---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/pt-BR/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk assessments

# Risk assessments in Privacy Management {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

You can perform risk assessments on your processing activities to determine their risk
scores and find out the privacy risk posture of your organization.

To understand the risk posture, the following assessments are performed.

## Criticality assessments {#risk-assessments-in-privacy-management__section_dfz_j3c_d2c}

A criticality assessment uses risk assessment to determine the initial risk level of a processing activity. Using the resulting criticality score, the privacy team can prioritize or deprioritize the activity accordingly. An
example of a criticality factor could be that the assessment questions help identify whether personal data is being processed in a way that influences key decisions or enables impactful autonomous decision making.  
Criticality assessments can be performed using one of the following two methods.

Manual criticality assessment
:   Using the manual method, as a privacy manager initiates the criticality assessment from a processing activity. If you're already working on a processing activity and want to assess its criticality, you can manually
    trigger this assessment using the Assess criticality action in the user interface. When you trigger the criticality assessment, the system automatically calculates the criticality score based on
    the information already available in the fields of the processing activity form. On the Regulatory details tab of a processing activity, you can provide the risk-related details. After entering this information,
    triggering the criticality assessment uses these values to calculate the risk score. The system can calculate the criticality score multiple times if triggered manually. Each time, it uses the most recent data entered
    in the processing activity fields and regulatory details.

Automated criticality assessment
:   Using the automated method, the privacy manager uses the Automated criticality factors risk assessment methodology (RAM) that is provided by default to calculate the criticality score of a
    processing activity. The privacy managers must publish this RAM before it can be used. By default, the RAM is provided in the Draft state. When a user performs a screening assessment, they are
    prompted to respond to several questions, including those related to criticality and risk assessment. If the user provides answers to these criticality-related questions during the screening assessment, the system
    automatically calculates the criticality risk score. The calculated score is then displayed on the Overview page when the user proceeds to the processing activity. Because only two RAMs are supported at a time, they
    must deactivate any other existing criticality factors RAM. It is crucial to note that when an existing criticality factors RAM is deactivated, all the in-progress risk assessments associated with that RAM get
    canceled.

## Privacy risk assessments {#risk-assessments-in-privacy-management__section_imd_p3c_d2c}

Privacy risk assessments are detailed assessments that are conducted if the criticality score is high. Assess each risk that is associated with the processing activity and know the aggregated risk score on the processing
activity. After you assess the privacy risks, you can view the privacy risk posture on the risk heatmap in the overview section. The heatmaps provide detailed information about your inherent and residual risks. See the following
image to understand how you can initiate the detailed risk assessment.

## Risk heatmap scores {#risk-assessments-in-privacy-management__section_nyq_s3c_d2c}

The risk assessments results and the risk heatmaps appear on the processing activity home page as shown in the following image.  
Figura 1. Risk scores on a processing activity Figura 2. Risk heatmap on the processing activity

To understand the details about how to perform the risk assessments, see [Privacy assessment configurations](https://www.servicenow.com/docs/RadRJolKgVH9U674ftd3xQ "To perform a processing activity criticality and privacy risk assessment, two risk assessment methodologies (RAMs) are provided by default.").
* **[Risk Assessment Methodology (RAM)](https://www.servicenow.com/docs/jf6b8jTKJOCp6j227oTsRw)**   
  Risk Assessment Methodology (RAM) provides a systematic and repeatable approach to identifying, evaluating, and mitigating privacy risks associated with data processing activities.
* **[Privacy assessment configurations](https://www.servicenow.com/docs/RadRJolKgVH9U674ftd3xQ)**   
  To perform a processing activity criticality and privacy risk assessment, two risk assessment methodologies (RAMs) are provided by default.

