---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Manage risks linked to the same risk statement

# Manage risks linked to the same risk statement {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Manage risks linked to the same risk statement

This feature enhancement allows ServiceNow customers to associate multiple risks with the same risk statement and entity combination, addressing the needs of organizations with both mature and less standardized risk taxonomies.
Previously, only one risk could be linked per risk statement and entity pair, which limited flexibility for customers with localized or diverse risk hierarchies.
Show full answer Show less  

## Key Features

* **Multiple Risk Associations:** Users can now link several risks to a single risk statement and entity combination, enabling more granular risk identification and management across different business units or lines of business.
* **Inherit from Risk Statement Option:** On the Risk form, selecting this option maintains the previous behavior---only one risk per risk statement and entity is allowed. If not selected, multiple risks can be categorized under the risk statement hierarchy.
* **Flexible Risk Taxonomy:** This option lets organizations define their risk taxonomy according to their specific needs, facilitating the alignment of local risks with enterprise-wide risk hierarchies.
* **Risk Naming and Description:** When multiple risks are linked under the same risk statement without selecting the inherit option, each risk must have a unique name and description, distinct from the risk statement itself.

## Benefits for ServiceNow Customers

* Enables better risk aggregation and scoring by allowing first-line risk owners to associate newly identified risks at appropriate levels of the risk hierarchy.
* Prevents creation of orphan risks that lack ownership or action by linking localized risks to enterprise risk taxonomies.
* Supports organizations with varying maturity levels in their risk programs, enhancing risk visibility and management efficiency.

## Practical Application

For customers managing risks such as those related to corruption, this feature allows defining broader risk statements (e.g., Corruption) while associating more specific risks (e.g., accepting a bribe) under the same entity. This ensures that detailed risks are captured, managed, and escalated appropriately within the enterprise risk framework.  
You can create and associate multiple risks to the same risk statement and entity
combination. This association benefits the risk managers and the entity owners.

Before the latest release, users could only associate one risk for a single entity and risk
statement combination. This ability was useful for customers who have a mature risk program with
a well-defined and standardized risk taxonomy. However, it did not meet the requirements of
customers who do not have a standardized risk taxonomy. Such customers usually have only two or
three levels of risk statement hierarchy while their actual risks are still local for each
business unit or lines of business. Also, when the first line identifies new risks, they
associate those risks to an enterprise risk hierarchy. This allows the new risk scores to
aggregate and impact the overall risk hierarchy. With the current release, a new option called
Inherit from risk statement is introduced on the Risk form. If this
option is selected, the risk creation happens in the previous manner. This means that there can
be only one instance of risk statement and entity combination. However, if this option is not
selected, the system allows the risk statement hierarchy to be used as categorization and
sub-categorization hierarchy and associates multiple risks to the same risk statement and entity
combination. This option also enables the first line to associate their newly identified risks to
the risk hierarchy at a level they want to. When this new option is not selected, the system
assumes that the name and description of the risk is overridden and must not be the same as the
risk statement name and description.

This feature benefits the risk manager as it allows the risk managers to define the risk
taxonomy according to the needs of their organization. It also benefits the entity owners to
identify risks for their entity and link them to enterprise risk taxonomy.  
To understand this feature, see the following image and consider the example. Most customers have risk statements defined until Corruption. Anything lower than Corruption such as accepting a bribe is defined as a risk as it is difficult to harmonize these risks across the organization. This feature of linking multiple risks to the same risk statement and entity enables customers to prevent the creation of orphan risks with no one acting on them.Figure 1. New risk statement hierarchy
**Related concepts**   

* [Workflow of a risk using Advanced Risk](https://www.servicenow.com/docs/Jt4zz8bc~m~UoPmUBaNRyw "When you migrate to advanced risk assessment, you can view the various states of the risks take the necessary actions. This ability simplifies your view of the risk form.")  
**Related reference**   

* [Risk hierarchy and scoring](https://www.servicenow.com/docs/EUsSeeOUa0iNQ50yr2d9Hg "Starting with New York, risk managers can create hierarchies that include different types of risk (operational risk, IT risk, or strategic risk). Once the underlying risks are assessed, the risk scores are automatically rolled up across the risk statement hierarchy, providing better tactical and strategic decision-making.")

