---
sourceDocument: Zurich Governance, Risk, and Compliance
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/governance-risk-compliance

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Workflow of Advanced Risk Assessment

# Workflow of Advanced Risk Assessment {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

To use Advanced Risk Assessment, you must set up the risk assessment methodology (RAM),
define the assessment scope, and perform the assessment.

Before using Advanced Risk Assessment, different users must perform different setup tasks.
These steps define the workflow of the assessment.

1. Set up the risk assessment methodology (RAM): A risk administrator with the sn_risk.admin role sets up the system. The administrator does the following:
   * Identification: Identifies if a risk or an object is being assessed.
   * Assessment: Determines how to assess the issue, such as with assessment criteria, risk scoring, or reporting preferences.

   {#workflow-ara__ul_xzp_22x_jlb} For more information, see [Configure a risk assessment methodology](https://www.servicenow.com/docs/VuTLZdQSKreQ6DIChweFDg "Configure a risk assessment methodology (RAM) in the Advanced Risk application so that you can assess the risks or objects in your organization.").
2. Define the risk assessment scope: After the RAM is defined, the entity owner defines and identifies the following:
   * The relevant risks for the entity.
   * The assessors and approvers for those assessments.
   * Periodicity of those risk assessments.

   {#workflow-ara__ul_pph_p2x_jlb}For more information, see [Create a risk assessment scope and initiate assessments](https://www.servicenow.com/docs/uRMmloXkyBs4RB_lK9DlHg "Create a risk assessment scope to define and identify risks for an entity. Identify assessors and approvers for assessments, and define the frequency of assessments.") or [Create a risk assessment scope in the Risk Workspace](https://www.servicenow.com/docs/UW4Fi5WhM3tsPQBvoQK6OQ "Create a risk assessment scope to identify risks for an entity, define assessors and approvers, set assessment frequency, and initiate assessments using the Risk Management application.").
3. Perform risk assessment: The risk assessor with the sn_grc. business_user role performs the following assessment tasks.
   * Assesses the inherent risks and the effectiveness of mitigating controls.
   * Reviews the residual risk and defines the risk treatment plan.
   * Perform a target risk assessment to define your desired future risk level.
   * Triggers the review and approval workflow.

   {#workflow-ara__ul_phb_t2x_jlb}For more information, see [Perform advanced risk assessment in the Risk Workspace](https://www.servicenow.com/docs/rYBKb5kGECsV_OZ_qs4PiA "Conduct risk assessments to assess inherent risks, effectiveness of controls, residual risks, and target risks in the Risk Workspace application. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.").
4. Monitor the assessments: After the risk assessment is approved, the assessment moves to the Monitor state. The risks assessed in the risk assessment must be monitored especially if it contains automated factors. Automated factors or questions that automatically fetch data from any of the data sources have ever-evolving risk ratings. Therefore, a risk which may currently have a low rating might have a higher rating later. This makes it imperative to monitor a completed assessment to reduce threats to your organization.
{#workflow-ara__ol_mvl_45s_rnb}

