira | Trigger from configured ServiceNow callbacks or scheduled polling, create or update Jira work items, retain the Jira key and ServiceNow sys_id, and return status or resolution changes to IRM. |
| Microsoft Entra ID | Synchronize users, groups, and organizational ownership used for risk, control, and remediation assignments. | Microsoft Entra ID → Martini → ServiceNow Integrated Risk Management | Retrieve approved identity and group data, validate matching ServiceNow users and groups, then update ownership or assignment fields while applying least-privilege and duplicate-prevention rules. |
| Workday | Supply worker, department, manager, and organizational hierarchy data for IRM ownership and entity structures. | Workday → Martini → ServiceNow Integrated Risk Management | Schedule incremental retrieval, transform organizational data into ServiceNow Entities, profiles, or ownership references, resolve reference fields, and quarantine records with missing owners. |
| SAP S/4HANA | Provide business-process, organizational, financial, or supplier information for risk and control scope. | SAP S/4HANA → Martini → ServiceNow Integrated Risk Management | Orchestrate API-based extraction from SAP and ServiceNow, map business keys into IRM scope data, enforce validation rules, and retain checkpoints for repeatable reconciliation. |
| RSA Archer | Exchange risk, compliance, control, or issue information during GRC platform coexistence, migration, or consolidation. | RSA Archer → Martini → ServiceNow Integrated Risk Management | Use staged extraction and transformation workflows, map legacy identifiers to ServiceNow sys_id or approved alternate keys, validate relationships, and produce exception results for reconciliation. |
How to build a ServiceNow Integrated Risk Management integration in Martini
Objective
Establish environment-specific access to the ServiceNow instance using an approved authentication method and a least-privileged integration user.
Instructions in Martini
- Configure the ServiceNow base URL and applicable REST or SOAP API
- Use OAuth 2.0 where approved, or Basic Authentication where permitted
- Store client secrets and credentials in Martini secrets
- Confirm roles, ACLs, scopes, domain rules, and attachment permissions
Objective
Select a trigger that matches the required timeliness and ServiceNow event coverage.
Instructions in Martini
- Use a configured ServiceNow callback for selected events
- Use a scheduled Martini workflow for incremental synchronization
- Use a manual or API trigger for controlled remediation or migration operations
- Define the tables, event types, and source watermark
Objective
Read the current ServiceNow resource or accept the callback payload needed for processing.
Instructions in Martini
- Use the Table API or product-specific API where appropriate
- Bound queries and paginate Table API reads
- Retrieve the current record when a callback contains only identifiers
- Use the Import Set, batch, asynchronous, or Attachment API for applicable workloads
Objective
Coordinate retrieval, enrichment, validation, target writes, and reconciliation as a maintainable Martini workflow.
Instructions in Martini
- Separate transport, transformation, business rules, and persistence logic
- Resolve ServiceNow reference fields explicitly
- Retain sys_id, external identifiers, correlation IDs, and checkpoints
- Route validation failures and unresolved references to an exception path
Objective
Convert ServiceNow IRM structures and choice values into the target system's canonical model.
Instructions in Martini
- Map Risks, Controls, Issues, Indicators, Policies, Entities, and profiles explicitly
- Avoid writing calculated, derived, journal, or read-only fields without confirmation
- Normalize dates, statuses, ownership, and priority values
- Handle binary attachments separately from JSON metadata
Objective
Enforce ownership, routing, idempotency, and source-of-truth decisions before writing changes.
Instructions in Martini
- Distinguish create, update, replay, and delete behavior
- Prevent duplicate records using sys_id or an approved alternate key
- Validate target references and required fields
- Account for ServiceNow business rules, flows, notifications, approvals, and audit side effects
Common ServiceNow Integrated Risk Management data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Risks | Synchronize identified risks, assessment results, ownership, status, scoring, and treatment information. | ServiceNow ITSM, Jira, GRC platforms, data warehouses | Martini reads or writes approved risk fields through REST APIs, retains sys_id or an alternate key, resolves references, and applies idempotent upsert rules. |
| Controls | Exchange control definitions, owners, effectiveness assessments, test results, and risk or policy relationships. | GRC platforms, Jira, document systems, reporting stores | Martini maps control fields and relationships, validates required references, and separates calculated or read-only fields from writable fields. |
| Policies and policy statements | Synchronize governance requirements, obligations, and mappings to controls or compliance activities. | Document platforms, GRC platforms, reporting stores | Martini transforms policy structures, preserves ServiceNow identifiers, and routes validation failures for review before updates. |
| Indicators | Exchange measurements for control, risk, or compliance performance, including applicable key indicators. | Analytics platforms, data warehouses, GRC platforms | Martini retrieves bounded datasets or aggregates where permitted, normalizes measurements, and records the source timestamp and scope. |
| Issues | Create and track control deficiencies, assessment findings, remediation items, and exceptions. | ServiceNow ITSM, Jira, case-management systems | Martini can trigger from configured callbacks or poll incrementally, map ownership and status, retain correlation IDs, and retry only transient failures. |
| Entities and profiles | Represent organizational units, services, applications, processes, locations, and assessment context. | Workday, Microsoft Entra ID, SAP S/4HANA, CMDB | Martini validates reference data and synchronizes owners, scopes, and profiles using stable identifiers and explicit reference resolution. |
Authentication and security considerations
Authentication and authorization
ServiceNow commonly supports OAuth 2.0 and Basic Authentication for REST integrations, subject to instance policy. Mutual TLS and certificate-based controls may also be available in selected configurations.
- Use a dedicated integration user with only the roles, scopes, table permissions, and field ACL access required by the workflow.
- Store ServiceNow credentials, OAuth client details, and certificates as environment-specific Martini secrets.
- Confirm application scopes, domain separation, IP restrictions, API access policies, and attachment permissions.
- Prefer OAuth 2.0 for managed production integrations when approved by the ServiceNow security team.
Operational considerations for ServiceNow Integrated Risk Management integrations
Design for controlled synchronization
ServiceNow API limits depend on instance configuration, user, API, licensing, and platform load. Use bounded queries, pagination, controlled concurrency, response-aware throttling, and retry backoff.
- Use sys_updated_on with a tie-breaker, an overlap window, or an approved synchronization watermark for incremental processing.
- Retain sys_id or a stable alternate key to support idempotent creates and updates.
- Distinguish ACL failures, validation errors, missing references, rate limits, conflicts, and transient 5xx responses.
- Test against a representative sub-production instance because releases, scoped applications, custom fields, business rules, and APIs can vary.
- Handle attachments separately and account for binary size, content type, parent-record access, and duplicate files.
Why use Martini instead of scripts or point-to-point integrations?
Integration control and reuse
Point-to-point scripts often combine authentication, API calls, mappings, retries, and business rules in code that is difficult to govern as requirements change. Martini provides a workflow-based structure for these concerns while preserving the option to add custom logic when required.
- Centralize ServiceNow API consumption, callback handling, transformations, and target-system orchestration.
- Reuse mappings, validation rules, authentication configuration, and error-handling patterns across IRM workflows.
- Support scheduled, event-driven, API-led, staged, and attachment-processing designs in one integration runtime.
- Expose controlled Martini APIs for ServiceNow callbacks or downstream consumers.
- Provide workflow logging, troubleshooting, retries, and reconciliation paths for operational support.
Frequently asked questions
ServiceNow IRM can be integrated primarily through the ServiceNow REST API framework, including the Table API, product-specific APIs, Import Set API, Attachment API, batch operations, and applicable asynchronous REST APIs. SOAP web services support legacy scenarios, while configured outbound REST messages, flows, business rules, or notifications can support selected callback-driven processes.
Yes. Martini can integrate with ServiceNow IRM by consuming its REST APIs, using SOAP where legacy compatibility requires it, receiving configured outbound callbacks, processing attachments, scheduling incremental synchronization, and exposing APIs for downstream systems. No native Martini ServiceNow connector is verified in the supplied context.
No. A dedicated ServiceNow IRM connector is not required. Martini can use ServiceNow's confirmed native integration mechanisms, including REST APIs, configured callbacks, SOAP services for legacy use cases, Attachment API operations, and supported authentication methods.
Lonti does not charge an additional per-connector or per-vendor fee to integrate ServiceNow IRM. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from ServiceNow, cloud infrastructure, or other third-party systems based on subscription, usage, and deployment model.
REST is generally the preferred approach. Use the Table API for controlled table access, product-specific APIs where available, the Import Set API for staged ingestion, and the Attachment API for evidence files. Use SOAP mainly for existing integrations that require WSDL-based compatibility.
ServiceNow can invoke Martini through configured outbound REST messages, flows, business rules, notifications, or scripted actions for selected tables and events. This is not a universal webhook feed for every IRM object. Scheduled incremental polling is an alternative when callback coverage is incomplete.
Martini can use bounded queries, pagination, sys_updated_on or another approved change field, overlap windows, and stable identifiers such as sys_id. Workflows map fields into a canonical model, apply source-of-truth rules, retain checkpoints, prevent duplicates, and reconcile rejected or partially processed items.
Martini workflows can distinguish authentication, authorization, validation, reference, rate-limit, conflict, and transient server failures. Retry policies should target only eligible transient failures, with backoff and controlled concurrency. Correlation IDs, sys_id values, alternate keys, and persisted processing state support idempotency and duplicate prevention.
Related Martini documentation
APIs
Data
Integrate ServiceNow Integrated Risk Management with Martini
Use Martini to connect ServiceNow IRM with enterprise applications through secure APIs, configured callbacks, scheduled synchronization, evidence processing, and maintainable workflows.