<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question How does 'Risk Assessment' result(s) affect Inherent &amp;amp; Residual impact/likelihood scores? in New Customers - Policy Risk forum</title>
    <link>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2817799#M514</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;A bit new in GRC Risk space.&lt;/P&gt;&lt;P&gt;I'm trying to understand how does Risk assessment process affects the Inherent &amp;amp; Residual risk scores, but I'm pretty mych confused:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I've tried so far&lt;/P&gt;&lt;P&gt;1. Created dummy 'Risk Statement' record (associated random Inherent and Residual values)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_0-1707273076206.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327822i84FC4ABCD70A11ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_0-1707273076206.png" alt="Valqe_0-1707273076206.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Generated Risk records through 'Entity Type' (Windows Servers) and as a result got my 'Risk' records created:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_1-1707273194297.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327823i779158FB3BBE3028/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_1-1707273194297.png" alt="Valqe_1-1707273194297.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I'm then completing 'Risk Assessment' process for individual 'Risk' records, &lt;STRONG&gt;but no matter what I'm puttin on risk assessment answers the&amp;nbsp;Inherent &amp;amp; Residual impact/likelihood scores are remaining the same as on the risk statement above.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_3-1707273463518.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327825i0188190C2972D616/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_3-1707273463518.png" alt="Valqe_3-1707273463518.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I would prefer to see inherent and residual scores affected when risk assessment is negative.&lt;/LI&gt;&lt;LI&gt;I would prefer this assessment to change Risk Overview dashboard heatmap resutls (Inherent Risk Heatmap and Residual Risk heatmap) but it doesn't&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;P.S. When I fail associated control attestations then &lt;U&gt;calculated score gets affected&lt;/U&gt;, but again not the inherent or residual impact/likelihood score.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your comments and any guidance.&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2024 02:45:00 GMT</pubDate>
    <dc:creator>Valqe</dc:creator>
    <dc:date>2024-02-07T02:45:00Z</dc:date>
    <item>
      <title>How does 'Risk Assessment' result(s) affect Inherent &amp; Residual impact/likelihood scores?</title>
      <link>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2817799#M514</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;A bit new in GRC Risk space.&lt;/P&gt;&lt;P&gt;I'm trying to understand how does Risk assessment process affects the Inherent &amp;amp; Residual risk scores, but I'm pretty mych confused:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is what I've tried so far&lt;/P&gt;&lt;P&gt;1. Created dummy 'Risk Statement' record (associated random Inherent and Residual values)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_0-1707273076206.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327822i84FC4ABCD70A11ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_0-1707273076206.png" alt="Valqe_0-1707273076206.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Generated Risk records through 'Entity Type' (Windows Servers) and as a result got my 'Risk' records created:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_1-1707273194297.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327823i779158FB3BBE3028/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_1-1707273194297.png" alt="Valqe_1-1707273194297.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I'm then completing 'Risk Assessment' process for individual 'Risk' records, &lt;STRONG&gt;but no matter what I'm puttin on risk assessment answers the&amp;nbsp;Inherent &amp;amp; Residual impact/likelihood scores are remaining the same as on the risk statement above.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Valqe_3-1707273463518.png" style="width: 999px;"&gt;&lt;img src="https://www.servicenow.com/community/image/serverpage/image-id/327825i0188190C2972D616/image-size/large?v=v2&amp;amp;px=999" role="button" title="Valqe_3-1707273463518.png" alt="Valqe_3-1707273463518.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I would prefer to see inherent and residual scores affected when risk assessment is negative.&lt;/LI&gt;&lt;LI&gt;I would prefer this assessment to change Risk Overview dashboard heatmap resutls (Inherent Risk Heatmap and Residual Risk heatmap) but it doesn't&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;P.S. When I fail associated control attestations then &lt;U&gt;calculated score gets affected&lt;/U&gt;, but again not the inherent or residual impact/likelihood score.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your comments and any guidance.&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 02:45:00 GMT</pubDate>
      <guid>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2817799#M514</guid>
      <dc:creator>Valqe</dc:creator>
      <dc:date>2024-02-07T02:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: How does 'Risk Assessment' result(s) affect Inherent &amp; Residual impact/likelihood scores?</title>
      <link>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818349#M515</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/344245"&gt;@Valqe&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Firstly, welcome to the risk world in IRM.&lt;/P&gt;
&lt;P&gt;What you are using is the Classic Risk management, where the Risk Score Rollup doesn't happen, which means&amp;nbsp;&lt;STRONG&gt;Inherent &amp;amp; Residual impact/likelihood scores will remain the same as on the risk statement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ratings are of three kinds: qualitative, semi-quantitative, and quantitative.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 id="d161335e38" class="title sectiontitle"&gt;Qualitative rating&lt;/H2&gt;
&lt;P class="p"&gt;Qualitative risk assessments rely on the assessor's perceptions of the probability and impact of a risk. If the method is purely qualitative, then the ratings are based on the list values such as high, medium, or low. In this case, the risk scores do not roll up. Because this method has minimal mathematical dependency, qualitative risk assessment is easy and quick to perform. This method also enables an organization to take advantage of the assessor's experienced knowledge of the process or asset that is being assessed. Users who are new to risk assessments usually use this kind of rating.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="d161335e61" class="title sectiontitle"&gt;Semi-quantitative rating&lt;/H2&gt;
&lt;P class="p"&gt;In a semi-quantitative rating, the qualitative ratings also have a corresponding numerical scale. For example, if the quantitative risk score is between 0-10, then the qualitative rating is low. Users who use this type of rating are not new to risk assessments. Most users belong to this category. In this category, the risk scores roll up and the risk appetite is qualitative in nature.&lt;/P&gt;
&lt;P class="p"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="d161335e84" class="title sectiontitle"&gt;Quantitative rating&lt;/H2&gt;
&lt;P class="p"&gt;A quantitative risk assessment focuses on data that is fact-based, measurable, and highly mathematical. In a quantitative risk rating that uses advanced simulation techniques, the risk is quantified in purely numerical terms. In this category, the risk appetite is quantitative in nature. &lt;EM&gt;&lt;STRONG&gt;You can choose only one Scoring type for Classic risk&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;The Risk Scoring Calculations for classic risk is as follows:&lt;/H3&gt;
&lt;DIV&gt;The inherent and residual scores for risk are calculated using the risk criteria, likelihood, and impact.&amp;nbsp;Use the following calculations to score risks:&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;Qualitative Inherent ALE = Inherent ARO x Inherent SLE&lt;/LI&gt;
&lt;LI&gt;Qualitative Inherent Score = Inherent Likelihood x Inherent impact&lt;/LI&gt;
&lt;LI&gt;Quantitative Residual ALE = Residual ARO x Residual SLE&lt;/LI&gt;
&lt;LI&gt;Qualitative Residual Score = Residual SLE&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When scoring is set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;qualitative&lt;/EM&gt;, the quantitative values are updated in the background.&lt;/P&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Calculated Score&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for risk is a read-only field designed to quickly assess a risk affecting the organization, and identify threats and areas of non-compliance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If controls are implemented to mitigate risk, then&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Calculated ALE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;=&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Residual ALE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;+ ((&lt;STRONG&gt;Inherent ALE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Residual ALE&lt;/STRONG&gt;) * (&lt;STRONG&gt;Calculated Risk Factor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;/ 100)).&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;So:&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;Calculated Score = Residual Score&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;only if Compliance with the controls is 100%.&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Calculated Score &amp;gt; Residual Score&lt;/STRONG&gt;, the organization is not 100% compliant with the controls used to mitigate risk.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meaning that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Calculated Score&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can never be less than the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Residual Score&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or greater than the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Inherent Score&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If controls are not implemented to mitigate risk, then&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Calculated Score = Residual Score&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Residual Score&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is not set, then&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Calculated Score = Inherent Score&lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The calculated risk factor value is calculated as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Calculated Risk Factor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;= (&lt;STRONG&gt;Indicator failure factor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;+&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Control failure factor&lt;/STRONG&gt;) / 2&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Control failure factor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;gt; Sum of failed controls weighting divided by total controls weighting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Indicator failure factor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&amp;gt; Uses the last result of each associated indicator. The number of last results failed divided by the total number of indicators associated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to see the scoring should gets affected based on Inherent, residual and control effectiveness, then you will have to move to Advanced Risk Management, Where the Risk Rollup happens, with the use of &lt;A href="https://docs.servicenow.com/bundle/washingtondc-governance-risk-compliance/page/product/grc-risk/task/configure-ram.html" target="_self"&gt;RAMs&lt;/A&gt; and &lt;STRONG&gt;Risk Statements has NO contribution.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.servicenow.com/bundle/vancouver-governance-risk-compliance/page/product/grc-risk/concept/risk-rollup-ara-concept.html" target="_self"&gt;Risk score rollup in Advanced Risk Assessment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 10:30:11 GMT</pubDate>
      <guid>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818349#M515</guid>
      <dc:creator>Community Alums</dc:creator>
      <dc:date>2024-02-07T10:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: How does 'Risk Assessment' result(s) affect Inherent &amp; Residual impact/likelihood scores?</title>
      <link>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818625#M518</link>
      <description>&lt;P&gt;Hi&amp;nbsp;@Community Alums&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much and I really appreciate your comprehensive response. This is very useful.&lt;/P&gt;&lt;P&gt;Before I close this post and accept the solution I came up with three questions, I hope you can help please:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Since heatmap reports depend only on "Impact" and "Likelihood" values, then from what I'm understanding "Inherent Risk Heatmap" and "Residual Risk Heatmap" are not so dynamic if you're not using advanced risk. They solely depend on initial 'Risk Statement' values rather than from assessed risk results. Am I correct on this statement?&lt;/P&gt;&lt;P&gt;2) If I continue utilizing&amp;nbsp;&lt;STRONG&gt;non&lt;/STRONG&gt; advanced risk, is there a way of creating "Assessment" records which once responded&amp;nbsp; on "Risk Assessment" record they will affect risk's Impact and Likelihood values?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Is advanced risk (RAM) the only way to take (dynamic) advantage of Inherent/Residual Heatmap reports from "Risk Overview" dashboard? I ask this since such reports exist even before 'Advanced Risk' is enabled, yet so far, at leased based on my limited understanding, they solely depend on initial 'Risk Statement' values rather than from 'Risk Assessment' responses?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Thanks a lot.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:10:25 GMT</pubDate>
      <guid>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818625#M518</guid>
      <dc:creator>Valqe</dc:creator>
      <dc:date>2024-02-07T13:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: How does 'Risk Assessment' result(s) affect Inherent &amp; Residual impact/likelihood scores?</title>
      <link>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818686#M519</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://www.servicenow.com/community/user/viewprofilepage/user-id/344245"&gt;@Valqe&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Thanks for your questions, but this calls for another question as your original question has been answered, request you to raise another question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2024 13:37:07 GMT</pubDate>
      <guid>https://www.servicenow.com/community/new-customers-policy-risk-forum/how-does-risk-assessment-result-s-affect-inherent-amp-residual/m-p/2818686#M519</guid>
      <dc:creator>Community Alums</dc:creator>
      <dc:date>2024-02-07T13:37:07Z</dc:date>
    </item>
  </channel>
</rss>

