---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Review responses and perform inherent risk assessment

# Review responses and perform inherent risk assessment {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Compute the overall risk score for an application by performing an advanced risk
assessment. After the IT application owner responds to the questionnaire, a risk manager
reviews the responses and performs the inherent assessment.

## Before you begin

Role required: sn_risk.manager

## About this task

After the risk assessor returns the assessment questionnaire, you can review the questionnaire as the risk manager. Based on your review, you can initiate a risk assessment for the application.

The risk assessment
task is initiated to the group responsible for performing the assessment. The task
is available in My Group Tasks. Any risk manager who is a
part of the group can perform the assessment. The assessors usually don't
vary.  
You can choose to use either the manual factors or the automated factors. By default, there are three manual factors which are associated to a risk assessment methodology. There are also three automated factors which are not associated to any risk assessment methodology. The names of the factors are:

* Confidentiality Impact
* Integrity Impact
* Availability Impact
{#review-responses-to-apm-risk-assmt__ul_zz2_fcj_1nb}

Some of the factors or questions on the risk assessment instance might
already have an answer or a response. These values are derived from the responses of
the application owner. You can view how the value was calculated.

## Procedure

1. Navigate to AllAdvanced Risk AssessmentRisk IdentificationAll.
2. Open the record with the assessment that you must review.
3. In the Questionnaires related list, click View responses for the required assessment.
   1. If you are not satisfied with the responses provided in the questionnaire, click Reject Questionnaire.  
      The respondent receives an email and is asked to resubmit the questionnaire.
   2. If you're satisfied with the responses provided by the application owner, then perform the inherent assessment by clicking Perform Inherent Assessment.  
      The risk assessment instance link is created.

   {#review-responses-to-apm-risk-assmt__substeps_kml_k2p_smb}  
   To understand the risk assessment process and how to respond to questions, refer to [Understanding the risk assessment instance](https://servicenow-prod.fluidtopics.net/jUoKAV2QYvBNbNOleY_eCA "A risk assessment instance is where a risk assessor can assess risks and objects by responding to questions or factors.").
4. Click the risk assessment instance link that is generated.
5. Respond to the questions or manual factors.
6. Right-click and save the form.
7. Click Request Approval.

## Result

The approver selected in the Risk Identification Configuration form can review the inherent assessment. The state on the Risk Identification form is moved to the Risk Mapping state.

## What to do next

[Associate risks, citations, policies, and controls with a risk identification record](https://servicenow-prod.fluidtopics.net/Imv~4ZFPClOrnFXXJrAKEQ "After the inherent assessment is completed, you can associate risks, citations, policies, and controls with the risk identification record. You can identify what methods to use to mitigate the risks.").

*[\>]: and then


