Risk & compliance tab
Summarize
Summary of Risk & compliance tab
The Risk & compliance tab within the AI Risk and Compliance workspace provides ServiceNow customers with a comprehensive view of the risk classification and compliance posture for AI asset inventories. AI assets include AI systems, AI models, and datasets essential for AI development and operations. This tab helps organizations monitor, assess, and manage risks and compliance related to these AI assets, ensuring adherence to regulatory and organizational policies.
Show less
Key Features
- Risk Classification: Visualizes risk levels (High, Medium, Low, Unacceptable) for AI systems, models, and datasets using donut charts based on risk assessments.
- Compliance Overview: Displays compliance status based on controls for selected authority documents or policies. Users can view compliance scores, compliant and non-compliant counts, and related issues or AI cases.
- Risk Overview: Monitors aggregated risk scores for AI systems (High/Low) and provides a risk heatmap visualizing risks by control effectiveness and impact/likelihood. Heatmap filters include residual/inherent risk and Risk Assessment Methodology (RAM).
- Regulatory Landscape Overview: Requires the GRC: Regulatory Change Management app to display regulatory alerts, change tasks, and assessments by workflow state or life cycle phase.
- Managed vs Unmanaged AI Assets: Only Managed AI assets are included in dashboard metrics; AI stewards can mark assets as Managed or Unmanaged, influencing visibility and reporting.
Practical Use for ServiceNow Customers
- Gain clear visibility into AI asset risks and compliance posture to support governance and regulatory adherence.
- Filter and drill down into specific AI assets, authority documents, or policies for targeted risk and compliance insights.
- Identify immediate compliance issues and AI cases requiring attention to mitigate risk effectively.
- Leverage risk heatmaps and aggregated scores to prioritize risk management activities based on impact and control effectiveness.
- Integrate with Regulatory Change Management to monitor regulatory changes, alerts, and related assessments.
- Customize displayed authority documents and policies to align compliance monitoring with organizational frameworks.
Important Notes
- Dashboards only reflect Managed AI assets; Unmanaged assets remain visible in inventory but excluded from metrics.
- The authority documents provided are for guidance and setup assistance and do not constitute legal advice or guarantee regulatory compliance.
- Ensuring compliance with applicable laws and standards remains the customer’s responsibility.
The Risk & compliance tab on the AI Risk and Compliance displays the risk classification of an AI asset inventory and the compliance posture for the selected authority documents and policies.
AI assets refer to the various components and resources that are essential for the development, deployment, and operation of artificial intelligence systems. These assets can include:
- AI systems: The complete software or hardware infrastructure that runs AI algorithms and processes. This can include machine learning platforms, natural language processing systems, and other AI-driven applications.
- AI models: The mathematical and computational models that are trained on data to perform specific tasks. These models can range from simple linear regression models to complex deep learning neural networks.
- Datasets: The collections of data used to train, validate, and test AI models.
Understanding and managing these AI assets is crucial for ensuring that AI systems are effective, reliable, and compliant with regulatory and ethical standards as defined by your organization.
The Risk & compliance dashboard has the following sections. You can drill down into the data on each widget in any section.
Compliance overview
- Regulatory risk classification
- This section displays the risk classifications of AI systems, AI models, Datasets using donut charts. The risks are qualitatively classified as High, Low, Medium, and Unacceptable. These classifications are based on the risk assessments of the AI assets.
- Compliance by authority documents and policies
- The section shows compliance based on controls implemented.
You can choose to view compliance data by selecting one of two options: Authority Documents or Policies. Additionally, you can view the overall compliance score percentage, along with the number of compliant and non-compliant authority documents and policies, by using the drop-down filter to select specific authority documents or policies. You can also see all the issues that require immediate attention and AI cases related to each authority document or policy.
The authority documents are provided solely for informational and guidance purposes to assist with the initial setup of AI Risk and Compliance frameworks. It doesn’t constitute legal advice or assurance of regulatory compliance. You’re solely responsible for ensuring that all use of the content complies with applicable laws, regulations, directives, and industry standards in their jurisdictions.
Note:You can configure which authority documents and policies you want to display on the home page. For more information, see Set up properties for compliance posture.
Risk overview
This section monitors and tracks the risk posture of the AI assets in your organization. Using the AI asset filter, you can filter risk posture insights by the type of AI asset inventory.
- AI systems by aggregated risk score
- This section displays the classifications of AI systems by aggregated risk score using donut chart. The risk scores are qualitatively classified as High and Low.
- Risk heatmap
- The Risk heatmap widget displays the visualization of all identified risks within the AI assets. By default, a residual risk filter is applied, but you can filter it based on inherent risk level. The heatmap is segmented, and the segmentation changes based on the filter. The activities fall under the respective combination of risk and control effectiveness, or impact and likelihood. The combination is based on the selected risk classification filter. You can filter the risk heatmap by Risk Assessment Methodology (RAM), if you have more than one risk RAMs published.
Regulatory landscape overview
You need to install GRC: Regulatory Change Management application to see this section. For more information, see Installing Regulatory Change Management.
- Overview
-
- Alerts
This section displays the distribution of regulatory alerts by workflow state or life cycle phase using a donut chart.
- Change tasks
This section displays the distribution of regulatory change tasks by workflow state or life cycle phase using a donut chart.
- Alerts
- Assessments
- This section displays the regulatory impact assessments and risk assessments linked to regulatory changes using a donut chart. By default, the regulatory assessments filter is applied, but you can change it to risk assessments.
The following image shows the Risk & compliance dashboard.