Risk Management Complete Lifecycle based on Role

Sumit Anand
Kilo Contributor

I would like to understand out of box Risk Manangement Workflow based on Role. we are working on Qualitative approach. 

I am penning down my understanding on Risk Management.

 Risk is either Created from Risk Statement or it is created manually and it has following state :  "Draft", "Assess", "Respond", "Review", "Monitor" and "Retired

  1. Which Role will start the workflow ?  is it Risk Manager  in OOB workflow ? 
  2. Who will move Risk from Draft to Assess ? 
  3. Once Risk Moves to Assess it generates an Assessment, which assessment respondent has to fill . Assessment resposndent are ideally Entity Owner/Risk Owner ? 
  4. After Assessment are filled by Entity owner/Assessment Respondent. who will populates liklihood and impact ? i can see these likelihood and impact fields are manual which implies Risk assessment are only there for reference .
  5. who is responsible for responding  ? is it Risk Manager or Risk Owner ? 
  6. Once you respond to a risk , Risk Response task is created and assigned to Risk Owner? 
  7. In Related links section who will link related controls ? 
  8. Once Risk is Reviewed it comes to Monitor state i believe post which we can use Advanced Risk Assessment to Assess Risk periodically . How does Risk Assessment impact risk Overall Ratings ? 

 

Bascially i want to understand Out of box Workflow for Risk Management  ?

Do we have complete demo from Risk Creation and Approval and then Performing RCSA using Advanced Risk Assessment ?

I have attended demo on Advanced Risk Assessment by Mr Uttkarsh Jain which gave a good understanding on  Advanced Risk Assessment (RCSA) .

Do we have similar demo for complete life cycle ? 

 

find_real_file.png

1 ACCEPTED SOLUTION

Ashutosh Munot1
Kilo Patron
Kilo Patron

Hi,

Check this out about the life cycle of RISK:

find_real_file.png

Well explain here:

https://docs.servicenow.com/bundle/orlando-governance-risk-compliance/page/product/grc-risk/referenc...

 

We have multiple ways how the risk is generated. We have integration with other tool to generate risk as well. Auditors are also one of the Source to create or indicate risk, which will be mitigated by our RISK managers

Thanks,
Ashutosh

View solution in original post

3 REPLIES 3

Ashutosh Munot1
Kilo Patron
Kilo Patron

Hi,

Check this out about the life cycle of RISK:

find_real_file.png

Well explain here:

https://docs.servicenow.com/bundle/orlando-governance-risk-compliance/page/product/grc-risk/referenc...

 

We have multiple ways how the risk is generated. We have integration with other tool to generate risk as well. Auditors are also one of the Source to create or indicate risk, which will be mitigated by our RISK managers

Thanks,
Ashutosh

Sorenrv
Tera Contributor

Hi Sumit, did you ever receive a good reply to your questions? I see that the only reply here is related to Risk Events which was something you did not ask about specifically. Please share your present understanding of the Risk Lifecycle, i.e. your original post's questions, because I have some of the same questions, one of them being: How and by whom will the Inherent and Residual risk values be updated on the Risk record, based on the values in the Risk Assessment response?

Thanks a lot in advance,

Soren 

sam47
Tera Contributor

It is Risk manager's role to identify the risks, perform risk assessment ,manage risk responses and create risk indicators. 

Risks can either be created manually or as a result of an indicator failure on a control.