Inherent Assessment score in Risk Identification vs Inherent score in Risk record

Dipi
Tera Contributor

How does the inherent assessment score on a Risk Identification (RI) record relate to the inherent assessment score on the Risk record?

In ServiceNow GRC / IRM, when a Risk is created from a Risk Identification record, does the inherent assessment score from the RI automatically flow through to the Risk record, or are the two inherent assessments treated as independent?

If they are independent by design, what is the intended purpose of performing an inherent risk assessment at the Risk Identification stage if that score is not reused or passed on to the Risk record created from the RI?

2 REPLIES 2

VaishnaviK3009
Tera Guru

Hi @Dipi !!

 

In ServiceNow GRC / IRM, the inherent assessment score on a Risk Identification (RI) record and the inherent assessment score on the Risk record are independent.

When a Risk is created from a Risk Identification record, the inherent assessment score from the RI does not automatically flow to the Risk record out of the box. A new inherent assessment is expected to be performed on the Risk record.

This separation is intentional and reflects the different purposes of the two records:

  • Risk Identification (RI) represents an early discovery or intake stage.
    The inherent assessment at this stage is a high-level, preliminary evaluation used to:

    • Determine whether the identified issue is material enough to be promoted to a Risk

    • Prioritize and triage identified risks

    • Support routing, review, and escalation decisions

  • Risk represents a formal, governed risk.
    The inherent assessment on the Risk record is the authoritative rating, performed once the risk is fully defined and is used for governance, reporting, approvals, and ongoing risk management.

Because the RI assessment is performed before the Risk is fully scoped and validated, ServiceNow intentionally does not reuse or pass forward that score to avoid treating an early estimate as the official risk rating.

If an organization wants to reuse the RI inherent score, this can be achieved through configuration or customization, but it is not standard platform behavior.

 

Mark this as Helpful if it clarifies the issue.
Accept the solution if this answers your question.

Regards,
Vaishnavi
Associate Technical Consultant

 

VaishnaviK3009
Tera Guru

Hi @Dipi !!

If my solution helps you then mark it as helpful and accept as solution.

 

Regards,

Vaishnavi

Associate Technical Consultant