---
sourceDocument: Brazil Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/governance-risk-compliance

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Managing risk responses

# Managing risk responses {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Managing Risk Responses

Managing risk responses in ServiceNow involves selecting and implementing strategies to address identified risks after assessment.
This process enables risk assessors to choose appropriate actions to handle risks effectively and assign tasks to responsible users based on their roles.
Show full answer Show less  

## Key Features

* **Risk Response Strategies:** Four primary strategies are available to deal with risks:
  * **Accept:** Acknowledge and accept the risk as is, with justification and approval.
  * **Mitigate:** Implement additional controls to reduce the risk impact or likelihood.
  * **Avoid:** Change plans to completely eliminate the risk.
  * **Transfer:** Share or transfer the risk to a third party.
* **Risk Response Tasks:** After selecting a strategy, risk response tasks are created and assigned to users with roles such as `sngrc.businessuser`, `sngrc.businessuserlite`, or `snrisk.implementationbusinessuser`.
* **Approval and Review Workflow:** Each risk response requires a plan submission and review by the risk manager (`snrisk.manager`), who can approve, reject, revert, cancel, or delete the response task.
* **Role-based Actions:** Risk owners and managers have defined responsibilities for approving acceptance, reviewing mitigation, avoidance, and transfer plans.
* **Risk Monitoring:** Accepted risks move to a Monitor state for the specified period, after which reassessment and response can be initiated again.
* **Limitations:** The risk response workflow is not applicable for object assessments.

## Key Outcomes

* Provides a structured approach to handle risks post-assessment, ensuring accountability and traceability of risk management actions.
* Enables continuous monitoring and re-evaluation of accepted risks to maintain up-to-date risk posture.
* Facilitates collaboration between risk assessors, owners, and managers through defined workflows and approval processes.
* Allows customization and flexibility in managing risk responses according to organizational policies and risk tolerance.  
A risk response is the strategy used to deal with risks after the risks are assessed.  
After risks are assessed, the assessor determines how to approach those risks. To deal with the risks, the assessor can choose from the following types of risk responses or strategies:

* Accept: Accept the risk as it is.
* Mitigate: Identify and implement additional controls to mitigate the risk.
* Avoid: Change the plan to completely avoid the risk.
* Transfer: Transfer or share the risk with a third party.
{#risk-response__ul_yjf_nhz_1qb}  
After an assessor identifies the appropriate risk response strategy, they can create risk response tasks and assign them to users with any of the following roles:

* sn_grc.business_user
* sn_grc.business_user_lite
* sn_risk.implementation_business_user (feature role)

{#risk-response__ul_irm_kgk_k3c}Each strategy is explained as follows:

Risk acceptance
:   When risk users accept a risk, they provide a plan for how they want to accept the risk, provide a justification for accepting the risk, and seek additional approval from the risk owner. Closure of the acceptance task
    implies you are accepting this risk for that time period. The risk then moves to the Monitor state. After the specified time period is over, you can re-initiate the workflow to assess the risk and then you can again
    respond to the risk. The risk owner can then respond with one of the following options:

    * Approve
    * Reject
    * Cancel
    * Request more information
    * Decide that it is no longer required
    {#risk-response__ul_fx2_vtz_1qb}

Risk mitigation
:   When risk users choose to mitigate a risk, a risk mitigation task is created. The risk user must provide a plan for how to mitigate the risk and request a review from the risk manager. When the risk mitigation task is in
    the Draft or Work In Progress state, you can either create more risk-mitigating controls for the risk or add existing controls from the library. The reviewer with the role sn_risk.manager then reviews the plan and selects
    one of the following options:

    * Close
    * Revert to draft state and provide additional comments
    * Cancel
    * Delete
    {#risk-response__ul_aw4_tzz_1qb}

Risk avoidance
:   When risk users choose to avoid a risk, they provide a plan for how they want to avoid the risk and request a review from the risk manager. The reviewer then reviews the plan and can select one of the following options:

    * Close
    * Revert to Draft state and provide additional comments
    * Cancel
    * Delete
    {#risk-response__ul_kb1_g11_bqb}

Risk transfer
:   When risk users choose to transfer a risk, they provide a plan for how they want to transfer the risk and request a review from the risk manager. The reviewer then reviews the plan and can select one of the following options:

    * Close
    * Revert to Draft state and provide additional comments
    * Cancel
    * Delete
{#risk-response__ul_utk_tb1_bqb}  
Note:  
The risk response workflow is not available for an object assessment.

