Now Assist
servicenow.com
Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.
- No formal subprocessor register disclosed
- No clear commitment that your data will not train their models
- Data retention window not stated
See Before you sign, with what to ask for ↓
Scanned Sep 3, 2026 · Public evidence · Point-in-time
Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.
Before you sign
Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.
What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.
Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.
What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.
“Customers control whether data is made available for fine-tuning and testing”
“Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.”
Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.
What to ask for: Get retention windows, in days, in writing.
Buyer questionsanswered only from the public evidence scanned — click a row for the answer
!Will they train on your data?Ask the vendor
ServiceNow states that chat conversations on its marketing website may be monitored and retained, including for training purposes. This statement is scoped to the ServiceNow websites and Events, not to the hosted services or to Now Assist.
Requires written confirmation — see Before you sign ↓
“Customers control whether data is made available for fine-tuning and testing”
“Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.”
!How long do they keep your data?Ask the vendor
Not found in the public sources scanned — ask the vendor directly.
!Who else can access your data?Ask the vendor
The Responsible AI white paper's contents list a section on handling Azure OpenAI LLM requests in production, indicating a third-party model provider sits in the production path alongside ServiceNow's own LLMs. Only the section heading is public; the section itself is behind the download form.
Requires written confirmation — see Before you sign ↓
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“We are committed to transparency and compliance with regulations such as GDPR and privacy best practices. We never sell customer data to third parties or use it for ads.”
“In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here”
“From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers. If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum”
“To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.”
!Where is your data processed?Ask the vendor
ServiceNow states that customer data storage locations vary by service type and customer location and are set in the Order Form, so residency is a contract-specific matter rather than a published position.
Confirm in writing: Ask the vendor to state this in writing before signing.
“Customer data storage locations vary depending on the type of service and location of the Customer, as specified in the relevant Order Form.”
“ServiceNow relies on EU Commission adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss specific data transfer language to enable transfers of Customer data to sub‑processors based outside of Europe.”
!What happens in a security incident?Ask the vendor
ServiceNow states that on a security incident affecting customer data it will provide an initial report to the customer contact named in the support portal, or as set out in the DPA and DSA. No notification timeframe is published.
Confirm in writing: Ask the vendor to state this in writing before signing.
“In the event of a security incident impacting customer data, ServiceNow will provide an initial report to the designated customer contact in the customer support portal or as provided in the DPA and DSA. Customers are responsible for ensuring the appropriate person is listed in the support portal.”
Key findingsclick a row for the evidence
✓AI governance is board-level and externally certifiedStrong
ServiceNow states that its Board, working with the Audit Committee, oversees an AI governance program, that an Enterprise AI Governance Steering Committee of executives approves the governance plan, that high-risk AI proposals escalate to a senior oversight committee, and that the whole arrangement is certified to ISO/IEC 42001, the AI management system standard. The principles are stated to be based on the NIST AI Risk Management Framework.
Most vendors publish AI principles. Far fewer name the body that owns them, describe an escalation path for high-risk systems, and put the management system through third-party certification. This is structural evidence rather than a statement of intent, and it is the strongest single signal in this assessment.
Question for vendor: Please supply the ISO/IEC 42001 certificate, naming the certification body and the scope statement, and confirm whether Now Assist falls inside that scope.
“The Board, in coordination with the Audit Committee, is responsible for overseeing the ServiceNow AI Governance program, which is focused on the responsible development and use of ServiceNow AI products and services, as well as third-party technologies ServiceNow uses internally.”
“Accountability mechanisms are built into the governance structure. For example, high-risk AI proposals are escalated to a senior oversight committee for approval.”
“Therefore, inspired by the NIST Artificial Intelligence Risk Management Framework, ServiceNow has embraced four guiding principles for developing responsible AI:”
“ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.”
✓Broad, dated third-party assurance across security and privacyStrong
The trust site sets out a long assurance ladder with start dates and audit cadence: ISO/IEC 27001 since 2012, 27017 since 2018, 27018 since 2016, 27701 from 2020, SOC 1 Type 2 since 2011, SOC 2 Type 2 since 2013, BSI C5 from 2020, PCI DSS from 2023, ISMAP registration from March 2022, MTCS Level 3, and an EU Cloud Code of Conduct verification quoted with a public Verification-ID.
Dated claims with named audit cycles are checkable, and the EU Cloud CoC verification ID and the FedRAMP marketplace listing can be confirmed against public registers without asking the vendor. That is a materially stronger position than an unlabelled badge wall.
“ServiceNow has been an ISO/IEC 27001 certified organization since 2012 and the certificate is available here”
“The certification is gained by an annual independent audit and ServiceNow has been an ISO/IEC 27017:2015 certified organization since 2018.”
“The certification is gained by annual independent audit and ServiceNow has been an ISO/IEC 27018:2019 certified organization since 2016.”
“This extension to ISO/IEC 27001 focuses on the establishment, and maintenance of a Privacy Information Management System (PIMS). This is relevant to ServiceNow as a processor of customer data which may contain Personally Identifiable Information (PII). ServiceNow received this certification in 2020.”
“ServiceNow is audited by a third party and has maintained its SSAE 18 SOC 1 Type 2 attestation since 2011 (SSAE 18 superseded SSAE 16 in 2017). SSAE 18 is aligned with international standard ISAE3402 and replaced the now-deprecated SAS70.”
“ServiceNow has also undertaken an annual SOC 2 Type 2 attestation since 2013, relevant to security, availability and confidentiality controls listed in the AICPA Trust Services Criteria (TSC).”
“C5 is a cloud-specific compliance controls catalog developed by the German Federal Office for Information Security (BSI) and leveraged in both the public and private sectors. The C5 Attestation Report follows a similar process and schema as AICPA SOC 2 reports, and has a high overlap of requirements with the AICPA Trust Services Criteria, with the addition of specific cloud-focused requirements. ServiceNow received its C5 Attestation Report in 2020.”
“Services are verified compliant with the EU Cloud CoC, Verification-ID 2022LVL02SCOPE3113.”
“was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.”
“ServiceNow is proud to have achieved MTCS Level 3, the highest level of certification available.”
“This is relevant to ServiceNow as a processor of customer data which may contain credit card data. ServiceNow became compliant in 2023.”
“ServiceNow is a Data Privacy Framework (DPF) Program participant.”
!The AI-specific evidence a buyer needs is gated, and the public privacy detail is datedGap
The documents that would answer the AI questions directly are not public. The Responsible AI white paper, the AI Security and Data Handling Controls white paper that ServiceNow says carries product-specific protections for Now Assist, the AI Testing and Evaluation methodology, the Enterprise AI Governance Policy and the SOC and ISO reports all sit behind a download form or the customer-only CORE portal. The most detailed public privacy document, the Privacy FAQ, carries a last-updated date of 17 January 2024, before the ISO/IEC 42001 certification and the AI Product Specific Terms it would need to describe.
An assessor working only from public sources cannot confirm what happens to prompts and outputs in Now Assist, how long they are kept, or which controls apply. Everything of substance requires a customer relationship or a form submission, so this assessment rests on organisation-level statements rather than product evidence.
Question for vendor: Please provide the AI Security and Data Handling Controls white paper and the AI Product Specific Terms, and confirm the retention period for Now Assist prompts and outputs.
“It covers data handling controls, data residency and processing infrastructure, AI Control Tower for enterprise-wide governance, and product-specific protections across Now Assist, Moveworks, and Veza from ServiceNow.”
“Customers control whether data is made available for fine-tuning and testing”
“Explore our methodology for testing large language model (LLMs) applications, including risk assessment frameworks and best practices to support enterprise-aligned AI systems.”
“In accordance with the audit clauses in the DPA and/or DSA, current customers may request access to the ServiceNow CORE, a comprehensive repository of information and documentation, including policies, procedures, as well as our then-current third-party audit reports against internationally recognized standards such as ISO 27001 and ISO 27018, and independent third-party assessments against security standards like SSAE 18 / SOC 1 and SOC 2 Type 2.”
“ServiceNow’s AI products and features have undergone Privacy by Design reviews and may be subject to additional contractual terms that govern how those AI‑powered services are provided, and how data may be processed, such as the AI Product Specific Terms”
!Model providers are named only in passing and the promised model cards are not reachableGap
The public material names Mistral-Nemo-12B as an example foundation model and shows a white paper section titled Handling Azure OpenAI LLM requests in production, which indicates a third-party model provider in the live request path. Neither is developed on any public page. The same white paper states that publicly available model cards explain each model's training data and limitations, but no model card was reachable from the AI or trust pages collected.
Which model serves a request, and who operates it, determines where prompt content goes and whose terms govern it. A buyer assessing Now Assist cannot presently establish either from public sources, and the one artefact that would settle it is described as public but was not found.
Question for vendor: Which foundation models and hosted model providers serve Now Assist in production, in which regions, and where are the model cards published?
“1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.”
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.”
!The strongest government authorisations do not cover the commercial platformGap
The FedRAMP High Provisional Authority to Operate is stated for the Government Community Cloud offering, and the IRAP assessment for OFFICIAL and PROTECTED data is stated for the Australian platforms. The ISMAP registration is stated for the Now Platform. None of these is presented as covering the commercial platform generally, and none mentions Now Assist.
These are the most demanding authorisations on the page and the easiest to read as covering everything. A commercial buyer of Now Assist gains no assurance from them unless they are buying the specific offering that holds them.
Question for vendor: Which of the listed authorisations extend to Now Assist on the commercial platform, and which are limited to GCC, the National Security Cloud or the Australian platforms?
“ServiceNow’s Government Community Cloud (GCC) offering currently maintains a Federal Risk and Authorization Management Program (FedRAMP) High Baseline Provisional Authority to Operate (P-ATO).”
“ServiceNow's Australian Platforms has been independently assessed by an endorsed IRAP assessor to meet the Australian ISM controls for OFFICIAL and PROTECTED data.”
“was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.”
?Technical dependency observed: GoogleObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.”
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.”
“In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here”
“From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers. If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum”
“To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.”
?Technical dependency observed: StripeObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.”
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.”
“In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here”
“From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers. If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum”
“To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.”
?Technical dependency observed: MicrosoftObservation
Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.
An undisclosed provider dependency is exactly the gap independent verification exists to surface.
Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.
“1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.”
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.”
“In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here”
“From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers. If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum”
“To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.”
Assurance dimensionsweighted components of one score — not eight separate ratings
Organisation & AI governance15% of the scoreorganisation-level evidence65
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.
Assessed against ISO 42001 · NIST AI RMF · AIUC-1
“The Board, in coordination with the Audit Committee, is responsible for overseeing the ServiceNow AI Governance program, which is focused on the responsible development and use of ServiceNow AI products and services, as well as third-party technologies ServiceNow uses internally.”
“Accountability mechanisms are built into the governance structure. For example, high-risk AI proposals are escalated to a senior oversight committee for approval.”
“Therefore, inspired by the NIST Artificial Intelligence Risk Management Framework, ServiceNow has embraced four guiding principles for developing responsible AI:”
“ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.”
Governance & accountability: vendor-evidenced, not yet independently corroborated.
AI system15% of the score40
What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.
Assessed against ISO 42001 · NIST AI RMF
“ServiceNow believes that the best way to unlock the value of AI for customers is to deeply embed it in the platform, rather than simply providing a gateway to an external AI engine.”
“It covers data handling controls, data residency and processing infrastructure, AI Control Tower for enterprise-wide governance, and product-specific protections across Now Assist, Moveworks, and Veza from ServiceNow.”
How AI features are evaluated before and after release — evals, red-teaming, monitoring.
Assessed against NIST GenAI · NIST AI RMF · ISO 42001
“ServiceNow AI solutions are continuously tested to promote fairness for all, and to minimize bias.”
“Explore our methodology for testing large language model (LLMs) applications, including risk assessment frameworks and best practices to support enterprise-aligned AI systems.”
How changes to models and AI features are controlled and communicated — versioning, notice, rollback.
Assessed against ISO 27001 · ISO 42001
“ServiceNow builds transparent, responsible, auditable, and safe LLMs through a well-governed lifecycle process.”
Model10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Which model providers and versions process customer data, and how changes to them are disclosed.
Assessed against NIST GenAI · ISO 42001
“1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.”
“Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production”
“Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.”
Customer data15% of the scoreorganisation-level evidence62
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.
Assessed against ISO 27018 · OAIC APPs · EU AI Act
“Customers control whether data is made available for fine-tuning and testing”
“by virtue of the cloud-based services we provide, we do not review or analyze the content of the data input by customers in the ordinary course of operating our services. As a result, we will not know whether personal data is uploaded into your instance of the services.”
“We are committed to transparency and compliance with regulations such as GDPR and privacy best practices. We never sell customer data to third parties or use it for ads.”
“Customer data storage locations vary depending on the type of service and location of the Customer, as specified in the relevant Order Form.”
“ServiceNow relies on EU Commission adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss specific data transfer language to enable transfers of Customer data to sub‑processors based outside of Europe.”
“Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.”
“Our processing may involve processing using machine learning and artificial intelligence.”
AI supply chain10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The named chain of AI and infrastructure providers behind the product, and how it is disclosed.
Assessed against ISO 27001 · ISO 27017
“In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here”
“To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.”
“From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers. If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum”
Security foundation15% of the scoreorganisation-level evidence85
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.
Assessed against ISO 27001 · NIST AI RMF
“Contact: https://hackerone.com/servicenow-disclosure Contact: mailto:[email protected] Policy: https://www.servicenow.com/company/trust/responsible-disclosure.html”
“In the event of a security incident impacting customer data, ServiceNow will provide an initial report to the designated customer contact in the customer support portal or as provided in the DPA and DSA. Customers are responsible for ensuring the appropriate person is listed in the support portal.”
“ServiceNow does not condone actively auditing our infrastructure. As you explore ServiceNow web properties, report vulnerabilities at [email protected]”
Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.
Independent assurance evidence10% of the scoreorganisation-level evidence71
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.
Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008
“ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.”
“ServiceNow has been an ISO/IEC 27001 certified organization since 2012 and the certificate is available here”
“ServiceNow is audited by a third party and has maintained its SSAE 18 SOC 1 Type 2 attestation since 2011 (SSAE 18 superseded SSAE 16 in 2017). SSAE 18 is aligned with international standard ISAE3402 and replaced the now-deprecated SAS70.”
“ServiceNow has also undertaken an annual SOC 2 Type 2 attestation since 2013, relevant to security, availability and confidentiality controls listed in the AICPA Trust Services Criteria (TSC).”
“Services are verified compliant with the EU Cloud CoC, Verification-ID 2022LVL02SCOPE3113.”
“In accordance with the audit clauses in the DPA and/or DSA, current customers may request access to the ServiceNow CORE, a comprehensive repository of information and documentation, including policies, procedures, as well as our then-current third-party audit reports against internationally recognized standards such as ISO 27001 and ISO 27018, and independent third-party assessments against security standards like SSAE 18 / SOC 1 and SOC 2 Type 2.”
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
Read from the registry record above — cited, not reproduced.
“The certification is gained by an annual independent audit and ServiceNow has been an ISO/IEC 27017:2015 certified organization since 2018.”
“The certification is gained by annual independent audit and ServiceNow has been an ISO/IEC 27018:2019 certified organization since 2016.”
“This extension to ISO/IEC 27001 focuses on the establishment, and maintenance of a Privacy Information Management System (PIMS). This is relevant to ServiceNow as a processor of customer data which may contain Personally Identifiable Information (PII). ServiceNow received this certification in 2020.”
“C5 is a cloud-specific compliance controls catalog developed by the German Federal Office for Information Security (BSI) and leveraged in both the public and private sectors. The C5 Attestation Report follows a similar process and schema as AICPA SOC 2 reports, and has a high overlap of requirements with the AICPA Trust Services Criteria, with the addition of specific cloud-focused requirements. ServiceNow received its C5 Attestation Report in 2020.”
“ServiceNow’s Government Community Cloud (GCC) offering currently maintains a Federal Risk and Authorization Management Program (FedRAMP) High Baseline Provisional Authority to Operate (P-ATO).”
“ServiceNow's Australian Platforms has been independently assessed by an endorsed IRAP assessor to meet the Australian ISM controls for OFFICIAL and PROTECTED data.”
“was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.”
“ServiceNow is proud to have achieved MTCS Level 3, the highest level of certification available.”
“This is relevant to ServiceNow as a processor of customer data which may contain credit card data. ServiceNow became compliant in 2023.”
“ServiceNow is a Data Privacy Framework (DPF) Program participant.”
None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.
Legal & contractual10% of the scoreorganisation-level evidence40
Graded from organisation-level evidence — it does not automatically establish assurance for this product.
The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.
Assessed against EU AI Act · OAIC APPs
“ServiceNow’s standard Data Processing Addendum (“DPA”) and Data Security Addendum (“DSA”) at https://www.servicenow.com/upgrade-schedules.html address our obligations as the data processor and your obligations as the data controller under relevant data protection laws.”
“ServiceNow’s AI products and features have undergone Privacy by Design reviews and may be subject to additional contractual terms that govern how those AI‑powered services are provided, and how data may be processed, such as the AI Product Specific Terms”
“As a global Software‑as‑a‑Service provider, ServiceNow acts as a processor under the General Data Protection Regulation (“GDPR”) when providing services to our Customers . Under the terms of our standard Data Processing Addendum with Customers and Partners, ServiceNow will only process personal data as instructed by the Customer or Partner, for the purpose of providing services.”
Not graded: Agent — not applicable to this scan.
What would strengthen assuranceeach figure is from today's score — resolving one changes the others
Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 57 → up to 78 with every identified gap resolved.
AI supply chainclick a node to focus it · drag to pan · zoom with the controls
View as list
What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0
This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.
Map your inherited responsibilitiesAssurance evidence: certifications 17 — registry checks and verification ladders, click to view
Stated as held, with no certificate number, certification body, scope statement or issue date given. Whether Now Assist falls inside the AI management system scope is not stated.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Certified since 2012; three-yearly recertification with annual surveillance audit. The certificate is linked but the scope statement was not collected.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Certified since 2018, by annual independent audit.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Certified since 2016, by annual independent audit.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Privacy information management extension to ISO/IEC 27001, received 2020.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Maintained since 2011; report available to customers via ServiceNow CORE, not publicly.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Annual since 2013, covering security, availability and confidentiality. Report available to customers via ServiceNow CORE, not publicly.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Attestation report received 2020.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Level 2 compliance with partial third-party audit coverage. The adherence ID quoted on ServiceNow's own compliance page (2022LVL02SCOPE3113) matches the register entry exactly.
Checked against EU Cloud Code of Conduct public register (eucoc.cloud), Sep 3, 2026: Verified on the registry
Scoped to the ServiceNow Government Community Cloud (GCC) offering, not the commercial platform.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Scoped to the ServiceNow Australian platforms. IRAP is an assessment, not a certification.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Registered as the ServiceNow AI Platform under registration number C22-0036-2, not the narrower 'Now Platform' the vendor's compliance page names. The register row also carries a dedicated generative-AI information document (生成AIに関する情報), so the scheme holds a generative-AI scope declaration for this service. Last updated on the register 2026-04-24.
Checked against ISMAP Cloud Service List (Japanese government, ismap.go.jp), Sep 3, 2026: Verified on the registry
Singapore multi-tier cloud security standard, highest level.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Stated as compliant since 2023; no attestation of compliance or assessor named.
Not yet checked against a registry — a verification task is queued with TrustyCyber.
Self-certified participation, including the UK extension and Swiss-U.S. DPF. Checkable on the DPF public list.
Checked against Data Privacy Framework (dataprivacyframework.gov), Sep 3, 2026: Verified on the registry
Checked against CSA STAR Registry, Sep 3, 2026: Verified on the registry
Checked against FedRAMP Marketplace (fedramp.gov), Sep 3, 2026: Verified on the registry
Sources 21 — click to view
Appendix: standards landscape 8 — click to view
Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.
This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.
