---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk assessment project

# Risk assessment project {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Risk assessment project

A Risk assessment project in ServiceNow enables assessors to evaluate multiple risks and controls simultaneously within a unified workspace, primarily using the Risk Workspace.
It is designed to streamline the Risk and Control Self-Assessment (RCSA) process by facilitating collaborative input, reducing manual data entry, and automating reporting.
This approach enhances coordination, accelerates the assessment process, and improves data accuracy by allowing stakeholders to collectively analyze risks' impact, likelihood, and mitigation strategies.
Show full answer Show less  
Note: Multi-risk and control assessments are supported exclusively in the Risk Workspace.

## Key Features

* Simultaneous assessment of multiple risks and controls, saving time and effort.
* Automated error handling with comprehensive summaries to reduce inconsistencies before finalization.
* Collaborative involvement of all relevant stakeholders, minimizing unnecessary communication loops.
* Easy navigation across different assessment stages without switching screens.
* Access to detailed summary reports and reference information for each risk via a sidebar panel.
* Streamlined process for collective sign-off on all risks within the project.

## Personas and Roles

* **Project Owner:** Creates and manages the project scope, context, and stakeholder identification.
* **Assessor:** Performs the assessments on multiple risks and controls, evaluates controls, and develops risk response strategies.
* **Approver:** Reviews completed assessments and provides final approval or rejection.

Required roles for managing risk assessment projects include:

* **Risk assessment project reader:** Read-only access to projects.
* **Risk assessment project user:** Can create and update projects they own.
* **Risk assessment project manager:** Full permissions to create, update, and delete any project.

## Workflow

The risk assessment project workflow within Risk Workspace involves:

* **Creating a project:** Define context such as assessable entity, risk assessment methodology, project name, description, and stakeholders.
* **Performing assessments:** Evaluate inherent risks, control effectiveness, residual and target risks using stacked or grid views; define risk responses to manage identified risks.
* **Reassessing projects:** Update completed assessments to reflect new information or organizational changes.
* **Reassigning assessors:** Facilitate smooth transitions by reassigning assessors across ongoing projects simultaneously.  
You can perform assessments on multiple risks and controls simultaneously by creating a risk assessment project. Risk assessment project enables assessors to review multiple risks and controls to understand their potential
impact, likelihood, and associated mitigation strategies.

## Overview of a risk assessment project {#risk-assessment-project__section_o4b_3yh_2dc}

A Risk assessment project is a structured process designed to assess multiple risks and controls simultaneously, particularly within workshop-based RCSA (Risk and Control Self-Assessment) environments. It replaces manual data entry
and fragmented workflows by enabling efficient data collection, collaborative input from stakeholders, and automated reporting. A Risk assessment project simplifies coordination, speeds up processes, and improves data accuracy by
providing a unified workspace for evaluating risks collectively and reliably.  
Note:  
Assessment of multiple risks and controls is supported only in Risk Workspace.

## Benefits of a risk assessment project {#risk-assessment-project__section_jpq_3j3_2dc}

The following are the key benefits of a risk assessment project:

* Simplifies the RCSA process by enabling multiple risks and controls to be assessed at the same time, which saves time on manual data collection.
* Reduces the chances of errors and inconsistencies by using automated error handling and providing comprehensive error summaries before finalizing assessments.
* Reduces unnecessary back-and-forth interactions among stakeholders by involving all required participants in the assessment project.
* Enables navigation between different stages of risk assessments and access multiple risks and controls simultaneously, without switching screens.
* Provides detailed summary reports on the assessment results.
* Simplifies the process of signing off on all the risks together within the project.
* Enables access to reference information related to each risk in the sidebar panel.
{#risk-assessment-project__ul_l2v_rj3_2dc}

## Personas involved {#risk-assessment-project__section_q3d_tzh_2dc}

The following personas are involved with the risk assessment project:

Project owner
:   The project Owner creates and manages the risk assessment project. It includes setting up the project context, identifying relevant stakeholders, and defining the scope of risks that must be assessed.

Assessor
:   The project assessor performs assessment on multiple risks and controls within the risk assessment project. They analyze each risk, evaluate the effectiveness of existing controls, and create risk response strategies.

Approver
:   The Project Approver reviews the completed risk assessments and provides the final sign-off on the project. They ensure that all scoped risks have been assessed and either approve or reject the risk assessment.

## Roles required {#risk-assessment-project__section_pbz_z23_2dc}

The following roles are required for a risk assessment project:

* Risk assessment project reader \[sn_risk_advanced.risk_asmt_project_reader\]: Provides read-only access to the risk assessment projects.
* Risk assessment project user \[sn_risk_advanced.risk_asmt_project_user\]: Provides the ability to create risk assessment projects and update or delete only the projects created by the user.
* Risk assessment project manager \[sn_risk_advanced.risk_asmt_project_manager\]: Provides the ability to create, update, and delete any risk assessment projects.

{#risk-assessment-project__ul_ocm_hwk_ddc}For more information, see [Roles installed with the GRC Risk Workspace](https://servicenow-prod.fluidtopics.net/9jb143Muo5XUHF95fgbZRw "The GRC: Risk Workspace application installs the roles for Operational risk manager and IT risk manager for the users to perform their respective tasks.").
* **[Workflow of risk assessment project](https://servicenow-prod.fluidtopics.net/12wxoAZRUjoN0TK5yit57g)**   
  The risk assessment project workflow is a structured process to assess multiple risks and controls simultaneously using Risk Workspace.
* **[Create a risk assessment project](https://servicenow-prod.fluidtopics.net/dBjPIqEREXtoCv13PcMVGg)**   
  Create a risk assessment project to perform assessments on multiple risks and controls simultaneously using Risk Workspace. You can define the project context, including the assessable entity, Risk assessment methodology (RAM), project name, description, and identify and add stakeholders.
* **[Perform assessment on a risk assessment project in stacked view](https://servicenow-prod.fluidtopics.net/9acug_SS8Rxjr2SLtLtGdw)**   
  Perform assessments on multiple risks and controls simultaneously in a risk assessment project using Risk Workspace. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
* **[Perform assessment on a risk assessment project in grid view](https://servicenow-prod.fluidtopics.net/w_j8DxooINcV6bLhEXPAcg)**   
  Perform assessments on multiple risks and controls simultaneously in a risk assessment project using the grid view. You can assess inherent risks, effectiveness of controls, residual risks, and target risks. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
* **[Reassess a risk assessment project](https://servicenow-prod.fluidtopics.net/80pr0r2xHPk46BF8O5tc~Q)**   
  Reassess a risk assessment project to assess any completed risk assessment project. It verifies that risks are reviewed and updated to reflect new insights or changing conditions, maintaining alignment with organizational goals.
* **[Reassign assessor for a risk assessment project](https://servicenow-prod.fluidtopics.net/g~e~vaDEd0UbC8BSbYLexw)**   
  Reassign assessors for multiple in-progress risk assessment projects simultaneously to minimize disruptions during stakeholder transitions.

**Related concepts**   

* [Workflow of risk assessment project](https://servicenow-prod.fluidtopics.net/12wxoAZRUjoN0TK5yit57g "The risk assessment project workflow is a structured process to assess multiple risks and controls simultaneously using Risk Workspace.")  
**Related tasks**   

* [Create a risk assessment project](https://servicenow-prod.fluidtopics.net/dBjPIqEREXtoCv13PcMVGg "Create a risk assessment project to perform assessments on multiple risks and controls simultaneously using Risk Workspace. You can define the project context, including the assessable entity, Risk assessment methodology (RAM), project name, description, and identify and add stakeholders.")

