---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Setup checklist for the Risk Management application

# Setup checklist for the Risk Management application {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This checklist includes the set up tasks that you are required to complete in your
ServiceNow AI Platform® instance. When you have completed these tasks, the base
system is ready for operation.

## Before you begin

Role required: sn_risk.admin

## Procedure

1. Create and print a PDF of the checklist topic and check off tasks as you complete them.
2. To generate a PDF, select the Save As PDF ![Save as PDF icon]()icon and at the top of the topic and select Selected topic.  
   {#setup-checklist-risk-impl__table_ns4_rt4_rcc__entry__2}

   | Item | Checklist |
   |-|-|
   | ![checkbox]() | A user with the sn_risk.admin role, can * define and modify the risk criteria * configure the risk properties * create assessments * modify the existing assessments * assign roles {#setup-checklist-risk-impl__ul_ps4_rt4_rcc} For details, see [Risk Management Administration](https://servicenow-prod.fluidtopics.net/hB70eTr2jLmk3FFCvCpmyg "Using the Risk Management application, administrators can customize risk categories, risk criteria, risk management properties, and risk assessment types."). |
   | ![checkbox]() | A user with the sn_risk.admin role, can also assign roles. For details, see [Roles installed with Risk Management](https://servicenow-prod.fluidtopics.net/rYK0_9piC5ljtWGv3dUpow "Roles are added with activation of GRC: Risk Management.") |
   | ![checkbox]() | A risk manager, with the sn_risk.manager role, needs to manage numerous risk statements. To achieve this goal, the risk framework must be defined. For details, see [Create a risk framework and associate risk statements to it](https://servicenow-prod.fluidtopics.net/SB5n9CftZi3WkvW1uRy2dg "Risk managers create risk frameworks to group risk statements into manageable categories."). |
   | ![checkbox]() | A risk manager, with the sn_risk.manager role, must create a risk statement to group risks logically. For details, see [Create a risk statement](https://servicenow-prod.fluidtopics.net/XxKcuAGDrJy92SSAAq2g_w "Risk managers create risk statements to group risks into manageable categories.") |
   | ![checkbox]() | A risk administrator or a risk manager can create a risk assessments using the Risk Assessment Designer. For details, see [Create a risk assessment using the Risk Assessment Designer](https://servicenow-prod.fluidtopics.net/dT8I1hVIK1bTsji87itBjg "Use the Risk Assessment Designer to create and edit metric types, use different metric types for different risks, select multiple respondents for a risk assessment, as well as change scoring parameters. The Question Bank offers a library of questions for various categories, so you do not have to build each questionnaire from scratch."). |
   | ![checkbox]() | Risk administrators and risk managers can create risk indicators. Risk indicators monitor changes in the levels of risk exposure and contribute to the early warning signs that enable organizations to report risks, prevent crises and mitigate them in time. For details, see [Create a risk indicator](https://servicenow-prod.fluidtopics.net/nsTpSLb2aDkXzRq1ttPsEQ "Create a risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system, and they enable you to take preventative action on the risks."). |
   | ![checkbox]() | Risk administrators and risk managers can create entities manually, rather than generating them from the entity types. For details, see [Create independent entities](https://servicenow-prod.fluidtopics.net/QnD2Lg17fPaZCCSMOGxjhw "Entities can be created manually, rather than generating them from the entity types. Entities can also be created without needing to refer to an existing ServiceNow table, like assets, applications, business services, or processes.") |
   | ![checkbox]() | Risk administrators and risk managers must create and edit entity types and map them to existing ServiceNow® tables for which you must track compliance. Entities are assigned to control objectives and risk statements, which generate controls and risks for every entity type. For details, see [Generate risks and controls from entity types](https://servicenow-prod.fluidtopics.net/aHJ8w8VQ4cz5hLB27D02eg "Create and edit entity types and map them to existing ServiceNow tables for which you must track compliance (applications, departments, regions, processes, systems, etc.). Entities are assigned to control objectives and risk statements, which generate controls and risks for every entity type.") |
   [Table 1. Risk Management application checklist]

   {#setup-checklist-risk-impl__table_ns4_rt4_rcc}
{#setup-checklist-risk-impl__steps_efm_1t4_rcc}

