Live on ServiceNow: What's new with Risk Management
so thank you all for all being here um we as we're talking about just two minutes ago i'm really excited about this new release um and what's new in risk management i am joined um with utkarsh today good first introduce yourselves introduce yourself sure hi everyone i'm utkarsh i'm part of product management team at servicenow and really excited to be here today talking about risk management yeah and a lot of stuff to talk about um in fact we have a lot of stuff to talk about in this whole release um we've got i can show you here we just had our um live on service now we've we've changed from the ask the experts the live on service now i'm talking about business company management last week so if you didn't see that one you can dial in and see it on demand um today we're talking about risk management and you can see the long list of features that we're going to be talking about today next later this week we're going to be talking about policy and compliance and audit management again we have a lot of really cool features and we'll follow that up the following week with operational resilience and with business continuity management i'm sorry outreach resilience and with vendor risk management and then we'll round it all out by breaking out the devops accelerator which is an amazing um integration between devops config and policy compliance in september so we have a lot coming up we hope you join us for those too but right now we want to dive into risk management so i am going to turn it over to you to be able to show us what we've got absolutely thanks tessa and i'm sharing my screen i hope all of us can see you are it's wonderful awesome so as i said this is a this is a release very very close to my heart i think in this release we try to base it based on the feedback we got from the customers and from the partners so thank you everyone actually so for providing us all the feedback providing us the continuous support and letting servicenow know what has to change what can be improved so so that's the reason we are the leader in this space so i really want to thank all of your effort keeping in with us with all the development that we have been doing so so really excited to showcase some of the cool new enhancements that we have uh this release so the first thing i'm gonna talk about and i'll let the system do most of the talking here is really the heat map so some of you may have seen this in our road path sessions as well so in this release we did some really cool trending and movement on the risk heat map and the objective is really to automate digitize your risk reporting so when you're going into a boardroom or maybe a room full of executives and you want to talk about a risk and they have all kind of questions around the rift so you should be able to use this what we call it as a heat map workbench to actually answer respond to those questions to live in right so so you don't have to create those power points that you are creating for the senior management but they can have it live in the system so so that's the objective with the first feature here the second thing is more of a theme you would see us investing in this team around ai assistant risk management so we want to use ai more and more to help our users operationalize and effective you make efficient use of technology in the world of risk management so one of the features that came in as an ask from customers is really to say if there are hundreds and thousands of risk events and these risk events are occurring throughout the organization so there can be cases where your similar risk events are actually reported across different geographies so how do we give more visibility of these similar risk events to the event owners so that they're not duplicating their effort and they can understand the larger impact that this event may have so that's a freaking feature i'm gonna demonstrate today the third thing is really around design and operational effectiveness assessment of controls so this is again a very strong feedback we got actually from all of you around when we do the rcss sometimes the rcss has to go very granular where you are just not assessing the overall mitigation effectiveness of the control but maybe you are assessing the design and operational effectiveness or maybe other other factors as well so so now you can do like a multi-factor assessment of controls and obviously this is configurable so which means if you don't want to you can continue doing it as a today but if you want to go granular get your more detailed assessment you can so so it's really giving that extra power of configurability to you to make that choice the fourth thing and this is again something which will take our risk assessment engine the advanced risk assessment engine in terms of configurability to the next level is really dynamic and multi-level approval workflow so so this is again something that came across as a strong feedback saying why is risk assessment approvals not as configurable as some of the other approvals in the platform so we are no we know servicenow for the configurability we want to make sure we have the same configurations available in advanced risk assessment as well so so as part of this release what you can do is you can actually define multi levels of approval workflow so that if a risk let's say is beyond your repetition of the organization you can actually do two or three levels or four levels of approval and these can be dynamic too so so like the condition i said only if it is beyond your respective then do these two levels so this takes away the noise in terms of reviewing everything and make sure that only the things that needs really management attention are brought up to them and they can focus on it so so this is a very important enhancement from that perspective and the last couple of them are really enabling the admins as well as users leverage some of the new capabilities in the system better so so what we have done is for the advanced risk assessment setup so a lot of partners actually gave this feedback to us saying it is it is actually very very powerful advanced risk assessment but setting it up we need visibility to understand okay how will this risk assessment look like once you actually trigger it so that they can make tweaks they can make changes in the scoring logic or the factor setup so so what you have done is provided like a simulation mode so that you can simulate your risk assessment setup and you can see how the impact is on the overall assessment and finally the metrics piece right where we i mean this is something we started as a journey in the last release where we are now gonna use our metrics capability for more kris and kci monitoring rather than the indicators as indicators has been repositioned as automated control test so so in this release what we did is essentially the out of the box widgets on the overview pages and the home pages which used to reflect only data from indicators will now reflect data from metrics on switch offer buttons so it's still a choice to you as a customer if you want to leverage matrix or if you want to leverage our indicators functionality we strongly advocate for the metrics functionality from a product standpoint because that's what it's designed for but still a journey that you can take and take your own sleep time so i know all of you are very excited by all of these features here so what i'm going to do is start with the first one here which is really your heat map right so so this is this is let's say the screen for a bus or for an operational risk manager and i'm going to impersonate as a business risk manager too so one of the things that business risk managers could do that an operational risk manager cannot do is really filter his view of the home page on the workspace based on the entity he's responsible for so so this is a use case again which i'm sure all of you would have seen in your respective organizations where i don't want to see everything but i really want to see data from my entities the entities that i am responsible for so on this page you can see there's a there's an option to actually filter in the last release we could not launch the heat map workbench from here so this is the first thing you'll be able to do you can actually now launch this cool wheat map workbench from even the business risk manager workspace and again the objective is you you launch from there to get into the details of it so you're seeing the account now you see the actual risk that are there and now i have the filters on the top and so so what we did is we based on our research we did we figured out there are two or three top filters that customers are generally used and that's where we brought them up on the top so the first filter allows you to switch your methodologies across to say okay if i want to look at data from an operational risk perspective or enterprise perspective i can simply use this filter and change my viewpoint here right so that's one the second thing is also a dynamic filter so a lot of times when you're walking into a room like it said you don't want to talk about all of the risk in your organization so what they're really interested in then seeing what are my top 20 risks so so your heat map should only be filtered based on this so now you see if you see what the heat map did is it took away the noise from your actual risk that you need to focus on so when you're having this conversation with your senior management what you could simply do is just click on this risk and now this is going to bring in all the information around this particular risk right so you can go risk virus get into details have that conversation capture your output here right here right and move to the next one so so that's that's the top risk filter here the second filter you would observe is ability to filter for a particular entity for example let's say my senior management says hey let's start with focusing on acme cd europe and let's see what are the top risks within acme cv europe that we need to worry about so you can start by that conversation across and the wonderful thing about this is it's just not bringing your entity which is acme cd europe but also all the downstream within it because we understand you are not just responsible for this entity but all the corresponding downstream so risk is composed of all those different areas and on the right you would see still some preferences for example if you want to toggle between a name view to an index view stuff like it or from inherent to residual so so let me do one thing now so let's say i'm talking about my enterprise risk management profile and i'm talking to all these stakeholders in my organization and generally a lot of times they would have this conversion conversation they would talk about a risk let's say availability of training content as a risk and you want to see all the details around it so you can see on the right hand side panel you have that complete 360 degree view of a risk so it talks about who the owner is which entity is it in what's my risk trend both inherent and residual and what are we doing about risk risk right so in this case there is no response because this is in a green zone so we don't need a risk response necessarily for this risk but if it was not if you could actually go ahead and do that now in this case what you can do is you can also see the movement so for example i want to see how the risk has changed from inherently residual so you can see nicely the trend of the wrist from inherent to residual here or you can even look at last five assessments right on how you have performed around this risk so the first time this risk process was in january 22 but at the current moment it's july 2018 two so definitely a lot of work has been done on this risk and i can see how the controls have mitigated the impact and likelihood right over the last six months when we reassess this risk so it gives a lot of talking points for you to justify all the costs around the controls how we have been managing this risk better over the period of time and how what the trend is so so this try the actions in terms of where we want to see okay i see some cushion spacers so should we take them up now well actually i was just gonna i was gonna say um the one question is actually something we can actually address a little bit later um but we've got someone to raise their hand i forgot to mention at the very beginning if you guys have a question please put it in the q a and we'll make sure we get to it um we do want to make sure we get your questions we want to make this interactive because this is something we're really excited about and you can see there's a ton of things in here um but put it in the q a and we'll get your questions answered awesome okay so so this is the first thing and really it's an important visualization just to communicate the risk profile across and this is a strong differentiation for us we haven't seen any other computers do things like this and one thing although i would mention is in terms of the risk movement the risk movement is only available for methodologies where inherent and residual risk is based on the same factors so if you are reassessing the residual to based on the impact and likelihood that is when you could plot the risk moment but if it's not then it's difficult to actually visualize it because your x's x axis and y axis are not same for inherent and residual so that's why you cannot actually plot them on the similar heat map chart so for those methodologies you would not see this option for wrist movement but the trend will be always available for you so you could simply see the trend across multiple assessments that you're seeing yeah so so really i think this is really i think what's important about this one are really interesting about this one is if you've got for example three risks that are in that sort of medium zone and you're not sure which ones you want to start working on first you can see this trend and it's going to help you make that decision i mean not knowing how the risk is moving you know that doesn't help you at all determine what you should be doing so risk informed decisions that's what we're really about here and i i think this is just amazing and i think the other thing i wanted to mention was i don't know if you're gonna mention this later on but i don't know if anybody noticed when utkarsh was dropping down to figure out who he wanted to be you can select from a variety of different roles you've got the enterprise risk manager he's on now he was the business risk manager previously you've got operational risk managers in there um you can really tailor your view to the what you care about and what matters to you to help you do your job more efficiently so i think that that is just it's amazing and i hope everybody is excited about the fact that they can get a little bit more granular and in their jobs absolutely does i think i think one of the key things that i really got a good feedback from customers around this is the the power of automation and the redundancy in their day-to-day work that we have been able to kind of simplify right because a lot of them what they were doing was they were creating these kind of reports offline and they told that it takes us for somewhere around 22 weeks in every three months right to actually create this now that is available in the system i could simply walk in into the room with the system and have that conversation so so that simplifies their risk reporting a lot yeah it's wonderful awesome so so the second thing i want to really talk about is and i'm going to switch my domain across all my persona across to an operational risk manager for this is really ai assisted risk management so you would see this like i just said like more of a theme right running across not just in this release but multiple releases and the objective is to build a story right to help our customers manage the risk the leveraging ai so we don't want to replace the humans but we want to make their life better we want to make sure we are providing the ai assistance to drive more insights from the tool so so that's the objective that we have now for this what we did is we actually created uh we leverage our predictive intelligence engine and on the risk event capability because that's one of the area we have been seeing customers volumes for ai we brought in a simple use case which is basically helping users identify what the similar risk events are so let's say there's a risk event around company director heading fraudulent credentials and i'm andrew taylor who is an operational risk manager here i'm working on this rest event but when i'm working on this risk event i also need to see if there are similar risk events that are popping up across the organization so i can see one such event which is happening across for my acme consumer durable organization so here's a duplicate one in fact so so you have this event in acme incorporation here but there's another one here in acme consumer durable so what you want to do is you want to associate them so that you can analyze the true impact of this event and also it's a regulatory mandate really it's a regulator asked to say if you have similar risk events happening across the organization you should actually link them so a lot of times what they were doing is they were actually going into this tab called similar risk events if ai was not there then clicking on this ad looking for simple text based search to see or if there are duplicates like these and stuff like that so it took a lot of pain again for the users to do this but now this ai engine is actually popping up these similar risk events and all i need to do is just quickly go through this event that has been showcased understand what this event is and if i just click on this action here it's going to establish that relationship across so now when i report this risk event and when i analyze this risk event i know there's a similar risk event happening uh not just in my entity but in an ndp around acme consumer durable so those people get notified as well so so that's how we want to leverage ai to make people's life simpler and make sure either you're sufficient the right information across the platform for them so we do have a question here so i i know we have to train the ai a little bit but the question is on what basis does the ai engine group similar risk events so so that's a wonderful question so so that's where the power of the predictive intelligence solution comes in from the normal platform right now we are basing it based on the name and description fields but a lot of times what i have seen in real life is based on the customer data you may want to tweak the model across right so maybe you have additional attributes like cost consequence or maybe the category of the event that could be used to vote the model to better predict what these similar risk events are and that's what we have done here i'll quickly showcase where the solution definition is so for some of my practitioners friend who are doing the implementation for the customers where they they run into the scenario and the customer says hey look this ai model needs to be retrieved so that's where they can go and actually do that so if you go into predictive intelligence and if i go into similarity solution definition and you can see the similarity solution definition for experience so the features are out of the box that we are training the solution definition is for name and description but you can add more so if you see test fields our name and description as well as the fields or the features as we call it in ai our name and description so both of them you can actually add more tweak this model across based on your data set here great all right that's perfect now the next question i actually like this question a lot because it allows us to to plug a couple of other things that we do um so our risk events entered manually or automatically created from another module in servicenow so i like that one because the first thing i want to say is you know we do have this amazing employee center where you can do for employees anybody can enter a risk event so a lot of times we're not going to talk about that much today but i did want to plug that one before you answer the question the rest of the way absolutely terrorists i think i think this is a wonderful question and what you have done as a platform is we have integrated this risk event across the platform so imagine you're working on a customer case and he files a class action lawsuit on you that could be a potential estimate so click of an action which we call it as a reporter risk event you can actually date copy data from your case management application or let's say major incidents into the risk event database or it could be even manual right so we want all our employees like one of the bank i was working with and they said we want all our branches to actually report all their events so they want to report all their receiving even if it means a dollar loss of hundred dollars we want to make sure all our employees are reporting it and we are getting visibility into so so anything it could be automated like i just said where you're working on a case task or maybe you're working on an incident and you wanna you have a feel that yes this could be a risky event so you can do that or it could be even like from the employee center where employees are going in and just reporting a rescue in they're not sure whether it's at risk event or not but you want to make sure you report it and then somebody can review and try it so both possibilities exist in the platform yeah you can even use the the chatbot which i think is pretty nice oh yeah i just asked you questions and you just answered the questions what day did it happen what's it called you know who's involved um it's super simple i also like the fact that we've got the different buttons on different applications so you've got the button on the vulnerability response application you can use you've got the button on the yeah it's it's it's it's pretty much everywhere and the idea is that anybody should be able to do this and then of course you can automate it through the other um other means too so i should be on the go as well on the mobile right on the mobile too yeah yeah yeah absolutely that's the questions for this one listen anything else that i could take up right now i don't think so i think we can go to the next one i forgot that awesome awesome yeah yeah so so the next one i'm gonna showcase is really what we call it as a design and official effectiveness assessment and i'm just gonna take one slide i know nobody likes light so i'm trying to reduce the number of slides we use but i really want to highlight this one so so what you want to do is when you're assessing your controls right so the feedback we really got from the customers and partners we only were allowing assessment of controls based on single factors which means they were only able to understand whether the control is mitigating the risk or not but they wanted to do a lit one level down and understand whether it's a design which is failing or whether it's the operational effectiveness which is failing so that's one side of the equation or it could be even deeper where somebody may say oh whether it's implementation or it's a policies that we have so so clearly a lot of times customers what they were doing is they were asking these bunch of three or four questions to assess the controls and based on that they were trying to do their rcsas in their uh ara journey so they had to do this outside in the in the product so they were either adding fields on the form on the control record or maybe using our control adjustation workflow but the experience was not seamless so so so they wanted everything in one screen where they assess the inner interest they assist the controls and then they move to the residual so that's what we are looking to do with this one here where you can now assess each control based on multiple criterias i'm just calling them design and operational effectiveness because that's the most frequently used ones but you can actually do this based on multiple other criterias as well so so so it's a very simple setup step where all you need to do is you need to first define the factors which will be used for your assessment of each control so it could be your design effectiveness your operational effectiveness like i was talking about and then group them into what we call it as a group factor right so this way all of these factors can be grouped into one major factor that will be used for the assessment of the actual control and that is something you can pick up in your risk assessment methodology setup so i'll show you an out of the box methodology which you are shipping as demo data so that you have a reference to how it works but the key point of node is this only works for scenarios where you're doing individual assessment of controls right because if you're doing control environment assessment you're not really assessing each and every control but all you're doing is actually just looking at the overall environment together so that's the reason this option is only available for those areas so so so once you set up the factors the individual factors group them into one group factor you can select that factor out and then you can actually define the scoring logic to say okay how should my overall control effectiveness value should be computed and then publish that methodology across so this is a very simple seven step process that you have so if you follow this you should be able to do this live in the system as well and i'm going to showcase that right now in the system on how it works so what we did is i imported it as a risk admin here and i go into my risk assessment methodologies so one of the pre-ship methodology you will see is what we call it in the business rcsa so here's my methodology around business rcsa and you can see in this methodology i'm assessing my inherent risk my controls my residual and if i go into controls i see that the control effectiveness is primarily based on individual assessment of the controls and here before august before this release the version 15 of the store application that we have you could only select manual factors you cannot select a group factor so now you could also select a group factor so in this case this is a group factor which we have created called control effectiveness and if i open this group factor up you can see this itself is composed of two manual factors one is the design effectiveness and the other one is an operational effectiveness and then you can define the formula across to say how are you computing this i'll show you how all of this impacts the life of a risk assessment but i wanted to just showcase how the setup has changed right because a lot of you i know will be doing these setups and i thought it would be good for you guys to see how the power is so so this is where you can define once your product is computed what your rating criteria is and everything else remains the same so you can then define how is it computed like an average of all controls and then the reading criteria across but this is what changes right so now instead of selecting just one manual group manual factor you can also select a group factor a group factor can have automated factors or it could have manual factors within it so all that power is up to you to decide on how you want to model it across i see some uh raised hands tessa do you want to take quickly take up question if there is anything yeah we got a question i'm not sure it applies directly to this but um are there any plans or options to perform or capture target risk scores oh yes yes probably i i mean that's one of the things we have from the roadmap perspective i don't know if we did it in this roadmap session so where we did showcase when are we planning to enhance it for target risk so it's definitely on the roadmap we're looking at it from a rough timeline perspective somewhere around feb next year or fm next to next year so which is feb 24 is what we are looking at at this point of time perfect and if anyone has any questions please put them in the q a i think maybe the next question we'll be able to talk about when you talk about dynamic approval workflows is that our next topic yes definitely i just want to showcase how this impacts my risk processor right so i'll just close this off and then move to the dynamic role workflow here so so what i've done is i have moved into back into my workspace as an operational risk manager and i'll showcase how the risk assessment looks like when you have this option enabled so i'm gonna go into my risk and let's say i'm talking about risk around offering up right and return for overlooking illegal activity and now when i click on this action to assess and i'm gonna specify an approver here specify users approver in the same person here for now it creates an assessment i could simply open this assessment up to perform it and just to save time i'm going to copy over the results so that i can show you what changed right so if i move to my inherent assessment inherent assessment is going to be the same nothing is going to change here but if i move to my control environment assessment you would see there are a bunch of controls in fact three of them that i'm on our first and for each of the controls i can now assess the design and operational effectiveness so remember the setup part i was showcasing where you could where you were setting up saying this is a group factor within the group factor you have the design effectiveness and operation this is where it impacts so you see you in this case it's just two but you can have multiple of them too so you can say how my design effectiveness is how my operational effectiveness it and you could do this for each control so a lot of times when you're focusing on your first line you want to do like a quick control self-assessment for them right to understand how the risk profile changes you could use this capability now for them to do a more granular assessment and give you visibility into whether it's the design whether it's operational effectiveness of controls that needs to be fixed so it's really enabling that more granular control assessment and making sure yes you have the understanding of what needs to be improved in order to mitigate that risk further so so this is the impact you would see into each of the different controls but then it rolls up right to an overall score like you can see two of the control two controls here whistle blowing and process to insure managers and i'm answering each of them individually but then that rolls up to an overall effectiveness operating effectiveness score and design effectiveness score absolutely absolutely so spot on so so so that's what i was saying it's driving that granular assessment right so you can see all these three controls are ineffective and you can see this here too right so your design was ineffective your operation was ineffective that's why it's ineffective if i'm supposed to change that and maybe make some of them as effective then you would see the entire recomputation happening and that would recompute and maybe drive the residual risk a bit down so the nice thing that is before you might have had these three controls but you didn't realize which ones were effective or not effective but in this case you could actually say it's you know it's control it's a whistleblowing control that's the problem so i need to go fix that and that's what's going on effective score yeah and within that whether it's a design which means it's not being designed well or is it the operational environment yeah right what's the core of that problem yeah absolutely that's awesome that's awesome we have a question um can you use automated factors for calculating the control scores pulling data from certifications or audit results and just show up on an rscsa screen similar to the risk scores absolutely absolutely so so you could be manual or it could be even an automated factor here so both possibilities exist you're just providing that flexibility for you to decide depending on your organizational processes yeah i think i think the key word here is flexibility you know flexibility everyone's got their own processes and the way they want to do things some are mature more mature than others um people are still in that journey it's meeting people where they're at and giving the ability to to improve the efficiency and the effectiveness of their program absolutely yeah it's a journey like you just said right it's a journey some customers are just starting it maybe they would start manual others are maybe at a higher level they would automate look to automate as far as possible so the tool meets you where you are right so so you don't have to be stuck with one out of the box things but you can take the tool forward in your journey reconfigure it as you need during your journey yeah and as long as another question i want to kind of twist the question a little bit has anyone leveraged a risk assessment like a high trust or other third party certification as a framework for tracking the i.t controls and i think one of the things we are trying to do is is use for example the cis we've got the control accelerators the cyber security control accelerators that we've packaged up for cis to be able to give people that that jump start on being able to to create their their their program that define their policies and assign their risks and controls and and all of that um i know high trust is something we've been talking to i don't think we've actually got there yet because it's obviously um needs to be agreed on both both parties but it is it is something that we're doing is we're looking at these different um frameworks and trying to create except what we're calling accelerators trying to create accelerators for them yeah yeah and i i mean i've seen some customers definitely using the ar engine for that when they want to do their risk assessments and then a lot of times because of the kind of volumes they deal with they leverage the automated factors to build in data from servicenow or outside service now to continuously do risk assessment and monitor the risk build risk profile so they're adding it's really good better together with all the data coming in from other sources as well as within service now and then automating your residual risk profile and giving you a near real-time view of how your risk is changing yeah yeah yep so we're going in that direction for sure all right so so so this is the one that i wanted to so i think there was a question around this so what the next feature i'm going to talk about is really around your approval workflows right so so remember we talked about ara being the platform for risk assessments right so it's not just focusing on it risk operas you want to be providing an integrated risk assessment platform for our customers which means you can do multi-facet risk assessments and there could be different kinds of risk assessments you are doing in your organization so one of the things that came forward for that is it has all the power but then when it comes to review and approval workflow it's really limited because you just have out of the box one level of approval that it has to go through if you want multiple levels it doesn't work it cannot be dynamic which means either you have to review everything or you cannot review anything so so all of that feedback that you guys have provided that's what gets bigged into this feature for providing you that flexibility again right to choose whether you want to do multi levels of approvals what the conditions are as to when it should kick on and here's the sample use case that i think is a very realistic one so a lot of times let's say i'm doing three kinds of risk assessment so i can create three different risk assessment methodologies as we call it one is an it risk assessment another one is an operational risk assessment and the third one is an enterprise risk assessment when it talks about an i.t risk assessment i want at least two levels of assessment are for approvals one by the owners of let's say business application or the id assets and the second one is by it risk managers so they are reviewing and signing off everything but then if your risk score crosses a threshold of 16 which let's say is the risk appetite for your organization when it comes to id risk management you want head of id risk to review and sign off to that too right so so it's really the third level is conditional and dynamic from that perspective so only if your risk score crosses a threshold of 16 you want to do that while when we talk about operational risk assessment let's say it's a simple two-step process where you have level one as your business owners or your entity owners and then level two is by opera speed right so simple no dynamic but it's two levels it is three levels or press two levels and then we have enterprisers because these are erm managers who are doing like more of a strategic risk assessment they have already maybe reviewed it offline or whatever is the case they don't want to do any approvals in the system right so you could do all three now within the same platform right so so you are as you are configuring your methodologies but you are not also configuring your approval workflow and the way we have done this is leveraging for using one of our application that we developed in bcm which we call it as an approval configurator and i'll show you how it works so if i impersonate as a risk admin sorry no worries we actually have a question so when you're when you're talking about talking through this um the question is can you delegate on the capability so for example some of the risk orders are senior stakeholders they will never perform any assessments but they want to be able to delegate the capability to ensure that risk owners are accountable but delegates are responsible for a particular risk absolutely absolutely so so so one of the new features that we released in the march release was delegation of risk assessment so you could actually delegate your risk assessments to other stakeholders on the organization and now because we have moved to what we call it as a platform approval engine essentially right so this also offers approval in i mean all those new features like delegation approval over email so all that now works even for risk assessment approvals so you can absolutely do that and then um is it possible to have approvals with an erm i mean you can always have approvals i mean you don't there's there's no there's no restrictions on it it's just that in general enterprise risk teams they don't require approvals yeah this is a sample scenario this is a possible business scenario that i just took where your erl team maybe does not want to do approvals right but if they want to absolutely they can and you're not going to stop that so that's where the power of the flexibility comes in so so this is what you will see there's something called as an approval configuration so if you go to into in the approval configuration you'll see a record called advanced risk assessment approval that is going to be available to all of you now and what we are doing is out of the box we are shipping one level of approval by default now the reason for that is we want to ensure backward compatibility so customers who are used to doing one levels of approval they can continue doing that single level of every work but if they want to do additional levels of approval like in the case today i wanted to do that so what i did is created new set of records here so this is my level 2 approval where i said the level 2 approval will only kick in for risk assessments with a risk score of six and above right as an example so sorry five and above in fact so it doesn't apply to all of the risk assessment so if your risk score is below five i don't wanna do level two and in case the level two happens it should go to this group called it risk manager and here if you see there's a lot of power you could you say it is it is in specific approver is it a dynamic approver or also is it any one of them or all of them right so even within level two there can be multiple people who are providing these approvals so i mean just that power that you get using this tool configurator is amazing and i don't think there's a workflow that you want to configure that you cannot actually model this across in this new engineer a lot of things you don't you don't need to use that that filter basically you could you could have no filter conditions at all and still have absolutely another approval as a level two approval yes yes yes absolutely so that filter is only for cases where we want to do dynamic approvals based on certain criteria right so if i wanted i i always want level two to be always there i could simply take that filter away and just cross this out as an example right yeah so so so if you see here now this is three levels approval so beyond five i said two which is your i.t risk manager but here if the score goes beyond 15 which is let's say our appetite of the organization it's andrew taylor who is gonna provide the sign of and there's just one possibility right i'm i'm saying that yeah residual score is this it could be other criteria so whatever criteria you need be it your persona who is doing the risk assessment or maybe like the methodology i talk about or maybe any kind of criteria so anything you want your criteria or your uh things to drive your reptile workflow you could simply specify in this filter condition here and that would drive your entire workflow of your approvals here so you don't have to actually codify anything it's just digitizing this your rules of approvals and the system will take care of everything for you i'll showcase it now yeah yeah i think the answer to this one question here i think you answered it is number two but can approvals be sent to a user within a reference field for example a user maybe yes i think i think absolutely in the previous example yeah yeah so so if you just change the condition here and instead of saying specific approach if you make it dynamic it's going to allow you to select the field from a table it could be your user table it could be any other table or we even discuss a sprint table so that's where the dynamic approvals comes in so i'll show you the level one configuration and that will so so one of the challenge it's an interesting one right so when i was talking about this feature one of the challenges that developers told me is hey of course you have this current configurations that we have provided and customers have maintained all this data where should we allow these customers to actually take that data and configure it so it's not that it's a brand new product we have the power so that's where we actually leverage this functionality within this approval configurator to say because your level ones are probably already maintained in the assessment scope or within the model windows that you are having you want to pick up right from there so if you look at it what it's doing is it's picking up from a particular source which is your risk assessment and it's using this field called approver or approver group for your level ones so you could really simplify that same logic to use it from other areas too perfect i think um so i've got a question here and i think this is a clarification so thank you so very much for clarifying i got that question wrong so i'm going to read it exactly so i can get it right this time um i was not referring to risk by risk delegation instead at a risk scoping level where i'm defining the scope assessors approvers etc i want to what i would want to define the delegates if i go that way i would end up assigning a hundred delegates a hundred times which is a huge time consuming task okay okay now that's an interesting ask i would strongly advocate to use our idea portal for logging this idea request and we will definitely look at it from a roadmap perspective but that's not something we support as of today thanks for classifying that with that yeah and thank you for those ideas because those are the things that we can put in our list to be able to look at for future releases absolutely yeah yeah so i'm just going to showcase now how it looks and feels on the assessment experience itself this dynamic multi-level of approvals so i go into my workspace and probably i'll go to the same assessment that i was working on so i can go into my task inbox and i will see my task that i was actually working on the risk assessment perspective so i could filter based on the in progress risk assessments here and we were talking about this one here right so i'm just going to kick off the approval workflow so i did my inherent assessment i did my controls i did my residue so if you see the score the residual risk score is nine which means based on the setup that i did it should actually go to two levels of approvals and the system will showcase me that so i'm just gonna provide a mitigation plan yeah and kick off my approval maybe some comments for my proverbs so now previously while the approvers were shown on the bottom screen now that that can be multiple so what we did is from a ui perspective there's a new tab which will showcase that there are two levels of epc ones and on level one it it has gone to end retailer because that is the user i have specified in the model window when i was initiating the risk assessment that's why and it's the same user who has changed the assessment so it's just a selfish or self-approved scenario here just for the walk through today so i approved it right and now if you see it will trigger the next level of effect to one which is your level two approvals so i'm just gonna refresh this out because it does have a bit of a time lag here so if you can see now that it has gone to three people it has gone to an i.t risk manager it has gone to end retailer which is this guy here and has also gone to karen zombo and either of them can actually approve it so i'm going to still use the same person here and approve this across and if you'll see automatically takes away the tasks from other two so that's where that configuration around whether it's a specific user or all of them comes into play so i had said yes any one of them so therefore any one of them can actually do a level two as well here and now your assessment is approved you can look at who approved it at what point of time and stuff like it what comments that they give so everything is now dynamic from that perspective that's fantastic so it gives you the flexibility to set those the way you want to set the approvers yeah absolutely absolutely i feel like i should know the answers this question and i'm not sure you know the answer to this question um it's about the the approval workflows we've got it for risk but do we have approval workflows for like policy exceptions i feel like we do yeah yeah we already have approval workflows for policy exceptions for risk events and multiple other areas too right i mean it's not just risk assessment you have the approval workflow a lot of irm products right are now moving towards this approval configurator as a single application to have to give more power or flexibility right so a lot of them still requires either a floor designer or maybe some kind of codification if you want to modify it so that's the journey you would see all the different workloads within irm take where all of them will move towards the septual configurator but most of them have that dual workflows in place already yeah that that's what i thought okay we've got about 10 minutes i think we've got about two features left to go through right absolutely tesla spot on so i'm gonna use now an interesting bit of a feature which is really risk assessment simulation and and this is again based on my conversation with all the all the partners all the people who are setting up risk assessment so one of the pains they constantly expressed is we don't get to see a risk assessment until unless we publish the methodology and unfortunately once you publish it you cannot modify it because yes you understand there has to be data sanity it cannot change because you want to validate yes what has been done the risk assessment on is something you want to you actually validate across from an audit standpoint right so so for that reason there was a need that always came up where we said okay i need like a simulated risk assessment i want to see how this risk assessment will appear on the form before even i publish the methodology so let's imagine a scenario i'm a risk admin i have this business rcsa now what i need to do is probably modify or create a new version of this business rcsa by modifying certain things but i'm not sure whether what i'm doing is correct or not whether what i mean and i want to make sure i'm able to like plug and play right i really play around like a demo environment or stuff like that so i could create i could create a copy of this and call it business rcs a3 and this time in my inherent assessment instead of actually doing a product let's say right i want to do maybe a sum of factors for whatever reason so i could simply modify the formula publish this across for me and if you see now what has happened is within the risk assessment methodology here i just need to republish the residual assessment because you just change the inherent assessment so i'm going to republish the residual assessment but now in my ram i have not yet published this methodology i i'm getting this action to simulate and now i can select a risk let's say i pick up a risk within one of the entities and let's pick up the same risk offering a price and i want to assess it right and if i have my workspaces installed which means i've migrated to the new interface the system is gonna take me to the new interface if it's not then it's gonna go to the classic interface and it actually showcases yeah this is a simulated assessment which means it's not going to impact your risk reporting so it's not going to be used for risk aggregation and it will be deleted once your methodology is published but within the assessment i can see everything i can see how the assessments will be how the scoring logic will be and i can make edits right so i can make edits we resimulate it and again validate whether i'm doing something which is right or wrong so it's really taking that risk admin to a path where you are able to see the end results make modifications right and then helping him set up the risk assessment system right for your respective organization right so so that's the power we are again giving to a risk admin so that he sees the end results and make modifications as we go on in this journey of risk assessment and the beauty of this is it's not just the risk assessment workflow it's the complete end-to-end workflow which means you can simulate your approvals you can simulate your risk response workflow so a complete risk assessment and all the connected bits of it is actually simulated so that you can validate whatever you have done the setup is correct or not makes it makes it a lot easier once it's a lot easier absolutely methodologies and and implement the risk assessments absolutely that's that's the end content so we want to really take our customers through that journey where we are able to guide them step by step and you'll see that as a constant investment from us going forward as well yeah so so this is the this is a simulated assessment that we have and i can go back like i said i could further make edits so for example let's say no sum was not the right thing to do i can again change it back to maybe product publish it again and again simulate now one of the things that i'll take is you could use this for manual factors but you could also use this for automated factors so one of the constant feedback again i got from customers and partners is when we do these automated factors you want to see whether the script we wrote or whether the logic we wrote is working correctly or not in the automated factors so you could use this functionality for that too so you could if you have automated factors and you want to see that for particular risk whether they are fetching the right results or not so you could really have this kind of a simulation mode for that so so it's it's really that strong power that you can now use to validate before it goes live in production that's fantastic yep i like the fact that you give you both manual and automated very good we and we don't have any questions on that one awesome i don't yeah we are almost on top of the ah so i'm gonna talk about the last feature i don't know how many of you have seen the metrics functionality from servicenow so far but if you have not i would strongly advocate to see that across because that's my that's our future for our krys and kci where you want to do threshold based risk and control monitoring on a continuous basis and it's really cool a lot of things that were not available to us and the indicators are now available in the uh matrix functionality and in order to further embed metrics what we did is we actually provided a configuration path so similar to how we provided a configuration path for customers from classic risk to advanced risk we have created a configuration path or migration path for customers to leverage the metrics functionality so if you go into advanced risk assessment properties you now have a new property where customers can say i want to migrate from indicators to metrics and once they do that what we will assume is all of your all of your uh details that you would managing using indicators will now be managed using matrix and therefore in your workspace experiences in terms of the overview pages as well as the home pages whatever widgets used to display data from indicators as a data source will not automatically replace and take the data source from their metrics table for example here so for example there are three kri bridges right as well as you have your kris and kcis based on different red ember green status so you can see there are two ember metrics there's a one metric which is red if i simply click on this i can see what that metric is open this up right and look at the details here so all of your overview pages all of your home pages will now get data from the metrics as a data source instead of indicators now important point to note indicators is not going to be deprecated it's going to be repositioned as a continuous control assessment so it's going to be very very compliance focused while metrics is a functionality that will be used for your kris kcis from your it risk and operational risk standpoint from your risk standpoint therefore we're gonna leverage more metrics but from your compliance perspective as well as your continuous control assessment perspective we're gonna leverage our indicators capability for it so so if you have that conversation with your customers keep this point in mind yeah and you've got um on the heat map i think you show all the different risk events you show like the metrics you show indicators too if you come from assessments and so you show it all kind of on the heat map so people get that visual of everything on the heat map yes absolutely absolutely absolutely yeah yeah i know we are almost on top of the r but that's all i wanted to showcase today i hope you find these features useful and as always if you have feedback please feel uh reach out to me or tear yourself and keep the feedback flowing absolutely i'm going to snag the uh the screen back here and just going to wrap it up we have one more question while we're wrapping this up this could be a road map question and it might be covered but i'm interested to know how to do risk assessments on active money laundering and fraud risks is there a store app or anything coming in the future or can we do it with our own product well you can absolutely do it in the product right so i've seen some customers using our products for fraud risk assessment so i'm happy to connect offline on how what is done and stuff like that it's it's a very similar process essentially yeah we have we have your contact information thank you so very much i've put in the chat the links to some of the on-demand recordings you'll have this one and you have some other ones that are already out there but you can also visit us on our servicenow.com risk page connect without the community and then this also is a qrc code for you to be able to get to that on demand webinars that we've been talking about which will be popping up here soon for this one thank you so very much to everybody um i really appreciate all of your time and energy thank you so much woodkarsh for for joining us and running us through all of this it was a lot and it's really exciting and i expect to see more next time
https://www.youtube.com/watch?v=Yxh5VhE5-LA