Many organizations are already enjoying the benefits of ServiceNow's GRC capability. The product helps transform inefficient processes across your extended enterprise into an integrated risk program. The Policy and Compliance application provides a centralized process for creating and managing policies, standards, and internal control procedures that are cross-mapped to external regulations and best practices.
One of the key external regulatory compliance content providers is LexisNexis, and until now there has been no wholistic integration solution that maximizes the value from the content and the capabilities in ServiceNow GRC.
TMLabs now take the power of the ServiceNow platform even further by introducing the LexisNexis Integration application for ServiceNow. A solution is tailor-made for use with ServiceNow GRC to provide a secure, seamless LexisNexis content management experience.
Simplicity: In a few simple steps, information from LexisNexis can be brought into ServiceNow GRC product suite.
Security: The application secures the LexisNexis client key in an encrypted field and it does not store tokens which are used to communicate with LexisNexis.
Use of ServiceNow GRC suite: The application leverages capabilities of ServiceNow GRC suite and allows managing GRC related content in one place. LexisNexis content can be used along with other GRC frameworks e.g. UCF.
Ease of fetching updated LexisNexis content: The application automatically updates new and modified content on a daily basis.
Easy configuration: The application applies simple configuration to ServiceNow GRC suite without customisation. The application changes do not affect existing configurations.
A one-stop-shop for all LexisNexis content:
- Captures all LexisNexis Tools & Alerts, and links them to the relevant Control Objectives and Obligations in ServiceNow.
- Keeps compliance managers informed about the latest changes to obligations via support for ServiceNow's Regulatory Change Management application.
Version 3.0 :
LexisNexis Source Data API v2 — POST-based Mandates and Regulators with cursor-based pagination ensuring no records are missed
· Intelligent CSV Fallback for large datasets — automatically switches to ZIP/CSV download when JSON response exceeds size limits.
· Concurrent execution guard — integration will not start a second run if one is already in progress; protected by isRunning property with automatic cleanup in all exit paths
· Seven-Dimension Automatic Taxonomy Classification for Obligations: Business Function, Industry, Compliance Area Topic, Compliance Requirement Level, Material Type, Risk Penalty Level, Impact Rating
· Parent-Child Industry Taxonomy Hierarchy — Financial Services / Banking / General Insurance auto-created with parent references on sn_grc_taxonomy_internal_taxonomy
· Mandate-to-Module M2M Linking — Authority Documents automatically linked to Content References via sn_grc_m2m_cont_ref_auth_doc
· Secure Token Caching with timezone-safe epoch comparison — eliminates stale-token 401 errors caused by timezone offset in previous versions
· Configurable token TTL via system property — defaults to 23 hours, overridable per instance
· New obligation fields: business_functions, industries, compliance_area_topics, compliance_requirement_levels, risk_penalty_levels
· New alert fields: impact_rating, industries (with parent-child taxonomy structure)
· New mandate field: modules (comma-separated module IDs linked to Content References)
· Fixed: subObligations casing mismatch in Mandate staging (was "subobligations", now correctly "subObligations")
· Fixed: state and level fields on Mandates and Regulators now correctly handle array values from API v2
· Fixed: _formatDate month off-by-one bug causing API from_date to be set one month into the future
· Fixed: getClassSysID logical operator (|| corrected to &&) in null guard
· Fixed: _addTaxonomy missing initialize() before insert causing GlideRecord state issue
Version 2.2.8:
- Extension of HTTP timeout from 30 to 60 seconds
Version 2.2.0:
- Dynamic Taxonomy Population for Regulatory Alerts
- Modules Widget under LexisNexis Application Navigation
- Please run a full load to fetch all the data by clearing "API 1 Fron Date" and "API 2 From Date" properties. This will ensure that any missing Taxonmoies are created and populated against the alerts and Mandates ( Authority Documents )
Version 2.0.1:
- Retrieve up to 2,000 regulators.
- Linking of modules with topics, obligations and sub-obligations to provide greater insight.
- A new alert effective date field for the regulator feed to capture more context on the alerts.
- Some changes to the module names and related lists to align more with the data standards.
- Minor enhancements for more flexibility on setup.
Version 2.0:
- LexisNexis Obligations mapping migrated from Control Objective to Citation. This change is based on customer and industry feedback and brings our mapping in line with contemporary usage of Obligation content.
- New relationships to show all Obligations related to a Mandate, and all Mandates related to an Obligation.
- Alerts (Regulator Feed) now displays the impacted Citations (Obligations) within Regulatory Change Management.
- Alerts and Tools linked to Citation (Obligation).
Version 1.2:
- Compatibility with Quebec.
- Support for ServiceNow Regulatory Change Management application.
Version 1.1:
- Compatibility with Paris.
- Additional granular settings that can be updated as per organisation requirements.
- Updated Control Objective form to display informative fields at the top of the form.
- Added linkages from Control Objectives to Alerts and Tools.
- Added review mechanism to Alerts.
- New reports.
- More information on responses when there is no new data to retrieve.
- Various background code enhancements.
Version 1.0: Initial release.
Plugin: GRC Policy and Compliance (13.0.3 onwards)
Plugin: GRC Regulatory Change Management Store Application (13.0.1)
Other Requirements:LexisNexis subscription.