The ServiceNow® Risk Management application within Integrated Risk Management (IRM) provides a centralized process to identify, assess, respond to, and continuously monitor enterprise/IT risks that may negatively impact business operations. The application provides structured workflows to manage risk assessments, risk indicators, and risk issues.
The Risk Management application includes the following features:
- Scoping - entities and entity types
- Risk library - risk frameworks and risk statements
- Risk register - risk creation and management
- Risk assessments
- Risk treatment - accept, mitigate, transfer, and avoid
- Risk monitoring - indicator templates and indicators
- Issue management
- Reports and dashboards
[New]
- Introduced entity-based access control for enhanced security on the following Risk Management tables: Risk, Risk Response Task, and Action Item.
[Changed]
- Updated field types for name and description on the Risk Statement and Risk tables from plain text to translatable text to support localization.
[Fixed]
- Improved performance on Risk Workspace home pages by adding indexes to the Risk table.
- Resolved an issue where role mappings appeared without the Business User Lite application; mappings now only show when the app is installed.
- Fixed an issue where the Assigned To field on the Action Item table became mandatory unexpectedly after sending it to the assignee.
- Addressed a limitation where only 15 assessments were shown on the My GRC Assessments page in the Employee Center.
- Fixed an issue where appetite values from the parent Risk Statement were not auto-populated before saving.
The following applications get installed automatically when the Risk Management application is activated:
- GRC: Profiles
- GRC: Approver Configurator
Permissions and roles
Role required to install the app: System admin (admin)
To upgrade the Risk Management application, make sure to upgrade the Risk Management Workspace and any other installed GRC applications to the equivalent release version. For example, version 15.x of Risk Management is certified to work with version 15.x of Risk Management Workspace and version 15.x of other GRC applications.