---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Request risk reduction for a vulnerable item or remediation task

# Request risk reduction for a vulnerable item or remediation task {#ariaid-title1}

Release version: Zurich  
Updated September 3, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read  
Request a reduction in risk for a host vulnerable item or a remediation task in the IT Remediation Workspace.

## Before you begin

Role required: sn_vul.remediation_owner

## About this task

Starting from v21.0 of Vulnerability Response, you can request risk reduction only for the following items:

* A remediation task only if all its vulnerable items are associated to the same Common Vulnerability Entry (CVE) regardless of whether its risk reduction is enabled for CVEs.
* A third-party (TPE) for which risk reduction is enabled.

{#request-risk-reduction__ul_zlw_1p4_21c}  
Note:  
The compensating controls feature is available for host vulnerabilities only.

A remediation task can include vulnerable items associated with more than one CVE or TPE. If risk change is restricted
for some of those CVEs or TPEs, you can still request risk reduction for the eligible vulnerable items. The Request Exception form shows how many of the selected items are eligible for risk change. If none of the selected
items are eligible, the form states that risk change is restricted and the request can't proceed.

## Procedure

1. Navigate to WorkspacesIT Remediation Workspace.
2. Select the List icon (![List icon]()).
3. On the List page, open a host vulnerable item or a remediation task.
4. Select the More options icon and select Request Exception.
5. On the Request Exception form, fill in the fields.  
   For a description of the field values, see[Request exception form for risk reduction](https://www.servicenow.com/docs/Mwkj279LV6fFuzM_Eqyeag "The following table shows the fields that you must fill on the Request exception form for risk reduction requests.").
6. Select Request Exception.
7. If a Take Questionnaire modal is displayed, answer the questions to provide additional information about your request and select Submit.  
   Note:  
   The Take Questionnaire modal appears only when the questionnaire is enabled for exception management. For more information, see [Configure Exception Management for Vulnerability Response](https://www.servicenow.com/docs/Jgwd1iACR_I6_Yf5JnVLSg "When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a vulnerable item (VI) or remediation task (RT) that cannot be remediated according to the policy.").

## Result

A message appears stating that your request is successfully submitted for approval. A notification is sent to the approver about your request.

* If your request is for a deferral and risk reduction:
  * Two state change approvals (VCA#) are created for deferral and risk reduction.
  * The state of the record changes to In Review.
  {#request-risk-reduction__ul_ip2_msk_zyb}
* If your request is for risk reduction only:
  * A state change approval (VCA#) is created.
  * The state doesn't change.
  {#request-risk-reduction__ul_x2s_n5k_zyb}

{#request-risk-reduction__ul_uhr_fqk_zyb}

On approval or rejection of your request, you'll receive a notification. For more information on the approval process, see [Approve or reject requests in the Vulnerability Manager Workspace](https://www.servicenow.com/docs/HTxH6Mc~xWADgatLF7Jq9g "Approve or reject requests that are submitted by remediation owners.").

For more information on how the Until date for risk reduction is updated for a remediation task and vulnerable item when a risk reduction request is approved, see [Impact of the compensating controls on risk score and expiration date](https://www.servicenow.com/docs/kvchkrutggx3Vwl52vO4TQ "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.").
**Related concepts**   

* [Understanding compensating controls for risk reduction](https://www.servicenow.com/docs/y51JfXKw~ptBSjGp66T7HQ "Compensating controls are the measures taken to reduce the risk posed by vulnerabilities that can't be patched immediately. They can be used to mitigate the likelihood or impact of a successful exploit.")
* [Impact of the compensating controls on risk score and expiration date](https://www.servicenow.com/docs/kvchkrutggx3Vwl52vO4TQ "As a Remediation Owner, you can request risk reduction for a host vulnerable item or remediation task. And the Vulnerability Manager or Analyst can approve these risk reduction requests.")  
**Related tasks**   

* [Restrict or enable risk change for a CVE or TPE](https://www.servicenow.com/docs/Wwedd2EZUxzzL~e8LLvshw "As a Vulnerability Manager and Analyst, you can restrict or enable risk change for the host vulnerabilities associated with a Common Vulnerability Entry (CVE) or Third-party Entry (TPE) in the Vulnerability Manager Workspace.")
* [Add a compensating control to the library](https://www.servicenow.com/docs/Xe0xnhFswV_MyoBPxfFeiQ "As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk reduction of host vulnerable items and remediation tasks.")

*[\>]: and then


