ServiceNow, Inc. (NOW) Earnings Call Transcript & Summary

October 24, 2024

New York Stock Exchange US Information Technology Software special 57 min

Earnings Call Speaker Segments

Michael Murphy

executive
#1

Good morning, everyone. Good morning, good evening, good afternoon, for those that are joining us from around the world. We're going to talk about turning compliance challenges into competitive advantage this morning. I'm Michael Murphy. I'm joined by Rawda Selim, she's going to introduce herself in just a moment. I lead up the global go-to-market for financial services, risk and compliance at ServiceNow. Prior to joining ServiceNow, I spent some time at Wells Fargo, leading international strategy and governance in the second line of defense, and prior to that about a decade at PwC focused on the intersection of risk, compliance and technology. Rawda, would you mind introducing yourself?

Rawda Selim

executive
#2

Yes. Thank you, Michael. So I will just echo -- good morning, good afternoon and good evening to everyone joining us today. My name is Rawda, as Michael just mentioned, I'm what's called a senior advisory solution consultant, so I sit within the risk sales organization, more of a technical consultant. I have about 10-plus years of experience in the GRC domain. I've worked in several other GRC vendors prior to joining ServiceNow. So over to you, Michael.

Michael Murphy

executive
#3

Let's jump right in with our agenda today.

Rawda Selim

executive
#4

So -- I'll take this one. So the elements that we're going to be talking about today is, number one, the pressing global regulations, boosting productivity with limited resources, leveraging AI and automation, navigating with confidence, and finally Q&A.

Michael Murphy

executive
#5

Okay. Let me get started here talking about the pressing global regulations. This is -- anybody who's in the risk and compliance space, this is a no-brainer for us, right? We're overloaded, it feels like, all the time from a compliance perspective, always trying to keep up. And as I note from the latest survey that Thomson Reuters published around the cost of compliance, in 2022 TRRI monitored an average of 234 daily alerts. This was across almost 1,300 regulators in 190 countries. The interesting thing is, I think in all the years I've been reading Thomson Reuters, they've always said the volume of regulatory change is expected to increase. But often what we see is the budgets are remaining flat, which is what we saw in fact in the latest report for '22 and '23. But really, what I think is so interesting is that nearly half of the firms do not track the cost of compliance. And we know that the cost of compliance is less on the left-hand side of the bowtie than it is on the right-hand. What I mean by that is post-event, right, post-incident, right-hand side is always going to cost more to remediate and then correct what should have been in the first place on the left hand of the bowtie. And so I think that's one of the challenges we have is really, as an industry, is really tracking the cost of compliance that we can ensure that we're doing the right things at the outset. This is about driving the strategy within a firm to ensure that instead of creating MVPs each and every time we have a compliance obligation, we're really thinking about long-term strategy for that compliance obligation and how it slots into what we want to do as a firm. And we also know that resources are becoming more costly. As we'll go through here in follow-on slides, a couple of very large regulatory obligations, global regulatory obligations, are really going to be driving high demand in certain skill sets. And as you think about budgets remaining flat, the volume increasing and the cost of your resources going up, there's only a few levers we're going to have to pull in order to address these challenges in a way that's sustainable and, what I would say is, like designed in the right way from the outset. So let's jump into a couple that we're going to talk about today, but I would say the really big ones that we're going to talk about. The first one is GenAI. And this is a hot topic for your business partners. Many of your business partners are already using GenAI. And I think that one of the challenges I hear all the time from our customers is that they're in fact not aware, fully aware of where their businesses are using GenAI. Another challenge that I hear often is that they just don't have the right staff with the right skill sets to drive oversight, governance and oversight relative to GenAI. And so this is going to be a big challenge. As we think about, right, we're only showing 2 on the slide here, from EU and the U.S., but fairly.ai is tracking over 300 AI regulations around the globe. Some of those are data privacy regulations that impact AI, but over 300 regulations around the world is going to be a challenge for any firm to address, right? And so it's moving so quickly and it's presented so much risk that governments through around the world are compelled to address it. And when they're compelled to address it, we, as an industry, must address it. And so as we think about the next slide and the next topic we're going to talk about, we have the same kind of concept and overlap.

Rawda Selim

executive
#6

So you want me to pitch in here, Michael?

Michael Murphy

executive
#7

Yes, please.

Rawda Selim

executive
#8

So Michael just mentioned AI and GenAI and how it's kind of like perplexing the industry and how to address that. The second thing that is coming out, it's operational resilience. I'm assuming everyone here has heard or known of operational resilience in whatever term it's called, whether it's DORA, whether it's the U.K. operational resilience, whether it's the Australia APRA one, whether it's Hong Kong, Japan, as you see on the slide here, it is coming and it's coming in droves, and it's not going to leave anyone behind. So this map just shows you if, for example, a multinational company, or like you have a presence across multiple jurisdictions, those that I've spelled out right now, those regulatory, let's say, areas or regulatory jurisdictions, that you will be, say, facing some kind of avalanche from all of those regulators that are spelling out that alert or however you are trying to harmonize across your organization. So just what Michael mentioned before about the TR findings about the cost of compliance and how you have to do more with less and how the regulators are not going to leave you alone, they will be spinning out regulations as they go and they will not be less as we go through. So how then do we, as ServiceNow, use GenAI to help you in this compliance challenge? We will see in the next couple of slides. Over to you, Michael.

Michael Murphy

executive
#9

Thanks, Rawda. One thing I would mention here as we move into the next section, too, is that any firm that's operating across jurisdictional boundaries can to be facing this same kind of concept that we just had on the prior slide. It doesn't -- it's not confined to international boundaries, it's in fact even state boundaries. So when you think about resilience regulations, sort of at the top of the house is the operational resilience concept, but there's a lot of tech and cyber resilience concepts that are implemented with regulation across the globe, too, even down to -- in the U.S., the state level, for example, the New York Department of Financial Services, right? So this is really important for us to consider is the harmonization, the efficiency that we want to achieve relative to our compliance obligations, because there is a correlation, a positive correlation between efficiency and effectiveness. So let's talk about boosting productivity with limited resources. And before we get started, I think it's important for us to note that there are some challenges that sit ahead of us. So as I think about the conversations that I'm having -- and Rawda, I'd ask you to chime in here as well, the conversations we are having effectively with our customers, I would say, like, let's not get too hung up on the left-hand side of this slide, but because the numbers are subjective, they're the conversations that I'm having again with customers. But what I hear very often is that, in the first line, the people that should be doing the work, right, the people that should be implementing changes or managing vulnerabilities or onboarding customers, those folks are spending somewhere between 20% and 50% of their time doing what I would call control administration activities. This is responding to second-line inquiries. This is performing attestations. This is responding to your internal audit teams as they perform an audit or for your regulators as they're coming in to perform exams. That's a lot of time. It's a lot of opportunity cost that your people in the first line, the people that should be driving your business activities, are doing that really they shouldn't be doing. They shouldn't -- definitely they shouldn't be spending that much time. To make things worse, right, we have a lot of confidence in what I would say is a really small sample size. I put 5% here. We all know that there are going to be some elements of your business where you're doing a much higher continuous monitoring and testing perhaps, but on average, I think we're roughly in the boat, right? If you look at the OCC, for example, they even describe how they perform sample testing. It's so common and it's seeing so much -- or so little, in fact, of your controls when you evaluate through these small sample sizes. It just puts -- for me, at least, it makes me think that we put a lot of confidence in, in fact, in the unknown, right? If we have a good sample size and we see that where controls are working, we just presume that the rest of the controls are working. And I would say that that was probably fine in the 2010s, but that is not fine as we move forward, especially as we think about AI and operational resilience. And so on the right-hand side of the slide, this is really around the second line and what's the second line, what are some of the challenges that they have. As you can see, the first top right there was a statistic from McKinsey that shows that only about 0.25% of FTEs -- and this looked at G-SIFIs collection of 30 banks across the globe and half of them were G-SIFIs -- so this is a very small percentage of people with expertise in the operational risk space to be addressing things like AI and operational resilience. And when you consider sort of how GRC systems have been designed in the past, which are mostly designed for and used by -- predominantly used by second line or third line defense, you don't see a lot of evidence of second line or CROs investing in first-line usability. In fact, this data point here in the bottom right reflects that, right? Just 10% are investing a small portion to integrate the 2 sides of the house. Any comments you'd like to make here, Rawda, before I move on to the next slide?

Rawda Selim

executive
#10

So just to reiterate what you just said, Michael, is a lot of first-line are definitely putting a lot of effort in those manual [ menial ] tasks, which is control attestations, control testing, doing the sample sizes, that sometimes doesn't really give like a real view of what is actually happening with your processes and the controls. And that just [ confirms ] what you mentioned before, is that it is the compliance, how compliance regulations are coming out. And there is -- you needed to do more with less and that is just taking up a lot of time first and second line. So just to hammer home the point that moving forward, there has to be some kind of change in how you do -- how you've been doing the same thing for the number of years and getting the same result.

Michael Murphy

executive
#11

Yes, that's right. Thanks for adding that, Rawda. I, as former consultant, have spent a lot of time building project plans. And so there are just 3 levers you can pull. I look at everything that I do at work as a project of sorts, and there are only 3 levers you can pull on a project. That's going to be the scope -- changes in scope, changes in resources or changes in time. And so we know when we think about compliance obligations, time is fixed generally, right? Your scope may or may not be able to change, depending on what the regulation is. But what we see from TR is that your resource allocations, both in terms of human resources as well as funding, aren't changing. And so that leaves us with very limited options in order to move forward to solve this idea of doing more with less. So I want to show a slide that sort of represents my experience in the second line of defense, engaging with the first line, engaging with internal audit, engaging with regulators in fact. And I would say that, as I use this slide to have conversations with customers, that this is pretty indicative of how they feel as well, which is really just not good handoffs between first and second line, even sometimes between first-line business activities and the control functions that might sit within them. But I think we must also consider how each of these firms -- or each of these teams, excuse me, are using technology. And so we, as a provider of integrated risk management software, we experience this all the time. You might have a CIO and/or a CISO that are, in fact, purchasing their own GRC solution because they don't like what the second line or the group team is using. It doesn't do the job that they need it to do. We're seeing COOs purchase GRC solutions to manage operational resilience, for example, and/or first-line controls more broadly across the industry. We know that CROs by GRC systems to manage things at the enterprise level generally, your risk and control libraries, perhaps, your RCSAs issues, et cetera. And we often find that the chief audit executives are very insular in terms of wanting to have their own system as well. And so this creates also additional challenges in terms of being able to get the data connected through those various systems and to the people that need them, right? There's an interaction that must take place, from compliance identifying an obligation to crafting the policy and procedures around that, perhaps, to then the business demonstrating how they're going to apply controls to that -- those policy statements or those regulations, and then in the second line ensuring that, right? And so there's this constant flow of data and communication that needs to go back and forth. And what we find is that it's very highly fragmented across each of these firms. And if you think about where we're seeing the industry go, especially around things like AI and operational resilience, which is really 2 huge opportunities from a risk and compliance perspective to drive competitive advantage, what we're seeing is firms that are making the switch, from viewing perhaps risk and compliance teams as a cost center and looking in the rearview mirror, right, at historical data to inform perhaps the future, to the firms that are really looking at connecting this entire series of stakeholders across the first, second and third lines in order to unite the teams, in order to manage risk more in line with the, I don't know, the timeline in terms of risk identification, risk materialization, incidents and incident management, right? And so getting much closer to the action, if you will, taking signals that turn into insights rapidly, right, to join people across both the experts in the second line as well as the people in the business in the first line in order to take the next best step. So let's talk about 3 ways, finally, to gain some efficiency and maximize effectiveness. As I mentioned earlier, there's a positive correlation between these two. So I was thinking about this slide, I really want to bring this back to something that's very personal to each of us. And so I would say that we all love our Apple and Android phones -- at least most of the time we love them. And it's because they give us these amazing dopamine hits. But we spend most of our time awake at work, engaging the software. It really does anything but give us a dopamine hit. It leaves us feeling exhausted and frustrated and really ill to do our jobs. And as I mentioned earlier, right, the GRC technology has really historically catered to second and third lines. And so if you think about this for a moment, right, if you consider how many people in your organizations are in the second or third lines, I'm guessing that it's somewhere between 3% and 7% of your FTE population. We might have some that are more than that, obviously. But largely what we see in McKinsey's statistic earlier, right, 0.25% [ are aligned ] to operational risk, a 3% to 7% FTE ratio for second and third lines is pretty close to what most firms are operating in. So the second and third lines aren't happy with their legacy GRC systems either. So you can imagine how averse the risk-taking side of the company is in the first line to use those systems. This is why we see CIOs and CISOs purchasing their own solutions in order to drive, right, the activities and the outcomes that they need to achieve. So let's talk about how ServiceNow is different for a moment. I'm sorry, I'm dealing with a cold here, so I'm going to throw a cough drop in my mouth and hope it doesn't become too confusing. But the ServiceNow was really born in the first line. It's one of the things that attracted me to ServiceNow when I was at Wells Fargo is really thinking about how do we do things differently? And I fundamentally believed at the time, and still do, in fact even more so since I've been here for 4 years, the idea of driving activity in the first line is how we're going to fundamentally change the industry. It's how we're going to deal with all the things we saw that are challenges at the outset before we got to this slide. And so there's 3 things I think we can all think about in a different way. First is outcomes matter. System fragmentation and manual processes, they might have created complexity in the organization through no fault really of anyone, right? We're all doing the best, nobody sets out to build a terrible process, right? But it's creating debt. It creates debt. It creates inefficiency. And so you should shed that debt at the earliest opportunity, right? It's true that most people fear change, but Apple and Google have really proven that people hate clunky technology more than they hate change, right? You get a newer thing -- an update on your phone, it gives you some new capabilities. You figure it out pretty quickly, and you're generally happy with that, right? I would say, business process change is one of those things that is -- firms are highly resistant to when they're talking about a new GRC or integrated risk technology entering their environment. And this is one thing that I look at and say, well, I can totally understand how difficult business change is. But I also say that's a one-time event, right? This is a, as you roll it out, this is the opportunity to change it. This is the one time -- one chance you got to change that, right? And the clunky technology is clunky every time you use it. And so we really got to be focusing on outcomes. And that means simplification, right? As you deploy new technology, do we need 27 steps for a risk in that process if we can do it in 12? I think the answer is pretty obvious. The second point here is there are at least 3 universal truths when it comes to risk management, right? No business opportunity exists without risks. And as we know, we've seen in the last few years, right, business conditions change on a dime. And you have to be flexible and responsive to that. You have to be able to adapt. This is in fact one of the things that operational resilience -- or the prime thing that operational resilience is trying to address. And regulation isn't going away, as we saw. It's not even slowing down. And we place, as I said earlier, right, so much trust in these sample sizes despite the risks that humans introduce into nearly every business activity, right? Humans must engage in every process. There are very few straight [ through ] processing opportunities within the middle and back office elements of the institution. And so humans introduce risk every time they touch their hands on a keyboard. And so we have to really think about how do we get ahead of this, right? And as a backdrop of operational resilience, many firms are embracing risk and compliance hyperautomation concepts. It means how far can we take this? I would in fact encourage you to go search, after this webinar, search what Westpac has said publicly around how they think that they can exceed perhaps up to 70% of continuous monitoring against their control library. But this is a really important concept, hyperautomation. And think about composable design concepts with modern technology like ServiceNow, right? You onboard a new asset, you immediately should be identifying what are the risks of that asset. It shouldn't be weeks later, when somebody gets a report, that we identify new assets that have been introduced in the environment and it's already in production. We should be ahead of that. We should be using this composable design concepts in order to make that happen. And the last one here in the process, progressive firms are reallocating capacity from what I would consider lower value tasks like manual control testing, right? You're using expensive resources that are highly skilled to perform control testing, for example, in a manual way. But really, these firms are thinking about how do we take -- how do we hyperautomate elements of control monitoring and then flip the script on the capacity in order to push those really skilled resources and costly resources to higher value subject matter expertise tasks or roles, right, essentially -- or especially in the second line where there's this very small population as we discussed earlier. And so these are some opportunities that we see to gain efficiency and effectiveness. And so I'm going to hand it over to Rawda here to pick up, talk about leveraging AI and automation.

Rawda Selim

executive
#12

Thank you, Michael. So just to follow up on what Michael just said, so how then does ServiceNow use AI, automation, GenAI specific, to help in those compliance challenges. So one thing is, we see growth or we see an opportunity, an opportunity to improve productivity, effectiveness, satisfaction with GenAI to enable risk and compliance teams to accelerate this journey, to integrate a risk management and deliver top line growth and bottom line improvements. For example, AI is poised to unleash the next wave of productivity, and GenAI is just the latest manifestation of this. And this impact will be felt across every industry, department, sector, role especially for risk and compliance teams. Getting a right AI strategy means you can unleash substantial productivity improvements. We've been seeing productivity improvements, efficiency, transforming the way employees and customers experience the view, the role of risk and compliance. And finally, making it more to utilize and accelerate your agility as a business to drive outcomes and stay ahead of the competition. Now I know it can be hard to separate hype from reality. Most of all, it's hard to know what to trust and what to listen to. And as you could see in the slide, we actually just give you a very simple example of what kind of feature functionality we will be coming up with to try to, let's say, manage or try to help the compliance, let's say, complexities and break it down into more easily digestible ways to be able to manage that and be able to, instead of looking at the rearview mirror, you're looking through the windshield like Michael was mentioning earlier. So one thing here is -- if I go to the next slide. This, for example, is a feature functionality that we came out with last -- this August, I'm sorry, 2024. This is mostly how AI-powered recommendations is used to map incoming regulatory changes and help organizations keep pace with the regulatory change. Michael mentioned earlier, you have about 100 alerts per day that comes from the regulatory changes that you see across your, let's say, horizon. And this is how, for example, the feature helps to reduce, for example, compliance risk and potentially hundreds of alerts daily that can be managed or compliance teams really struggle to map incoming changes to the internal environment, the subregulations, leading to delays. [indiscernible] to keep it up with an automated way to strengthen the mapping and the process, ensuring the timely identification and alignment of relevant regulations with the internal environment that I just said. This is where the AI-driven regulatory compliance mapping provides the ability to smartly identify the closest match within your internal environments and the incoming alerts, and that enables you to make informed decisions, associating AI and ML powered recommendations that increase your user engagement and improve time to resolve, improve time to address, addressing your impact assessments. So again, mostly taking those manual tasks outside of your first and second line and making them more specialized and giving them the time to actually do that what they are supposed to do within the day-to-day tasks. And that just allows you to move forward with the journey of compliance powered by AI, and compliance powered -- and how to manage the overall tasks and burdens within your daily activities. And finally, by 2025 Generative AI will account for about 10% of all data created, compared with less than 1% last year. And Michael, I will hand over to you, if you want to add anything to what I just mentioned or...

Michael Murphy

executive
#13

Thanks, Rawda, I do. Yes, in fact. This is just a small sample of -- because we're constrained by time -- a small sample of AI that we're delivering on. And you can imagine, as a firm that spends, I think last year we spent over $2 billion on research and development, we are the only GRC firm, and the only IRM firm that's digitizing the work side of the house, the first-line activities. And so -- if you think about where we want to go as a business, as a large business, we're really focused on GenAI. We're really focused on driving business outcomes with GenAI, for example. And so it gives us a unique opportunity to see both sides of the fence. And what I mean by that is -- unfortunately, I don't have the slide here, but this is a good follow-up conversation for us to have one-on-one after these -- after the webinar, we have -- we're obviously customer zero for the software that we create. And so our CIO function has in fact really beta tested and continues to be the ones that adopt the newest innovation that we have on our platform. And they have unleashed AI within our CIO function. And what I find really interesting is to be able to see in the GenAI outputs in the dashboard, the CIOs dashboard, is to be able to see what they would really be considering performance data, performance data from the perspective of like changes, change velocity, change failures, for example, or vulnerabilities and patches, things like that. They're looking at metrics from a performance indicator, but in the risk and compliance world, right, what we would often see is that there's an inverse relationship between performance indicators on the business side and risk indicators on the risk compliance side. And so as I look at the performance indicators, I am actually seeing really insightful data that's being gleaned through GenAI capabilities around technology risk that in fact we're not quite yet seeing through the traditional model of risk management using a GRC technology. So what this gives us as a firm is a unique opportunity to be able to say, all right, well, what I want to do is, I want to scrape the data from the dashboards of the CIO, the CHRO, the CISO and others in order to be able to pull that information in, evaluate where we see perhaps performance metrics on their side that are trending downward, and the KRIs that are trending upward. I want that relationship to be made. And it could inform ways that I may accelerate ideas and concepts around risk and compliance, right? Effectively, I'm skipping a few steps as the organization in the risk compliance world matures. I'm skipping a few steps because our business is moving so fast and using this technology, but now I can just take advantage of the information that they are supplying for themselves and use that for the role that I need to -- and I don't have an internal risk management role, but this is how I'm interacting with our teams in order to drive for sort of these new concepts. And so I think that's really important, is to really consider it's going to be difficult to identify where firms are -- your business partners might be using GenAI. But once you do, once you're able to do that, right, then we have a path backward to the models that they're using, right, which is going to be really important from a model risk management perspective. And also to be able to leverage that information or those insights that they're getting from their use of GenAI in order to accomplish sort of the two birds with one stone idea from a performance and a risk perspective. So I'm going to hop into -- the next section was around navigating with confidence. And a pretty simple slide here, but something that I really want to spend quite a bit of time on here. And this is from -- this is -- what we have here is, in effect, 3 insights that we found from what we call risk leaders. And this was performed, a survey that we did with a company called ThoughtLab last year. And we effectively created this survey because we couldn't find the data that we were really looking for relative to understanding risk and compliance more holistically and sort of the direction that firms are going or the industry is going. And so we separated them into tiers, right? We -- lower end, less mature organizations, sort of middle or medium tier, and then the high end tier, which is the people that are really forward-thinking around risk and compliance management. And so if you were to think about -- I've had, in fact, a CRO say to me, well, I'm not trying to be a risk leader, which I thought was kind of interesting. And I said, well, characterized in that way, I can perhaps understand why you might say that, but your whole -- sole purpose is to guide your business, right, and so business counterparts. And so I would say from that perspective, you do want to be a risk leader, because unless you're a risk leader, you're going to continue to manage the downside of risk. You're going to continue to look in the rearview mirror. You're going to continue to report the news rather than being on the leading edge of your business activities, right, understanding where you have room in your risk appetite to take additional risks. And this is the concepts that we're seeing in the risk leader space. And there are these 3 -- first 3 or the top 3, I would say, insights that we got from those results, which, by the way, was I think, 750 or so C-level executives or C-1s that we targeted, we had 50 CEOs reply and it was a range of institutions across the globe. We did a distribution that was about 250 people in the Americas, 250 in Europe and 250 in the APJ region. So we have a really good sample size that covers the globe, covers all different sizes of institutions. So the first that they came back with is that they're all striving for a single source of truth. Now I think -- Rawda and I, in fact, were having this conversation the other day about data lakes or lakehouses and some of these concepts. And they exist, but they have yet to prove, I think, at scale at least, that they are really valuable from a risk and compliance perspective. So this is one of those times if I was a creator, an influencer, I would say, hey, put it in the chat below, let me know if you disagree with me, that's maybe an opportunity for you to have some questions here, that we've included in this conversation here in just a few minutes. But I see that most firms are really thinking about how do we have a single source of truth from a risk and compliance perspective. Not necessarily a single source of truth from a business and performance perspective -- that's necessary, obviously, right, you've got to have a 360 view of your customer. That's really important, right? You can span across all businesses. They have lots of touch points in your company. So being able to understand your customer is really important. But what we often miss out on is, I think, from a technology investment perspective, is how do we do something for the business but also do something for the risk and compliance teams that are helping those businesses. And so the risk leaders are really focused on creating a single source of truth. And McKinsey says we're in this sort of -- data fabric is going to change this a little bit, so as GenAI moves forward and we have new concepts like Data Fabric, this is perhaps going to change what I'm about to say. But McKinsey was saying, within the last year, right, that we're in the learn and train mode for GenAI. And learn and train mode needs as -- it needs good data. Otherwise you're spending a lot of time learning and training, and you're not getting a lot of the outcomes that you'd want to get from that data. And so McKinsey has theorized that data products are the secret sauce for scaling AI. And they use, I think, an example around customers -- having that -- all that investment we've made in the 360 view of customers so that we know when they're touching a couple of lines of business, how we can upsell or cross-sell, for example, right, we might [ want to ] see where they have disappointment, we're able to perhaps improve service for them. But this is a really important concept for us to consider around risk and compliance as well, having a 360 view. And the data products should be at the lowest level in the organization. And I'll just tell you that ServiceNow has a concept called entity structures in our software. And people often go to this idea of entities being just a legal entity, but an entity is really just a thing. It's a person, place or thing. It's an object, if you will. And there's everything in your business, from a network router to a human being to a product, has regulatory obligations associated with it -- policy obligations, right, risks, controls, and can result in issues or losses. And so getting down to the lowest level in the organization in these data products is where you're going to start to see high value from GenAI in the future. Firms that are really thinking about structuring the data to that level so that GenAI can make quick use of that information in a very structured way. So you need to be able to see those assets and those activities and all the things that apply to them from a risk or compliance perspective. And as you think about ServiceNow as an enterprise platform for transformation, we're digitizing controls relative to change management or vulnerability management or onboarding your customers or we have a partnership with Visa around dispute management. We're digitizing the controls of these processes. For us, it's a natural opportunity to have on the same platform this single source of truth between the business activity and the risk compliance and control activity. We're digitizing the controls on the left-hand side, and we're able to use that information very quickly on the right-hand side. The second concept they're focused on is really integrated risk processes. And I think that most firms would -- given that GRC technology is catering to the second line or third line, that most firms are really thinking, and we saw this with the KPMG statistic around CROs that are investing. I think less than 10% are investing at least $5 million in helping integrate with the first line, right? That's a very tiny number, if I didn't say that earlier. But the leaders are really focused on what I would say is inter- and intra-line processes. They must both be reimagined in terms of outcomes to simplify and digitize. And so the leaders are thinking about first line, second line and third line, if they can all hop into the same train. Often it's first and second line, those are the two that need to be working the most closely together. Thinking about how they bring those teams together, within the first line, within the second line, and then across the first and second line. And if you think about concepts that we've talked about here around AI and operational resilience, this is so important. These things are moving so quickly that you have to have digitization that exists between first and second line in order to understand the risk and do something about it and then understand the incident or the event and do something about it. Those are going to be critical. Those gaps in time must shrink from identification to reaction. And then the last one is around end-to-end risk management. And I would say that operational resilience -- now we're going to -- what we're going to see is a wave of firms that have probably taken an MVP approach to operational resilience. They're going to have SharePoint sites and spreadsheets and all kinds of things that I would consider not within the realm of resilience in terms of a definition. But they're going to do it because, right, this is new, and they're going to see what they can effectively get away with. It's a very sound strategy, I think, from a compliance -- risk and compliance space, but regulators are going to go though and they're going to identify who the leaders are. And in fact, I would say that we've already found customers who use ServiceNow for operational resilience who have told us that they have realized that this is a competitive differentiation for them. And in fact, it hinders us because they've told us they won't be reference customers for us -- good problem for us to have, we'll sort through that. But the point is, is that operational resilience requires end-to-end risk management, and end-to-end risk management, as I mentioned earlier, requires really composable design concepts and hyperautomation concepts. You've got to be thinking about those 2 things to change the way you work, because we are at that inflection point. The future of risk management is continuous monitoring. If I recall from that Westpac article, they feel that the industry is stuck around the 40%, 40% of controls can be monitored. And Westpac is looking at something they feel they can confidently get to somewhere around 70%. And when you think about continuous monitoring, once you have that in place, you can automate compliance more. You can trigger assessments using these data products. You can -- you're obviously going to keep your RCSAs. You have to do something that tells the story at the highest level in the organization, but the industry's struggled to get down to process risk and control assessments. And through these data products and the concepts we have already built into our solutions and the digitization of the business, the processes on the left-hand side with the integrated risk management capabilities on the right-hand side, getting to a place where you can trigger risk assessments down to the process levels, down to the process owner, for example, down to the control owner, this is possible with us today. And this is the future of risk and compliance automation. This is how we get beyond all of the repetitiveness we see in each report that Thomson Reuters puts out every year around, right, not having the right skill sets in place, not having the capacity to do the job, always having an increase in regulatory compliance obligations. This is really what we need to think about. So we're going to hop over this last one. Just want to give you some information here relative to what we're trying to communicate and a little more for you to dive into post this conversation. We have a couple of videos and some things you can read on our latest release. As Rawda mentioned, right, the AI we have relative to regulations and controls is one in our newest release, and so I'd encourage you to go read up on that. And then we do want to have a little bit of time here for Q&A. So if we have any questions that have come up through the conversation today, we'd love to be able to address those. And then we'll save a few minutes here at the end for us to be able to close out with some future webinars or fireside chats that we have and some other events. So do we have any questions that have been queued up?

Rawda Selim

executive
#14

We have a couple.

Michael Murphy

executive
#15

Okay.

Rawda Selim

executive
#16

So let me read out the first one: so my business partners are using GenAI in various parts of the business. Do you see other firms using GenAI from a risk or compliance perspective yet?

Michael Murphy

executive
#17

Yes. This is a good one. I mean, I think what I'm hearing is from firms is we know our businesses are using GenAI, which the question acknowledges. They don't have a full handle on how they're using or where they're using GenAI. I think that's just -- that's the condition of the industry at the moment. And I am seeing some, I'd say, pretty successful elements of AI taking place in what I would say is more of the structured elements of risk and compliance. So like if you think about in the credit risk side of the house, being able to leverage information that is -- that allows you to have boundaries, for example, within your boundaries and limits, for example, those sorts of things are fairly easy for us to adopt GenAI capabilities in. But when you get down to the operational side of the house, the operational risk elements, those are historically always been really difficult for firms to manage. And you think about, as resilience -- operational resilience is an outcome of what I would say is good or proper operational risk management, having the fragmentation that sits within operational risk teams in terms of documenting business processes in a BPM tool that's disconnected from a GRC tool or, right, needs to be stitched together through human middleware, those become -- it becomes a lot harder for us to deploy, at the current time, deploy those capabilities around AI in that space. But as we're seeing from that survey, leaders are really thinking differently and thinking about how they can create these concepts through things like data products.

Rawda Selim

executive
#18

That is quite correct, especially from an operational [ learnings ] perspective, as you said, Michael. Especially from the operations side, it is forcing leaders or it's making a lot of leaders rethink their strategy about how do they discover, how do they monitor, how do they capture the data points to enable them to automate, because that human middleware is not going to be working for them too long. It's not going to be a sustainable solution as we go into the next years and how to be more competitive. So yes, that is quite correct. The other question that we have: with firms having presence in multiple jurisdictions and having to comply with multiple regulations, how can technology, namely ServiceNow, help in streamlining or harmonizing compliance across these geographies?

Michael Murphy

executive
#19

How much time do we have left? That's a big question. I think maybe a couple of ways that I'm seeing this happen. And I'll talk through the lens of ServiceNow obviously, but -- so there's a couple of ways that we're trying to do this, assist with this idea of efficiency and effectiveness from a regulatory harmonization perspective. So the first is like being able to really, again, going back to this entity structure, entity models that we have in our integrated risk management solution that allow you to get down to the data product level, which is, again, what McKinsey says is the secret sauce to scaling AI. We have this concept of being able to assign at a top level -- a set of controls at a top level and cascade down. And so for example, right, you might have a regulatory obligation around change management that needs to be associated with your internal policies and procedures around change management, right? You must ensure that you're doing the things internally that are expected of your regulators externally. And then those cascade down into the data products that apply to change management, for example. And so this allows you to say, well, I might have, I don't know, some firms have a dozen change management -- major change management processes across the organization. They might have one for crown jewels, they might have one for P1 assets, whatever, different dev environments. And so being able to cascade that down, right, to each one of those change management data products allows us then to have what I would say is the digital connections to be able to go back up the stack. So I've described it down -- coming down the stack from regulation to policy, down to the data product, down to the actual activity. But then you think about what we're trying to do from either a monitoring, continuous monitoring and testing perspective, which is going back up the stack. And so this allows us, right, to get to a place where when we have those digital connections between all of these things, with data products and otherwise called entities for us sitting at the center, then we can come back to this concept of testing once, complying many times, and being able to see compliance scoring relative to that across each of the data products. That's really important. The second thing that I'm seeing is we're investing in partnerships. We recently released or entered a partnership and released content from Cyber Risk Institute. And Cyber Risk Institute is U.S.-based nonprofit. It was originally formed in the government, the U.S. government, but is a nonprofit now. And they effectively are looking at how do you take and then -- they've got great content, I encourage you go read up on our ServiceNow docs site about this. But they're effectively taking things like NIST and NISO, the foundations we would see across most organizations, and to be able to then harmonize those, what I would say is global standards, down to financial services-specific regulatory obligations. And so again, concept of sort of test once, comply many times, we're doing that additionally by providing content, in this case, through Cyber Risk Institute.

Rawda Selim

executive
#20

So just to highlight as well, just to add another point. So from a -- so I -- we mentioned that in a couple of slides before, about how -- from a technology perspective, we do see that there is a shift in how compliance, operational resilience, discovery of elements or how infrastructure needs to be linked from the lowest part of the organization to the process to the service to all of that. So one of the things is just like AI helps you harmonize, or just, for example, if there's any kind of regulation that comes in, they would, for example, one of the AI capabilities is trying to map or trying to elevate the manual task is taking away some of the time that you spend reading the regulation than reading your internal controls or your internal policies and trying just to understand, are they repeated? Do I have the controls that cover this regulation? Do I not? For example, Michael, you mentioned change management. Change management, I think, is a staple across a lot of operational resilience regulations. So one of the things that we see maybe as a low-hanging fruit is, from a GenAI to an AI capability is, it will read whatever operational resilience regulation out there and it will tell you: by the way, your internal environment, 90% complies with this regulation, you just need to add another 10% on top. So that's also part of how we see GenAI, AI changing this whole compliance discourse that is going on plus the risk, because if you're good on compliance, then you're mitigating your residual risk, so you're able to have a risk appetite, be able to do the R&D, be more competitive within the market and so on and so forth. So we do have a final question.

Michael Murphy

executive
#21

Okay.

Rawda Selim

executive
#22

"The general consensus in my company is that most people are unhappy with our current GRC tool," ooh, "but politics keep it in place." Very saucy question, that one. "What is your advice on how to navigate the introduction of modern GRC solutions?"

Michael Murphy

executive
#23

This is a difficult one. I think that if you spend 20 or 25 years in the banking world, you'll probably only go through -- probably only replace a GRC system perhaps twice. And it's just one of those things that is so deeply entrenched in an organization that switching to something else despite how you feel about the current solution becomes very problematic and very, very costly for most firms, right? And that's the way they view it. And so they generally just make do and have lots of end-user compute tools that supplement the gaps that are in their GRC technology. I'm sure that what I'm saying is -- people are shaking their heads up and down -- but what I see as an opportunity is like there's very few organizations that come to us and say, hey, we're going to -- we want to rip out whatever we have and put in ServiceNow. Some do. But most of the ones that I'm seeing that have this sort of political component to keeping it, they're looking at ServiceNow at -- as sort of picking off use cases. So maybe there's something that the current technology you have doesn't do and you're making up for that gap in -- and using compute tools. Maybe it's a program -- individual program you created or it's in Excel, right, and doing manipulation in Excel. And so that's a good opportunity to introduce the idea of can we do a proof of concept around a use case that we are not currently covering in a way that we should that's really inefficient and perhaps ineffective. And/or another opportunity is, look, we have this use case in our current system, but the use case isn't providing us the results we need. It's not generating the outcomes we need. And so this is another opportunity for us to think about just, at the use case level, how can we drive some change. And I think what you'll find with ServiceNow is what I call the workflow, the big W, is about uniting the people and the teams across the lines of business. And so that's where we really shine, and ideally what we have is a situation where we can showcase that, right? We can showcase how we can integrate with your current GRC system. We can showcase how we bring first and second and even third line together on our platform and do that in a way that is much more efficient, much more effective perhaps than the way you do it today. So I would encourage you to take us up on that offer. If you have a use case out there that's just really problematic and you're in a situation where you can't displace the GRC solution just yet, you need to gain some momentum, the use case level and building our way up the momentum up the stack is a way to do that. I think that's the all the time we have for the session today. I've got a couple of slides to cover at the end here. And so I'll close this out here. Rawda, thanks for joining me today. I really appreciate it. It's been great to work with you on this. But we have a fireside chat coming up this -- next month, in fact, a little over 3 weeks away, that's going to feature Dave Wright and our Deputy CISO, Jeff DiMuro. And we'd love for you to join us. We think that this is very closely in line with the conversation we've had today, and this is going to be around cybersecurity resilience and resilience in the world of AI. So it's a similar topic, but you're going to hear from people that are on the leading edge in our firm, inside ServiceNow, on AI and cybersecurity. On-demand webinars, we have a link here for this, and I think you have access to this information. So I'd really appreciate it if you guys take a look at that. We've got a couple of world forums that are -- they're coming up next month as well, November 7 in New York and the 13th in Toronto. You have a QR code there. If you click on the QR code you'll get more information. And that's going to close us out for the day with 1 minute to spare. So we're going to give you 1 minute back in your life. You'll have just enough time for perhaps a bathroom break before your next meeting starts. Appreciate your time today. Thank you very much for joining us. You can always find Rawda and I on LinkedIn, or reach out to somebody you know in ServiceNow. Happy to have follow-up conversations from anything you heard today or start a new conversation. Thanks so much. Enjoy the rest of your day.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete ServiceNow, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to ServiceNow, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.