---
sourceDocument: Yokohama Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/governance-risk-compliance

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Create a Risk Assessment Methodology

# Create a Risk Assessment Methodology {#ariaid-title1}

* Release version: Yokohama
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Configure a risk assessment methodology (RAM) in the Privacy Management application so that you can assess the risks in your organization.

## Before you begin

Role required: sn_privacy.manager or sn_privacy.admin

## About this task

Create a standardized method to support risk-based decision-making across departments, projects, and systems. By using a RAM, your organization can have different methodologies for assessing risks.

After you move a RAM to the Retired state, you can also move it back to the Draft state if you want to make some changes later. You can only move a RAM to the
Draft state if it doesn't have any assessments in the Monitor state or the Closed state. When you move a RAM back to the Draft,
the on-going assessments and the associated scopes are deleted.

## Procedure

1. Navigate to AllPrivacy ManagementRisk AssessmentsRisk assessment methodologies.
2. On the Risk Assessment Methodology page, select New.
3. On the form, fill the details.  
   For a description of the field values on the risk assessment methodology form, see [Risk Assessment Methodology form](https://www.servicenow.com/docs/qJOuXP0qfsMRsH~N3eVegQ "Use the Risk Assessment Methodology form in the Advanced Risk application to specify the types of risk assessments and the entities on which the risk assessment is performed.").
4. Right-click and save the form.
5. To configure the various assessments, select one of the following options.

   | Choice | Related link |
   | Configure inherent assessment | See [Configure an inherent assessment](https://www.servicenow.com/docs/yac7gq8HDoXAmh2fQPUk9A "Configure and publish an inherent assessment in the Advanced Risk application to assess the inherent risks in your organization."). |
   | Configure control effectiveness | See [Configure a control effectiveness assessment](https://www.servicenow.com/docs/oNbBEVFR~epulUtBLifDRw "Configure and publish a control effectiveness assessment to assess the effectiveness of controls in mitigating risks.") |
   | Configure residual assessment | See [Configure a residual assessment](https://www.servicenow.com/docs/KM_cMhzrQSIz3Vi_kJBpUQ "Configure and publish a residual assessment in the Advanced Risk application to assess the residual risks in your organization.") |
   | Configure target assessment | See [Configure a target assessment](https://www.servicenow.com/docs/SYhvkUSd8W_E76lZD8tFNw "Configure and publish a target assessment in the Advanced Risk application to assess your desired future risk level. By configuring a target assessment, you enable the assessors and approvers to perform a target risk assessment in the Next Experience.") |
   |-|-|

   {#create-a-risk-assessment-methodology__choicetable_rjk_kfz_rnb}
6. Select Publish.  
   Note:  
   After a new assessment is created on the same risk and the assessment is in the Monitor state, the other assessments automatically move to the Completed state. When an assessment instance is in the Monitor state, you can't move the RAM back to the Draft state. A RAM can only be moved back to the Draft state if there are no assessment instances.

## Result

A new Risk Assessment Methodology is created and is available for use.
* **[Risk assessment methodology form](https://www.servicenow.com/docs/4JNIF9B4WXct4DQxen71oA)**   
  Use the Risk Assessment Methodology form in the Core UI to create a risk assessment methodology (RAM).

*[\>]: and then


