Exploring Risk Management

  • Release version: Yokohama
  • Updated January 30, 2025
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Exploring Risk Management

    The Risk Management product in ServiceNow provides a centralized framework to identify, assess, respond to, and continuously monitor enterprise and IT risks that could impact business operations. It supports structured workflows for managing risk assessments, indicators, and issues, helping organizations systematically reduce their risk exposure.

    Show full answer Show less

    Key Features

    • Risk Frameworks and Statements: Organize risks into manageable categories using risk frameworks and individual risk statements, stored centrally in a risk register.
    • Risk Events Management: Track potential or actual financial and non-financial losses, near-misses, and gains within the organization.
    • Risk Hierarchy and Scoring: Create hierarchical groupings of risks (operational, IT, strategic) with automatic roll-up of risk scores for better decision-making.
    • Classic Risk Assessments: Use the Risk Assessment Designer and question bank to create, edit, and distribute risk surveys efficiently.
    • Advanced Risk Assessments: Integrate multiple risk assessment methodologies into one platform, embedding risk assessment into overall decision-making.
    • Policy Exceptions and Extensions: Manage temporary relief requests for non-compliant controls, including approval workflows involving control owners, compliance managers, and risk managers.
    • GRC Workbench Integration: Leverage CMDB data to visualize upstream and downstream entity and risk dependencies, enabling consistent risk mapping across the enterprise.
    • Risk and Control Indicators: Continuously monitor risks using key indicators, supported by automatic or manual data collection, to update risk scores and generate audit evidence.
    • Risk Issues and Remediation: Document and manage audit observations, remediation plans, or accepted issues either manually or automatically from indicator and control results.
    • Integration with Vulnerability Response: Enhance continuous risk monitoring by linking with Security Operations Vulnerability Response to identify high-impact vulnerabilities aligned with business impact.
    • Analytics and Reporting: Utilize preconfigured Performance Analytics dashboards offering actionable data visualizations to improve risk management processes.

    Practical Use for ServiceNow Customers

    This product enables a cross-organizational risk management process involving audit committees, IT steering committees, risk officers, and management. It helps define acceptable risk levels, develop policies and procedures, implement controls, and regularly measure risk exposure and improvements.

    By using ServiceNow Risk Management, customers can expect a streamlined, integrated approach to risk management that supports comprehensive risk visibility, systematic assessment, and continuous monitoring, ultimately empowering better tactical and strategic decisions to protect business operations.

    The Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues.

    Request apps on the Store

    Visit the ServiceNow Store website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the ServiceNow Store version history release notes.

    Who uses Risk Management

    The complete risk process involves all areas of your organization working together.

    • Audit committee
    • IT steering committee
    • Risk officers (conduct risk assessment and identify all that can go wrong in business)
    • All levels of management (assist the risk officers with the identification of what can go wrong in their processes)

    Key activities for Risk Management

    Once the key roles are identified, work to identify the following items:
    • Determine what level of risk the organization is willing to accept? Get risk data in place and then determine what is acceptable.
    • Develop a risk management policy, through risk frameworks and risk statements.
    • Develop risk assessment and response procedures.
    • Implement controls to reduce your organization's exposure to risk. Repeat on a regular interval.
    • Measure your risk exposure and improvements.

    Risk Management and the ServiceNow AI Platform


    Risk Management and the NowPlatform
    The Risk Management and the Advanced Risk applications enable you to do the following.
    • Manage risks, risk statements, and risk frameworks: The risk library contains all risk frameworks and risk statements. Risk frameworks are used to group risk statements into manageable categories, while risk statements group the individual risks. The risk register is the central repository for all potential risks that could occur at any time, anywhere in the organization.
    • Manage risk events: Risk events are potential or actual financial and non-financial losses, near-misses, and gains that occur within an organization.
    • Risk hierarchy and scoring: Starting with New York, risk managers can create hierarchies that include different types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are assessed, the risk scores are automatically rolled up across the risk statement hierarchy, providing better tactical and strategic decision-making.
    • Manage classic risk assessments: Risk assessments are surveys that gather evidence to determine risk. The Risk Assessment Designer provides a single interface that users can use to create, and edit attestations, as well as change scoring parameters. The question bank offers a library of questions for various categories, so you do not have to build each questionnaire from scratch. Risks start in a Draft state then move to Assess, which sends a notification to the Assessment respondents.
    • Manage Advanced Risk Assessments: With Advanced Risk Assessment, create an integrated risk platform. This integrated platform supports various kinds of risk assessment methodologies and enables you to integrate risk assessment as a part of your overall decision-making process.
    • Manage policy exceptions and extensions: Policy exceptions and extensions provide temporary relief for a non-compliant control. The policy exception captures the rationale, comments, and evidence to support the acceptance or rejection of a policy exception request. Also, extension to an approved policy exception can be requested before the policy exception validity period. The control owner, the compliance manager, and the risk manager may be involved in the policy exception and extension workflow.
    • Use entity and risk dependencies using the GRC: Workbench: The GRC: Workbench utilizes CMDB information to show the upstream and downstream relationships across all applications. These relationships enable consistent risk mapping and modeling across the enterprise.
    • Risk indicators, control indicators, and indicator templates: Continuous monitoring involves activities related to identifying and creating key risk and control indicators. Supporting information can be collected for those indicators through automatic data collection or manual tasks. Indicator results are then used to create issues for controls, update risk scores, and provide supporting information for audit activities and control testings.
    • Manage risk issues and remediation: Issues can be created manually to document audit observations, remediations, or to accept any problems. They are automatically generated from indicator results, attestation results, or control test effectiveness.
    • Manage continuous monitoring for risks between Risk Management and Vulnerability Response: Continuous monitoring for risks is a feature integration between the GRC: Risk Management and the Security Operations Vulnerability Response products, which uses indicators to quickly identify high impact vulnerabilities based on business impact.
    • Analytics and reporting solutions for Risk Management: Performance Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.