How can I configure Risks that are identified as Fraud in Servicenow?

sam47
Tera Contributor

My organization identifies 3 kinds of risks - Fraud, Inherent and Residual.

On the Risk table I can see Residual and Inherent risks are there but if I want to categorize a risk as Fraud what will be the best approach to do that?

1 ACCEPTED SOLUTION

Community Alums
Not applicable

Hi @sam47 ,

You need to understand What is Risk Category and What are the Risk Assessment Types.

When you say, you want to add a new risk category , then you are talking about below :

SandeepDutta_0-1702442845389.png

Which can be found in the actual Risk , in "sn_risk_risk" table.

 

Whereas, Inherent and Residual are Risk Assessment types. you cannot add another type called as "fraud" in terms to assessing the Risk.

 

Inherent Risk is typically defined as the level of risk in place in order to achieve an entity's objectives and before actions are taken to alter the risk's impact or likelihood.

Residual Risk is the remaining level of risk following the development and implementation of the entity's response or after the controls are applied.

 

Let's take an example of RAM in advanced risk management, you can see the assessment types selected are Inherent, Residual and Control Effectiveness:

SandeepDutta_1-1702443285242.png

 

 

 

View solution in original post

1 REPLY 1

Community Alums
Not applicable

Hi @sam47 ,

You need to understand What is Risk Category and What are the Risk Assessment Types.

When you say, you want to add a new risk category , then you are talking about below :

SandeepDutta_0-1702442845389.png

Which can be found in the actual Risk , in "sn_risk_risk" table.

 

Whereas, Inherent and Residual are Risk Assessment types. you cannot add another type called as "fraud" in terms to assessing the Risk.

 

Inherent Risk is typically defined as the level of risk in place in order to achieve an entity's objectives and before actions are taken to alter the risk's impact or likelihood.

Residual Risk is the remaining level of risk following the development and implementation of the entity's response or after the controls are applied.

 

Let's take an example of RAM in advanced risk management, you can see the assessment types selected are Inherent, Residual and Control Effectiveness:

SandeepDutta_1-1702443285242.png