Assessed before company and product grades were shown separately; see the product assessments below.
Products assessed
A product is graded only on evidence scoped to that product. Where a dimension rests on company-level evidence the report card marks it as such, so it reads as context rather than established product assurance - which is why a product can score below its parent company.
Certifications
What the vendor claims, and how far each claim has been independently corroborated. A claim is only ever as strong as the rung it reaches.
Stated as held, with no certificate number, certification body, scope statement or issue date given. Whether Now Assist falls inside the AI management system scope is not stated.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Certified since 2012; three-yearly recertification with annual surveillance audit. The certificate is linked but the scope statement was not collected.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Certified since 2018, by annual independent audit.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Certified since 2016, by annual independent audit.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Privacy information management extension to ISO/IEC 27001, received 2020.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Maintained since 2011; report available to customers via ServiceNow CORE, not publicly.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Annual since 2013, covering security, availability and confidentiality. Report available to customers via ServiceNow CORE, not publicly.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Attestation report received 2020.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Level 2 compliance with partial third-party audit coverage. The adherence ID quoted on ServiceNow's own compliance page (2022LVL02SCOPE3113) matches the register entry exactly.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- ✓ Current
Verified on the registry · EU Cloud Code of Conduct public register (eucoc.cloud) · checked Sep 3, 2026
Valid until Jul 27, 2027
Scoped to the ServiceNow Government Community Cloud (GCC) offering, not the commercial platform.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Scoped to the ServiceNow Australian platforms. IRAP is an assessment, not a certification.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Registered as the ServiceNow AI Platform under registration number C22-0036-2, not the narrower 'Now Platform' the vendor's compliance page names. The register row also carries a dedicated generative-AI information document (生成AIに関する情報), so the scheme holds a generative-AI scope declaration for this service. Last updated on the register 2026-04-24.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · ISMAP Cloud Service List (Japanese government, ismap.go.jp) · checked Sep 3, 2026
Singapore multi-tier cloud security standard, highest level.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Stated as compliant since 2023; no attestation of compliance or assessor named.
- ✓ Vendor claimed
- ✓ Evidence cited
- — Registry corroborated
- — Scope verified
- — Current
Self-certified participation, including the UK extension and Swiss-U.S. DPF. Checkable on the DPF public list.
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · Data Privacy Framework (dataprivacyframework.gov) · checked Sep 3, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · CSA STAR Registry · checked Sep 3, 2026
- ✓ Vendor claimed
- ✓ Evidence cited
- ✓ Registry corroborated
- — Scope verified
- — Current
Verified on the registry · FedRAMP Marketplace (fedramp.gov) · checked Sep 3, 2026
Supply chain
Third parties this vendor’s AI depends on, as disclosed in its own public material. Responsibility transfers; accountability doesn’t.
How to read this
This assessment is automated and point-in-time, built only from evidence the vendor publishes publicly plus checks against official certification registries. It is not an audit, not a certification, and not an endorsement. A low score means public evidence was thin or uncorroborated - which is a finding about disclosure, not proof of a weak control environment. Where too little was found to characterise a product at all, no score or grade is published rather than a low one: absence of evidence is not a number, and a letter grade would read as a verdict on the vendor when it would only be a verdict on what we could collect. This record reflects the evidence available on Sep 3, 2026.
