logo

NJP

Learn about Risk Management

Import · Mar 30, 2022 · video

all right i see the numbers slowing down why don't we go ahead and go through uh some of these tips so welcome everybody we're really excited to have you join us good morning good afternoon or good evening depending upon where and when you're joining us um i know some of you are even joining us on demand which is wonderful um we are here to talk about risk management and i'm joined with my co-worker udkar cars would you like to introduce yourself hi everyone nathan i'm part of product management team at servicenow and i'm responsible for everything around risk and advanced risk so those are my passion areas too and glad to be here today thank you my name is teresa law i am the director of product marketing for the risk products we have got a jam-packed session for you we want a lot of interaction please ask questions we want to know what you're thinking we will do our best to try to answer as many as possible as a q a button on the bottom of your screen please use that um i will be jumping in with questions as we go along we're going to start out with a very brief overview of some of the other sessions that we're going to be hosting in the next month this is part of a series um we're starting out with risk management today but later this week we're going to talk about privacy management so please mark your calendars for that the beginning of april next week after we'll be talking about vendors management and we're very excited to be joined by one of our integration partners ecovatus and then we're going to finish up with policy and compliance on the 8th we might be sneaking another one in at the very end for business continuity management um so be on the lookout for that but i believe that is it again please utilize your q a button the session is being recorded so um be aware of that it will be up on the ask the experts channel on youtube shortly after the event so if you're looking forward again please look for that and i'll put a link in the chat for that playlist so you'll be able to find it and without further ado i'm going to turn it over to utkarsh to walk us through some really cool stuff um purpose management thank you teresa and i think like i said this is a really exciting release for me so the san diego new look and feel of the entire application it's something that i have been waiting for personally when i initially saw the designs i was very excited about it and i think now it looks more modern no need and some of the good things that we have really done around the san diego release is having these workspaces integrated so something we released last september and i'm just showing that across so you can see these new workspaces that are there so if you are a user who has multiple workspaces you can see that it's quick to navigate to a particular area you can mark certain things as favorites to say this is something i want to go about and even this home page design right it is something that is the first thing right when i log into the system i can see the tasks that are assigned to me approvals so it's really bringing in a lot of great information to me up front and that simplifies the navigation a lot from what we were used to and i love this new purple color the dark theme effect that is really good to the eyes in the night specifically so a lot of good things in the san diego family release you can make it black too you make the background black also if you wanted to yeah i mean so it's really very configurable but yeah i like the fact that the workspace is there if you click on workspaces you'll get a list of all the different workspaces so you can jump between workspaces really easily that i mean i think i think they did a nice job on that absolutely tessa and the icing on the cake is all the new features that on top of what we have done right so so you're getting a lot more new features in all the applications across the board here so you can so for example in risk i'm really excited to talk about some of these today for example the new heat map workbench which you see on the left hand side so this is something where released uh in the september release of our where we released the new heat map which is based on seismic but now you have a much more neat it's very very sleek user interface that you get along with san diego family so it's really great there i'm also excited to talk about the first line integration so one of the questions i was always getting from all the partners customers and even internal sales is what's our ux strategy right how can we ma how can we embed risk and compliance into the first line workflows and i think our integration with employee center is setting us there right so it's actually a spot on in terms of how employees how you want your grc activities and tasks to be embedded for employee then making sure they can complete their task across so really interesting bit of things that we have done there there's also a new application all together so in fact this is a application that we released last year in our esg offering so i know this is still on esg still on pilot mode but now metrics is being used for monitoring your kris and kcis so that you can manage your reg status and monitor your key risk and controls more effectively delay define the elect mechanism and stuff like it so i'll showcase some of this today right when i talk about it but i know everybody is waiting for one thing and it is really that support for more than one entity class in risk assessment methodology so i think all of you whosoever has interacted with me has given this feedback that they have been facing this as a challenge during implementation where customers are saying we want to apply the risk assessment methodology to more than one entity class so that's available to you too as well right so a lot of great things to talk about and without further ado i would like to go into the details and maybe showcase some of this today would that be interesting to see teresa for you and uh i think it would be fantastic yeah i'm actually really i'm excited about it i've been uh looking at some of these features the last few days and they look really really really nice yeah absolutely so let me show the first one which is really the heat map right it's a new look and feel on the heat map and for that what i'm going to do is i'm going to login into my environment to because i always find it better to actually do live demos than the actual powerpoints i think i think seeing it live is great but this heat map is actually really very very very useful honestly i mean i didn't realize that you could change it so that you could see the the actual risks yeah that was that was pretty slick so if you look at this now visualization so there's a shortcut here so the idea is you get a quick summary on like a dashboard or a home page and that's from where you can launch this heat map workbench which is like the full page view and the intention behind this is really you are walking into a room of senior management and executives and you don't want to create a powerpoint you want to take this system and go across with you so that when you go into a room and talk about let's talk about our risk profile for our organization so now typically your conversation will start on the top right zone so you can see these are there are 14 address so a lot of times your conversations will start around there and people would say hey let's go through each risk one by one understand what is happening around it and that is where we have developed an immersive mode where you can see what those 14 are and as soon as you go into immersive mode the system understands this is where you want to kick start your conversation around this record or around this risk it brings all the different information around this risk so for example what's my risk rating trend both inherent and residual what's my description about this risk what so who's the owner of this risk if there are kris risk events issues or the hierarchy what is there so so all of this information really helps you have that conversation where if somebody has a question if this risk is high what are we doing about it you can go check that across or did this risk really materialize for us in the last six months yeah it did because you had risk events here right so so those are the kind of things and a lot of times you would go and talk about how what what was the discussion point last time and that's where you can look at the activity log see all the comments that you made last time when you were reviewing this risk with your senior management and then capture them this time across as well to say next time when i come i should have a history of what we have done so this is how you can look at the details a lot of times you may want to pull an additional details or additional context and that's where you have actions on the top to actually see the complete 360 degree view of this risk so this is gonna launch our cool 360 degree visualization so that you can analyze all these details around this risk come back to it on the workbench or maybe open up the assessment too if you need to right so so this is how you can look go have a conversation with your senior management there you can also do once you're done with this particular zone you can move to the next one maybe next thing they want to look at is the high impact risk with a likely uh likelihood right so you can go into the second one and if you see the system highlights the one that are in bold and everything as grey is grays out but then it is still clickable so that you can see those here too right so so that's how the you can have that conversation even without creating a powerpoint you can always go back and let's say if you are now maybe sharing it across for some reason yeah yeah the nice thing is all on one page so you know think about the number of clicks that you've eliminated of having to go go to all the different pages to be able to pull this information up it's it's phenomenal absolutely and that was the purpose behind it when you're having this conversation you don't want to click multiple things lose context of things you want to focus on that risk bring everything together there so this is the question here is are we looking at a risk instance so i think i think it has yeah that is correct yes and a lot of times you may want to just look at it from an aggregated perspective too right so so that's why you can toggle between different views so you have the name view you have the index view depending on how much of information you want to see or what's your communication mechanism generally so again in this view here if you just mouse over a lot of times you may want to see what this 2 2027 is and you have the same information on the right by the way so so you have the full card for you to understand that context make sense of it what my2027 is if you are if you want to see or toggle between an inherent and a residual profile you can do this here too and obviously compare and contrast the different viewpoints across the organization so this is mainly from an operas perspective i can always switch to a different context let's say in this case i have a methodology which is servicenow erm and if you see it adjusted from a three by three matrix to a five by five matrix here right so how how quickly you can toggle between these different viewpoints compare and contrast things and if you're looking for a particular risk let's say in this case here i'm looking for a risk around let's say ide as my risk category i can simply type in i t and it will show me all the risk that are matching the risk category as id for me right so so really simple to use in terms of creating those filters if you have advanced filters you can always apply them here similar to the way you are doing on the list view here you can say yeah i want to look at maybe risk around a particular entity right so you can always type in that entity saying the accessible entities acme branch banking right and you you and you can filter on different departments or division divisions absolutely yeah i've got a few questions that come in you know one of them was we already answered it you know you can change it for a five by five or a six by six or a three by three it's very configurable you can filter on different departments or divisions can you use this for quantitative or only qualitative so generally heat maps are morely used for all qualitative risk assessment it's not really used for quantitative risk assessment so so that's why this one is focused on the qualitative side that's true awesome so you can always save this filter too so next time around i don't have to apply or build my conditions to say these are the data that i want to look at i can simply save my my heat map and when i when i'm back next time around i can simply go to my saved list here and i can see the different views that i'm always used to looking at so the system remembers what you have done so that you can always apply those views next time around when you're there yeah and i think um just to remind people the way you got here was from your dashboard you had your heat map on your dashboard you just clicked on the icon went into the heat map um workbench absolutely absolutely so this is the first thing that really excites me because it simplifies the reporting it it really brings your communication of risk posture very easily to senior management and a lot of times this is the key visualization that is being used by customers so we wanted to make sure we are providing the best-in-class visualization to our customers and delighting them when they are having that experience across and and you know you use the ui builder to build the the workbench but you don't have to you don't you did it comes with the product right you don't have to have the customers not building it themselves yes absolutely it comes out that's exactly so that's a question and then really question our last question i see for heat map here is can you share this because you want to share it with your team or with others is there a way to to share the information uh not as of today but that is certainly as a roadmap item we are tracking terrorism so there was a lot of feedback from customers so earlier we were thinking of sharing this as a pdf but when we did our research we figured out the need is a bit more right rather than just taking a print of it so what we are planning to do is maybe integrate with the powerpoint or pdf so that you can have your heat map along with the text along with some additional reports and things like that so look at it like maybe servicenow enterprise risk management report which is a 30 page document and that is going to be automated so that is what we are looking to do in the future releases that that sounds fantastic well we will wait to see how it manifests itself absolutely well i don't see anything i have no more questions on heat map great great thank you guys for asking the questions we really appreciate all the interaction always always it's always good to have it interactive rather than being a one-sided affair always yeah and the second thing which is improving your risk monitoring again is really metrics so so we have been getting a lot of feedback and a lot of customer needs to say how do we manage our redempt green thresholds in the system easily so we are really leveraging our indicators capability primarily for it earlier or we were actually using our performance analytics to position such kind of red ember green but both have their challenges while indicators didn't have really thresholds performance analytics indicators were too cumbersome for business managers and business risk managers or operational risk managers to define so we we heard you we we analyzed what you need so what you are doing is we are releasing a net new capability now which we are calling it as matrix and the objective is for your kri and kci monitoring this is what we're gonna use primarily right since this is a new concept i'll use maybe a couple of slides just to set the context up and then i'll switch into the system to talk about what uh how do you actually do end-to-end lifecycle of the metrics so so in terms of the business problem like i said it's really around the indicators that we got feedback that the indicators do not really fulfill all the use cases that we hear from customers around reg metrics so there was a definite need there was a definite gap and we also realized currently a lot of our customers were using indicators more for continuous control monitoring and continuous control assessment so from a future direction perspective what we're going to do is reposition our indicators so indicators will always exist in the product but metrics will be used more for krs and kcis kind of use case so so in terms of the key features right there a lot of unique features in metrics in comparison to indicators and in fact i have a slide which clearly differentiates between the two because i know there are a lot of confusion around these so so what we are trying to do is we are trying to position our indicators capability more towards continuous control assessment continuous control uh testing kind of use case while your metrics will be used for krys and kcis and therefore it's very very quantitative driven so there's no notion of pass and fail it's a numeric number that you are collecting and based on that value you are comparing with the thresholds and targets that you have defined to say where do you stand and then we're going to have integration with a flow designer to make sure when you have these breach of thresholds you can define your action plan to say what are you doing in order to manage that breach of threshold and also maybe the initiate risk assessment as an action plan for you so those are the capabilities in terms of making sure you are able to monitor your key risk and controls and also take actions as you see the risk and the control profile changing right so obviously this will allow you to automate and digitize your complete kri and kci management workflows and because of the power of the servicenow platform you can obviously use this capability not to not just to collect data within servicenow but even outside service now so that if you have let's say kris which are fetching in information from maybe sap system workday system and other enterprise platforms you can always leverage our automated metrics to collect those kind of information from those areas or if you want to start small which is normally through a manual process you also have a review and approval workflow for you to define to make sure before the data the manual data is getting published somebody is reviewing it and somebody is providing a sign off it across so that's really an end-to-end comprehensive workflow that you get as part of the metrics for functionality and in order to further automate in order to further reduce the mundane tasks that customers were doing when they were managing their metrics one of the insights we got is a lot of time if there's a metric let's say or a kri around let's say number of customer incidents now i'm watching that metric across different product lines but i want to also watch it from an aggregated enterprise risk perspective to say how are we doing for let's say servicenow as a whole so what the system does is it automatically does that aggregation too so that you don't have to create that metric at multiple levels so you can monitor these metrics at a granular level and automatically it would pull up the information at an aggregated level to say what's happening in an enterprise level so really a lot of exciting stuff and this is available to all irm professional and enterprise customers so so in terms of the packaging that that's the packaging that is available to you for the metrics application all right we want to see it now absolutely let's do that so i'll just flash one slide just to compare and contrast the indicators and metrics and then i'll move into the live demo so if you see uh these are the features that we had for indicators obviously there's an overlap with metrics because some of the core functionalities remain the same but if you see the delta the specific set of features which are specific in indicators and those are aligned to more continuous control assessment so have we haven't brought it to matrix but then there are a lot of new features that you only get as part of the metric functionality that we are relieving right so so so this is what you will get and typically this is the kind of report customers are looking to get out of the kri and let me show you how do you do it in the system now yeah it really complements yeah really complements our indicators which are so powerful the indicators are so powerful so this is the system so so here's a here's a metric like an indicator template let's say just to draw some analogies so so we call it as a metric definition so this is like a template of the metric that you're defining this is generally done by the second line who is saying if you in order to monitor this risk or maybe a group of risk this is the kri that we are tracking so you define what your kri is so so you can provide all the details around the kris such as the name description whether it's a manual one or an automated one who the owners are right from in the ownership of a metric as well as who the data owners are of this metric right so because this is a manual ki it means somebody is going to provide that data task so you can always assign that ownership across so that you have a net to hold in case there's a breach of this metric and somebody wants to understand what's happening around it right and you'll also be able to add attributes such as whether the metric is gonna be a leading metric or a lagging metric so generally customers like to classify their kris and kcis by that you can also define what's my strategy around it right is it something that we are looking to minimize as a value or is it something that we are looking to maximize as a value and that has a bearing on the thresholds so when you go and define your thresholds out which by the way can vary period on period so you're not restricted to just one threshold but you can define multiple thresholds for all the future periods so imagine your sales target i know every quarter we have different sales target that we set for our sales team as an example so i'm sure customers would like to do the same when they want to do their ember and threshold as well as the target value so you can do that here and the the the point is generally if it's a minimize kind of a metric that uh if you're looking to minimize the metric your red threshold will be generally be higher than your ember threshold but if it's a maximized kind of a metric it would be vice versa so that's why there's a business validation in place to make sure you're inputting the right set of data here and maintaining that so this is how you can create a metric set it on an autopilot mode so like always you can say the go collect information on a monthly basis or on a quarterly basis and these are the users who to whom these tasks will be sent across and then these are the approvers who are going to review and approve it so once those metrics are data task is collected making sure that somebody is reviewing it and now in case you have confidential metrics right so really metrics where you want or need a restricted sort of users to see that information you can always define that confidential metrics and you can say these are the users of the group who will have access to that information so this is really optional so that's really a security that's one of the security uh things in place here protection data protection basically yes and that's a focus area across the product line so you'll see this being a focus area for us this year a lot of focus on security tightening the access control so this is just a step in that direction here now once you've defined that metric and define the thresholds out the next step is generally applying it to the risk statements to say what are the risks we are monitoring this metric from so in this case you can see i'm monitoring this metric in correspondence to the risk around bribe where employees are involved in private related activity or maybe they are receiving preferential treatments right and what the system does is smartly it looks at all the risks that are attached to this risk statement and it creates like a metric instance for me and then it creates the data task across for individual owners to respond to and based on the thresholds that you have defined you can then compare and contrast how are we performing so in this case you can see for acne rbus we are in green for retail banking we are amber and while for small finance bank we are fred so three different entities three different statuses of the metric and icing on the cake is at each of the metric level the thresholds may differ so we do understand that each bu or each line of business may be at different level of maturity they may want to have flexibility to define their own thresholds out so you're not restricted to just one enterprise threshold you can set your bu level thresholds or line of business level thresholds where you can say even though the enterprise view is the ember threshold is maybe 30 but from this context perspective we want to make sure the maybe the thresholds are lower to say 10 and let's say maybe no yeah i mean not 10 maybe 20 and maybe 30 right as a change so that's how we make it easy for each line of business to adopt these thresholds align them to their respective needs and if you see suddenly things will change in this case it did not because it's still below the ember threshold yeah but otherwise things would have to change here so so i think the couple questions that come in um just to kind of clarify a little bit about metrics um you know the question is you know how what's the difference between this and evidence request process and i think that there's kind of not a subtle difference but you know we're really not trying to collect evidence here i mean you definitely you could definitely use this to determine whether or not you're meeting your your assigned um you know policy requirements um but it's not really designed to be an evidence collection tool yes it's not it's i mean metrics are generally used by customers to monitor their risk key risk and key controls let me put it that way right so if you have let's say 100 risk in your organization and out of that you analyze these are the top 20 risks you have to monitor them more closely your assessments are happening every three months every six months or maybe yearly fashion you don't want to wait for that three months or six months to say what's happening around that risk and that's where metrics comes in to say i can create a monthly metric and it's going to give me an early warning indication right to say oh suddenly the risk is changing and i'll draw one analogy just to kind of do that clarification whenever i drive my car i'm always looking at the fuel gauge to tell me oh how many kilometers can i drive more how many miles can i cover more that for me is a metric right it's telling me how soon i'm gonna run out of fuel so so similarly when you're managing your risk and controls you want to monitor the key risk and define your metrics out so that whenever there's a change in the posture you're quickly able to understand analyze it and take actions on it before it's too late yeah no that's a great analogy um that's a great analogy so i think hopefully that clears that up for that question um are the metrics create are metrics created for every entity automatically or does the user have the ability to select the entities so so it's a choice and that's an excellent question in fact so what we have done is we i mean there could be two ways you can create metrics either it could be top down where the second line is saying if you have this risk you need to have this metric in place and that is where the system would push down these metrics across there's always a choice to the first line to create their own metrics and say this metric it does not apply to the enterprise as a whole it's very very specific to our line of business and that's where you can track your metrics against your respective entities too so really it's dependent on you as a customer to make that choice yeah which is great i mean the whole concept of servicenow product is flexibility you know giving the people the ability to to make it work for them for their unique circumstances um another question here is you've got your enterprise owner you've got your user you've got your approver um is there a way is there a way to make it so that there are multiple enterprise owners or multiple approvers or multiple users that you want to send this to absolutely you can always use this option of user group where instead of assigning to a named user you're assigning it to a group and anyone within that group is actually owning the metric or maybe providing the data or providing the approvals on it so that's always the possibility here perfect flexibility again yeah all right that's all the questions we have for for our metrics awesome questions awesome i'll just finish up i'll just finish up with a small data task uh ui on how it looks and feels and there's a lot of investment so in fact because we have realized this as a as a product is gonna also cater to our esg product line so there's a lot of investment we're gonna make where there are investment into the look and feel of how the metric data test should look like so in case you have let's say 50 odd tasks of metrics that you have to respond to we don't want you to do those 50 clicks and then do that job so right now i know it's a simple form but from a direction perspective there is investment into this to make sure it's much simpler you can do like a bulk activity on this and also i know a lot of you may be having that question in mind hey we used to have pa what happens to pa there's a lot of overlap of functionality is service now doing some level of self cannibalization no we are not so what you are looking to do is the matrix functionality in the future may use pa as the back end engine for itself so you get all the goodness that you associate with the pa engine all that power of trending forecasting analysis that you get with pa engine but the front end is where we will focus on the front end and the workflow is where we will focus on as a bu to add that intelligence layer on top of it so so that you don't have to go and define a pa indicator you don't have to go through that training or defining a pa indicator for you it's a very simple metric that you're defining and in the back end we are doing all the heavy lifting to making sure yeah we are able to define those p indicators so that's the direction uh from a strategic perspective we are heading to there's no cannibalization there are clear differentiations between indicators metrics and performance and analytics indicators in place here good to know got a couple more questions that came in while you were talking um can you create a shared metric across multiple risk statements absolutely so that's why your metrics to risk statements mapping is a m2m so many to many mapping so you can use this metric not just to monitor one risk but you can use it to monitor multiple of these risk statement always yep all right that answers that question and then another question on your approvers um if you've got a list of five approvers do they all have to approve to move it to the next page so that is configurable too because we are using the sys approval workflow primarily so right now out of the box when you let's say send it to a group in terms of the approval any one of them can approve it but if this is something you want to change that is always as confused configurability is always an option that is provided in the servicenow platform for you you have all the right answers um so one more one more question here um you know and i'll just preface this with you know in general with servicenow product we don't provide predefined kris or kcis or templates or because every organization is different we realize that we do have content packs that include controls or or um or assessments that have not been assigned yet we do provide some of those for specific use cases like around rmf for example or sox and we do have we have partners integration partners on the servicenow store that provide these content packs that provides indicators that you can always use but we don't we don't really have pre-defined krr kcis that can be uploaded and used as a starting point right that is correct yes uh so so we depend on our partners and the content providers as of today we don't want to get into that space at least right oh and i would encourage you know the person who asked the question to go look at the servicenow store because we do have some great content packs that are out there both that we have created and that our partners have created um that do include krs and kcis that you can use um so i think that's the end of the questions for the metrics awesome i'm really excited to share the next one right so really it's around the employee center so for those of you who are unaware about or maybe you have not heard about employee center employee center is servicenow-wide initiative to harmonize and bring all employee-related workflows on one out-of-the-box portal so what was happening previously is each product line was building its own portal experiences which means from an employee perspective it was too it was too disconnected as an experience so if i want to raise an i.t request i was supposed to go to maybe an ittsm portal if i had an hr request i was supposed to go out to an hr portal even if i have a grc task i have to go to a portal third portal so it led to a lot of issues a lot of i would say friction from the employees to remember what portal to log to so that's where employee center comes in where employee center harmonizes all these workflows which are employee phrasing and bring it into one integrated experience that is available to customers and needless to say grc is definitely one of the initial ones there so we wanted to make sure we are simplifying we are embedding our workflows our grc activities and tasks into where employees go on a day-to-day basis so there's low friction for the employees to actually have visibility of those trucks and complete them so you have one less reason for an overdue grc task now that's how i want to put it and really i mean i would kind of highlight some of the key areas in terms of what employee center looks and feels so so i know it's going to be a new topic for a lot of you so so i'm just going to talk about two things right in in employee center from just from a capability perspective so there are two packages one is a basic package so earlier prior to i think rome release what we were doing was we were charging customers for this employee center or employee portal experience but as a basic package now it's available to all servicenow customers so you don't have to pay for the basic package if you buy service now you get employee center standalone right while the professional package is where there are a lot more features and a lot more capabilities and that's where you can actually procure that additional license so what we have done is we have also integrated rgrc experience into it so this is just a quick snapshot of how the two versions of the employee center look like but really from a grc focus perspective when we were trying to analyze what kind of task what kind of workflows we want we want employees to do we thought there are three broad buckets of the task the first one is really being more proactively involved being a whistleblower in the organization to report a issue maybe report a risk event or maybe request a policy exceptions and those are just out of the box catalog items i've seen you guys and our partners customers building their own catalog items where they want employees to be more involved and that's where we position employee center again to say okay this is these are the drc requests or report uh incidents that you can report second thing is grc task your control registration task your risk assessments your metric data task now or maybe things like just reviewing and approving stuff so all of these comes as things which again you want employees their managers your business leaders to complete and perform in order for you for grc to be pervasive so we brought all those across as well for employees to focus on and and really simplify that experience across again for them and i'll show you how it looks and feels as well so what i'm going to do is i'm going to impersonate as an employee and show you that experience of how it looks and feels here so this is anybody in the organization this is just every employee should be able to use this this is what this is meant for this is your go-to portal for all of your it your grc your service requests your this is this is it no more multiple portals to try to change between and this this is out of the box native experience right so you don't have to spend a lot of time configuring your own poodle and i know a lot of customers have been burnt their fingers right and trying to configure trying to understand what are the best practices around configuring a portal yeah and this actually replaces the servicenow portal right yes that's correct so the service portal will be primarily used for id i mean not employee but more from an id perspective so so this is any employee related workflow so you will have it on employee center are there any specific roles that are needed for this it's just it's every employee i mean there's no there's no specific role right so for you to do your grc activities you obviously need grc rules so you need to have things like a grc business user role that's when you can actually perform the grc task right okay so we want to make sure yeah okay so as an employee if i had to acknowledge a policy i would have to be i would have to be designated as a as a grc business user that's good i'll just lay down the kind of a navigation pattern here in the employee center so on the top you'll see the banner obviously you can configure this banner to personalize it for your respective organization and there are two links here on the top the first links allow you to track your task the second thing allows you to track your requests that you made or maybe things that you have reported right and below that this is where the navigation menu is for for example if there are multiple things around id right that you have or maybe even hr or csm so depending on the products that you buy from servicenow the respective menus would be enabled the respective pages would be enabled so we have an out of the box page for grc which is really around risk in compliance and if you open this page you can see the three catalog items which are really reporting a risk event reporting an issue or requesting a policy exception so for example here if i want to report a risk event i get a really nice conversational interface so that as an employee again i'm i'm i'm informed about what kind of details are being asked and it's very simple for me i don't have to go through rounds and rounds of training for me to report a simple risk event to my risk management team right so that's how using this interface here i could simply type in what the event is describe the details across tag it to maybe my entity where i belong and provide an estimate as to how much loss are we gonna incur because of this event right once you report it you can obviously track it so i'll show you where you can track it across so that in case somebody has let's say further questions around a particular risk event so so let's say this is a risk event that i reported now somebody in the risk management team is analyzing it and they need inputs from you as your business as your employees around this risk even you can obviously have that conversation right here you can add more evidence keep track of it so that you know whatever you reported is being looked on is being actioned on right and it's not sitting in a silo so that's the first focus area for you as an employee making things easier right for you to track those items across so i've got i've got a question for is the treatments as a trick question so you just showed me the form for a risk event what if i used the virtual agent to enter my risk event i would still see my risk event in that list of risk events so it doesn't matter how i enter it right whichever i'm more comfortable with um i'll still see my risk event and i can still add more information in from that list also so we again right this is all about flexibility absolutely teresa we all about multiple options to employees depending on the preference they have so that's always available to you yeah so the second thing i want to show is on the employee center controller destinations or maybe privacy assessment risk identification questionnaires so all kind of things where you are asking employees for inputs and there are certain things that you want employees to do so for in this example you want the control knowledge within the first line to attest to the controls so you can see i had 11 attestation requests and all of them are over you here for me so i can simply click on one and understand what that control is in context of which entity i want to test it and complete mass attestation right from here right so so again it's all about simplicity it's all about providing that options to employee to complete their task quickly and efficiently so that you don't have to spend time in training them across while using your grc system so i i actually don't know the answer to this question so i'm going to i'm going to ask the question here because employee center is actually it's not we didn't from the risk business unit we didn't create it i mean we're basically plugging into you know an employee workflow product do you know if employee center is available on the mobile app it is it is employed but i wasn't going to say yes all right and there's a lot of investments i mean one of the things that i've realized is from the senior management within servicenow there's a lot of investment into employee center so you'll see a lot of features a lot of simplification of all employee related experiences on employee center being the core of it and that's why jrc is so very important for them so so you just showed an assessment that's a sparked a question for somebody so they're asking if you can use the group assessment option here also that's part of the plan so we were not able to scope it in the first release but that's definitely something we are looking to enhance in our future releases okay perfect so so i talked about control registration risk identification questionnaire what about other tasks right what about other experiences like maybe an rcsa is an example so that's where you can see the style which is showing you all the grc tasks that you have now one of the things we realized is we have two different ui technology stacks technically speaking the employee center still uses the service portal technology while we have migrated all our experiences to the new seismic ui so that's where we designed this page to integrate with employee center simply where you can look at all the tasks that are assigned to you so i can look at the 15 different tasks in this case that are assigned to me as an employee i can obviously deep dive into what those 15 tasks are and i can see 11 of them are around controlled registration four of them are on risk assessments so i can go and complete those across two so it's not just the tasks which are i would say like an assessment or an investigation so if you are building your own workflows let's say and if you have designed on workspace experience which is simple enough for the employees to actually do that complete the task across you can always leverage this kind of an integration we have done to provide visibility into that task and the good thing i like about it is again the focus on not just your task but as a team so so with pandemic we have been moving into this model where instead of having uh individual ownership you have a team ownership and that's where we want to provide that visibility of those tasks also provide sub metrics to say if these tasks are owed you or them in progress so that you can quickly filter it and go and complete those across so that's always available as an option too for you to provide that so complete end-to-end visibility of grc task on one single page is what you get with this capability here yeah and i think that this is that the answer to the question that someone actually asked i think it's a really good a good thing to point out is you know the employee center is really for your your control owners your everyday employees your business users right this is this is how we're really engaging that that front line of of users that it's so hard to engage we're not doing away with workspaces workspaces are still there you know we just saw how we can get to them easily um i mean workspaces are used primarily really for what second and third line honestly um not so much that front line that the employee center is for so no workspaces are here to stay they're only going to get better um this is this is for your employees so i think we have good i just clarify one point here specifically so so so like i said there was a lot of inputs or uh i mean queries from the partners customers around our ux strategy right how do we differentiate between a portal a workspace right so like you said wherever we see there's a practitioner there's a power user in the system right he needs more power he's aware about let's say grc workflows he's driving the change right so he's the change driver so that's where we use workspace so even from a first line perspective if there are risk specialists in the first line and that's very much prevalent in the operational risk as an area so they're going to be having a workspace and in fact natively we have a workspace for them too as part of this release we call it the business of risk manager so that's a new workspace that you're getting but for areas where you it's really an employee it's not a day-to-day job to manage risk or compliance it's just one of his responsibilities and that's why we want to leverage employee centers so so that's that's how i would differentiate if you're a practitioner if you're a power user workspace if you are a employee you want to just do your tasks that are assigned to you maybe at times report some things that's where you use employee center okay that makes perfect sense i think about 10 minutes left i know we got a lot more stuff we could possibly talk about but what can you talk about in 10 minutes i know there's a lot of things that you cover i'll skip some of these and i'll try to medium to see if i can share it across with everyone here otherwise but really what i want to focus on is also some of the era enhancement and again this is based on what we heard from our customers so our entire roadmap is very very customer driven so so i would like to actually thank all of you present on the call today some of you have really provided us input into these roadmap items so for example i must have spoken to 10 plus partners and they requested a need for support for more than one entity class in the risk assessment methodology so so when they are defining their risk assessment methodologies one of the challenges they ran into is if i have an i.t risk assessment methodology as an example it can be used for assessment of business application network servers routers pretty much every i t asset but they were not able to model this across because we were asking them what is that one pointed entity class right so now with the new release that has been enabled where if you go into your risk assessment methodology form you can just not focus on one methodology but you can apply the same methodology to pretty much do risk assessment from multiple of these areas so that really reduces the amount of maintenance the amount of uh setup that you are supposed to do with respect to the risk assessment methodology here so in this case here is an example i.t risk assessment can be used to for assessment of asset it could be used for assessment of business applications business service computer server and you can keep adding to the list right so that in the future if you have more classes of things right that you want to use this assessment methodology to you can keep adding to the list without the need for creating a new one here okay so that that is the first one really i wanna i mean showcase i know a lot of you are waiting for this second thing i wanna talk about is really driving or again embedding risk assessments as part of the digital workflows in your organization so we heard from you you have flow designer you have a powerful engine to configure your workflows but within those workflows i want to embed risk assessments so that i can say if there is an event automatically initiate a risk assessment why should somebody wait for a user to initiate a manual risk assessment so i want to make sure i can embed that and what we have done again is focus on that need focus on that requirement and with this release we are just not providing an api for you to initiate these risk assessments but there's a out-of-the-box flow designer action which enables you to initiate these risk assessments at pa as part of the different workflows so let's say there's a change there's an idsm change that somebody has requested on a configuration item and that impacts my business application and now you want to reinitiate the risk assessment corresponding to that business application with this enhancement you should be able to do that right so so that's the importance of this enhancement in trying to embed risk assessments across the different workflows in your corresponding organization out of the box for example we have enabled this for risk events where whenever you have a risk events then and you tag or identify a risk corresponding to that risk event that has been uh uh uh i mean that has been analyzed you can on click of a button you can request a risk assessment on it so so a lot of you may be wondering what that flow designer action looks like so here's a screenshot of that there's mandatory inputs and then there's our output so that you can use that to embed your risk assessment workflows across there's also a nice kb article which provides all the details around the api and the flow designer action as well as providing that model window which appears when you initiate a risk assessment so for example in this case here let's say in the risk event form i had this risk and i have i want to initiate a risk assessment on it because i know some things may have changed i could simply click on this initiate risk assessment it would bring a model window and it would initiate a risk assessment for me so that's how easy it is now you for you to initiate risk assessment you don't have to go to scope you don't have to go to other places any place within the work within the workspaces you can embed this action to initiate risk assessments awesome i think we're almost out of time we've got a bunch of questions i want to see if you can just answer the questions we don't probably don't have time to show people the the answers but if we can answer the questions uh i think that would be awesome um so for this i think um can an entity belong to multiple classes like cloud and application uh no no so so entity has to belong to one entity class right now so it cannot belong to multiple entity classes here okay and then you got a big thank you from one of our customers that says thank you for listening to your customer um we appreciate it another question here is do do we need to define only one risk assessment scope for multiple classes uh so risk assessment scope is per entity and per assessment methodology right so let's say if i'm assessing a business application right which is let's say worked as an example so that will have an assessment scope for let's say id risk assessment so for each of the different entities you have to define your risk assessment scopes across but one of the things that i would like to highlight is i know there's no time but in case you're finding it difficult in adoption of this process of creating a risk assessment scope we have also initiated a risk assessment from the risk form itself so so technically speaking your ara assessments can now be initiated from the risk form on click of a button similar to the way you were doing classic risk assessment so again that is the feedback thank you for all the inputs that you guys have given in fact and we have incorporated that change as well we have simplified it taken away the need for risk assessment scope if you were finding that challenging and i think we're probably gonna have to have another session to go through the rest of these this this is actually recorded is i put the link in the chat for you um are we listening to share um we do have a couple more questions just hopefully really quick from the back in the heat map you can show residual risk in addition to inherent risk right so that hasn't changed okay um and then the final question here is um and i forgot which feature this was but is there a plan to include data security segregation across teams so that you can have um the same irm application for example enterprise risk managers versus it risk managers but they have the same risk manager role if they can restrict the related lists yeah i think the question is around access control maybe i will touch base offline i do want to understand that question in details it doesn't yeah i think we need to give us we kind of get past that so we i told you as a jam packed hour um thank you so much for joining us everybody um truly appreciate it i'm gonna grab the screen really fast here and um [Music] show everybody hopefully the [Music] couple places where you can can find some more information our products and links that are important and we really appreciate your time thank you so very very much for joining us and again check the chat for the link to the ask the expert session thank you all and have a great day thank you akash thank you bye bye bye

View original source

https://www.youtube.com/watch?v=yc1dKT_ZPrE