Exploring Risk Management
Summarize
Summary of Exploring Risk Management
The Risk Management product in ServiceNow offers a centralized, structured process to identify, assess, respond to, and continuously monitor enterprise and IT risks that could adversely affect business operations. It supports collaboration across organizational roles such as audit committees, IT steering committees, risk officers, and management at all levels. The solution enables organizations to establish risk tolerance levels, develop policies and procedures, implement risk controls, and measure risk exposure and improvements on an ongoing basis.
Show less
Key Features
- Risk Frameworks and Statements: Organize risks into manageable categories using risk frameworks and statements stored in a centralized risk library and register.
- Risk Events Management: Track potential or actual financial and non-financial losses, near-misses, and gains within the organization.
- Risk Hierarchy and Scoring: Build risk hierarchies (operational, IT, strategic) with automated roll-up of risk scores to support tactical and strategic decision-making.
- Classic and Advanced Risk Assessments: Create and manage risk assessments using the Risk Assessment Designer and question bank for streamlined evidence gathering; advanced assessments enable integration of various methodologies into decision-making.
- Policy Exceptions and Extensions: Manage temporary relief requests for non-compliant controls, involving control owners, compliance managers, and risk managers in approval workflows.
- Entity and Risk Dependencies: Use the GRC Workbench with CMDB data to visualize dependencies and ensure consistent risk mapping across applications.
- Risk and Control Indicators: Facilitate continuous monitoring by defining indicators with automatic or manual data collection, linking results to issues, risk scores, audits, and control tests.
- Risk Issues and Remediation: Document audit observations, remediation efforts, or accept issues manually or automatically generated from indicator and assessment results.
- Continuous Monitoring Integration: Integrate Risk Management with Security Operations Vulnerability Response to quickly identify high-impact vulnerabilities based on business impact.
- Analytics and Reporting: Access preconfigured Performance Analytics dashboards with actionable visualizations to support process improvements.
Practical Benefits for ServiceNow Customers
By leveraging this Risk Management solution, organizations can establish a unified, repeatable risk process that spans multiple departments and risk types. Customers can expect improved visibility into risk exposure, enhanced ability to prioritize and respond to risks, and stronger alignment between risk management and business objectives. The integration capabilities and advanced assessment tools also enable more informed decision-making and efficient compliance management. Continuous monitoring and analytics further support proactive risk mitigation and ongoing performance evaluation.
The Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.
Request apps on the Store
Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.
Who uses Risk Management
The complete risk process involves all areas of your organization working together.
- Audit committee
- IT steering committee
- Risk officers (conduct risk assessment and identify all that can go wrong in business)
- All levels of management (assist the risk officers with the identification of what can go wrong in their processes)
Key activities for Risk Management
- Determine what level of risk the organization is willing to accept? Get risk data in place and then determine what is acceptable.
- Develop a risk management policy, through risk frameworks and risk statements.
- Develop risk assessment and response procedures.
- Implement controls to reduce your organization's exposure to risk. Repeat on a regular interval.
- Measure your risk exposure and improvements.
Risk Management and the ServiceNow AI Platform
- Manage risks, risk statements, and risk frameworks: The risk library contains all risk frameworks and risk statements. Risk frameworks are used to group risk statements into manageable categories, while risk statements group the individual risks. The risk register is the central repository for all potential risks that could occur at any time, anywhere in the organization.
- Manage risk events: Risk events are potential or actual financial and non-financial losses, near-misses, and gains that occur within an organization.
- Risk hierarchy and scoring: Starting with New York, risk managers can create hierarchies that include different types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are assessed, the risk scores are automatically rolled up across the risk statement hierarchy, providing better tactical and strategic decision-making.
- Manage classic risk assessments: Risk assessments are surveys that gather evidence to determine risk. The Risk Assessment Designer provides a single interface that users can use to create, and edit attestations, as well as change scoring parameters. The question bank offers a library of questions for various categories, so you do not have to build each questionnaire from scratch. Risks start in a Draft state then move to Assess, which sends a notification to the Assessment respondents.
- Manage Advanced Risk Assessments: With Advanced Risk Assessment, create an integrated risk platform. This integrated platform supports various kinds of risk assessment methodologies and enables you to integrate risk assessment as a part of your overall decision-making process.
- Manage policy exceptions and extensions: Policy exceptions and extensions provide temporary relief for a non-compliant control. The policy exception captures the rationale, comments, and evidence to support the acceptance or rejection of a policy exception request. Also, extension to an approved policy exception can be requested before the policy exception validity period. The control owner, the compliance manager, and the risk manager may be involved in the policy exception and extension workflow.
- Use entity and risk dependencies using the GRC: Workbench: The GRC: Workbench utilizes CMDB information to show the upstream and downstream relationships across all applications. These relationships enable consistent risk mapping and modeling across the enterprise.
- Risk indicators, control indicators, and indicator templates: Continuous monitoring involves activities related to identifying and creating key risk and control indicators. Supporting information can be collected for those indicators through automatic data collection or manual tasks. Indicator results are then used to create issues for controls, update risk scores, and provide supporting information for audit activities and control testings.
- Manage risk issues and remediation: Issues can be created manually to document audit observations, remediations, or to accept any problems. They are automatically generated from indicator results, attestation results, or control test effectiveness.
- Manage continuous monitoring for risks between Risk Management and Vulnerability Response: Continuous monitoring for risks is a feature integration between the GRC: Risk Management and the Security Operations Vulnerability Response products, which uses indicators to quickly identify high impact vulnerabilities based on business impact.
- Analytics and reporting solutions for Risk Management: Performance Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.