logo

NJP

What’s new in Risk Management

Import · Feb 16, 2023 · video

we're gonna get started and uh yeah fun music what I was saying is we have lots of webinars to you know too but you guys can join and and learn about we've got technical webinars for maturity you're maturing your organization also from just getting started we've got these great what's new webinars we've got some great webinars with our third parties lots of webinars today however we're going to be talking about what's new in Risk Management which is one of our our most exciting topics I'm I we've got some really cool stuff to talk about also so I'm here with uttarsh John Taurus you introduce yourself hey hi everyone I'm utkosh part of product management team at servicenow I'm responsible for everything around risk management and excited to be here today good morning good afternoon good evening and looking forward for the conversation today and with cards she's going to demo this for us obviously you know so it's going to be really great but first it's a couple of housekeeping tips you're all on mute obviously but we've got the Q a panel here we really want you to use this we want to make this interactive we usually get some great conversations going so want to have that happen today um the session is going to be recorded and I will put in the chat the link to the YouTube playlist where this will show up later if you've got colleagues that could make it that you want to share with um so it will be available um and at the end there may be a survey so if you know if you have a few minutes to take that that would be awesome um let's jump into it all the excitement look at that yay we've done another release on the servicenow store for irm integrated risk management applications so great great exciting thing we already had one webinar um earlier this week so hopefully you guys were able to catch that if you didn't catch it you'll be able to catch it on the playlist around operational resilience and the great user experience that we've got now for it and and there's some really cool stuff happening there too today we're going to talk about risk appetite and there's a lot to show there and we're also going to talk about risk categorization using artificial intelligence so everything's getting smarter um we've we're not going to talk about the issue data model or the common controls because we're saving that for our webinar on the 21st um but we you know we we can ask about it if you'd like it obviously applies to risk management um so without further ado let's hop into risk appetite and I'm going to turn it over to uttarsh to be able to walk us through what this new enhancements are absolutely and I'm sure a lot of people joining in today with conquer this is one of the hottest topic that we keep hearing from all our customers right so all our customers all our partners and this was one of the key enhancements that we've always asked on the race how do we manage risk appetite so we are doing great in terms of assessing where we are by doing rcsas or risk assessments using the AR engine but organization-wide customers why they wanted to document their risk appetite in the system which is where they want to be so now we can actually measure where you are against where you want to be and that just say it everybody wants to be in right so you want to make sure your business whatever decisions they are taking are actually within the risk appetite I when I look at risk appetite I always look at it as a way to define your limits right documenting what is okay or what risk are you willing to take what risk you are not willing to take so it's important from a cultural perspective uh that the board and the Senior Management the this clearly defines what kind of risk employees should take and what kind of risk employees should not take right what's okay what's not okay so it's a very fundamental concept uh which helps organization make better decisions and hence we fundamentally believe this is going to enable better decision making across the organization now the way we developed this feature is specifically around risk of 10 and I'll get into the details of what our skipped ideas how does it differ from risk capacity and risk tolerance but if you look at it the way we developed this feature based on our research with our customers as well as all the readings that we did from our secondary perspective one size does not fit all so we wanted to make sure that the real skeptide framework we give you it's highly configurable which means it could meet the organizational maturity at at and it doesn't have to force it you to achieve there so so you can actually tailor this as per your unique level of risk maturity and then you can grow along with it so we always focus on making sure we are not just focusing on a particular segment of the customer but all our customers are able to use these capabilities so this is a very important piece the second thing you'll be able to do is not just document your risk appetite statements but also being able to define those limits across to say okay when we have these riskeptide statement in our organization what does it mean both from a qualitative risk rating perspective as well as your actual loss thresholds that you are expecting the organization to become comfortable with why and not just that what happens when there's a breach of an appetite right what workflows do you want to drive we are the king of workflows we want to make sure we are able to digitize those workflows so it's not dependent on the risk management or the risk Champions to always drive okay if you are breach of appetite these are the actions you should take but if you could digitize it we could help them right or automate some of these processes and make it easy for the first line to manage risk and get guidance as to what they should do in case there's a breach of an appetite and there's a lot of focus on reporting so as you can see the heat map visualization which is one of the key visualization used in which you generally report risk so when you're talking to your Senior Management you want to make sure you're filtering out the noise and only talking about risks which are outside the appetite right because that's what where the conversation need to be and they'll be interested in understanding what the action plan is and how are you bringing those risks within the peptide so this is a very very important concept making sure you are reporting the right set of risks and having a very filtered conversation with the senior management yeah that heat map workbench is something that we just enhanced just just the last release also so it's really changed a lot so that that I think if you have if you guys on the phone haven't checked that out yet that's something that that you should definitely look at and I've been getting great feedback on this and the vision we had was to actually automate the entire risk reporting out so that you don't have to create like a PowerPoint or anything like that you could actually do this live in the system have that conversation and assure you how we are making that happen absolutely during the demo fantastic all right next slide yeah so if you look at it now why do we actually need risk appetite so risk appetite is a very powerful tool which enables risk-based decision making and it helps prioritization and deployment of resources across the organization this is a very very integral component of the overall risk management process and if you look at any of these Frameworks from OCC FSB USA coso they will always talk about risk appetite being something which helps the Senior Management and the board Define what kind of risk you should take within an organization and what risk you should look to avoid taking right so this is where the Senior Management it stopped down where you're defining what kind of things you are okay today right and this is like I said it's different from risk capacity and risk tolerance and the way we differentiate between the essentially your risk appetite are things which you're comfortable in taking right so this is what you plan to be your tolerance is probably a deviation over your appetite where you are still operationally okay but you get uncomfortable right so and your capacity is the limit Beyond which you will not even be in business right so we this capacity is absolute maximum level Beyond which you may not even be in business anymore so we want to make sure customers are able to differentiate between the three and generally speaking you want to be staying within the green zone which is your within the risk appetite Zone but if you are between your risk appetite and your risk tolerance maybe an Amber but anything beyond tolerance is where you have not planned for and that's a red flag we just enabled that in the system so so customers will be able to quickly filter that out and being able to see that is pretty cool and I'll show you that yeah so really quick we're walking through kind of the how how it works the flow give us the flow and then and then we'll see the demo awesome so so it all starts with like I said always with the CEO and the leadership team for defining the business goals targets their kpis and when they're doing it they're working very closely with the risk management function to identify what kind of risk are we getting ourselves exposed to so if if a company wants to do a billion dollar business obviously if it's at let's say half a million it's gonna take a lot more risk and maybe expand into a different market now when you do this it's important that the risk function actually Define the Enterprise risk management framework and as part of that definition you will constantly see that they work with the CEO and the leadership team to say okay when we have these risks we have the streams work what kind of risk are we looking to take and what kind of risk we should avoid and that's what gets documented in your appetite statements which is then actually used to have that conversation being clearly documented out for the first slide right so that they know okay this is the thought process behind it but before you percolate it down to the first line you want to make sure your board has reviewed it you have a formal sign off from the board around your risk peptide framework the overall ERM function that you are looking to implement an organization in a particular year and once you have that sign off you're going to work with your first line risk champion and the leadership to actually Define and populate down those Enterprise goals into bu goals and obviously those corresponding each quiz right that are associated with The Bu goal and their risk of diet limits so that's where we believe from a top-down perspective while risk assessment is very very bottom up risk appetite is drop down here but you want to make sure your reporting is being done at appropriate level so if you see in the day it's being done at different levels of maturity so when somebody had a risk Champion or a bu leadership looks at it he's only looking it from a bu perspective but then it gets aggregated to the second line who are looking at it maybe from a cross organizational perspective right and then the CEO and the leadership team who is only looking at their top goals and objectives that they are looking to achieve and how does the risk roll ups to that and that is what gets reported to the board and the Senior Management when we are having these quarterly board meetings out so you'll see it live in the system on how we have been able to automate some of these processes here awesome all right so I think we've got a good overview now it's time to actually see it in action you want to grab it absolutely and show us uh show us what it actually looks like absolutely I'm always in for more demos than PowerPoints it's always more exciting to see stuff live in action and what I've done here is I'm gonna impose need as a risk uh uh as an operational risk manager but before I get there I want to show a bit of a setup because I talked about the tailoring activity so I'm going to impose need as somebody like a risk admin so that you can see what kind of setup activities are involved in setting this up now one of the important points you notice this is not a mandatory feature which means if there's a customer maturity to do the skeptide they can turn it on otherwise they can also turn this off completely right we don't wanna enable it by default for all our customers so it's an opt-in kind of a functionality that you will get so if you go into your Advanced assessment properties the first thing you will see is it's very closely related to migrate to Advanced risk assessment so only if this property is turned on you could actually use the risk appetite functionality now given the fact most of our customers I have turned it on the next thing you can do is there may be a class of customers who have the advanced risk assessment turned on but they may still want to opt out for risk peptide because the maturity may not be there or their uh processes may not be there informally documenting out the risk appetite so that's why we are still supporting those classes of customers and what you can do is just simply say none which means the entire risk appetite functionality will be turned off but in case you want to obtain there are two levels of maturity that you can Define your skeptide in the first level is where you just manage let's say a single level of limit saying okay let's say we were planning that the rest should be maybe less than a million dollar that's it right so I don't want to have like a red in an Amazon it's just anything beyond this is a red that's how we Define your appetite only which means it's a one point scale but in case you are looking into that red Ember green kind of uh monitoring of your appetite that's where you can select your risk peptide and risk tolerance right so this is the first configuration where customers can then enable saying what how do they actually use rescripted and this may be relevant for some of our partners who are doing this implementation for our customers as well the next thing customers can also do is they can Define how do they express risk update right again depending on your risk management maturity you may only be doing qualitative appetite which means there is no dollar value associated with it it's completely qualitative in nature which means you say oh all risk should be medium and low right as an example right so that is your qualitative appetite your quantitative appetite is actually quantifying those risk and then comparing against the Lost thresholds your annual loss expectancy values and clearly defining that this business can only incorporate this much of risk right so that is what we do in terms of defining the skeptide qualitatively and quantitatively so qualitative gets compared to your risk readings with an advanced recipient assessments and quantitative appetite gets compared to your annual loss expectancy values within Advanced responses so those are the four set of configurations you can make the second thing you could also do quickly is you could also Define your risk appetite scale now if you look at it this is different from your methodology rating criteria that we have and the reason is risk appetite is a central topic right so it cannot happen that it Universe has a different appetite from an operational risk I mean the scales cannot differ your appetite May differ for operational risk and ideas but the skills cannot differ so that's why it's a one Central table that we created where customers can go and Define their risk appetite skills these are your qualitative skills values and then once those are defined you can actually map it to your rating criteria so when you open up the assessment methodology for example now one of the things we have enabled for our customers who are already let's say using Advanced risk assessment is even on on the published methodology they will be able to map their rating criteria to your prescription scale so this enables quick adoption for customers they don't have to recreate their methodology but they can quickly map it so I can say very low actually maps to an adverse risk appetite so if I say let's say fraud I am a verse as a risk it means the rating can only be very low very low right if I say oh I'm okay taking uh let's say uh misuse of authority kind of risk right but with a cautious approach it means if I have a risk rating of low and moderate I'm gonna be within the epidemic so that's how we are enabling customers with having multiple grading criterias to be able to map to one Central risk heptied scale now I know some of this may be technical in nature but I do want to cover this given the fact some of this uh some of our partners also joined this call so I just wanted to kind of cover this across for custom for those classes of audience here the next thing you'll also be able to do is there's a section here called business validation that has been added into the risk assessment methodology record and here you can actually Define the workflow out to say what should happen in case there is a breach of an appetite so I can say mandate up mandate final comment or do you want to manage your list response strategy or automatically create issues right so all these are ways to make sure when there's a breach of an appetite so you did your assessment and as soon as there's a breach of an appetite the system is able to automatically guide you saying where you want to be next right what is the next recommendation that you're there so this enables my second line laying down that policy on what should happen in case there's a breach of unlimited right and not just this you could also Define your configurable approval workflow so I can say for example I can say if there's a breach of an appetite actually make sure there's an additional sign off that is being provided by either The Bu red or maybe the second line so I can Define that additional level of sign off right and this makes shows again that you're not reviewing and approving every risk assessment but only risk that of your own appetite as an example so I can see that I could Define an additional level of approval here using our approval configurator that we released uh in the last release and here I'm saying in case the risk appetite status is outside appetite or outside tolerance make sure you are getting a sign off from anybody in the operational risk management team so does that mean with a question here that you can have multiple risk appetite scales for multiply multiple um Rams so so the appetite scale is going to be single but the mapping can differ so you can say because let's say it risk uses a three-point scale and let's say all press Q to the five point scale right the mapping between the skipped right skill and the rating criteria May differ okay awesome so and not just this right we have also given a flow development of action making it even more powerful for our customers so it's not just like talking about having what should happen or we are restricted on what we are doing but Partners have not complete flexibility in terms of what the additional workflows that should be triggered in case there's a brief inch of connected so that is what differentiates us from any of the uh our computers here so you could complete your automate your workflow as to what should happen in case there's a breach of an implant so now I'm gonna impersonate as somebody in the second line right actually talking about how do you define this update so I have impersonated uh Andrew Taylor now before I do this one of the callout I would make is even though I'm showcasing everything in context of the new UI this feature actually works both in the new UI and all UI so if you have still not migrated to the new UI you can continue using this feature right in your classic UI or the old UI as well so but I'm gonna demonstrate it in context of the new UI currently here so yeah so I start by going into my Ruth statement because generally your risk update is something which is generally starting from there so I can go into let's say fraud related risk and if I go into my top risk which is your operational risk in this case so I can quickly see where you go and Define that right across so I can go and open up the risk statement record for the operational risk and there's a new section called riskeptide where you can Define your qualitative as well as your quantitative appetite and tolerance values right so I can say yeah for operational risk I want to take a cautious approach but I may be okay or okay at all reading up to open right and then clearly documenting out the risk update statement so that it's not just a value but somebody is understanding what the rational was behind this what the thought process was and what should happen in case there's definitely a bleach open update so this is a very important step in terms of defining that across and what we have also done is you could also Define because these little skeptides are not something which are lifelong you want to continuously revisit this on a year-on-year basis in the system you can define a date and based on the date that is defined the system is going to trigger a reminder notification hey look this is an upcoming review of your rescript right so that you can reset it and you can actually Define it based on your cycles that are there when you're defining that data cost so this is the place where you will come and Define this appetite values so now this is in context of the risk statement record that I'm defining it and once I do this I could even populate this down to all my child levels because what we have seen is a lot of customers when they Define the risk appetite they would start at let's say level zero or level one then go to level two level three but maybe stop there and not even go to level four or they may be stopping at level two so you may want to do that and that's why this action saves Risk Managers time in trying to define the same appetite values across all the corresponding child statement and the risks that are associated with this risk statement is actually this is actually a theme that we've got this this particular release right this inheritance you know where we're allowing you to to um you know inherit inherent inherent the risk appetite or the control tests or whatever from the parent it's sort of thing for this this uh this particular release and also I like this because this is going to make sure that people are are really really reviewing the appetite right so that it's not just don't set it and forget it it's constantly being reevaluated yeah we don't want our users to waste time in maintaining this data into multiple places we want to make sure some of these redundant tasks are easier to do right we are not wasting time there so definitely you'll see this constantly there in the product that thought process so so this way you can Define it at a risk statement level and one of the things optional you could also do is you can also assign ownership again the reason behind this ownership concept is to make sure at an Enterprise level let's say we talk about operational interest right so generally who the owner is in case the breach of an appetite when you're reporting it there's a neck to be the whole thing this is the person responsible for it and he can manage that make sure you have an action plan depend so that's the concept behind having ownership now in certain organizations it may be there it may not be there so that's why these fields are optional in nature right if you have it you can use it otherwise just hide it or maybe leave them there so so that's what I would say in terms of the risk statement similarly you could also Define your appetite values at an entity level too so it's not just at the risk statement level but even at the entity level as well and conceptually the way we look at it is saying okay while Enterprise risk team would Define this at each of the uh just taxonomy perspective those risk appetite statements and the limits generally the business teams may have somewhat of a different appetite at their each business level so as I as a business owner I can actually have that visibility or that control to say within my business right I want to Define this update so that's where you will see the apparent values being able to Define not just at the risk statement level but also at the entity level here and then once you do it automatically it percolates down to the risk so once your risk appetite values are defined it percolates it down to the risk level and that's the lowest level of mature or lowest level at which you may want to Define your appetite now at this level this also an option right for the risk owners to override that so like I've done here let's say this is my business where for whatever business reasons I need to take more with so I can simply flag this across saying I want to actually override the skeptide and what once I do that what you will be also be able to do is actually capture the justification so I'm I'll open the rest sorry open up the wrong one I'm gonna open it now UK no worries this is this there's just so much here it's there you've got every level absolutely the chair that you're addressing yeah so so like I said right we want to tailor it to the level of maturity customers are at right if you want don't want to provide something which is only working for a subset of the customers you want to make sure everybody can benefit from a large customer base from these features so that's the thought process so like I said you could say yeah I'm gonna override it this is justification that you can capture so that second line can again come and they can understand why there was an override of the risk update right so this transparency in the system making sure that the purse line is not stopped there's no red flagging but at the same time the second line can come in and understand why that business has to override that appetite so this is the value which will then be used for your assessments right and let me show you that so I'm gonna I'm sorry a couple questions for you um I hope I think I think it fits in here is this visible to APM with the GRC APM integration or or only on entity tables so so that's a great question so because this value exists at an NTT level potentially you could pull it up into let's say an application record so that the application owners can also see the appetite values for their respective applications that they own out of the box you have not done it but it's just a simple configuration to pull those fields and enable it into the APM record great and then the next one here is is the risk appetite on the top level entity based on the aggregated risk score for the primary Ram or do Downstream risks also aggregate across various Rams so what I've been focusing so far is just defining the appetite values right so defining your limits you're defining your budgets I have not talked about how do we do actually monitoring whether you're complying with those updates or not complying with it that's where the quote that's an excellent question and I'll address that once we actually do an assessment and I talk about how those assessment values are then getting rolled up to provide you visibility to say whether you're within outside appetite or outside tolerance so we're jumping ahead okay so that so that person can wait wait a couple minutes and we'll get to that one absolutely awesome so if we have no further questions our impersonate as a business risk manager to actually show you how do you actually do your risk assessments right so I'm impersonating as a business risk manager going back to my workspace and you'll see how we are making it very easy for the first line to understand what your appetite values are right so you want to make sure when you're defining those limits on your defining your appetite it's easy to communicate to the first line so that's where the focus is again from uh from first line empowerment perspective so so let's see that so if I open up the assessment and let's say the business manager or those Champion here is doing this assessment now as soon as you open up the risk assessment record there's a new site panel that appears and this site panel here just does not ex give you the risk Capital details but this ton of more information that is now visible to him before he can take this so there's a full risk details to understand what the risk is who the owner is what the entity is what hierarchy does it belong to right so your risk taxonomy so if you are assessing this risk I understand it's going to roll up to operational risk as a risk taxonomy and that's where it's getting impacted whatsoever was my previous assessment right I know previously I was high the controls were ineffective that residual was also high if I want to go see the details about the previous assessment it's just a click away and finally most importantly the risk applied value right so you are assessing you are going to assess this risk my appetite for this risk is minimalistic while my tolerance is cautious right and these are the quantitative limits that have been defined in the formula skeptide statement so I can go through these details understand them and then actually use it when I'm doing your risk assessment to automatically try the workflow so for example here just to save time what I've done is I have already done an assessment now where I've done my internet assessment I have assessed my controls and when I come to my residual let's say the residual comes out to be I right which means because your inherent was high your controls were ineffective the system based on the risk assessment that you did automatically computes and says hey look your appetite is outside appetite now at this point of time as a user you may be wondering why and that's where what you have done is we have provided a clear description of why that is right so if you don't know how to buy the ocean make a transparent for you those to understand this transparency in the distance saying oh you have a risk rating of I and that's why which exceeds the appetite value of cautious and therefore you are outside the tolerance Zone it's a red flag clearly calling it out and then this comment here becomes mandatory so somebody if I delete this comment out actually will be not be able to proceed so this is making sure that the first second line what the policy is within the organization is getting instrumentalized in the first line right so you can capture your comments here so you can say x y r capture the comments and move on so I can say yeah I have provided my action plan as to why this risk is outside the appetite and then I when I go into a risk response the configuration I maintained is if the risk is outside tolerance I also need to define a plan of action to mitigate it I cannot go away with it so therefore here if you see I selected the mitigation and the plan of action and the system mandates you to do it if you delete this out so if I cancel this task out for example it's not gonna allow me to submit it because it's gonna say select at least one response strategy as your skill outside update so only if I say I'm gonna mitigate it document the plan of action here in this window I'll be able to proceed and say this is I know this risk is outside appetite and this is how we are mitigating right so you can capture it across and then finally send it for approval right so this is where again customers can come Define and configurable approval workflow to say okay if this risk is outside that right or outside the tolerance go for additional level of approval so I could initiate that across so this is this is the power that we are giving to the second line to make sure that's genderization can happen within the first line when you are empowering them to manage risk right without much involvement from the second line so this helps and you're actually and you're actually giving them that that almost like a road map that they have to follow and they're keeping them within the guard rails they're not letting them stray off so it's it's um they're making them do the right thing really absolutely is this what it is but but it's done in a way that it's not intrusive and it's very intuitive yes absolutely so that's the thought process right we already want to enable the first line you want to guide them right they should always the system should be able to provide that prescriptive guidance as to what they should do in case the breach of an apparent they don't have to contact the risk management team to know oh we have reach the appetite what should we do the system is telling you what best practices best practices you're really you're you're sort of implementing best practices for for organizations and for the first line and this is truly I mean this is what we say you know we're we're we are you know risk integrated risk management it engages the first line Second Gate line and third line and this is a great example of how we're engaging the first and second lines absolutely so now once you do that assessment on the risk record you will be able to track what your status of the appetite is right so I can clearly see this risk is actually into the red flag zone so when I'm talking about I as a risk owners and let's say a bunch of risk maybe I only worry about risks which are outside the tolerance or outside EB Tech right risks which are within I'm not bothered right so the basis of this is again the primary and methodology right so only for the primary methodology the system is going to compute the appetite status at the risk record level and show you what your appetite status is now let's say there are a bunch of stress that are associated with a particular entity what we do is actually aggregate those risk information as we do in our roll up and then compare it with our appetite values so for example let's say acne RB UK I know my risk profile for Acme ABI UK is medium right that's my residual risk trading let's see what my appetite values are so it was minimalistic and open now based on that you can clearly see the system Auto computes my update status right and chase you are outside update now there can be two statuses one which is qualitative and the other one which is quantitative but probably from a reporting standpoint you only want to report one which is the overall status right and so what we do is we also do that saying the worst case is what generally gets reported and therefore this is the value right so if I as an entity owner again wanna keep track this is the value I will keep track of so that's it yeah my risk is outside the appetite which means I mean sorry mandate is outside Deputy which means some of these risks and that is where I can go into the staff understand what those risks are which are outside the appetite quickly understand what the risk owners are doing for those individual risk and maybe have that conversation so this is how you're enabling the business owners right making sure they can track keep track of the business all the application owners or any other owners of those entities in a very simple method to say oh organization expected me to do this am I doing that or not right and again the point around transparency to say if there if they're curious about whether how did the system compute the rating they can always click this question mark icon here and the system is going to explain you why that trading was computed more intelligence more intelligence uh so attention to details as well right I mean a lot of times we build systems which are black box but then the is user is curious as to what is happening so that's where we are looking to make it more transparent making it more easy for the first line to understand how the system is doing the math behind the scene to private these status values and the point somebody asked it is the primary methodology whose risk rating will be used to compare it against so this is where the concept of the primary methodology at the entity level thumbs up okay and then you're able to aggregate that to all the you know across the hierarchy so I'm looking at across yeah yes so now when I move into let's say somebody at a higher up maybe I can make Banking and investment level so it's not just taking into account you would risk that are associated with let's say Acme uh Banking and investment but also all the downstream risk because ultimately if I'm the head of business attack my banking investment my risk is being contributed from across the board there so your aggregated risk posture is actually factoring in all those different things so the score of this is already factoring in all the downstream entities to compute it and then we compare it with your reptile to compute say oh what's your updated Center yeah amazing and this is not just at an entity level but also at a risk taxonomy right so for example let's say I'm an ID risk manager so I'm worried about all my ID risk across the board so I know I'm not concerned about at each entity level at each application Level so I'm looking to understand how are we doing at operational risk overall so I can simply open this up see oh I'm good now if you want to understand the Big Town of it so I can see that even though operational risk is within appetite I do have a pro Improvement in the process related risk so those seems to be outside that dead right even procurement for example maybe outside appetite but because of the other risk being clean at an aggregated level I'm still doing okay so this gives somebody complete visibility the right hand side panel to understand what are those risks taxonomies that you need to worry about and probably if I am owning the operational risk I'll be looking at this risk right saying recorded fictional business transactions for personal gain this seems to be at the red flag level right so this is where I can quickly go into areas where I should focus my attention on right so I want to filter the noise again so making risk appetite monitoring easy for our customers is what we wanted to achieve by simply reporting this across here I'll show you something cool now right even in the heat map visualization when I open this up you'll be able to quickly see the red flags and the Amber zones of the risk so this is where things become very very interesting so for example let's say I'm looking at all my business rcsas and it can happen that technically you are in this Red Zone from a risk perspective but you expected this risk to be a bit High right that's why you see it can happen that some of these risks you were expecting them to be high right so it may be okay but there are rules that you're not expecting like inability to secure a visual sufficient resources for the project so this is where the system flagged these risks as red and this is where probably your senior management wants to have a conversation around it so that's where you can actually go have that pointed conversation and even you can look at the trend so for example I can see the trend across how this risk was doing on a period on period basis so whenever I talk about this risk I can look at it oh was it always in the Red Zone yeah I mean was it always in the red flag or is this something which changed over the period of time right so so this is very very important for customers to understand how the different risk rating over the period of time impacted your appetite values and being able to have appointed conversation with the business look yeah we were doing better in the past but we have actually changed so you can see here for example right initially when we started with we were just in the Amber Zone which was okay but yeah we've been to in between with the red flag but the latest value is also red so you are able to control this risk in the middle but it has gone again out of control so maybe you need to revisit some of the actions that you do yeah I love that I love the trending I think that I think that's really important I to be able to see which direction your risks are moving absolutely absolutely and then be able to see the red flags I mean see the ones that are actually a problem that you didn't expect to be there yeah I think it's amazing I mean see risk management is always about figuring out your priorities right what risk should you focus on and that's what we want to enable our customers to quickly get to risk that should that they should need to manage better right so these are indications visual indications to quickly get there filter out those reports and have a more pointed conversation now we also got the Insight from some of our customers when we look at this risk right maybe at times when we are having this conversation we want to actually reassess it so what we did is we simply provided this action here to say reassess it and you can actually do a reassessment of this risk right from here right so making it very very powerful for our customers to say okay in case we are having this conversation let's say you are into a room and this is a scenario that actually happens you're into a room and somebody says no this risk assessment was done let's say three months back it may not be correct maybe you want to quickly update the risk rating across and that's what you want to enable our customers to so you can quickly reassess this risk looking at it right here so some of those minor feedback that you guys give are always Incorporated we try to make sure we are listening to you and improving our experience across on a constant basis yeah that's fantastic all right do you want to move on to the next feature absolutely and this one is pretty exciting too there's I think I just choose the art of possible oh and this is an AIML feature so what we wanted to do in this feature is really enable our customers in the first line when they are creating a risk you are able to tag it to the right risk statement so when we actually spoke to a lot of our customers they said one of the major problem the second line phase is the tagging of the risk to the right risk taxonomy because as a human behavior let's say I'm I'm documenting a risk around misuse of authority it's very very human to say oh let me search something around misuse of authority so I will start typing in misuse of authority in the risk statement I don't find anything I will go see the first page and quickly get it right whatever I seem relevant I quickly selected and there's a significant list you will have to go through so that's where we wanted to see how can AI help in this right can AI based on the name and the description that you're typing in can go and say hey look this local risk that you're creating in your first line the nearest Risk in the risk taxonomy seems to be this right so that enables that the first line saves time at the same time you're reducing the amount of Orphan risk that the first line would create and make sure that when you do these risk assessments they can aggregate across to the actual second line so that you can your risk taxonomy so that you can understand the true impact of that corresponding risk to your overall organization so I know a lot of customers have that business goal saying we don't want to have orphan risk but because first line is creating these local risks it's very difficult for the first line to actually identify the right stigma and that's where we want to leverage AI for this so if you see on the right hand side panel there's something called as recommended actions that will appear and as part of that recommended actions you can see I should be tagging this risk to probably something around internal fraud is what my system is suggesting me to do so this is available as part of the GRC predictive intelligence application of plugin and available to all our professional and Enterprise customers and this is just one of the possibility I always tell this to our customers we have the AIML framework and one of the things I would love them to explore is also the recommended actions framework because it now provides also a UI layer to actually surface some of these AI recommendations to our customers so what we are shipping is just art of possible and if you have other use cases you would love to have a conversation and talk about how you could enable it yourself into your organization without depending on service now or not so that's how we are empowering you to use AI within the GRC framework and make better decisions better do better risk management right using AI smarter smarter is mismanagement so I think we've got a couple questions let me go ahead and steal the stream from you um and we will get to the questions here are you seeing my question screen I hope uh we've seen the sliders the questions like yeah absolutely all right so we've got a question here roles this has to do with the end of your app at risk appetite presentation but roles normally need to be assigned to assess to access the workflow can this also be done through the workspace the rules assignment yeah assigning the roles yeah so right now uh all the admin experiences are still not available awesome if anyone has any more questions please put them in the questions panel um we got a great comment actually not a question but you know we got a one of our attendees is loving the workspace says that it's really well done and it's very powerful so that that's a great thing we love we love to hear good things too not not just questions um and we always love to hear it as if we have any of our partners customers have feedback please feel free to reach out to the product management teams and tell us what we can do better so you're always listening to you all of your feedback is what we try to incorporate on a constant business and you are the reason the product is where we are we are the market leader so you want to make sure you guys are having you we are having that constant conversation so please please feel free to reach out and share your feedback always absolutely I have put the link to the um to more webinars that you can register for and to the recordings in the chat so everybody if you want to go ahead and check out the chat um I will you can find it there um I'm gonna put it in again real quick here we are one real quick question about a pen test I'm not sure if this is something that we've actually thought about is pen tests um once implemented would be able to carry out a pen test on this is that something that we've thought about at all so pinteresting is part of any service now I would say product development so whenever we do new product development or feature development it goes through a round of penetration testing at a service now level right it's not just specific to risk so that is already done so whatever applications we delete on the store it is always tested thoroughly for all those nfas well that's all for the questions we have today thank you so much for joining us please continue to connect with us um you can visit us on our website and go to the community as I said I put links to the YouTube playlist in the chat along with the link to the registration form where we have a lot more webinars I want to really thank ukarsh for joining us today and for that fantastic demo that was amazing and again don't join us again on February 21st we're going to have our next webinar in the series around um policy and compliance which we will talk about common controls and the new issue management that we've got going on so thank you again everyone thank you for joining us join us again soon bye-bye thank you bye-bye have a good day bye

View original source

https://www.youtube.com/watch?v=oPXAl20lQcA