How can we customize the inherent and residual score based on impact and likelihood on the risk form

chitra1
Tera Contributor

Hi,

 

Wanted to know the score calculations and can we customize the score based on impact and likelihood.

 

Thanks,

CD

4 REPLIES 4

jaikishan1
ServiceNow Employee
ServiceNow Employee

Hi @chitra1 ,

Please go through the following link which should answer your question:
https://www.servicenow.com/community/grc-forum/risk-calculation-in-advance-risk-management/m-p/29695...

Please let us know if you have any further question.


Please mark this as helpful if it solves your query.

Regards,
Jai

Satishkumar B
Giga Sage
Giga Sage

Hi @chitra1 

After the risk assessment questionnaire is completed, the scoring for inherent and residual risk is completed manually based on the results of the questionnaire. Please note; if default inherent and residual scoring is defined at the risk statement level, all corresponding risks will inherit the scoring.

 

Both qualitative and quantitative scoring methods for measuring impact and likelihood are supported which are configured and maintained in the risk criteria table found in the risk administration area. This is where quantitative and qualitative values are cross-referenced to support the calculations described below.

SatishkumarB_0-1721728717990.png

Risks must be measured using a single methodology, either qualitatively or quantitatively. This can be set by the GRC Administrator in the properties area (by default the scoring method is set to quantitative).

 

SatishkumarB_1-1721728729423.png

The Annualized Loss Expectancy (ALE) is automatically calculated by the system as SLE x ARO or Impact x Likelihood. Where qualitative methodology has been used, the relevant values are taken from the risk criteria table. The Inherent and Residual scores are translations of the ALE which will depend on the values configured in the risk criteria table. 

 

The Calculated ALE is automatically populated based off all calculations:

Residual ALE + ((Inherent ALE - Residual ALE) * (Calculated Risk Factor / 100))

 

The calculated risk factor is also automatically calculated:

(Indicator failure factor + Control failure factor) / 2 *100

The control failure factor is the impact of control failures on the calculated score of risks and the indicator failure factor is the impact of risk indicator failures on the calculated score of risks. These values can be found on the ‘Monitor’ tab.

……………………………………………………………………………………………………

Please Mark it helpful 👍and Accept Solution✔️!! If this helps you to understand. 



Hi @Satishkumar B ,

 

Thanks for your detailed explanation.

 

Actually we are trying to change the currency values for the impact and I have updated those on the risk criteria table , but after updating the inherent score values are changing but we need to populate the scores as per the table [ Risk level matrix ].

 

Is there any way to customize it? Any suggestion please.

 

Thanks,

CD

 

chitra1_0-1721729954611.pngchitra1_1-1721729992260.png

 

Hi @chitra1 

If you need any help feel free to connect. i may be interested in seeing the below config you made:

1. Impact Configuration:
• Share a screenshot of the configured factors for impact.
• Provide the transformation criteria used for impact assessment.
2. Likelihood Assessment:
• Display the guided text for the choices in likelihood.
• Explain how these choices influence your re-rating criteria.
3. Inherited Assessment Configuration:
• Show the configuration settings for inherited assessments.
• Indicate whether your assessment is quantitative or qualitative.
4. Qualitative Rating Criteria:
• If the assessment is qualitative, reconfigure the qualitative rating criteria based on specific values.
5. Heat Map Colors:
• Adjust the heat map colors as necessary to align with your rating criteria.

……………………………………………………………………………………………………

Please Mark it helpful👍 and Accept Solution✔️!! If this helps you to understand.