---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Roles installed with Risk Management

# Roles installed with Risk Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Roles installed with Risk Management

Activating the GRC: Risk Management application in ServiceNow installs a set of predefined roles, each with specific permissions tailored to different responsibilities within risk management processes.
These roles enable users to access, create, manage, and administer risk-related data and tasks efficiently, supporting comprehensive risk governance.
Show full answer Show less  

## Key Roles and Their Capabilities

* **Risk Reader \[snrisk.reader\]**: Provides read-only access to risks, indicators, entities, risk events, and dashboards. Users can act on assigned issues, remediation tasks, and indicator tasks, as well as perform advanced risk assessments and create risk events.
* **Risk User \[snrisk.user\]**: Builds on the Risk Reader role by allowing creation of risks, working on risk acceptance and remediation tasks, and accessing advanced risk dashboards. Users can view entity types, controls, policy exceptions, and have read-only access to Policy and Compliance Management modules.
* **Risk Manager \[snrisk.manager\]**: Includes all Risk User privileges plus the ability to create issues, entity types, content references, indicators, risk frameworks, risk statements, remediation tasks, and assessment schedulers. Managers can also associate risk statements with information objects and access related dashboards.
* **Risk Admin \[snrisk.admin\]**: Encompasses all Risk Manager permissions and adds administrative capabilities such as deleting risk frameworks and records, modifying risk criteria, creating causes and consequences of risk events, configuring feedback integration, and managing advanced risk properties and assessment methodologies.
* **Assessment Creator \[snrisk.asmtcreator\]**: Focuses on creating GRC risk assessment metric types, supporting assessment design and configuration.
* **GRC Business User \[sngrc.businessuser\]**: Enables users to take risk assessments, create response tasks, view risk data and reports, respond to indicator tasks and questionnaires, report issues, and work on assigned remediation and issue tasks. This role also supports integration with Project Portfolio Management for viewing project risk dashboards and managing enterprise risks.

## Practical Benefits for ServiceNow Customers

These roles allow ServiceNow customers to:

* Assign precise access levels to users based on their risk management responsibilities.
* Enable efficient collaboration on risk identification, assessment, remediation, and monitoring.
* Ensure controlled creation, modification, and deletion of risk-related data and configurations.
* Support integration with other GRC and project management modules for holistic risk oversight.
* Maintain security and data integrity by restricting actions according to role permissions.  
Roles are added with activation of GRC: Risk Management.
{#r_RolesInstallWRisk__table_gtf_wpk_qjb__entry__3}

| Role title \[name\] | Description | Contains roles |
|:-|:-|:-|
| Risk Reader \[sn_risk.reader\] | In addition to the inherited permissions, the risk reader has read-only access rights to the Risk application and modules. The risk reader can do the following in the GRC scope: * Act on issues assigned to him. * Have read access to all Indicator templates. * Can act on indicator tasks assigned to them. * Have read-access to indicators. * Have read-access to entities. {#r_RolesInstallWRisk__ul_ipr_fld_d4b} The risk reader can do the following in the Risk Management application: * Act on the Remediation tasks assigned to them. * Have read-access to risks. * Take old risk assessment. * Have read-access to risk statement and risk framework. * Perform advanced risk assessment. * Create risk events. * Work on risk event tasks and issues. * Access all risk events and risk dashboards. * Have read-access to feedback. {#r_RolesInstallWRisk__ul_acj_ymd_d4b} | * sn_grc.reader * survey_reader * sn_rvw_feedback.reader {#r_RolesInstallWRisk__ul_psx_cqk_qjb} |
| Risk User \[sn_risk.user\] | Contains the reader and business user roles in sn_grc scope, and the reader role in the Risk Management application and business user role in the sn_grc scope. In addition to the inherited permissions, the risk user can view: * entity types * entities * risks * remediation tasks * control * control objectives * policy exceptions {#r_RolesInstallWRisk__ul_tks_mch_znb} The risk user can also create risks. The risk user can be assigned risks and has read-only access to the Policy and Compliance Management application and modules. Risk user can do everything that the risk reader can do. The risk reader can do the following in the Risk Management application: * Work on risk acceptance tasks and remediation tasks. * Create risks. * Access the Advanced Risk related dashboards. * Have read-access to the risk identification functionality of Advanced Risk and can take assessment related to risk identification. * Create assessment scope. {#r_RolesInstallWRisk__ul_uh5_rmd_d4b} | * sn_grc.user * sn_compliance.reader * sn_risk.reader * survey_reader * sn_grc.business_user * sn_risk_advanced.ara_creator {#r_RolesInstallWRisk__ul_jbt_lbh_znb} |
| Risk Manager \[sn_risk.manager\] | Contains the reader, user, and manager roles in sn_grc scope, and the reader and user roles in the Risk Management application. In addition to the inherited permissions, the risk manager can do the following in the GRC scope * Create issues and issue ratings. * Create entity, entity types, and entity classes and class rules. * Create content references. * Create indicators and indicator templates. * Have read-access to entity tier. {#r_RolesInstallWRisk__ul_qct_fpd_d4b} In the Risk Management application, the risk manager can: * Create risk frameworks * Create risk statements * Create risks * Create risk event response template. * Create risk identifications and can view the dashboard related to risk identification. * Create remediation tasks. * Create assessment scheduler. * Associate risk statements to Information objects using Associate risk statements module. {#r_RolesInstallWRisk__ul_gp5_r2h_znb} | * sn_grc.manager * sn_risk.user {#r_RolesInstallWRisk__ul_gsx_cqk_qjb} |
| Risk Admin \[sn_risk.admin\] | Contains the reader, user, manager, and admin roles in sn_grc scopes, and the reader, user, and manager roles in the Risk Management application. In addition to the inherited permissions, in the GRC scope, the risk admin can create an entity tier. In the Risk Management application, the risk administrator can: * Delete risk frameworks. * Delete entity, tables, indicator, risks, issues, tasks. * Create risk statements and risks. * Modify admin properties. * Modify risk criteria. * Create causes and consequences of risk event. * Access to risk, advanced risk related properties. * Create risk identification configuration. * Create a risk assessment methodology, all types of factors. * Perform administrative activities. * Configure a feedback integration setup for any record type. {#r_RolesInstallWRisk__ul_ecc_v2h_znb} | * sn_grc.admin * sn_risk.user * sn_risk.manager * sn_grc_appr.admin * sn_rvw_feedback.admin {#r_RolesInstallWRisk__ul_prx_cqk_qjb} |
| Assessment Creator \[sn_risk.asmt_creator\] | The assessment creator is used for creating GRC risk assessment metric types. | assessment_admin |
| GRC Business User \[sn_grc.business_user\] | Users with this role can perform the following tasks: * Take risk assessment. * Create risk response tasks. * View risk statements. * View risk assessment scope. * View and report risk events. * Work on assigned risk event tasks. * View indicator supporting data. * Respond to indicator tasks. * Respond to risk identification questionnaire. * Respond to metrics data tasks. * Report issues. * Submit issue triage requests. * Work on assigned remediation tasks. * Work on assigned issues. * If there is an integration with Project Portfolio Management: * View the Project Risk Overview dashboard * Create risks from library. * Elevate enterprise risks. * Initiate any object assessment. {#r_RolesInstallWRisk__ul_bhd_cnh_gtb} {#r_RolesInstallWRisk__ul_ykp_5dh_gtb} | None |
[Table 1. Roles installed]

{#r_RolesInstallWRisk__table_gtf_wpk_qjb}

