Using the Risk Workspace
Starting with Version 13.0.5, a new workspace has been introduced for the Risk Management application. The new workspace provides you with an improved User Experience (UX) and a simplified user journey.
- Create a risk framework in the Risk Workspace
Create risk frameworks to group risk statements into manageable categories and generate risks. After the risks are generated, you can identify methods to mitigate them. - Associate a risk statement with a control objective in the Risk Workspace
Associate risk statements to control objectives in the Risk Workspace. This association helps you to manage your risks by ensuring that the risks have mitigating controls. - Common controls in Risk Management
By linking the risks to a common control in the Risk Management application, you can reduce the time and effort that is needed to manage and apply these centralized controls to your reliant entities. For example, a fire sprinkler system can be a common control for multiple business units (BUs), such as finance, security, and human resources (HR). - Create and run a manual risk indicator in the Risk Workspace
Create and run a manual risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system and they enable you to take preventative actions on risks. In a manual indicator, the results are manually gathered using task assignments. - Create and run a basic risk indicator in the Risk Workspace
Create and run a basic risk indicator to identify the possibility of a future adverse impact on your organization. Indicators are an early warning system and they enable you to take preventative action on the risks. Basic indicators are automated indicators based on an indicator source. - Create and run a scripted risk indicator in the Risk Workspace
Create and run a scripted risk indicator to identify the possibility of a future adverse impact on your organization. A scripted indicator enables you to write your own script to run the indicators. Indicators are an early warning system and they enable you to take preventative action on the risks. - Issue management in the Risk Workspace
The issues landing page in the Risk Workspace provides logged-in managers and users with all the information they need to manage issues on a single page. The landing page features actionable insights, quick action buttons, filters, and access to open issue triages. - Create a risk assessment scope in the Risk Workspace
Create a risk assessment scope to identify risks for an entity, define assessors and approvers, set assessment frequency, and initiate assessments using the Risk Management application. - Schedule risk assessments in the Risk Workspace
Schedule risk assessments automatically for multiple entities. The risk assessment scheduler helps the risk managers save time by automatically initiating the assessments based on the defined frequency. - Perform advanced risk assessment in the Risk Workspace
Conduct risk assessments to assess inherent risks, effectiveness of controls, residual risks, and target risks in the Risk Workspace application. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process. - Perform any object assessment in the Risk Workspace
Assess the risks on any object or record in ServiceNow®. An example of object assessment is assessing change management or assessing a citation. - Workflow of risk response task
The risk response task workflow is a structured process to manage assessed risks by defining plans of action to either accept, mitigate, avoid, or transfer those risks. - Workflow of action item in risk response task
The action item workflow is a structured process for managing the granular tasks associated with risk response tasks, which are assigned to multiple stakeholders. - Create a risk response task in the Risk Workspace
Create a risk response task to define plan of actions, assign responsibilities, set priorities, and establish deadlines to ensure effective management of the assessed risks. - Workflow for risk identification in the Risk Workspace
Workflows provide step-by-step guidance for completing the risk identification process in the GRC Risk Workspace. - Create a risk event in the Risk Workspace
Create a risk event in the Risk Workspace. Risk events are potential or actual financial and non-financial losses, near misses, and gains that occur within an organization. - Associate similar risk events
Train a similarity solution definition that uses machine learning by activating the Governance, Risk, and Compliance: Predictive Intelligence plugin. The solution enables the system to display similar risk events automatically. - Categorizing risks with the Governance, Risk, and Compliance: Predictive Intelligence plugin
By using the Governance, Risk, and Compliance: Predictive Intelligence plugin, you can predict the risk statements for your orphan risks (the risks that don't have risk statements) on the risk records for your organization. You can then identify the correct risk statement for the risks and then aggregate them into manageable categories. - Analyze a risk event in the Risk Workspace
Analyze user-submitted risk events. You can add additional details to the risk event, request more information from the submitter, or reject the risk event if the event is not valid. - Create a risk event entry in the Risk Workspace
Create a risk event entry to determine the monetary or non-monetary impact of the risk event. A risk event can have multiple risk event entries. - Create an ORX external event
Create an Operational Riskdata eXchange (ORX) external risk event to share the risk event of your company with other organizations. This exchange of risk events information acts as a learning for other organizations in the industry and prevents them from making the same errors. - Report a risk event from the Risk Portal
Report a risk event from the Risk Portal. The Risk Portal provides an easy method to quickly report risk events. - Chart colors for risk data
You can view your risk data visualizations in different colors for a quick overview of your risks. - Create a business process in the Risk Workspace
Create a business process in the Risk Workspace and define the owners, approvers, business criticality, and review frequency for the process. - Create a test plan in Risk Workspace
Create a test plan to document the control testing procedure. You can create a test plan from scratch or based on a test template to describe how a feature is to be tested. - Filter data in the risk heatmap workbench
As a risk user, filter data in the risk heatmap workbench to get a granular view of your risks. - Define the risk appetite for an entity
Define the risk appetite on the entity records in the Risk Management application to evaluate all the possible risks and to set the boundaries for the acceptable and unacceptable risks for your business. - Define the risk appetite for a risk
Define the risk appetite on the risk records in the Risk Management application to evaluate all possible risks and to set the boundaries for acceptable and unacceptable risks. - Define the risk appetite for a risk statement
Define the risk appetite on the risk statement records in the Risk Management application to evaluate all the possible risks and set the boundaries for the acceptable and unacceptable risks. - Parallel Review and Feedback in Advanced Risk
The Parallel Review and Feedback workflow enables second-level and third-level line managers to review records and provide feedback at any stage, facilitating collaboration across management lines and ensuring feedback is tracked through closure. - Risk assessment project
You can perform assessments on multiple risks and controls simultaneously by creating a risk assessment project. Risk assessment project enables assessors to review multiple risks and controls to understand their potential impact, likelihood, and associated mitigation strategies. - Matrix report in Risk Workspace
Matrix report is a structured report that you can configure to view in a grid or table format in the Risk Workspace. You can use the matrix report to access and analyze the risk posture of your organization using entity-related data, such as risks, controls, KRIs, and events.
Parent Topic:Governance, Risk, and Compliance