Advanced Risk Assessments in the Risk Workspace

  • Release version: Xanadu
  • Updated August 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Advanced Risk Assessments in the Risk Workspace

    The Risk Workspace in ServiceNow provides an enhanced and simplified user experience for performing Advanced Risk Assessments. It allows operational risk managers and assessors to quickly access and manage their assigned risk assessments through the GRC Risk Portal or directly within the Risk Workspace. This workspace offers a more intuitive interface with comprehensive data readily available to support effective risk assessment activities.

    Show full answer Show less

    Key Features

    • Risk Assessment Methodology Filter: On the home page, users can filter risk assessments by methodology, such as operational risk assessments, enabling targeted reviews aligned with organizational frameworks.
    • Contextual Side Panel: Provides explanatory content and training on assessment sections to help new users understand the process. This panel is configurable, allowing you to display your own training materials or close it when not needed.
    • Risk Assessment Home Page Summary: Displays essential details including the entity under assessment, due dates, assigned users, approvers, risk descriptions, assessment results, and selected risk response strategies at a glance.
    • Reference Information for Risks and Controls: The contextual side panel shows interactive graphical data such as:
      • Risk events graph displaying gross and net loss aggregates and forecasts.
      • Quarterly percentages of key indicator breaches.
      • Control indicator failure rates and control test results.
      • Number and severity of open issues, with quick creation of new issues via a plus icon.
    • Factor Guidance Display: Users can easily access guidance related to specific risk factors by clicking the “Show guidance” icon, streamlining understanding and response efforts.
    • Reassign Risk Assessments: If a risk assessment needs to be reassigned, users can do so from the home page. The reassignment feature includes viewing email addresses to avoid assignment errors when users share the same name.
    • View Factor Weighting: First line risk assessors can view qualitative weightings, qualitative scores, and quantitative scores for risk factors by clicking on “Overall rating,” providing transparency into scoring methodologies.

    Key Outcomes

    ServiceNow customers using the Risk Workspace for Advanced Risk Assessments can expect a streamlined process that improves efficiency and accuracy in risk evaluation. The workspace consolidates critical risk data and guidance, enabling faster, more informed decision-making. Enhanced reassignment controls reduce errors, while configurable training support accelerates user onboarding and proficiency. Overall, these improvements empower organizations to better manage and respond to operational risks within a user-friendly environment.

    The Risk Workspace offers an enhanced and a simplified user experience for users to perform Advanced Risk Assessments. You can quickly access the risk assessments assigned to you or your group from the GRC Risk Portal or the Risk Workspace.

    With the new Risk Workspace, your risk assessments are more intuitive with more data readily available for you to refer for every assessment that you perform in the risk assessment instance. As an operational risk manager, when you use Advanced Risk Assessments, on the Home page, in the Risk Summary field,you have a filter available to select your risk assessment methodology. For example, you can select the risk assessment methodology that shows you the operational risks assessed. For more information on risk assessment methodologies, see Advanced Risk Assessment.

    For a new user to understand risk assessments, a Contextual side panel is provided with an explanation about the assessment sections. While a default explanation and a brief training are provided, you can also configure the system to show your training content related to risk assessments. If you do not want to keep the side panel training information open, you can also close it using the information icon.

    At a glance, the risk assessment home page shows you the entity being assessed, the due date for the assessment, the person the assessment is assigned to, the approver, and the risk description. The home page also shows the results of the risk assessment and the selected risk response strategies.
    Figure 1. Risk assessment home page
    Risk assessment home page

    Some of the major enhancements for Advanced Risk Assessments in the Risk Workspace are as follows:

    View reference information for associated risks and controls

    The Contextual side panel shows the reference information for associated risks and controls. The graphical representations can be clicked to get detailed information about the risk events, issues, indicator breaches and so on. The reference information shows the following:
    • Risk events graph that displays the gross loss and the net loss of the aggregated risk events for that particular risk. This graph also displays the forecasts of the losses.
    • Percentage of key indicator breaches for every quarter.
    • Percentage of control indicator failure graph. When performing a control assessment, you can refer to the control test results, indicator failures, and so on
    • Number of open issues with their severity. You can also create issues by clicking the plus icon.
    Figure 2. Reference information for Advanced Risk Assessment
    Additional information for Advanced Risk Assessment.

    View factor guidance

    In the workspace, while responding to factors, you can quickly view the guidance by clicking the Show guidance icon Show guidance.. This ability saves your time as you can view the guidance and understand the factor while responding.

    Reassign assessments

    If you are assigned a risk assessment that must be assessed by another user, you can reassign the assessment from the risk assessment home page. In case there are two users with the same name, you have the ability to view their email addresses while reassigning the assessment. This ability prevents users from assigning the assessment to the wrong users.Reassign assessment to another user.

    View factor weighting information

    As a first line risk assessor, you may need to view the qualitative weight, the qualitative score, and the quantitative score of a factor. You can easily access this information by clicking Overall rating.