---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk hierarchy and scoring

# Risk hierarchy and scoring {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Starting with New York, risk managers can create hierarchies that include different
types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are
assessed, the risk scores are automatically rolled up across the risk statement hierarchy,
providing better tactical and strategic decision-making.

## Risk Hierarchy {#risk-hierarchy-scoring__section_lym_k5g_f3b}

Risk managers and administrators create and view hierarchies on the risk statement form:

* Define a parent risk statement using the Parent field
* Add children risk statements using the Risk Statements related list

{#risk-hierarchy-scoring__ul_c3z_44h_33b}  
Note:  
Risk users can view the hierarchies established by the managers and administrators.

Depending on the risk areas, different people in the organization own and manage their own
risks. However, top-level risk scores take into account the score of all the risks below
it. Therefore, managing all the different risk areas in a central location provides an
integrated view of your organizations total risk posture.  
Figure 1. Hierarchical risk taxonomy showing integrated view of risk

## Translate quantitative risk scores to qualitative values {#risk-hierarchy-scoring__section_wsl_ybj_33b}

The Tolerance Status and the Calculated Score are based on the Calculated Annual Loss Expectancy (ALE) of the underlying risks:

* Sum of calculated ALE
* Average calculated ALE
* Maximum calculated ALE
* Minimum calculated ALE

{#risk-hierarchy-scoring__ul_onc_ycj_33b}  
Note:  
Only risks in the Monitor state can contribute to the risk statement scores.
Figure 2. Risk Rollup and Tolerance tab
* **[Association of entities at any level of a risk statement](https://servicenow-prod.fluidtopics.net/7LybDQTyucrEIXShpUbsQw)**   
  You can associate entities, entity types, and indicator templates, at any level of the risk statement hierarchy. Creating this association is useful for risk managers while assessing risks.

**Related concepts**   

* [Workflow of a risk using Advanced Risk](https://servicenow-prod.fluidtopics.net/CqUDOs~n8UXcMTMSieMBnw "When you migrate to advanced risk assessment, you can view the various states of the risks take the necessary actions. This ability simplifies your view of the risk form.")
* [Manage risks linked to the same risk statement](https://servicenow-prod.fluidtopics.net/~JPDXj4ItpERMVu1nuw9~A "You can create and associate multiple risks to the same risk statement and entity combination. This association benefits the risk managers and the entity owners.")

