Risk appetite in Risk Management

Kumar56
Tera Contributor

We have seen we can set up a Risk appetite at different levels, for instance:

Risk Statement

Kumar56_0-1732526292345.png

 

Entity

Kumar56_1-1732526292352.png

 

Risk

Kumar56_2-1732526292354.png

 

How do the different configurations relate to each other?

What is the order, or which one is valid for IRM?

If a risk has a risk statement with a different appetite than the one calculated with the methodology, what happens? Is there a conflict?

 

#GRC #risk #ARA

 

1 REPLY 1

Harihara Subra1
ServiceNow Employee
ServiceNow Employee

Hi,

Risk appetite set on the Risk is considered while assessing the risk. The appetite set on the Risk statement and Entity are used to compare the Aggregated risk at the Entity level and the Risk Statement level.

So all the settings are valid. It is evaluated at different levels. Hope this is clear.

Thanks,

Hari