Advanced Risk Assessment - Multiple Risk Rating Matrices for a Single Risk Assessment Methodologie

Yacine
Tera Contributor

 

Hi everyone,

 

We are using ServiceNow IRM Risk Management (Australia release) with Advanced Risk Assessment (ARA).

 

The organization has a single enterprise risk methodology, but different legal entities use different financial impact thresholds for risk rating.

 

For example:

 

Legal Entity A: Low impact = €0 - €1K

Legal Entity B: Low impact = €0 - €10K

Legal Entity C: Low impact = €0 - €50K

The assessment process, factors, workflows, and scoring logic remain the same. Only the impact rating matrix differs by legal entity.

 

Is it possible in standard ARA to:

 

Associate multiple risk rating matrices (or qualitative rating criteria) with a single Risk Assessment Methodology (RAM)?

Dynamically select the appropriate matrix based on the legal entity or business unit being assessed?

Or is the recommended approach to create a separate RAM for each legal entity/matrix?

I would appreciate any guidance on the standard product capabilities versus customization options.

 

Thanks!

0 REPLIES 0