Now Assist

servicenow.com

Automated, point-in-time. Not independently reviewed or approved by TRUSTYCYBER unless expressly stated.

TrustyCyber Score
57 / 100C
Procurement decision
Approve with conditions
3 conditions outstanding
  • No formal subprocessor register disclosed
  • No clear commitment that your data will not train their models
  • Data retention window not stated

See Before you sign, with what to ask for ↓

Evidence MediumFreshness CurrentVerification Partial

Scanned Sep 3, 2026 · Public evidence · Point-in-time

Higher scores indicate stronger, independently supported AI assurance — governance, AI systems, models, data, supply chain and third-party assurance evidence. The score and the decision are related but different: a well-scored vendor can still carry conditions.

Before you sign

No formal subprocessor register disclosedCondition

Why it matters: The vendor names AI-related providers or partially addresses its supply chain, but the public sources scanned do not include a formal, dated subprocessor register.

What to ask for: Request a dated subprocessor register with change-notification terms for the DPA/order form.

No clear commitment that your data will not train their modelsCondition

Why it matters: The public sources scanned do not clearly state that customer prompts, files, and outputs are excluded from training or fine-tuning of first- or third-party models.

What to ask for: Get a no-training clause covering first- and third-party models into the DPA/order form.

Evidence
Customers control whether data is made available for fine-tuning and testing
Vendor publishedWebsite and Events Privacy Statement - ServiceNowretrieved Sep 3, 2026
Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.
Data retention window not statedCondition

Why it matters: The public sources scanned do not give a retention period for customer data or prompts/outputs.

What to ask for: Get retention windows, in days, in writing.

Buyer questionsanswered only from the public evidence scanned — click a row for the answer

!Will they train on your data?Ask the vendor

ServiceNow states that chat conversations on its marketing website may be monitored and retained, including for training purposes. This statement is scoped to the ServiceNow websites and Events, not to the hosted services or to Now Assist.

Requires written confirmation — see Before you sign ↓

Evidence
Customers control whether data is made available for fine-tuning and testing
Vendor publishedWebsite and Events Privacy Statement - ServiceNowretrieved Sep 3, 2026
Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.
!How long do they keep your data?Ask the vendor

Not found in the public sources scanned — ask the vendor directly.

Requires written confirmation — see Before you sign ↓

!Who else can access your data?Ask the vendor

The Responsible AI white paper's contents list a section on handling Azure OpenAI LLM requests in production, indicating a third-party model provider sits in the production path alongside ServiceNow's own LLMs. Only the section heading is public; the section itself is behind the download form.

Requires written confirmation — see Before you sign ↓

Evidence
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Vendor publishedPrivacy and Data Protection - ServiceNowretrieved Sep 3, 2026
We are committed to transparency and compliance with regulations such as GDPR and privacy best practices. We never sell customer data to third parties or use it for ads.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers.  If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.
!Where is your data processed?Ask the vendor

ServiceNow states that customer data storage locations vary by service type and customer location and are set in the Order Form, so residency is a contract-specific matter rather than a published position.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
Customer data storage locations vary depending on the type of service and location of the Customer, as specified in the relevant Order Form.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
ServiceNow relies on EU Commission adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss specific data transfer language to enable transfers of Customer data to sub‑processors based outside of Europe.
!What happens in a security incident?Ask the vendor

ServiceNow states that on a security incident affecting customer data it will provide an initial report to the customer contact named in the support portal, or as set out in the DPA and DSA. No notification timeframe is published.

Confirm in writing: Ask the vendor to state this in writing before signing.

Evidence
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
In the event of a security incident impacting customer data, ServiceNow will provide an initial report to the designated customer contact in the customer support portal or as provided in the DPA and DSA. Customers are responsible for ensuring the appropriate person is listed in the support portal.

Key findingsclick a row for the evidence

AI governance is board-level and externally certifiedStrong

ServiceNow states that its Board, working with the Audit Committee, oversees an AI governance program, that an Enterprise AI Governance Steering Committee of executives approves the governance plan, that high-risk AI proposals escalate to a senior oversight committee, and that the whole arrangement is certified to ISO/IEC 42001, the AI management system standard. The principles are stated to be based on the NIST AI Risk Management Framework.

Most vendors publish AI principles. Far fewer name the body that owns them, describe an escalation path for high-risk systems, and put the management system through third-party certification. This is structural evidence rather than a statement of intent, and it is the strongest single signal in this assessment.

Question for vendor: Please supply the ISO/IEC 42001 certificate, naming the certification body and the scope statement, and confirm whether Now Assist falls inside that scope.

Evidence
The Board, in coordination with the Audit Committee, is responsible for overseeing the ServiceNow AI Governance program, which is focused on the responsible development and use of ServiceNow AI products and services, as well as third-party technologies ServiceNow uses internally.
Accountability mechanisms are built into the governance structure. For example, high-risk AI proposals are escalated to a senior oversight committee for approval.
Therefore, inspired by the NIST Artificial Intelligence Risk Management Framework, ServiceNow has embraced four guiding principles for developing responsible AI:
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.
Broad, dated third-party assurance across security and privacyStrong

The trust site sets out a long assurance ladder with start dates and audit cadence: ISO/IEC 27001 since 2012, 27017 since 2018, 27018 since 2016, 27701 from 2020, SOC 1 Type 2 since 2011, SOC 2 Type 2 since 2013, BSI C5 from 2020, PCI DSS from 2023, ISMAP registration from March 2022, MTCS Level 3, and an EU Cloud Code of Conduct verification quoted with a public Verification-ID.

Dated claims with named audit cycles are checkable, and the EU Cloud CoC verification ID and the FedRAMP marketplace listing can be confirmed against public registers without asking the vendor. That is a materially stronger position than an unlabelled badge wall.

Evidence
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow has been an ISO/IEC 27001 certified organization since 2012 and the certificate is available here
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
The certification is gained by an annual independent audit and ServiceNow has been an ISO/IEC 27017:2015 certified organization since 2018.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
The certification is gained by annual independent audit and ServiceNow has been an ISO/IEC 27018:2019 certified organization since 2016.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
This extension to ISO/IEC 27001 focuses on the establishment, and maintenance of a Privacy Information Management System (PIMS). This is relevant to ServiceNow as a processor of customer data which may contain Personally Identifiable Information (PII). ServiceNow received this certification in 2020.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is audited by a third party and has maintained its SSAE 18 SOC 1 Type 2 attestation since 2011 (SSAE 18 superseded SSAE 16 in 2017). SSAE 18 is aligned with international standard ISAE3402 and replaced the now-deprecated SAS70.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow has also undertaken an annual SOC 2 Type 2 attestation since 2013, relevant to security, availability and confidentiality controls listed in the AICPA Trust Services Criteria (TSC).
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
C5 is a cloud-specific compliance controls catalog developed by the German Federal Office for Information Security (BSI) and leveraged in both the public and private sectors. The C5 Attestation Report follows a similar process and schema as AICPA SOC 2 reports, and has a high overlap of requirements with the AICPA Trust Services Criteria, with the addition of specific cloud-focused requirements. ServiceNow received its C5 Attestation Report in 2020.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
Services are verified compliant with the EU Cloud CoC, Verification-ID 2022LVL02SCOPE3113.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is proud to have achieved MTCS Level 3, the highest level of certification available.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
This is relevant to ServiceNow as a processor of customer data which may contain credit card data. ServiceNow became compliant in 2023.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is a Data Privacy Framework (DPF) Program participant.
!The AI-specific evidence a buyer needs is gated, and the public privacy detail is datedGap

The documents that would answer the AI questions directly are not public. The Responsible AI white paper, the AI Security and Data Handling Controls white paper that ServiceNow says carries product-specific protections for Now Assist, the AI Testing and Evaluation methodology, the Enterprise AI Governance Policy and the SOC and ISO reports all sit behind a download form or the customer-only CORE portal. The most detailed public privacy document, the Privacy FAQ, carries a last-updated date of 17 January 2024, before the ISO/IEC 42001 certification and the AI Product Specific Terms it would need to describe.

An assessor working only from public sources cannot confirm what happens to prompts and outputs in Now Assist, how long they are kept, or which controls apply. Everything of substance requires a customer relationship or a form submission, so this assessment rests on organisation-level statements rather than product evidence.

Question for vendor: Please provide the AI Security and Data Handling Controls white paper and the AI Product Specific Terms, and confirm the retention period for Now Assist prompts and outputs.

Evidence
It covers data handling controls, data residency and processing infrastructure, AI Control Tower for enterprise-wide governance, and product-specific protections across Now Assist, Moveworks, and Veza from ServiceNow.
Customers control whether data is made available for fine-tuning and testing
Vendor publishedResponsible AI - ServiceNowretrieved Sep 3, 2026
Explore our methodology for testing large language model (LLMs) applications, including risk assessment frameworks and best practices to support enterprise-aligned AI systems.
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
In accordance with the audit clauses in the DPA and/or DSA, current customers may request access to the ServiceNow CORE, a comprehensive repository of information and documentation, including policies, procedures, as well as our then-current third-party audit reports against internationally recognized standards such as ISO 27001 and ISO 27018, and independent third-party assessments against security standards like SSAE 18 / SOC 1 and SOC 2 Type 2.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
ServiceNow’s AI products and features have undergone Privacy by Design reviews and may be subject to additional contractual terms that govern how those AI‑powered services are provided, and how data may be processed, such as the AI Product Specific Terms
!Model providers are named only in passing and the promised model cards are not reachableGap

The public material names Mistral-Nemo-12B as an example foundation model and shows a white paper section titled Handling Azure OpenAI LLM requests in production, which indicates a third-party model provider in the live request path. Neither is developed on any public page. The same white paper states that publicly available model cards explain each model's training data and limitations, but no model card was reachable from the AI or trust pages collected.

Which model serves a request, and who operates it, determines where prompt content goes and whose terms govern it. A buyer assessing Now Assist cannot presently establish either from public sources, and the one artefact that would settle it is described as public but was not found.

Question for vendor: Which foundation models and hosted model providers serve Now Assist in production, in which regions, and where are the model cards published?

Evidence
1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.
!The strongest government authorisations do not cover the commercial platformGap

The FedRAMP High Provisional Authority to Operate is stated for the Government Community Cloud offering, and the IRAP assessment for OFFICIAL and PROTECTED data is stated for the Australian platforms. The ISMAP registration is stated for the Now Platform. None of these is presented as covering the commercial platform generally, and none mentions Now Assist.

These are the most demanding authorisations on the page and the easiest to read as covering everything. A commercial buyer of Now Assist gains no assurance from them unless they are buying the specific offering that holds them.

Question for vendor: Which of the listed authorisations extend to Now Assist on the commercial platform, and which are limited to GCC, the National Security Cloud or the Australian platforms?

Evidence
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow’s Government Community Cloud (GCC) offering currently maintains a Federal Risk and Authorization Management Program (FedRAMP) High Baseline Provisional Authority to Operate (P-ATO).
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow's Australian Platforms has been independently assessed by an endorsed IRAP assessor to meet the Australian ISM controls for OFFICIAL and PROTECTED data.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.
?Technical dependency observed: GoogleObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Google as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Google appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers.  If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.
?Technical dependency observed: StripeObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Stripe as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Stripe appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers.  If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.
?Technical dependency observed: MicrosoftObservation

Technical evidence (DNS, certificate, or HTTP) shows a dependency on Microsoft as a service provider. This dependency is not identified in the vendor's published materials.

An undisclosed provider dependency is exactly the gap independent verification exists to surface.

Question for vendor: Verification required — Microsoft appears to be involved as a service provider: confirm whether this dependency exists, and whether it processes customer data.

Evidence
1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers.  If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.

Assurance dimensionsweighted components of one score — not eight separate ratings

Organisation & AI governance15% of the scoreorganisation-level evidence65

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Governance & accountability

Who owns AI risk — policies, responsible-AI principles, human oversight and administrative controls.

Assessed against ISO 42001 · NIST AI RMF · AIUC-1

Partial
Evidence — Governance & accountability
The Board, in coordination with the Audit Committee, is responsible for overseeing the ServiceNow AI Governance program, which is focused on the responsible development and use of ServiceNow AI products and services, as well as third-party technologies ServiceNow uses internally.
Accountability mechanisms are built into the governance structure. For example, high-risk AI proposals are escalated to a senior oversight committee for approval.
Therefore, inspired by the NIST Artificial Intelligence Risk Management Framework, ServiceNow has embraced four guiding principles for developing responsible AI:
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.

Governance & accountability: vendor-evidenced, not yet independently corroborated.

AI system15% of the score40
AI system description

What AI the vendor actually runs and where it sits in the product — the map everything else is judged against.

Assessed against ISO 42001 · NIST AI RMF

Partial
Evidence — AI system description
ServiceNow believes that the best way to unlock the value of AI for customers is to deeply embed it in the platform, rather than simply providing a gateway to an external AI engine.
It covers data handling controls, data residency and processing infrastructure, AI Control Tower for enterprise-wide governance, and product-specific protections across Now Assist, Moveworks, and Veza from ServiceNow.
Testing & evaluation

How AI features are evaluated before and after release — evals, red-teaming, monitoring.

Assessed against NIST GenAI · NIST AI RMF · ISO 42001

Partial
Evidence — Testing & evaluation
ServiceNow AI solutions are continuously tested to promote fairness for all, and to minimize bias.
Vendor publishedResponsible AI - ServiceNowretrieved Sep 3, 2026
Explore our methodology for testing large language model (LLMs) applications, including risk assessment frameworks and best practices to support enterprise-aligned AI systems.
Change management

How changes to models and AI features are controlled and communicated — versioning, notice, rollback.

Assessed against ISO 27001 · ISO 42001

Partial
Evidence — Change management
ServiceNow builds transparent, responsible, auditable, and safe LLMs through a well-governed lifecycle process.
Model10% of the scoreorganisation-level evidence40

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Model & provider transparency

Which model providers and versions process customer data, and how changes to them are disclosed.

Assessed against NIST GenAI · ISO 42001

Partial
Evidence — Model & provider transparency
1. Research — an appropriate industry-standard foundational model is selected, such as Mistral-Nemo-12B for tasks like automated code generation.
Handling ServiceNow LLM requests in production 9 Handling Azure OpenAI LLM requests in production
Publicly available model cards explain each specific LLM model’s context, intended use, training/fine-tuning data, limitations, and other important information.
Customer data15% of the scoreorganisation-level evidence62

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Customer data treatment

Whether customer data trains models, how long it is retained, where it is processed, and how it is protected.

Assessed against ISO 27018 · OAIC APPs · EU AI Act

Partial
Evidence — Customer data treatment
Customers control whether data is made available for fine-tuning and testing
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
by virtue of the cloud-based services we provide, we do not review or analyze the content of the data input by customers in the ordinary course of operating our services. As a result, we will not know whether personal data is uploaded into your instance of the services.
Vendor publishedPrivacy and Data Protection - ServiceNowretrieved Sep 3, 2026
We are committed to transparency and compliance with regulations such as GDPR and privacy best practices. We never sell customer data to third parties or use it for ads.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
Customer data storage locations vary depending on the type of service and location of the Customer, as specified in the relevant Order Form.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
ServiceNow relies on EU Commission adequacy decisions, EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss specific data transfer language to enable transfers of Customer data to sub‑processors based outside of Europe.
Vendor publishedWebsite and Events Privacy Statement - ServiceNowretrieved Sep 3, 2026
Additionally, if you contact us through our chat feature, we may monitor and retain the chat conversation, including for training purposes.
Vendor publishedWebsite and Events Privacy Statement - ServiceNowretrieved Sep 3, 2026
Our processing may involve processing using machine learning and artificial intelligence.
AI supply chain10% of the scoreorganisation-level evidence40

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Subprocessors & supply chain

The named chain of AI and infrastructure providers behind the product, and how it is disclosed.

Assessed against ISO 27001 · ISO 27017

Partial
Evidence — Subprocessors & supply chain
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
In order to provide our services, ServiceNow may use ServiceNow group entities and third-party sub‑processors. A full list of our appointed sub‑processors for the different ServiceNow services is available here
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
To deliver and support our service, ServiceNow engages its affiliates located throughout the world, including in the United States, Australia and India, and other sub- processors for various services, as listed in the DPA.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
From time to time , ServiceNow may update our sub‑processors as needed to continue to provide the services to Customers.  If this happens, ServiceNow will notify Customers of new sub‑processors through the mechanism identified in Clause 6 of the Data Processing Addendum
Security foundation15% of the scoreorganisation-level evidence85

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Vulnerability & incident handling

How security problems are found, reported and handled — disclosure channels, bug bounty, incident response.

Assessed against ISO 27001 · NIST AI RMF

Partial
Evidence — Vulnerability & incident handling
Vendor publishedservicenow.comretrieved Sep 3, 2026
Contact: https://hackerone.com/servicenow-disclosure Contact: mailto:[email protected] Policy: https://www.servicenow.com/company/trust/responsible-disclosure.html
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
In the event of a security incident impacting customer data, ServiceNow will provide an initial report to the designated customer contact in the customer support portal or as provided in the DPA and DSA. Customers are responsible for ensuring the appropriate person is listed in the support portal.
Vendor publishedResponsible Disclosure - ServiceNowretrieved Sep 3, 2026
ServiceNow does not condone actively auditing our infrastructure. As you explore ServiceNow web properties, report vulnerabilities at  [email protected]

Vulnerability & incident handling: the certifications above are independently corroborated, but they cover the management system — these specific disclosures are the vendor's own statements, not yet independently verified.

Independent assurance evidence10% of the scoreorganisation-level evidence71

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Independent assurance

Whether claimed certifications and attestations are independently corroborated — checked against official registries and issuing bodies. Which certifications, and what each one does and does not establish, is stated per certificate.

Assessed against ISO 17021-1 · ISO 42006 · ISO 27006-1 · ISO 27008

Covered
Evidence — Independent assurance
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ISO/IEC 42001 is the first international standard for managing artificial intelligence responsibly across its lifecycle. ServiceNow's certification demonstrates our commitment to building and operating AI systems with strong governance, transparency, and risk management, helping customers adopt AI with confidence while meeting global regulatory and ethical expectations.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow has been an ISO/IEC 27001 certified organization since 2012 and the certificate is available here
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is audited by a third party and has maintained its SSAE 18 SOC 1 Type 2 attestation since 2011 (SSAE 18 superseded SSAE 16 in 2017). SSAE 18 is aligned with international standard ISAE3402 and replaced the now-deprecated SAS70.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow has also undertaken an annual SOC 2 Type 2 attestation since 2013, relevant to security, availability and confidentiality controls listed in the AICPA Trust Services Criteria (TSC).
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
Services are verified compliant with the EU Cloud CoC, Verification-ID 2022LVL02SCOPE3113.
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
In accordance with the audit clauses in the DPA and/or DSA, current customers may request access to the ServiceNow CORE, a comprehensive repository of information and documentation, including policies, procedures, as well as our then-current third-party audit reports against internationally recognized standards such as ISO 27001 and ISO 27018, and independent third-party assessments against security standards like SSAE 18 / SOC 1 and SOC 2 Type 2.

Read from the registry record above — cited, not reproduced.

Registry verifiedCSA STAR Registry record — CSA STAR Level 2retrieved Sep 3, 2026

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Read from the registry record above — cited, not reproduced.

Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
The certification is gained by an annual independent audit and ServiceNow has been an ISO/IEC 27017:2015 certified organization since 2018.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
The certification is gained by annual independent audit and ServiceNow has been an ISO/IEC 27018:2019 certified organization since 2016.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
This extension to ISO/IEC 27001 focuses on the establishment, and maintenance of a Privacy Information Management System (PIMS). This is relevant to ServiceNow as a processor of customer data which may contain Personally Identifiable Information (PII). ServiceNow received this certification in 2020.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
C5 is a cloud-specific compliance controls catalog developed by the German Federal Office for Information Security (BSI) and leveraged in both the public and private sectors. The C5 Attestation Report follows a similar process and schema as AICPA SOC 2 reports, and has a high overlap of requirements with the AICPA Trust Services Criteria, with the addition of specific cloud-focused requirements. ServiceNow received its C5 Attestation Report in 2020.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow’s Government Community Cloud (GCC) offering currently maintains a Federal Risk and Authorization Management Program (FedRAMP) High Baseline Provisional Authority to Operate (P-ATO).
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow's Australian Platforms has been independently assessed by an endorsed IRAP assessor to meet the Australian ISM controls for OFFICIAL and PROTECTED data.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
was independently assessed by a registered ISMAP assessor to meet the Control Criteria of ISMAP controls and has been registered as ISMAP Cloud Service since March, 2022.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is proud to have achieved MTCS Level 3, the highest level of certification available.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
This is relevant to ServiceNow as a processor of customer data which may contain credit card data. ServiceNow became compliant in 2023.
Vendor publishedServiceNow AI Platform Compliance - ServiceNowretrieved Sep 3, 2026
ServiceNow is a Data Privacy Framework (DPF) Program participant.

None of the corroborated certifications is AI-specific (ISO/IEC 42001 or AIUC-class) — this assurance is security and data-transfer attestation, not AI-management-system assurance.

Legal & contractual10% of the scoreorganisation-level evidence40

Graded from organisation-level evidence — it does not automatically establish assurance for this product.

Legal & contractual transparency

The contractual backbone a buyer can rely on — terms, DPAs, privacy commitments and regulatory posture.

Assessed against EU AI Act · OAIC APPs

Partial
Evidence — Legal & contractual transparency
Vendor publishedGDPR Compliance Corporate Statement | ServiceNowretrieved Sep 3, 2026
ServiceNow’s standard Data Processing Addendum (“DPA”) and Data Security Addendum (“DSA”) at https://www.servicenow.com/upgrade-schedules.html address our obligations as the data processor and your obligations as the data controller under relevant data protection laws.
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
ServiceNow’s AI products and features have undergone Privacy by Design reviews and may be subject to additional contractual terms that govern how those AI‑powered services are provided, and how data may be processed, such as the AI Product Specific Terms
Vendor publishedPrivacy FAQ – ServiceNowretrieved Sep 3, 2026
As a global Software‑as‑a‑Service provider, ServiceNow acts as a processor under the General Data Protection Regulation (“GDPR”) when providing services to our Customers . Under the terms of our standard Data Processing Addendum with Customers and Partners, ServiceNow will only process personal data as instructed by the Customer or Partner, for the purpose of providing services.

Not graded: Agent — not applicable to this scan.

What would strengthen assuranceeach figure is from today's score — resolving one changes the others

+3Complete the Customer data treatment disclosureData 6282
+2Have Governance & accountability disclosures independently corroboratedOrganisation 6580
+2Complete the Legal & contractual transparency disclosureLegal Contractual 4060
+2Complete the Model provider transparency disclosureModel 4060
+2Complete the Subprocessors & supply chain disclosureSupply Chain 4060

Resolving an evidence gap strengthens the dimension it belongs to, and with it the score: 57 → up to 78 with every identified gap resolved.

AI supply chainclick a node to focus it · drag to pan · zoom with the controls

ORGANISATIONPRODUCT & AI FEATURESMODELS & AI PROVIDERSServiceNowServiceNowNow AssistNow AssistServiceNow AI PlatformServiceNow AI PlatformMistral-Nemo-12BMistral-Nemo-12BAzure OpenAIAzure OpenAI
View as list
ServiceNow Uses AI Service Mistral-Nemo-12B
ServiceNow Routing Or Fallback Azure OpenAI

What you inheritTrustyCyber's AI Shared Responsibility Matrix v1.0

This scan names the vendor’s AI supply chain without assessing the responsibility split — that depends on how you consume the product. Under the common managed models, a deployer inherits 16 of the matrix’s 41 responsibilities from providers, each with named evidence owed.

Map your inherited responsibilities
Assurance evidence: certifications 17 — registry checks and verification ladders, click to view
ISO/IEC 42001Claimed, scope unclear

Stated as held, with no certificate number, certification body, scope statement or issue date given. Whether Now Assist falls inside the AI management system scope is not stated.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27001:2022Vendor claimed only

Certified since 2012; three-yearly recertification with annual surveillance audit. The certificate is linked but the scope statement was not collected.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27017:2015Vendor claimed only

Certified since 2018, by annual independent audit.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27018:2019Vendor claimed only

Certified since 2016, by annual independent audit.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISO/IEC 27701:2019Vendor claimed only

Privacy information management extension to ISO/IEC 27001, received 2020.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SSAE 18 SOC 1 Type 2Vendor claimed only

Maintained since 2011; report available to customers via ServiceNow CORE, not publicly.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

SOC 2 Type 2Vendor claimed only

Annual since 2013, covering security, availability and confidentiality. Report available to customers via ServiceNow CORE, not publicly.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

BSI C5Vendor claimed only

Attestation report received 2020.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU Cloud Code of ConductClaimed & corroborated

Level 2 compliance with partial third-party audit coverage. The adherence ID quoted on ServiceNow's own compliance page (2022LVL02SCOPE3113) matches the register entry exactly.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Currentuntil Jul 27, 2027

Checked against EU Cloud Code of Conduct public register (eucoc.cloud), Sep 3, 2026: Verified on the registry

FedRAMP High P-ATOClaimed, scope unclear

Scoped to the ServiceNow Government Community Cloud (GCC) offering, not the commercial platform.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

IRAP assessment (OFFICIAL and PROTECTED)Claimed, scope unclear

Scoped to the ServiceNow Australian platforms. IRAP is an assessment, not a certification.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

ISMAP Cloud Service registrationClaimed & corroborated

Registered as the ServiceNow AI Platform under registration number C22-0036-2, not the narrower 'Now Platform' the vendor's compliance page names. The register row also carries a dedicated generative-AI information document (生成AIに関する情報), so the scheme holds a generative-AI scope declaration for this service. Last updated on the register 2026-04-24.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against ISMAP Cloud Service List (Japanese government, ismap.go.jp), Sep 3, 2026: Verified on the registry

MTCS Level 3Vendor claimed only

Singapore multi-tier cloud security standard, highest level.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

PCI DSSVendor claimed only

Stated as compliant since 2023; no attestation of compliance or assessor named.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Not yet checked against a registry — a verification task is queued with TrustyCyber.

EU-U.S. Data Privacy FrameworkClaimed & corroborated

Self-certified participation, including the UK extension and Swiss-U.S. DPF. Checkable on the DPF public list.

Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against Data Privacy Framework (dataprivacyframework.gov), Sep 3, 2026: Verified on the registry

CSA STAR Level 2Claimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against CSA STAR Registry, Sep 3, 2026: Verified on the registry

FedRAMP AuthorizationClaimed & corroborated
Vendor claimed
Evidence cited
Registry corroborated
Scope verified
Current

Checked against FedRAMP Marketplace (fedramp.gov), Sep 3, 2026: Verified on the registry

Sources 21 — click to view
Put AI to Work with Now Assist for Customers and Employees
AI Documentation · Vendor · retrieved Sep 3, 2026
ServiceNow Trust and Compliance Center - ServiceNow
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Privacy Management - ServiceNow
Privacy Notice · Vendor · retrieved Sep 3, 2026
ServiceNow AI - Put AI to Work for People
AI Documentation · Vendor · retrieved Aug 31, 2026
https://www.servicenow.com/.well-known/security.txt
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Website and Events Privacy Statement - ServiceNow
Privacy Notice · Vendor · retrieved Sep 3, 2026
Responsible AI - ServiceNow
AI Documentation · Vendor · retrieved Sep 3, 2026
Security on the ServiceNow AI Platform - ServiceNow
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
GDPR Compliance Corporate Statement | ServiceNow
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Responsible Disclosure - ServiceNow
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
AI Security and Data Handling Controls in the ServiceNow AI Platform
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
ServiceNow: Shared Responsibility Model
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Privacy and Data Protection - ServiceNow
Privacy Notice · Vendor · retrieved Sep 3, 2026
Privacy FAQ – ServiceNow
Privacy Notice · Vendor · retrieved Sep 3, 2026
ServiceNow AI Platform Compliance - ServiceNow
Trust Or Security Page · Vendor · retrieved Sep 3, 2026
Data Privacy Framework (dataprivacyframework.gov) record — EU-U.S. Data Privacy Framework
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
CSA STAR Registry record — CSA STAR Level 2
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
FedRAMP Marketplace (fedramp.gov) record — FedRAMP Authorization
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
EU Cloud Code of Conduct public register (eucoc.cloud) record — EU Cloud Code of Conduct
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
ISMAP Cloud Service List (Japanese government, ismap.go.jp) record — ISMAP Cloud Service registration
External Registry Or Certification Evidence · Registry · retrieved Sep 3, 2026
Appendix: standards landscape 8 — click to view

Where each standard behind this assessment stands today, from TrustyCyber’s continuously maintained standards radar.

AI management system · Anchor for responsible AI governance — internal audit, management review and continual improvement. World's first AI management system standard.
NIST AI RMF 1.0 (AI 100-1)Published (2023; GenAI profile 2024)
AI risk management (+ Generative AI Profile) · Voluntary AI RMF (Govern/Map/Measure/Manage); the US counterpart to ISO/IEC 42001 for AI governance.
ISMS requirements · Core assurance anchor. Amendment 1 (2024) adds climate-action considerations to clauses 4.1/4.2; base edition remains 2022.
Interpretation of the 13 APPs · Authoritative APP interpretation under the Privacy Act 1988; watch for privacy-reform updates.
EU AI Act (Reg 2024/1689)In force, phased to 2028 (amended by Reg (EU) 2026/1744)
AI regulation — risk tiers, GPAI, high-risk obligations · Extraterritorial AI law; GPAI obligations and the Code of Practice are live. The Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 Jul 2026, in force 27 Jul 2026), defers Annex III standalone high-risk obligations to 2 Dec 2027 and Annex I embedded high-risk to 2 Aug 2028; Article 50 transparency duties applied from 2 Aug 2026.
PII protection in public clouds · 3rd edition (Aug 2025), aligned to 27002:2022 with a new Annex B; useful for SaaS privacy, processor obligations and customer assurance packs.
130-control AI usage framework · Control-level AI usage framework with mandatory/supplemental classifications and evidence guidance.
Requirements for management-system certification bodies · The base certification-body standard that ISO/IEC 27006-1 and 42006 extend; foundational for audit/cert integrity (also in the reference vault).

This automated result is based on publicly available information at the time of scanning. It is not an audit, certification, legal opinion or assurance engagement. Publicly unavailable evidence may materially change the conclusion.