Vancouver |
- Target risk assessment in Advanced Risk
- Do a target risk assessment to determine the desired risk level that you want to achieve. By evaluating the desired level of likelihood and impact of the identified risks, you can allocate a target risk level for each risk
and assess your target risk posture and monitor its progress.
For example, when assessing a risk, you consider the inherent risk, the effectiveness of controls, and the residual risks. However, you can also capture the
desired risk level that you want to attain after your risk response is implemented. The target risk is the optimum risk level that you want to achieve after your action plan is successfully executed. By determining the
target risk level, you can measure the benefits that your organization gets in relation to the cost of implementing those actions.
- Enhanced configurability of the Advanced risk assessment form
- Modify the Advanced risk assessment forms based on the unique organizational requirements without requiring customization of the interface in the ServiceNow
Next Experience. The latest enhancements enable you to do the following tasks:
- Assess the control environment without adding controls, and override the computed scores on the assessment form. This enhanced workflow provides your assessors with greater flexibility when assessing the overall control
environment. For more information, see Perform advanced risk assessment in the Risk Workspace.
- Rename the section title, score label, and annual loss expectancy label for each assessment type in the Risk assessment methodology (RAM) form. This customization improves clarity, consistency, and understanding during
risk assessments by aligning with familiar terminology that reflects the risk management practices of an organization. For more information, see Configure a risk assessment methodology.
Note: Section label renaming applies only to the Advanced Risk Assessment interface while the terminology in the reports, dashboards, heatmaps, and other areas are
unchanged.
- Modify the messages and text that are displayed on the Risk assessment form. For more information, see Modify Advanced Risk messages.
- Configure the RAM form to restrict assessors from selecting multiple risk responses while performing an assessment, so that only a single risk response is allowed. For more information, see Configure a risk assessment methodology.
Note: This option can be enabled only when there are no ongoing assessments.
- Write scripts to calculate the residual score that is based on the inherent risk and control effectiveness. You can create a customized calculation method that aligns with the unique requirements of your organization.
For more information, see Configure a residual assessment.
Note: You can write or modify scripts only for assessment types that aren’t published.
- Define the conditions to make the risk response as required on the assessment form by using a conditional builder and scripts. For more information, see Configure a risk assessment methodology.
- Playbook integration with risk assessment scope and risk assessment scheduler
- Create a risk assessment scope and schedule risk assessments with a guided experience by the playbook integration. Each stage within the playbook includes one or more activities that must be completed, providing a structured
approach to the risk assessment scope and risk assessment scheduler. The playbook guides you through each stage, recommending the necessary activities, and ensuring comprehensive coverage of the workflow. Stages can also
include automated activities, such as auto-sending an email to the assessor when you initiate an assessment. By using a playbook, you can visualize the entire life cycle of the Risk assessment scope and Risk assessment
scheduler workflow. For more information, see Create a risk assessment scope in the Risk Workspace and Schedule risk assessments in the Risk Workspace.
- Risk heatmap enhancements
- The latest risk heatmap enhancements enable an operational risk manager to visualize the risk details and gain a better understanding of the entity risk posture. The following enhancements have been made:
- The heatmap includes the display of color names or risk severity information for individual heatmap cells. The color names or risk severity information is derived from the Risk color style field.
This field is configured in the assessment type for the selected methodology.
- The heatmap automatically adjusts its size to fit in the available space, which reduces the need for additional scrolling.
- Bulk response and approval of metric data tasks
- Use the grid interface to respond to the multiple metric data tasks that are assigned to you from the Risk Workspace and Employee Center. Approvers can use this interface to review and approve the metric data tasks in bulk. By using the grid interface, you not only save time but also elevate the overall satisfaction of users
when responding to and approving the metric data tasks.
|
Washington DC |
- Parallel Review and Feedback in Advanced Risk
- Enable your second and third-line managers to become active participants in first-line activities by digitizing the review and feedback workflows. They can provide feedback on a record or fields in a record to recommend
improvements that are related to data integrity, compliance, operational procedures, and other areas such as disposition and accountability. For example, a risk manager can provide feedback by requesting a root cause analysis
task from the first-line risk user and also ask them to capture additional loss entries for the same risk event. With parallel review and feedback, your managers can perform the following actions:
- Provide feedback at any stage of the workflow.
- Update the feedback responses directly from the source record by using the side-panel feature.
- View and manage the feedback workflows that are raised against the records from a centralized dashboard.
- View the change history, which enables a quick comparison of the pre-feedback and post-feedback.
- Reopen the feedback if the responses are deemed unsatisfactory.
- Monitor the feedback and follow up with the record owners through an intuitive dashboard.
- Collaborate effectively with the reviewer, respondent, and other stakeholders through a sidebar discussion chat.
- Initiate and link further actions as outcomes of the feedback, such as creating an issue or linking to an existing one.
- Configure a feedback integration setup for any record type, including the custom tables where you can define the table or record type to create feedback from.
Important: The Parallel review and feedback feature is only available in Next Experience.
- Generating a report in Microsoft Word
- Use the Management Reporting of Risk application to create reports in Microsoft Word that are based on the information that is available in the ServiceNow AI Platform. Risk managers can create reports independently, using real-time data, without relying on administrators. Also, report generation is enabled by one-click updates of the report data directly from the ServiceNow AI Platform.
- Exporting risk heatmap information
- Download or copy the risk heatmap information to include in reports or share with relevant stakeholders as needed.
Important: The copy and download of heatmap information is only available in Next Experience.
- Enhanced object-based assessment
- Configure a risk assessment methodology (RAM) for multiple objects without having to select only one assessment object. You can reduce the additional effort to manage multiple methodologies for different objects. You can
compare and report the data to promote enhanced data accessibility and coherence.
Risk administrators can also add multiple RAMs for a single object. For example, a compliance case table can be assessed using separate
criteria for IT and corporate compliance, which enables a comprehensive understanding of risks across different domains.
- Auto save feature in the risk and control assessment form
- Improve the experience of performing advanced risk assessment with auto-save. When assessors respond, the application saves their responses and calculates the overall risk score. It significantly reduces the number of clicks
required, which improves efficiency and the overall employee engagement.
Important: The auto-save feature is only available in Next Experience.
- Bulk approval and reassignment of risk assessments
- Approve multiple risk assessments simultaneously, which significantly reduces the time that your team spends on individual approvals. Workflow efficiency is enhanced, especially when you're dealing with a high volume of
assessments. An approver or an assessor can easily reassign multiple risk assessments to different stakeholders or team members.
- Adding risks and controls from the library
- Create and manage the risks and controls within the designated workflows by eliminating unnecessary navigation. Your team can do the following tasks:
- Add controls from a control taxonomy by using the Create from control objective option during control assessment.
- Identify and create ad-hoc controls by using the Create control option when responding to risk mitigation tasks.
- Add the controls from control taxonomy by using the Create from control objective option when responding to risk mitigation tasks.
- Identify and map the risks from risk taxonomy by using the Create from risk statement option while defining the risk assessment scope.
- Enhanced user experience in Advanced Risk
- Streamline your processes with the following enhancements:
- Use the Comments field to provide a brief response for the group factors in Risk Workspace. You can configure the comments from the group factors in the RAM form.
- Eliminate the need for assessors to navigate manually through the entire page to locate the areas that require attention. When moving to the next assessment stage on the risk assessment form, the application
automatically scrolls to the unresponded factors.
- Reassign the in-progress assessments in bulk to new assessors in the absence of the current assessor. This feature helps to redistribute assignments, especially in cases of restructuring or emergency medical leave, and
enables bulk reassignment as needed.
- Initiate a sidebar discussion for the risk event and issue record types. Your team gets a dedicated space to discuss events or issues. This space enhances the clarity and efficiency in the risk management processes.
- Use the Reviewer field on the risk response task page to inform the assessor about the reviewer's details.
- Use drop-down options for factor choices on the risk assessment form to enhance readability.
- Enable a horizontal layout for factor choices on the risk assessment form to minimize scrolling.
- Use a simplified navigation with a single breadcrumb trail from the advanced risk assessment homepage to the main page. Your team doesn't need to open multiple tabs.
- Use a vertical list view that is grouped by the related list for a manual, automated, and calculated metrics definition record.
- Collapse section headers within the advanced risk assessment to reduce scrolling on the advanced risk assessment page and optimize the screen space for accommodating more content.
|