Integration of advanced risk assessment with other applications
Summarize
Summary of Integration of advanced risk assessment with other applications
This feature enables ServiceNow administrators to embed advanced risk assessments directly within other application workflows, automating the initiation of assessments based on defined rules. This digitization eliminates manual effort and allows event-driven risk assessments, providing timely and accurate insights into the organization's risk posture compared to periodic cyclic assessments.
Show less
Key Features
- Event-driven risk assessments: Automatically trigger assessments when specific events occur, enabling faster identification and response to risks.
- Integration with any application in your workspace: Administrators can configure risk assessment integration beyond the default Risk Workspace, allowing risk assessments to be initiated contextually within other applications such as risk events.
- Initiate risk assessment button: After configuration, users can start assessments directly from related records without manually creating risk assessment scopes.
- Flexible risk assessment methodology selection: While the primary RAM is preselected, users can choose other methodologies linked to the entity class of the risk during assessment initiation.
- Role-based assessor and approver assignment: Only users with specific roles (snriskadvanced.araassessor for assessors and snriskadvanced.araapprover for approvers) can be assigned. Approvers can be set dynamically, including automatically assigning the assessor’s manager.
- Overdue assessment management: Define the number of days after which assessments are considered overdue to maintain timely risk management.
- API support: Risk assessments can also be initiated programmatically, with risks added to scopes and frequencies managed as per scope settings.
Important Considerations
- Risk assessments cannot be initiated simultaneously for multiple risks if they belong to different entities or use different methodologies.
- Initiation is blocked if an assessment is already in progress for a risk.
- Assessments cannot be started if no risk assessment methodology is defined for the entity involved.
Practical Benefits for ServiceNow Customers
By integrating advanced risk assessments into various applications and automating their initiation based on events, customers can maintain a more accurate and current understanding of risk exposure. This integration streamlines workflows, reduces manual steps, and supports prompt corrective actions, ultimately enhancing risk governance and compliance efforts within the ServiceNow platform.
As an administrator, you can embed risk assessments within other workflows and define rules for when risk assessments must be initiated. The key benefit of embedding risk assessments is the digitization of the workflow so that assessments are initiated automatically without manual effort.
Prior to the San Diego release, you could perform risk assessments in a cyclic manner. This means that earlier risk assessments were performed only few times in a year and thus your risk posture reporting might not be accurate. To address this issue, you can now perform event-driven risk assessments. Event-driven risk assessments mean that when an event occurs, you can perform a risk assessment. Performing event-driven risk assessments help you to get a quick view of the actual risk posture and take the necessary corrective actions. You can integrate advanced risk assessment with any application and perform risk-based assessments in your workspaces. By default, ServiceNow® provides the integration of advanced risk assessment with risk events in the Risk Workspace.
To integrate risk assessment in an application in your workspace, you must perform the configuration steps given in the Risk assessment integration in workspace [KB0999135] article in the Now Support Knowledge Base. After you perform the configuration steps, you can see the Initiate risk assessment button.
Although you can integrate the Initiate risk assessment feature on any application in your workspace, this article uses risk events as an example. When you analyze a risk event and identify the relevant risks, you can easily initiate risk assessments for those risks by integrating the advanced risk assessment workflow in your risk events. This integration enables you to perform risk assessments without going through the entire process of creating risk assessment scopes. Prior to the San Diego release, for a risk assessor to perform a risk assessment, the risk user was required to create a risk assessment scope defining the entity, the assessor, and the approver.
When you initiate an assessment for a risk that is created for a risk event, although the risk assessment methodology (RAM) is set to the primary RAM of the entity class, you can select a different relevant risk assessment methodology. Only those risk assessment methodologies that are associated with the entity class of the selected risk are available for selection. You can then specify the assessor and approver for the risk assessment. Only users with the sn_risk_advanced.ara_assessor role can be the assessors and users with the sn_risk_advanced.ara_approver role can be the approvers. For more information on these roles, see Roles for performing advanced risk assessment. Earlier, the approvers were defined when the risk administrators created the risk assessment scopes. However, when you initiate a risk assessment from an application, you can specify the approvers at the time creating the assessment. You cannot change the approvers once you have specified them. If the approver is set as Same as assessor's manager, then the approver is automatically set depending on the assessor. You can also define the number of days after which the assessment will be considered overdue.
Even when you initiate a risk assessment from an application using the API, you can add those risks to the risk assessment scope at any time. After the risk is added to the risk assessment scope, the frequency of the assessment is based on the frequency defined in the risk assessment scope.
- If you select multiple risks and try to initiate the assessments at once. The reason for this is that different risks can have different entities and can have different risk assessment methodologies.
- If an in-progress risk assessment exists.
- If a risk assessment methodology is not defined for the entity for which the risk exists.