GRC forum
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Forum Posts

Risk Assessment Scope Approval

Hello,  We had a customer provide a requirement in which they want to review and approve the scope of a risk assessment and all the responses after the completion of all the assessments.   Essentially they want a way to show an entity owner signing o...

GRC - Risk manager unable to see buttons for mitigation task

Our scenario is that our compliance team has created a Risk and it is owned by a standard GRC user. The assessment was taken and the response was set to mitigation. A mitigation task opened as expected and the GRC user who is assigned to the task wro...

Screenshot 2024-01-23 at 4.36.31 PM.png
mday by Tera Contributor
  • 2099 Views
  • 5 replies
  • 0 helpfuls

Resolved! Test Templates Vs Test Plans

HiWhat is the difference between a test template and test plan? Looking at the system architecture the test templates are linked to the control objective which in turn than links to the test plan when generating a control test. What is the reason for...

Scribe80 by Giga Contributor
  • 4681 Views
  • 5 replies
  • 6 helpfuls

Risk Response and Object based risk assessments in ARA

According to the SN documentation for Vancouver for Advanced Risk Assessments, the risk response workflow is not available for object-based risk assessments. What are the alternatives to document a risk response? For example, if I do an object-based ...

AristonColland_0-1706553037530.png

How are risk scores calculated after multiple assessments completed?

When there are 2, 3, 4, or more Tiering Assessments or Vendor Risk Assessments – all with different scores – how does the system arrive at just one overall value at the Vendor (Company) level? For example, Company XIt’s Risk rating is “4 – Low”.This ...

Nabilah by Tera Contributor
  • 2271 Views
  • 3 replies
  • 0 helpfuls

Resolved! Third Party Risk - Due Diligence Request - Vancouver Release

Hi,  The Vancouver release of TPRM provides a catalog item that can be used to submit a due diligence request for a number of scenarios. My question is related to option to onboard a new engagement.  Per ServiceNow documentation, we are informed the ...

VM7 by Tera Contributor
  • 1693 Views
  • 2 replies
  • 0 helpfuls

Auto-update Entity Owner

Hi All,   I have used the recently added functionality of Auto-update Entity Owner. I follow the next steps:   - Changed the Owner on the Source record - Entity Owner is dynamically changed - Ownership on the Control & Risk levels does not update to ...

Resolved! Compliance Workspace, Pending Group Tasks, filter issues

Good morning, I have an issue on PROD environment that in Compliance Workspace on "Pending Group Tasks" list the filter is not working properly, no records are displayed, I can't even see the filter, but on INT environment it is working fine. I don't...

Marius8 by Tera Contributor
  • 1485 Views
  • 1 replies
  • 1 helpfuls

GRC - PCI 4.0

We currently have PCI 3.0 citations in our instance. I have been asked to find out when PCI 4.0 will be available from ServiceNow or a vendor. Anyone have an insight?

Christine C by Tera Contributor
  • 1581 Views
  • 5 replies
  • 2 helpfuls