---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk Workspace for the operational risk manager

# Risk Workspace for the operational risk manager {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Risk Workspace for the operational risk manager

The Risk Workspace for the operational risk manager in ServiceNow Yokohama release enables operational risk managers to effectively manage risks arising from people, processes, systems, or external events.
These risks can range from minor errors to major incidents like fraud that threaten organizational stability.
Operational risk managers are responsible for defining risk management frameworks, conducting assessments, monitoring risk events, and communicating the organization's risk posture.
Show full answer Show less  

## Key Responsibilities and Capabilities

* **Define the Operational Risk Framework:** Establish a comprehensive framework including risk identification, measurement, mitigation, and reporting to manage operational risks systematically.
* **Set up Libraries:** Create standardized risk statements to clarify risk severity and priority, define control objectives for risk mitigation, and organize entities and their relationships for accurate risk aggregation.
* **Conduct Risk Assessments:** Schedule and perform annual and periodic risk assessments to keep risk registers up to date and aligned with organizational policies.
* **Record and Monitor Risk Events:** Maintain a loss event register to capture financial and non-financial losses or near misses, perform root cause analyses, and track remediation efforts to reduce future risks.
* **Define Key Risk Indicators (KRIs):** Continuously monitor the risk posture using KRIs and control indicators, automate data collection where possible, and escalate threshold breaches to stakeholders.
* **Manage Issues and Incidents:** Track and manage changes or threats (issues) and actual negative events (incidents) ensuring proper closure and remediation.
* **Communicate Risk Posture:** Use dashboards and reports to provide executives and risk teams with aggregated risk data, highlighting top operational risks and facilitating informed decision-making.

## Practical Benefits for ServiceNow Customers

By leveraging the Risk Workspace, operational risk managers can maintain a clear, structured approach to identifying, assessing, and mitigating operational risks. The platform supports standardized risk documentation, continuous monitoring through KRIs, and comprehensive reporting. This ensures proactive risk management, regulatory compliance, and enhanced organizational resilience.

## Key Features Summary

* Risk framework creation and association of risk statements with control objectives.
* Comprehensive libraries for risk statements, control objectives, and entity definitions.
* Scheduling and executing advanced risk assessments.
* Risk event capture and analysis with loss event registers.
* Automated and manual monitoring of risk and control indicators.
* Issue and incident management capabilities.
* Customizable dashboards and reports to communicate risk posture effectively.  
Operational risk managers manage operational risks such as losses due to errors,
breaches, or damages that are caused by people, internal processes, systems, or external events.
Operational risks range from the small, such as the risk of loss due to minor human errors, to the
large, such as the risk of bankruptcy due to serious fraud.

## Operational risk manager {#risk-workspace-operational-risk__section_tw2_tq3_jpb}

Operational risk managers are a part of the operational risk team that manages the risk posture of the organization. Risk posture is the current risk profile for a company. As an operational risk manager, you must perform the following tasks.

Define the operational risk framework
:   Effectively manage the operational risks of an organization by defining a robust risk
    management framework. This framework helps to identify risks and to define the control
    framework to mitigate those risks. A risk management framework consists of the following
    components:

    * Risk identification
    * Risk measurement or scoring
    * Risk mitigation
    * Risk reporting and monitoring
    {#risk-workspace-operational-risk__ul_kqv_hmp_qpb}

Set up libraries
:   Set up comprehensive libraries by doing the following:

    * Creating risk statements: A risk statement is used to record a risk in a way that everyone can reach a common agreement on its severity or relative priority.
    * Creating control objectives: A control objective defines the aim or purpose of risk-mitigating controls. These controls need continuous monitoring.
    * Defining entity classes, entity types, and entities: For more information on entities, see [Understanding entities](https://servicenow-prod.fluidtopics.net/FIyspwKK_ZiLRfOKa9Nt8w "Entities are one of the most fundamental and crucial elements for using Governance, Risk, and Compliance. Entities can be people, processes, departments, applications or objects that are examined for risks.").
    * Defining the upstream and downstream entities.
    {#risk-workspace-operational-risk__ul_ndn_gm2_rpb}
:   The first step is to set up risk statements so that your team has a specific idea of the
    risk. For example, simply calling a risk as a cybersecurity risk is not specific.
    Cybersecurity risks could mean different things to different people. Therefore, a common
    statement to define cybersecurity is created as a risk statement. To create risk statements
    and their hierarchy, clearly define the risk impact, the assets at risk, and the source of
    risk. By defining the risk statements and creating their hierarchy, you can ensure that the
    risk scores are aggregated thus giving the complete risk status.

Conduct risk assessments on a periodic basis
:   Perform the annual risk assessments according to your organization's policies. Also,
    ensure that the risk register is updated and accurate. Create risk assessment scopes and
    schedule assessments. To learn more about risk registers, see [Risk register in the Risk Workspace](https://servicenow-prod.fluidtopics.net/IouoLmnj5cGIqz6VT9Q~2g "The risk register contains the information about identified risks, results of risk analysis such as risk scores, and risk response plans. The risk register enables you to monitor and control the risks of your organization.").

Record and monitor risk events
:   Risk events are potential or actual financial and non-financial losses, near misses, and
    gains that occur within an organization. To effectively manage risks, it is essential to
    monitor risk events, perform a root-cause analysis, and track the remedial tasks.
    Organizations use risk events to understand their losses and analyze areas of improvement to
    reduce further losses. You must maintain the loss event register to capture complete event
    information and to suggest additional controls to mitigate risks in the future.

Define key risk indicators
:   Monitor the risk posture of your enterprise on a continuous basis. Continuous monitoring
    of risks and controls involves identifying and creating key risk and control indicators.
    Supporting information can be collected for those indicators through automatic data
    collection or manual tasks. Indicator results are then used to create issues for controls,
    signal a change in the risk posture, and to provide supporting information for audit
    activities and control testing. If the indicator thresholds are breached, you must escalate
    to the respective stakeholders.

Manage issues and incidents
:   An issue is created when there is a change in the environment, process, or system that
    poses a threat. An issue requires action to prevent an incident or loss. An incident is a
    successful outcome or event with a negative impact. As the operational risk manager, you can
    view, create, and manage issues and incidents. Ensure tracking, proper closure, remediation,
    and monitoring of issues and incidents.

Communicate the operational risk posture
:   Define dashboards to report data effectively and accurately. You must create the required
    reports which can be shared with the executives and the head of the operational risk team.
    The reports and dashboards ensure that the aggregated assessment results across the
organization help to identify the top operational risks for the enterprise.  
The following table lists the key tasks that you perform in your role as an operational risk manager.{#risk-workspace-operational-risk__table_syj_kcj_jpb__entry__2}

| Activity | Task |
|-|-|
| Define the operational risk framework | * [Create a risk statement](https://servicenow-prod.fluidtopics.net/PsHcKOPzcmFaMXoRKMy_xQ "Create risk statements to group risks into manageable categories.") * [Create a risk framework in the Risk Workspace](https://servicenow-prod.fluidtopics.net/7sMqCyoC9_a6nePukvjCqQ "Create risk frameworks to group risk statements into manageable categories and generate risks. After the risks are generated, you can identify methods to mitigate them.") * [Associate a risk statement with a control objective in the Risk Workspace](https://servicenow-prod.fluidtopics.net/mxhJh2L30DFQ9AwK3HOfJQ "Associate risk statements to control objectives in the Risk Workspace. This association helps you to manage your risks by ensuring that the risks have mitigating controls.") {#risk-workspace-operational-risk__ul_dvj_qpj_qpb} |
| Communicate the operational risk posture | * [Operational risk heatmap for Advanced Risk Assessment in the Risk Workspace](https://servicenow-prod.fluidtopics.net/f0yOSWxha8m4ZHSTj5P_xg "As an operational risk manager, you can configure and manage your risk heatmaps in the Risk Workspace.") * [Risk heatmap for classic risk assessment](https://servicenow-prod.fluidtopics.net/ARSwdCg_ilRAPVEoBkrg8A "As an operational risk manager, if you opt to use the classic risk assessment to assess the risks in your organization, you can view the risk heatmap to get an overview of the risk posture for your organization.") {#risk-workspace-operational-risk__ul_cmw_kgc_4qb} |
| Monitor the critical incidents and issues | [View, create, and manage issues](https://servicenow-prod.fluidtopics.net/b464yqKuSY4Xt7w9GSEvVQ "The issues landing page in the Risk Workspace provides logged-in managers and users with all the information they need to manage issues on a single page. The landing page features actionable insights, quick action buttons, filters, and access to open issue triages.") |
| Define the key risk indicators | [Risk indicators, control indicators, and indicator templates](https://servicenow-prod.fluidtopics.net/DiDhTpo0Dhr5hi3umY2nkQ "Indicators are an important tool used to manage your organization's risks. Indicators collect data to monitor controls and risks, and to collect audit evidence. Indicators monitor a single control or risk. They are used to enhance and facilitate the monitoring, mitigation, and reporting of risks.") |
| Conduct the annual risk assessment process | * [Configure a risk assessment methodology](https://servicenow-prod.fluidtopics.net/trRQS6vsLOAPtnK7vQ0VSw "Configure a risk assessment methodology (RAM) in the Advanced Risk application so that you can assess the risks or objects in your organization.") * [Create factors](https://servicenow-prod.fluidtopics.net/8TxqCfvM_ggrdSAXg41Vig "Factors are questions that you can use to analyze risks. Factors appear on a risk assessment instance.") * [Create risk assessment scopes](https://servicenow-prod.fluidtopics.net/MNe1hn2255bDBX~j_wZ4aQ "Create a risk assessment scope to identify risks for an entity, define assessors and approvers, set assessment frequency, and initiate assessments using the Risk Management application.") * [Schedule risk assessments in the Risk Workspace](https://servicenow-prod.fluidtopics.net/1Z_~53Bk5jrSwetMEyC0fQ "Schedule risk assessments automatically for multiple entities. The risk assessment scheduler helps the risk managers save time by automatically initiating the assessments based on the defined frequency.") * [Perform advanced risk assessment in the Risk Workspace](https://servicenow-prod.fluidtopics.net/FYNeZ8PlGlL4pyEsdGlzZA "Conduct risk assessments to assess inherent risks, effectiveness of controls, residual risks, and target risks in the Risk Workspace application. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.") {#risk-workspace-operational-risk__ul_jbz_vyr_4pb} |
| Facilitate recording and learning from loss events | * [Manage risk events](https://servicenow-prod.fluidtopics.net/Zqtw_gRWgcAC64zvU05Tig#manage-risk-events "Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. Risk events are also known as loss events or loss entries.") * [Create a risk event in the Risk Workspace](https://servicenow-prod.fluidtopics.net/qjHSPkABjYkjGEz0HG2QQw "Create a risk event in the Risk Workspace. Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization.") * [Analyze a risk event in the Risk Workspace](https://servicenow-prod.fluidtopics.net/scEYbs7Led7NUL2eEBfirQ "Analyze user-submitted risk events. You can add additional details to the risk event, request more information from the submitter, or reject the risk event if the event is not valid.") * [Create a risk event entry in the Risk Workspace](https://servicenow-prod.fluidtopics.net/0Cpuv8liRLHGfXTqeLoviQ "Create a risk event entry to determine the monetary or non-monetary impact of the risk event. A risk event can have multiple risk event entries.") {#risk-workspace-operational-risk__ul_zkg_vst_ypb} |
| Create aggregated risk reports | [Reports in the Risk Management application](https://servicenow-prod.fluidtopics.net/eRzYQx_oRXnvh8xgrVKRVA "Platform Analytics Solutions contain preconfigured dashboards. These dashboards contain actionable data visualizations that help you improve your business processes and practices.") |
[Table 1. Tasks of an operational risk manager]

{#risk-workspace-operational-risk__table_syj_kcj_jpb}  
The following image shows the view for the operational risk manager.Figure 1. Home page for the operational risk manager
**Related reference**   

* [Roles installed with the GRC Risk Workspace](https://servicenow-prod.fluidtopics.net/9jb143Muo5XUHF95fgbZRw "The GRC: Risk Workspace application installs the roles for Operational risk manager and IT risk manager for the users to perform their respective tasks.")

