---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk Assessment Methodology (RAM)

# Risk Assessment Methodology (RAM) {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Risk Assessment Methodology (RAM) provides a systematic and repeatable approach to identifying, evaluating, and mitigating privacy risks associated with data processing activities.

RAM is central to establishing accountability in data handling practices and supports regulatory compliance by embedding risk management into daily operations. It helps privacy and compliance teams to assess data processing
risks, identify exposure across systems, and implement timely strategies to reduce those risks. As organizations operate in an increasingly complex regulatory environment, the methodology confirms that risks are evaluated
consistently and documented transparently.

For information about configuring your own RAMs, see [Create a Risk Assessment Methodology](https://servicenow-prod.fluidtopics.net/Pq6obhAKXBq81uhwxxGEjA "Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.").

## Base Risk Assessment Methodologies {#risk-assessment-methodology-prm__section_b5d_nv3_yfc}

The Privacy Management application provides the following RAMs in the Draft state:

* Automated criticality factors
* Criticality assessment
* Privacy Risk Assessment
{#risk-assessment-methodology-prm__ul_uqz_4v3_yfc}  
Note:  
Starting with the Yokohama release, you can publish up to three Risk Assessment Methodologies.

