---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Assess risks of policy exception

# Assess risks of policy exception using advanced risk assessments {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Take the advanced risk assessment to evaluate the risk involved with the policy
exception.

## Before you begin

Role required: sn_compliance.manager

GRC: Advanced Risk is the required plugin for the integration with Advanced risk
assessment to assess risk using the advanced risk assessment feature.

## About this task

After the policy exception is submitted, as a compliance manager you can do the risk
analysis on the policy exception to evaluate its risk status and determine its
approval based on its risk impact on the policy.

## Procedure

1. Navigate to AllPolicy and ComplianceCompliance Workspace.
2. In the Compliance Workspace, click the List icon (![List]()).
3. Click All policy exceptions in the Policy exceptions list.
4. Click the link to the policy exception record, for which you want to assess the risk, in the Name column.
5. Select the Take risk assessment option in the Method field of the Risk assessment section.  
   For more information on the risk assessment options, see [Risk assessment](https://www.servicenow.com/docs/crtqC1hPFnT~AYAf_V5hkg#request-policy-exception-ws__take-risk-assess) section.
6. Click Save.
7. Click the Assess risk button.  
   You can assess the risk of a policy exception only when its state is Analyze.
8. Select a risk assessor and an approver in the Specify risk assessor and approver pop-up.  
   Any user with compliance user role or risk user role can be a risk assessor or an approver.
9. Click the Send assessment button.  
   Assessment is sent to the user selected in the pop-up. For more information, see [Assess risks and
   objects on an assessment instance](https://www.servicenow.com/docs/5YcyR656r4_c37kekjzTsw "Assess the risks that you have configured and reassign the risks to relevant approvers.").

   After the assessment is
   complete, the Risk rating field on the policy
   exception form is auto-populated with the values configured in Policy
   exception risk rating mapping table.
10. Click the Details tab.  
    The score calculated based on the risk assessment responses that you provided is mapped with the value in the Risk rating field.

*[\>]: and then


