UpGuard connects to ServiceNow across the whole platform. Vendor risk findings, breach alerts, and user risk signals all land in the same ticket queue your team already works from, not a separate, siloed risk dashboard.
With this integration, you can:
Risk Automations makes this possible. You define the events that matter: a monitored vendor picks up a new risk, a risk score drops below a threshold you set, a credential breach turns up on a watched domain, or a questionnaire response comes in.
UpGuard Risk Automations includes pre-built automations that power actions across your risk ecosystem, including ServiceNow. Here’s how two of them work.
The moment a new risk surfaces for a monitored vendor, this template triages the finding and opens a ServiceNow ticket with remediation instructions already attached. Whoever picks up the ticket isn't starting from a blank screen.
When a vendor's score drops below the threshold you've set, this template opens a ServiceNow ticket with an AI-generated summary of what changed and suggested next steps, instead of a bare notification that sends your team back into UpGuard to investigate.
Both are ready to configure in Risk Automations now.
Risk Automations runs on a configurable, flexible automation engine, with these two templates serving as a starting point. Here are five more use cases teams have built on top of them.
A new onboarding request triggers this template the moment someone submits it. Risk Automations assigns a risk tier, begins monitoring, opens a ServiceNow ticket, and notifies the internal owner and vendor contact, all before the security questionnaire goes out. The onboarding is already moving by the time your team sees it.
It works in reverse too: a vendor intake submitted in ServiceNow can be the trigger instead. UpGuard adds the vendor, starts monitoring, and automatically sends the questionnaire. Whichever direction triggers it, the ticket is stamped. The vendor addition and questionnaire completion both appear there, so the status is visible when cross-checking both platforms.
When the questionnaire comes back, the automation can branch based on the results. For an approved vendor, the automation attaches its reports directly to the ticket, and one that falls short opens a separate ticket for manual review instead of quietly closing it out.
For the full step-by-step breakdown of this template, see our roundup of Risk Automations templates for Vendor and User Risk.
Not every event that matters shows up as a risk score. A questionnaire response comes back with a concerning answer. A remediation deadline passes without an update. Events like these can automatically open a ServiceNow ticket, routed to the right queue, instead of waiting for someone to spot it in UpGuard first.
Only vulnerabilities on flagged domains and assets need a ticket. This template opens a ServiceNow incident only for vulnerabilities on the domains and assets a team has flagged as in scope. The automation runs an AI assessment on each one first, checking exploitability and exposure, then comparing the vendor’s historical posture. By the time the incident lands in the queue, it already carries a severity rating (high, medium, or low) and a recommended action.
When UpGuard flags a monitored domain in a credential breach, an automation filters for breaches that exposed passwords and emails, then prompts a password reset. This is the same handoff as a vendor risk triage, but triggered by a breach risk or user risk signal rather than a vendor score.
A vendor's score can shift overnight, a new finding can surface without warning, and remediation can wrap up before anyone thinks to check back on it. Each of those changes updates the vendor record in ServiceNow, too, so the information your team works from during triage isn't a snapshot from when someone last updated it by hand.
Risk Automations runs as a standalone add-on, alongside Vendor Risk, Breach Risk, or User Risk. Start a free trial to see it running with your own ServiceNow.