---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Manage continuous monitoring for risks between Risk Management and Vulnerability Response

# Manage continuous monitoring for risks between Risk Management and Vulnerability Response {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Manage continuous monitoring for risks between Risk Management and Vulnerability Response

This feature integrates ServiceNow Governance, Risk, and Compliance (GRC) Risk Management with Security Operations Vulnerability Response to enable continuous monitoring of high-impact vulnerabilities based on business impact.
It helps risk administrators, managers, and users quickly identify critical vulnerabilities affecting business services, assess their impact on risk posture, and streamline remediation efforts.
Show full answer Show less  

## Key Features

* **Business Services Entity Type:** A new entity type called *Critical Business Services* identifies impacted critical services with vulnerabilities older than two weeks. This entity is inactive by default and must be enabled.
* **Real-Time Data Exchange:** When activated, Risk Management (IRM) and Vulnerability Response (VR) exchange vulnerability data, business service context, risk issues, and remediation status in near real-time.
* **Data Visibility:**
  * Vulnerabilities from VR appear on IRM risk dashboards and are linked to risk records.
  * IRM dashboards highlight business services affected by vulnerabilities, helping prioritize remediation based on criticality.
  * Risk issues derived from vulnerabilities show in IRM and are linked back to VR for remediation tracking.
  * Remediation progress is viewable in IRM dashboards, while VR remains the source of truth for remediation actions.
* **Automated Risk Issue Creation:** Vulnerability Response automatically creates or updates risk issues in IRM as vulnerabilities are ingested and matched to indicator templates.
* **Dashboards for Stakeholders:** Both risk and security teams receive notifications and have dashboards reflecting business impact and remediation progress respectively.

## Practical Steps for Activation and Configuration

* Activate both Risk Management and Vulnerability Response plugins in System Administration.
* Create indicator templates in Risk Management to represent key vulnerabilities and their business impact.
* Activate and associate the *Critical Business Services* entity type with risk statements and indicator templates to link business criticality.
* Configure Vulnerability Response to ingest vulnerability data and map findings to business services.
* Test integration by triggering vulnerability scans and verify that risk issues appear promptly on IRM dashboards.

## Benefits for ServiceNow Customers

This integration enables comprehensive, continuous risk monitoring by linking vulnerability data with business impact context, allowing risk and security teams to prioritize and address high-impact vulnerabilities efficiently. Customers can expect improved visibility into how vulnerabilities affect critical services, faster notifications of risks, and coordinated management of remediation activities through synchronized dashboards in both Risk Management and Vulnerability Response applications.  
Continuous monitoring for risks is a feature integration between the GRC: Risk Management and the Security Operations
Vulnerability Response products, which uses indicators to quickly identify high impact
vulnerabilities based on business impact.
Risk administrators, managers, or users can monitor critical vulnerabilities by viewing the direct effect on risk posture. A new Business Services entity type and indicator templates automatically identify impacted services that are critical, represent a loss of availability, and are greater than two weeks old. These high-risk vulnerabilities can result in a breach and possible loss of intellectual property.  
Note:  
The Entity type called 'Critical Business Services' is set to inactive by default and must be turned on.

## Data Visibility Between Risk Management and Vulnerability Response {#continuous-monitoring-risk__section_data_visibility}

When continuous monitoring is activated and configured, Risk Management (IRM) and Vulnerability Response (VR) systems exchange data in real-time. The following table clarifies where updates are visible in each system:
{#continuous-monitoring-risk__table_data_visibility__entry__3}

| Data Type | Visible in Risk Management (IRM) | Visible in Vulnerability Response (VR) |
|-|-|-|
| Vulnerability Data | Vulnerability issues from VR appear on IRM Risk dashboards and linked to relevant risk records. Vulnerability metrics (age, severity, affected services) update in near real-time on IRM indicators and dashboard widgets. | VR issues display as individual records in the standard VR interface with vulnerability scan data, severity, and remediation status. |
| Business Service Context | IRM dashboards display which Business Services are impacted by vulnerabilities, enabling risk managers to prioritize remediation based on business criticality. | VR issue records linked to Business Services show the associated risk context through related records and can display IRM risk statement associations. |
| Risk Issues | Risk issues created from high-impact vulnerabilities appear in IRM risk records and risk registers. | VR users can view linked Risk records to understand the broader risk context and organizational response to identified vulnerabilities. |
| Remediation Status | IRM dashboards show remediation progress tracked in VR, allowing risk managers to monitor mitigation activity. | VR issue records are the source of truth for remediation actions and timelines. |
[Table 1. Data Visibility Map]

{#continuous-monitoring-risk__table_data_visibility}

## Continuous monitoring for risk workflow {#continuous-monitoring-risk__section_ars_qs3_l2b}

1. The system admin activates the Risk Management and Vulnerability Response plugins.  
   Note:  
   Both plugins must be active for data synchronization to occur. Verify plugin status in System Administration \> Plugins.
2. The risk administrator creates risk statements and indicator templates that represent key vulnerabilities and their business impact.
3. The risk manager associates the Critical Business Services entity type to the risk statements and indicator templates. This step links business criticality to vulnerability monitoring.  
   Note:  
   The Critical Business Services entity type is set to inactive by default and must be activated before it can be associated with risk statements. Activate in System Definition \> Entity Types.
4. The Vulnerability Response application ingests vulnerability data from security scanners and related tools, automatically categorizing findings by affected business services.
5. As vulnerabilities are identified and matched to the configured indicator templates, the system automatically creates or updates Risk Issues in IRM. These appear on IRM dashboards and in the Risk register within seconds of VR ingestion.
6. Risk and security teams are notified of high-impact vulnerabilities through their respective dashboards. Risk managers can view vulnerability details in IRM context; Security Operations teams manage remediation in VR.
7. Dashboards in both systems provide an up-to-date view for business stakeholders as risks are identified and remediated. IRM dashboards show business impact; VR dashboards show remediation progress.
{#continuous-monitoring-risk__ol_lff_ss3_l2b}

## Activating and Configuring Continuous Monitoring {#continuous-monitoring-risk__section_activation}

To enable continuous monitoring between Risk Management and Vulnerability Response:

1. Navigate to AllSystem AdministrationPlugins and verify that both com.snc.grc.risk (Risk Management) and the appropriate Vulnerability Response plugin are active.
2. Navigate to AllRiskSetupIndicator Templates and create indicator templates for the vulnerabilities you want to monitor.
3. Associate the Critical Business Services entity type to your risk statements. Navigate to AllRiskSetupRisk Statements, open a risk statement, and add the Critical Business Services entity type in the Entity Associations section.
4. Configure vulnerability ingestion settings in Vulnerability Response to map vulnerability data to your business services.
5. Test the integration by triggering a vulnerability scan or import. Verify that Risk Issues appear on your IRM dashboards within the expected time window.

*[\>]: and then


