Delegation of risk assessment
Summarize
Summary of Delegation of risk assessment
Delegation of risk assessment in ServiceNow enables a risk assessor to appoint another user as a delegate to perform risk assessments on their behalf when they are unavailable. This delegation is time-bound and allows the delegate to fully manage the risk assessment tasks during the specified period, ensuring continuity in risk management processes.
Show less
Key Features
- Delegates can perform risk assessments from both the Risk Workspace and the Risk Portal.
- Delegates receive all system notifications originally sent to the primary assessor.
- The assessment record displays both the original assessor and the delegate’s names, maintaining clear accountability.
- Delegates must have the snriskadvanced.araassessor role to perform risk-based assessments.
- Only individual users, not groups, can be assigned as delegates.
- Delegates can reassign tasks, view ongoing assessments for the original assessor, create issues, and initiate risk response tasks with approval requests.
- All delegate activities are captured in the activity stream for audit and tracking purposes.
- Delegates count as licensed users and their usage is tracked within GRC licensing.
Practical Notes for ServiceNow Customers
- Delegation is limited to performing assessments; approval of risk assessments cannot be delegated.
- To enable delegation, configure your user profile to display and manage the Delegates related list.
- The original assessor’s name remains visible in the Assessor field, while the delegate is shown in the Assessor’s delegates field.
Benefits
This delegation functionality ensures that risk assessments proceed smoothly even if the original assessor is unavailable, maintaining compliance and risk oversight without interruption. It supports clear role assignment, accountability, and audit tracking, all essential for effective governance, risk, and compliance (GRC) management within ServiceNow.
If a risk assessor is unavailable to perform a risk assessment, the assessor can appoint a delegate to perform the risk assessment for a specified time period. The ServiceNow AI Platform enables you to appoint your delegates.
Delegation is the assignment of authority to another person to perform specific activities. It is a process of entrusting work to another person. In the context of risk assessments, at times, it may happen that the assigned assessor for a risk assessment is unavailable to perform their risk assessments. In such a scenario, the assessor can assign another user as a delegate and the delegate can perform the risk assessment on behalf of the original assessor for a specified time period. A delegate can perform the risk assessment from the Risk Workspace and the Risk Portal. A delegate also receives a copy of all the system notifications that are sent to the original assessor. Once the delegate starts performing the assessment, the delegate's name is visible on the assessment instance.
As a risk assessor, to understand how you can assign a delegate, refer to Configure a delegate for your tasks.
To delegate tasks to another user, configure your user profile form to display the Delegates related list. For details, refer to Add the Delegates related list.
- The ability to assign a delegate is only available to perform an assessment. You cannot assign a delegate for approving a risk assessment.
- After a delegate is assigned an assessment, the assessment shows the names of the original assessor as well as the delegate.
- You can only assign an individual user as a delegate and not a group.
- A delegate must have the sn_risk_advanced.ara_assessor role to perform risk-based assessment.
- A delegate must have the sn_risk_advanced.ara_assessor to perform any object assessment.
- All delegates are considered licensed users and are tracked for their GRC usage.
- When the delegate logs in to perform the risk assessment on behalf of the assessor, the original assessor's name remains in the Assessor field. The new field Assessor's delegates displays the name of the delegate.
- The delegate can reassign the task to another user.
- The delegate can view the on-going assessments for the original assessor under Tasks in the Workspace.
- The delegate can create issues.
- The delegate can create risk response tasks and request approval.
- All activity performed by the delegate is captured in the activity stream.