---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Report an Operational vulnerability from the Importance assessment

# Report an operational vulnerability from the Importance assessment {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Report an operational vulnerability from the Importance and impact assessment in the Operational Resilience Workspace.

## Before you begin

Role required: sn_oper_res.manager

## About this task

To create an Operational vulnerability from the assessment record, you can use the Operational vulnerability related list in these records. This example shows creating a vulnerability from the Importance and impact tolerance assessment record. When you associate an assessment record to
the Operational vulnerability record, the related area for the vulnerability is displayed in the Related areas related list.

When a vulnerability is reported, it is opened in the New state, marking the beginning of its initial review.

## Procedure

1. Navigate to WorkspacesOperational Resilience WorkspaceImportance and impact tolerance assessment.  
   A list of the available assessments is displayed.
2. Select an assessment from the list.  
   The Importance and impact tolerance assessment record with Operational vulnerabilities related list is displayed.
3. Check the state of the Importance and impact tolerance assessment.  
   If the state is in the Assessment received state, you cannot add a vulnerability at this stage as shown in the example. You can add or remove the vulnerability before the vulnerability is in
   the Assessment received state.

   You can create an Importance and impact tolerance assessment record and then add a vulnerability.
4. Create an Importance and impact tolerance assessment record and save it.
5. Add a service to the Importance and impact tolerance assessment record.  
   The service record is shown in the example.  

   When the service is added to the Importance and impact tolerance assessment record, you can add the operational vulnerability and the New button is displayed in the Operational
   vulnerabilities related list.
6. Select New in the Operational vulnerabilities related list and add an operational vulnerability.
7. On the Vulnerability New record form, fill in the fields.  
   The source of the vulnerability is the Importance and impact tolerance assessment. Therefore, the Source field on the form shows the source as Importance and impact assessment and the
   Source table field on the form shows the table as Importance and impact tolerance assessment.

   To view more information on the fields, see the [Create New Operational vulnerability form](https://www.servicenow.com/docs/5aD83bcJ5u4LB54gsVhBwA "On the Create New Operational vulnerability form, fill in the fields.").
8. Select Save.  
   The Vulnerability record is saved. When you associate the Importance and impact tolerance assessment to the vulnerability, the related area is created as shown in the example.

   You can add another related area to the vulnerability.
{#create-op-vul-from-other-records-in-or-ws__steps_mqj_mls_tcc}

*[\>]: and then


