---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk assessment project workflow

# Workflow of risk assessment project in AI Risk and Compliance {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The risk assessment project workflow is a structured process to assess multiple risks and controls of an AI asset simultaneously.

## Exploring the user journey for AI asset risk assessment projects {#workflow-of-risk-assessment-project-airc__section_ykm_wrc_jhc}

The stages of a risk assessment project are as follows:

1. Define: In this stage, the risk assessment project is created. Users with sn_risk_advanced.risk_asmt_project_user can create a risk assessment project and complete the following tasks:
   1. Define the related assessable entity and the risk assessment methodology (RAM).
   2. Specify the project name and description.
   3. Identify and add the relevant stakeholders, including the risk assessment project owner, assessors, and watchlist users.
   {#workflow-of-risk-assessment-project-airc__ol_u5g_1x3_2dc}
2. Risk scoping: In this stage, the risk assessment project owner is responsible for defining the risks to be assessed. The following options are available to map risks for the selected composite or single entity:

   Create risk from risk statements
   :   Option to add risks from the risk statement.

   Create ad-hoc risk
   :   Option to add a risk that is not in the library.

   Add risk
   :   Option to create risks from the internal risk library.
3. Assessment: In this stage, the assessor evaluates each scoped risk using the defined RAM. Throughout the assessment, the assessor can access a summary of the assessment. Automated error handling enables assessors to validate risk assessment projects, reducing the likelihood of errors and inconsistencies. After the assessment is completed, the assessor submits the assessment for approval. Assessors can also add risks during the assessment stage.  
   Note:  
   If any risk assessment has a High inherent rating, the approval is sent to the risk assessment project owner. If the project owner and assessor are the same user, the approval is skipped. To use this approval flow, you must activate the default approval configuration 'Bulk risk assessment approval config.'
4. Approval: In this stage, the approvers configured in the approval configurator review the assessment summary. Based on the approvers' satisfaction with the assessment, the approver can do one of the following:

   Approve
   :   The project moves to the Completed stage.

   Reject
   :   The project moves to the Assessment stage for the assessor to address identified issues and make necessary revisions.

{#workflow-of-risk-assessment-project-airc__ol_qs3_xrc_jhc}  
Note:  
After the project reaches the Completed state, you can create a new project with the same RAM and entity. When the new project reaches the Completed state, the old project moves to the Archived state.
**Related concepts**   

* [Risk assessment project in AI Risk and Compliance](https://servicenow-prod.fluidtopics.net/5V2PrO7aqIBibVxX0bZQnw "You can perform assessments on multiple risks and controls simultaneously by creating a risk assessment project for an AI asset. This feature enables assessors to review multiple risks to understand their potential impact, likelihood, and associated mitigation strategies.")  
**Related tasks**   

* [Create bulk risk assessment](https://servicenow-prod.fluidtopics.net/yJSyiJhz3WbWQ1d62LT6iQ "Create a bulk risk assessment project to perform assessments on multiple risks and controls simultaneously using the AI Risk and Compliance workspace. You can define the project context, including the assessable entity, Risk assessment methodology (RAM), project name, description, and identify and add stakeholders.")
* [Perform bulk assessment in stacked view](https://servicenow-prod.fluidtopics.net/eZPIIjCMO7kadtCeGYLvhQ "Perform assessments on multiple risks and controls simultaneously in a risk assessment project using AI Risk and Compliance Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.")
* [Perform bulk assessment in grid view](https://servicenow-prod.fluidtopics.net/qpTItEslOoaWriCGBs6swQ "Perform assessments on multiple risks and controls simultaneously in a risk assessment project in the grid view using AI Risk and Compliance Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.")

