Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Perform Advanced Risk Assessment

Use the ServiceNow® Governance, Risk, and Compliance (GRC) Advanced Risk Assessment feature to create an integrated risk platform.

To see the roles required for performing and approving the assessment, refer to Roles for performing advanced risk assessment.

  • Create a manual factor
    Create manual factors to evaluate and assess risks on a risk assessment instance.
  • Create a group factor
    Create group factors to evaluate and assess risks on a risk assessment instance.
  • Create an automated factor
    Create automated factors to automatically fetch data from other data sources such as tables or database views.
  • Create a scripted automated factor
    Create scripted automated factors that use a script to fetch data from ServiceNow® records or from external sources. During risk assessment, scripted automated factors automatically calculate and provide the responses for factors.
  • Copy a factor
    Create a copy of a published factor to make minor modifications and then reuse the factor.
  • Configure a risk assessment methodology
    Configure a risk assessment methodology (RAM) in the Advanced Risk application so that you can assess the risks or objects in your organization.
  • Copy a risk assessment methodology
    Modify your risk assessment methodology (RAM) and factors by creating a copy of the record. The option to copy allows the system to create a true copy of the underlying record including all the related lists. This action saves the time of risk administrators as they do not have to create the records from the beginning each time.
  • Retire a risk assessment methodology
    Retire a risk assessment methodology (RAM) that is no longer used. Retiring unused RAMs makes it easier to manage the active RAMs for the risk administrator.
  • Configure an inherent assessment
    Configure and publish an inherent assessment in the Advanced Risk application to assess the inherent risks in your organization.
  • Configure a control effectiveness assessment
    Configure and publish a control effectiveness assessment to assess the effectiveness of controls in mitigating risks.
  • Configure a residual assessment
    Configure and publish a residual assessment in the Advanced Risk application to assess the residual risks in your organization.
  • Configure a target assessment
    Configure and publish a target assessment in the Advanced Risk application to assess your desired future risk level. By configuring a target assessment, you enable the assessors and approvers to perform a target risk assessment in the Next Experience.
  • Create risk color styles
    Create a library of risk color styles to use for different assessment types and matrixes. A risk color style is a combination of a background color and a text color. The color styles help maintain consistency when you configure risk assessments.
  • Configure risk heatmaps
    Within a risk assessment methodology (RAM), configure the heatmap visualization for inherent and residual assessments. Use different heatmaps for different risk assessment methodologies.
  • Create a risk assessment scope and initiate assessments
    Create a risk assessment scope to define and identify risks for an entity. Identify assessors and approvers for assessments, and define the frequency of assessments.
  • Simulate a risk assessment
    Simulate a risk assessment to verify the associated risk assessment methodology (RAM) configuration when it is in the draft state.
  • Assess risks and objects on an assessment instance
    Assess the risks that you have configured and reassign the risks to relevant approvers.

Parent Topic:Using Risk Management