---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Risk Workspace for the IT risk manager

# Risk Workspace for the IT risk manager {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Information technology or IT risk is any threat to your business data and critical
systems. It is the risk associated with using and operating IT within an organization. An IT risk
manager is the primary person responsible for establishing and maintaining the organization-wide
IT risk management program.

IT risks vary in nature. It is important to be aware of all the different types of IT risks potentially affecting your business. An IT risk manager works with various stakeholders to confirm that IT risks are managed within the
risk appetite of the organization. To facilitate risk assessments for IT risk managers, a preconfigured risk assessment methodology (RAM) is also provided by default. IT risk managers can use this RAM or make modifications to it
according to their requirements.  
{#risk-workspace-for-it-risk-manager__table_syj_kcj_jpb__entry__2}

| Activity | Task |
|-|-|
| Identify risks using a workflow. | [Workflow for risk identification in the Risk Workspace](https://www.servicenow.com/docs/co3l8XxTuG80zPLhjMiFDQ "Workflows provide step-by-step guidance for completing the risk identification process in the GRC Risk Workspace."). |
| Identify, assess, mitigate, and monitor all IT risks. | * [Create a risk assessment scope in the Risk Workspace](https://www.servicenow.com/docs/UW4Fi5WhM3tsPQBvoQK6OQ "Create a risk assessment scope to identify risks for an entity, define assessors and approvers, set assessment frequency, and initiate assessments using the Risk Management application."). * [Schedule risk assessments in the Risk Workspace](https://www.servicenow.com/docs/obaZgVi56SEEZDaaBhB~qw "Schedule risk assessments automatically for multiple entities. The risk assessment scheduler helps the risk managers save time by automatically initiating the assessments based on the defined frequency."). {#risk-workspace-for-it-risk-manager__ul_mck_3sq_sqb} |
| Manage IT risk remediation actions and define the action plan. | [Managing risk responses](https://www.servicenow.com/docs/yInZbQ8OHmiNaQo3ZiCXZw "A risk response is the strategy used to deal with risks after the risks are assessed."). |
| Communicate the IT risk posture. | [Risk heatmap for classic risk assessment](https://www.servicenow.com/docs/bhF1ajB_kcxJq0vq7SgeCw "As an operational risk manager, if you opt to use the classic risk assessment to assess the risks in your organization, you can view the risk heatmap to get an overview of the risk posture for your organization."). |
| Define the key risk and control indicators. | [Risk indicators, control indicators, and indicator templates](https://www.servicenow.com/docs/fTsH9DVYtRzkrxNk9GCoTA "Indicators are an important tool used to manage your organization's risks. Indicators collect data to monitor controls and risks, and to collect audit evidence. Indicators monitor a single control or risk. They are used to enhance and facilitate the monitoring, mitigation, and reporting of risks.") |
| Create control test plans | [Create a test plan in Risk Workspace](https://www.servicenow.com/docs/rLdsPFzumg4r6rz4SjXTeQ "Create a test plan to document the control testing procedure. You can create a test plan from scratch or based on a test template to describe how a feature is to be tested.") |
[Table 1. Tasks of an IT risk manager]

{#risk-workspace-for-it-risk-manager__table_syj_kcj_jpb}

