Aggregate Risk score

Rakesh11
Tera Contributor

I have submitted risk for 4 entity and submitted them(the state of risks is monitor). But the aggregate risk is not getting updated. Pleas let me the scheduled jobs which is getting used here.

3 REPLIES 3

Jan Spurlin
ServiceNow Employee
ServiceNow Employee

Need more information - are you using Advanced Risk?

Have you set the system property flag to migrate to advanced risk?

And have you performed ARAs on the risks associated with these entities?

is it mandatory to migrate to advanced risk if yes after migration can we use functionalities from classic risk ??

 

Community Alums
Not applicable

Hi @Rakesh11 ,

If you are using Advanced Risk Management only then aggregated risk score would make sense.

In Advanced Risk Assessment, risk scores are calculated across risk statement hierarchy, entity hierarchy, or a combination of both. These methods enable stakeholders to monitor their risk posture and provide visibility of the overall aggregated risk score.

Before you understand the rollup feature, consider the following points:

  • Each entity might have multiple scores based on the different risk assessment methodologies.
  • Only the risk assessments in the Monitor state contribute to the risk score.
  • Each risk assessment methodology might have a different formula to calculate the rollup qualitative score and the rollup quantitative score. The formula is specified in the Rollup configurationssection in the risk assessment methodology form.
  • Whenever the Advanced Risk plugin is activated the risk scores get rolled up.

The scheduled job which runs OOTB is "GRC rollup assessment scores" in GRC: Advanced Risk Application Scope.