The Advanced Risk application helps you manage risks on both the proactive and reactive sides of risk management. On the proactive side, use Advanced Risk Assessment to assess your organization's risk posture. On the reactive side, use Risk Events to capture operational losses, near misses, and events with non-financial impact, so you can learn from them and prevent similar losses in the future.
Advanced Risk Assessments
Use Advanced Risk Assessments to manage your organization's risk assessment needs on an integrated platform. This application helps you do the following:
- Configure multiple types of risk assessments in a single application. Perform top-down or bottom-up risk assessments by defining assessment template criteria, such as risk factors, scoring logic, rating criteria, and reporting preferences, to create an integrated risk platform.
- Perform comprehensive risk and control assessments in a guided workflow, including inherent risk, mitigating controls, residual risk, and target risk rating.
- Connect risk silos and perform risk assessments in near real time by automating risk assessment responses.
- Reduce barriers to risk management and make risk-driven decisions by integrating risk assessments into any ServiceNow record type using object-based risk assessments.
- Tailor assessments to different levels of risk maturity within your organization by determining whether a risk must be analyzed qualitatively (using a numerical scale), quantitatively, or both.
- Reduce the need to follow the software development life cycle when deploying risk assessment templates.
- Configure multi-level, dynamic risk approval workflows to digitize the risk review process and confirm that all required stakeholders have approved.
- Manage and schedule risk assessments at scale by scoping entities and defining assessment intervals using the Risk Assessment Scheduler.
- Manage a risk assessment program for a specific entity by initiating periodic risk assessments.
- Automate reporting by aggregating risks across multi-level risk statement hierarchies, entity hierarchies, or both, and pivot between them. Compare rolled-up risk scores using functions such as worst case, best case, average, or sum.
- Analyze risk trends and monitor risk using integrated reports and dashboards.
Risk Assessment Project
- Perform bulk assessments on multiple risks and controls at the same time.
- Set up the context of an assessment project with a name, risk assessment methodology (RAM), and other relevant information.
- Scope multiple risks to evaluate as part of the assessment project.
- Move between stages of a risk assessment in a focused UI, without switching between screens.
- Review assessment results in an assessment summary for quick review and informed decision-making.
- Improve the accuracy and reliability of assessment projects with error handling and a validation framework.
- Configure dynamic approvals for risk assessment projects using the approval configurator.
Risk Assessment Project in Grid Mode
- Rapidly compare, edit, and prioritize risks and controls in a flexible, spreadsheet-style risk and control self-assessment (RCSA) designed for power users.
- Assess risks quickly with bulk editing, side-by-side comparison, and improved risk prioritization.
- Use the traditional RCSA if you prefer a focused, methodical approach that assesses one risk at a time.
Risk Appetite
Define the amount of risk that your organization is willing to take to achieve its strategic objectives, and set acceptable boundaries in a digitized workflow. This feature helps you do the following:
- Tailor and configure the risk appetite framework based on your organization's needs and maturity.
- Manage the complete risk appetite lifecycle, including qualitative risk appetite statements, amber and red thresholds for qualitative ratings, and loss expectancy. Link risk appetite to the risk taxonomy for easier monitoring and compliance.
- Digitize the risk appetite breach management workflow so that follow-up actions continue after a breach until the risk returns within defined levels.
- Focus on risks that are outside appetite and need management attention using the risk appetite visual status.
Risk Identification
Collect information from the front lines using a simple questionnaire to identify, map, and manage your risks, policies, and regulations. This feature helps you do the following:
- Configure workflow stages to meet your organization's needs.
- Ask relevant questions by creating a unique questionnaire for each entity in your organization.
Risk Events
Risk events are financial or non-financial losses, gains, or near misses that occur during regular operations and have a material impact on organizational risk. This feature helps you do the following:
- Capture all types of risk events, such as near misses and actual losses, with financial and non-financial impact.
- Create risk events from other ServiceNow applications, such as Incident Management and Case Management, or through a simplified interface that any employee can use to report risk events.
- Manage the complete risk event lifecycle: configure approval rule thresholds, perform root cause analysis, and identify remediation plans to prevent future losses.
- Associate risk events with citations, risks, and controls, and use them to drive quantitative risk assessments and identify control deficiencies.
- View prepackaged dashboards and reports that aggregate and analyze loss trends by department, loss type, and source.
- View prepackaged Basel dashboards with standard regulatory reports (for financial organizations).
- Manage external risk events with the Operational Risk data eXchange (ORX) integration (for financial organizations).
[New]
This release adds a GRC Advisor configuration for the Risk and Risk Event tables, which enables correctness and suggestion capabilities on records in these tables. The configuration is available with the Innovation Lab release of the Data Quality Optimization for Governance, Risk, and Compliance application and applies only when that application is installed.
The following applications are installed automatically when you activate the Advanced Risk application:
- GRC: Risk Management (com.sn_risk)
- GRC: Advanced Risk Assessment (com.sn_risk_assessment)
Required role
Role required to install the application: System Administrator (admin)
Upgrades
Before you upgrade the Advanced Risk application, upgrade Risk Management Workspace and any other installed GRC applications to the same major release version. For example, Advanced Risk version 14.x is certified to work with Risk Management Workspace version 14.x and other GRC applications version 14.x.