Understanding Risk Management The Risk Management product provides a centralized process to identify, assess, respond to, and continuously monitor Enterprise and IT risks that may negatively impact business operations. The application also provides structured workflows for the management of risk assessments, risk indicators, and risk issues. Who uses Risk Management? The complete risk process involves all areas of your organization working together. Audit committee IT steering committee Risk officers (conduct risk assessment and identify all that can go wrong in business) All levels of management (assist the risk officers with the identification of what can go wrong in their processes) Key activities for Risk Management Once key roles are identified, work together to identify the following items: Determine what level of risk the organization is willing to accept? Get risk data in place and then determine what is acceptable. Develop a risk management policy, through risk frameworks and risk statements. Develop risk assessment and response procedures. Implement controls to reduce your organization's exposure to risk. Repeat on a regular interval. Measure your risk exposure and improvements. Risk Management and the NowPlatform Because the Risk Management application is built on the Now Platform, data and evidence is provided back to Risk Management. Activate Risk ManagementThe GRC: Risk Management (com.sn_risk) plugin is available as a separate subscription.Configure Risk ManagementAdministrators in the global domain can set properties to determine how the system defines the Risk Management application.Establish profile scoping for risksUnderstanding how various parts of the organization are related to each other provides a more comprehensive risk assessment process. Stakeholders can discern how risks in different parts of the organization and at different levels of the organization impact each other. The scoping of profiles is permitted in each of the GRC applications, but the GRC Workbench, which provides a visual presentation of those dependencies, is only activated for use with Risk Management.Manage risks, risk statements, and risk frameworksThe risk library contains all risk frameworks and risk statements. Risk frameworks are used to group risk statements into manageable categories, while risk statements group the individual risks. The risk register is the central repository for all potential risks that could occur at anytime, anywhere in the organization.Manage profile and risk dependencies using the GRC WorkbenchThe GRC Workbench utilizes CMBD information to show the upstream and downstream relationships across all applications. These relationships enable consistent risk mapping and modeling across the enterprise. The GRC Workbench does not work with Legacy GRC.Manage risk indicatorsContinuous monitoring involves activities related to identifying and creating key risk and control indicators. Supporting information can be collected for those indicators through automatic data collection or manual tasks. Indicator results are then used to create issues for controls, update risk scores, and provide supporting information for audit activities and control testings.Manage risk issues and remediationIssues can be created manually to document audit observations, remediations, or to accept any problems. They are automatically generated from indicator results, attestation results, or control test effectiveness.