logo

NJP

Let's talk: Building engagement around your IRM program

Import · Apr 25, 2023 · video

all right well it's 901 Let's uh just go ahead and get started um folks can join or listen to this recording in the future uh good morning everyone I'm Anne-Marie Fernandez I'm a senior uh product Solutions marketing manager what that means is really I uh tried to bring out the product features and stories for risk um basically videos and uh help everyone understand the tool a little bit better and how to use it and with us we've got John hello good morning my name is John Quintanilla I am a principal business process consultant uh within our expert Services Department here at servicenow um I focus on implementations is really what it is I help customers Implement our Solutions specifically risk and compliance and help them be successful in in using our tool and helping their users use it awesome all right so let's go ahead and get started um just a couple housekeeping things um if uh we've got some time at the end for Q a use a q a at the bottom of your screen um we'll answer those instead of the chat that way we can get the questions recorded and we can answer them later on if we run out of time um and obviously this presentation is recorded and it will be shared on the community um a couple uh days or a week after and at the end of the event uh please please fill out the survey really helps us understand how we can um be better and answer any questions um and improve as well oops is that right oh yeah and then on Thursday we've got a follow-up session uh office hours it's a 30 minute not recorded session to follow up um and deep dive a little bit more on some of these questions if you've got deeper product questions we can go in and take a look at things together um or just kind of free form answer any questions that you have uh this Thursday at 8 30 Pacific awesome and so as I mentioned so I mentioned earlier I'm on the expert Services team risk and Brazilians team and so again we are a group of experts technical consultants and process experts that will work with you and work with your stakeholders to understand your use cases and implement the solutions that we have whether it be irm BCM ESG we have a lot of brm all the different solutions that we have we we work together uh closely and you know the best part about it is that you can obviously there's Partners out there that you can work with that are great also we love our partners but sometimes we want a little bit more close to home expertise and that's where we come in as expert Services living service now awesome all right so quick agenda obviously we did that in introductions then we'll get now we're going to get right into talking about common engagement challenges what does engagement look like for an irm program um and then also how to approach engagement in your organization um it's not a lot of time so we want to just give you some quick bites effective things that you can take and Implement right away um and then obviously for these sessions we like to spend a good amount of time on a demo so we're going to focus on obviously the features and how a service sound actually intended the tool to engage your stakeholders and then we'll wrap up and answer any questions so the first question is um John for you is stakeholder engagement in the irm implementation different from other implementations such as itsm PPM or or HR and if so how yeah so in my experience I I believe it is right and really as you can see on the right hand side risk happens whether you manage it or not meaning you know if you're working with an employee workflow or something like that you only engage it if it's going on but in in Risk risk is everywhere and and it's everybody's job as a second bullet says right you will need to interface with all levels of the board sea levels the risk teams to I.T to the front line you know risk happens everywhere and anywhere that's why irm as an implementation is a little bit different from some of the other solutions that we might have is because your stakeholder levels can be at the highest level or it could just be it could also be your customer your customer could even find be a way that that they are introducing risk into what you're doing you're trying to collect information and data from that so that's really where the difference lies uh uh within irm implementation it's an engagement awesome all right so again when we're talking about managing risk right and resiliency and everyone's responsibility you can see where we obviously start with with the employee uh and and what they're interacting with on a daily basis so uh whether you're whether you're taking a call or a phone call or some of that or you identify something and then from there it goes all the way up from a business leader to a corporate function to a senior leadership to a board of directors right so the information is being captured at the at the first line is what we call gets pushed all the way up through all the way out to the deported records even sometimes with external Partners right when you have Regulators like like the OCC and things like that depending on who you're talking to but all of the work that is captured and done excuse me is typically at the employee level and finding a solution and working with a solution like servicenow where we try to balance not only the work that is being done at the first line and how the information is shared across channels is something that's really key when it comes to risk and compliance when you talk about risks and controls right right and that's because accountability is at every level right that's right accountability you know even responsibility for standpoint right even Consulting right we're going to talk about a racy later but the Consulting the information all that stuff everything that you're providing from an irm perspective from risk can span across multiple channels multiple channels in our organizations absolutely so this is a good example right what we were talking about the the the front line business users right in the center now you can have multiple second line of defense partners that are asking for information right if you talk about operational risk you talk about Enterprise risks you talk about third party risks compliance all of these partners are responsible analysts that have to provide information about our risk and what we're doing but we're also all going to the front line user to collect that information and we're saying hey give me this info give me that info you know I need more details I need more information this poor person I say this poor person because not only do they have the responsibility to perform in their daily job function now they're also having to stop and explain all the information maybe five six seven times that's the same information but it's just siled and shared disparately across multiple lines right so the other thing that breaks down here is first second and even third line right so third line also needs information sometimes audit will come in and they'll start to ask questions right so that's that's why I love this this illustration because it really shows how this one single person is being asked to provide multiple details about the same situation the same occurrence the same issue the same event whatever you want to call it and they're having to share it with multiple people to collect the same information and when you go into your implementations do you see that each of these groups the resilience team the risk team the compliance team have their own tool that common it is common it is common for everybody to have their own way of managing it right sometimes you know one area will have Excel another area will be using SharePoint another area will be a lot more sophisticated and they'll already have servicenow another area will have Archer another area like audit loves to use teammate plus like so you've got all these different systems that are in place and they're asking this Frontline user to provide information into all these different tools uh in order to collect the data right and so that that makes it really challenging not only do they have to know their job but now they have to know all these different technology mediums on how to actually report the information right and good luck reporting it up yeah yeah the aggregation right because all these Enterprise risks third party all of these are going to have c-level Executives that are going to want data and want to know where are my hot zones in my area that's that's the one what is my Hot Zone where's my red well each one you're gonna have to aggregate some of this data how do you how do you bring all that together with it with disparate sources right yeah yeah absolutely absolutely all right all right so guys we've got our only uh poll question just one quick whole question to get a feel for the team here or the folks on the line what is the top challenge you face in operational life in operationalizing a risk culture in your organization today um they may all apply so just kind of um let us know what your top one is if you had to pick one so we'll give you a couple seconds um to reply okay awesome I think that's actually everyone John okay cool 50 50 organizational silos and lack of maturity and standardized or documented business process which is the highest number we see even ourselves in our implementation work that we do yeah yeah and some of those are a function of the other ones right so not having terminology not making compliance or focal point leads to you know it's like a negative cycle yeah absolutely absolutely so we touched on some of these right organizational silos is a big one that just it's really difficult when you have multiple Executives with multiple goals and everybody has their understanding and their View and their approach on how to solve the problems especially when it comes to risk and compliance right the other one was that I saw in there was you know unstandardized processes and and and while we may think that that is the biggest challenge the standardization of the process that's worth something like a servicenow tool can really come in and help because our the service now tool is not only flexible in being able to work the workflow and add approvals and add reviews but it can also uh be be useful for areas to mature right we can you can you can implement the solution at a very um what I like to call a a a a start point and then as your organization insurers as the processes mature as they get documented as they grow your solution can now mature with it and be scalable as we release more stuff so that's really the cool part but the organizational silos from an engagement perspective is really I think the biggest key right is how do we bring all of these Partners together how do we have these conversations that's really what they are how do we have these conversations to write down what are the requirements what do we really need what's the Baseline and and that's that's what I like to bring on here but the other thing to point out too right the the you'll see some of these lack of system Integrations these are things that we talked about right no aggregated view point in time risk assessments these are all things that we're talking about as the challenges of having disparate sources of data and having multiple Tools in Flight that are trying to capture the same data yeah yeah excellent so let's talk a little bit about those organizational silos right so if you excuse me one of the things that we talk about is from identifying an issue perspective you know 80 should be identified from the Frontline user 20 from the second line and then 10 at the third line that would constitute a healthy risk uh a healthy risk model for your organization to say most of the stuff we're identifying we're identifying them early we're we're presenting preventative controls you know detective controls we're getting these in Flight we'll get these in place and we're getting these early on right and then our second line is coming in and they're doing oversight and they're helping us grow and mature those those processes and how we document and then third line hopefully third line is coming in and just saying hey let me rubber stamp that yes it's looking great we don't have any issues identified right that's kind of how this plays out but the cool part or the important part about this is all of these people need a seat at the table right we can't that's engaged that is what real engagement is if we if we only build uh uh if we only Implement a solution with the second line in mind risk and compliance teams only and they're siled with their it team and we're building it for them we sometimes lose sight of the experience for the first line user number one and number two we sometimes Miss to make the connection with what third line needs to capture right so if we only use one party in here to build our tools that's really where engagement falls apart right right so and and that engagement piece starts off early right it's not like oh hey I've got this let me go communicate it this is a it's not a change management strategy it's I've got to engage people early to understand what are those challenges and how am I going to implement that going forward right so even if you're a new irm program low maturity you can have one use case you're saying we still need to consider the these three levels it's best to even if it is it could be one simple use case to say you know what I've got one area with one small group of users that I'm only you know it's not huge it's not big but it's still in important to bring in the site of first second and third line when you're building a comprehensive risk compliance program right right exactly so not only the work the heavy lifting but getting the stakeholders the business engage and also thinking about how you're going to report that up to audit or or the board that's right that's right awesome I like that all right so oh too many uh too many arrows yeah this is what we're talking about with the boards right I'm coming in now engage embed and evolve right that's the that's the biggest um I love the three E's what we call the three is a simple repeat approach now the good thing about engage is this is where we talk about you take your Business Leaders your literature your your leadership and you find a way to either through like voice of the customer um or interviews you know you could do regular interviews and as you can see on the bottom these are the different Frameworks or the different areas that we're looking at right so if you're looking at regulatory change or regulatory management indicator management policy control testing all these areas are going to have Executives or Business Leaders that have input in the approach of what they're trying to accomplish so that so one aspect is the engage piece the second piece would be the embed right embed common risk and compliance libraries this is where on the questions we asked you know the nomenclature or the library the governance structure has anybody spent any time kind of identifying what those parameters might be for the development and the building of a risk library of a control Library uh uh of a policy management library right and then after that has evolved so the Evolve pieces the indicators and automatic factors and accelerators so this is the fun part right once we've once we've got the people involved once we've established governance then we can actually get faster about what we're trying to accomplish right we try to move off of manual processes and manual testing into indicators and automated factors and stuff but the thing about this it's a it's and the reason it says rinse and repeat approach is because it's constant it doesn't stop right the engagement can't be just on front and then say okay I got everything you need I'll see you later I'm gonna go build and then I go build and then I come back and then all of a sudden it's like well wait a minute I guess I misunderstood your requirements because this is what I got and I know that's not what I needed right and so that's why the rinse and repeat approach is important that periodically throughout implementation throughout your REM program you know you can do it quarterly I mean so so in my experience I was a product manager for 10 years at a at another institution and and every quarter I would meet with every executive I had it on my calendar every Court I would meet with them and say hey these are the things that we're delivering these are things that we've worked on what are the new challenges you're getting right because they've already met with The Regulators they've met with the board members and now it's evolved now it's it's increased or it's escalated right I need to know what are those new things so that we can be agile on our project delivery and and keep working that out absolutely and I think this this slide um maybe we could have made it a one two three but it does kind of go in that order um and whether you let me know if you agree or not John so I feel like it starts with engage it starts with the people like we could say we start with process and we could start with process we can embed and involve but if we never go back to engaging people it's not a full program right or it's not really a full like Inc you know you're getting the information you need uh or feel good about the clarity of the information right so the risk assessments need to go out to Front Line people have to you have to have control owners um right you can have processes but I think people shy away from engaging because nobody wants to think about risk and nobody really was talking about control but we have to right well think about this if we ignore the people side then we are automatically introducing operational risk into our projects right because what is operational risk it's people processing technology right so if I look at embed and I look at evolve this is my process embed is my process and evolves my technology but if I ignore the engage and I ignore the people I have automatically introduced operational risk into my process into my project right that's why it's important to look at all three of these from an operational risk perspective say people process and Technology where are we at right so what this is saying is really leverage your people to then embed the risk and embed the controls that's right into the processes and then from there you can do awesome things yeah all right so did you want to um well I mean this is irm and csdn so csdm is common common uh Service delivery model comments common service data models we get we get uh confused with our academics common service data model and the reason it's important is because irm risk management is really a piece of all of the data that you've got going on right you can see on the very bottom in the green box you'll have things like company units Department locations support groups processes these things are sometimes they're already documented sometimes sometimes they're not we're struggling to document we had that you know we had that poll question but you'll also have the infrastructure data right Cloud resources printers endpoints databases servers all this together becomes your common service data model all of this information is what is then fed up through risks and controls as you document your processes as you document for example something as simple a single sign-on right when I single sign on onto my laptop especially right now in this new virtual world where everybody has this I have to know you know I have an application I have applications that are being managed by single sign-on they're in specific locations sometimes they impact me globally sometimes they don't right sometimes they're support groups like that all that information then gets fed in in through irm through audit you know through risk management compliance risk and audit and then you have your your um your risk and controls that are put in you can see the green box in the middle that's called entities right interest Ci's Services applications departments vendors groups users those are the what you would call databases or data to this common service data model that's on the bottom that's how they come into irm so if you haven't established a foundational data now engagement wise sometimes these all have different leaders that are responsible for different items right so that's what I'm saying if you have a very small use case that's easier right I can go work with that individual and I can start to build that out and we also when we're doing implementation we also recommend say hey can we build this out with a few use cases first get get get really good at it and then we'll start to scale and bring everybody else on board once we once we're comfortable so this is kind of tries to bring it all together for you absolutely absolutely um all right so I see Dan's got a question about let's do the demo real quick and then we'll get back to uh the question okay Renee um all right so now let's do a quick demo um John do you want to go ahead and start I'll take it all right we should have my screen you should be able to see the service portal that's what we call the service portal um this is a little bit outdated I know we're working on a new and improved version of it I know our product team has already been working on that but the main point of what I want to do here is as we were talking about engagement that there's first second and third line and how they use it and how we use the tool can very can fluctuate very much from a first line user perspective I've got to remember I've got systems that I'm working with that are it's either in customer service where I'm taking phone calls and I'm having to report tickets and I'm having to do all that stuff or whatever I'm working it could be I'm in front of a client and I'm meeting with a client and so I can't have a very complicated front page that just throws everything at me right so the service portal is really from an end user perspective you could see they've got very simple buttons here request something knowledge base get help but the other cool thing from a risk and compliance perspective is we can have this little button here that allows them to do some of the work that they need to do from from a GRC effective right so you can see my risk events my policy exceptions my issues so if they find an issue that they want to report they can click on my issues and they would go in here and report an issue right now I'm I'm I'm in as Jacob Williams he's actually a compliance manager so he would just report an issue through here now you would select some basic information right the good thing about this it's not meant to be extremely lengthy because this is just the starting point this is just the beginning point right I just want to get this introduced as something that might I might have a problem and so I'm bringing this in right so that's how you would do that in some cases you might be looking at a policy and you say you know what I need a I need a I need to I need to submit a policy exceptions of something that I'm working on you can submit it through here new policy exception and you would fill out the information right right so this is the this is the the main point of this first screen is really just to be how can I get simple items in front of my first line users with Simplicity for them to report and give information for either our second line until then take and work and then and mature it and what do you call uh enhance the information as you go deeper right now the other part now when we move over to segment I'm still as Jacob you can see here Jacob Williams he's a corporate compliance manager is user base now when he comes in he goes to something called a compliance workspace he's got I've got a bunch of money here but this is a compliance workspace and on here as a compliance manager I've got a few things that I'm looking at right I'm looking at authoritative documents which are regulations that you have to report on some internal policies that I might be responsible for these are the entities that are tied to it now the cool thing you can see a compliance score is assigned to some of these right so business records and media manager this is a policy that I have to and it's a high priority there's four high priority issues I can click on here to see my compliance score at 81 percent mm-hmm it's coming up sorry come on all right now uh we can see that the the policy business records and media management it's already been published it's 81 compliant right the compliance and what's non-compliant can tell you here and what is compliant I'm sorry excuse me these are the entities that are associated with it remember entities it could be applications it could be Pro it could be any type of product process so these are the items the entities that are associated with this policy and it tells you their compliance score you can go even Deep dive even further and find out here's the controls that are associated with this policy it can tell you 542 are active the green ones which are 262 are compliant and right now nine are not compliant two percent are not compliant and then you've got some that are not applicable sometimes they're not applicable just need has been tested hasn't been related that kind of stuff the other cool thing about this compliance workspace is as a compliance manager you know sometimes there's work to be done so I can go to my tasks and I can see what pending tasks I have right from an engagement perspective maybe there's an Evidence request task that I've been pending that I need to submit uh maybe there's an issue that I have been looked at yet that's been assigned to me right and the priority on it and then there's also a groups task so sometimes the people that I work with they have stuff that got to get done and maybe somebody's out of the office I go to my group's task and kind of help jump in on some of these if I need to to work through them right here's a policy exception that's been submitted I need to review it and see am I going to prove it or not going to prove it that kind of stuff and I will click in on it so this is the compliance workspace for a compliance manager um Anne-Marie you want to take it over from the resource space yeah sure so let me just grab it all right guys so I was just going to demo the risk workspace and a little bit of audit which will actually lead us into Dan's question um about control tests I believe um so here's the risk workspace I'm logged in as Andrew Taylor um which should be the same Persona that's in your instances if you use a free instance um from the developer servicenow developer.servicenow.com um so you see it's really similar to the compliance workspace but obviously it you go to risk workspace you land here what I wanted to focus in on you'll see a lot of similarity to the compliance on this left nav there's the home um there's your list of tasks and then there's issue issue management application which is Central to all of GRC if you guys haven't gone through the training meaning if there's a risk issue a compliance issue an audit issue if you have anything assigned to you or to your team this is the same um uh it's one place that you can sort of track all the issues that need to be worked on um and then obviously the list which I'll go through but I wanted to focus in on this right here in the middle which is the risk heat map this was new in Tokyo I believe um so again I'm in as Andrew Taylor I'm using the risk assessment methodology operational risk management so I can get to this risk heat map and you can click on this um I forgot what it's called sci-fi technology or something so I can launch it and this is where um sort of the dream was you know you take all your Excel files you put them in a risk you um want to be able to oh to be able to um have that data um aggregate in real time and okay obviously it's it's super slow so this is where they sort of aggregate into all the risks and it puts it into a nice heat map but why this supports a conversation is that it's intended to show um you can go right from you know picking one of these risks here and you can see sort of the the risk trending um what was he oh my gosh I forgot the one that we wanted to show uh uh anyways so you can see here you can see the wrist Trend so if you've done a risk assessment over time you'll be able so this one there was one risk assessment done April 23rd over time you can see like is this going up or down so this is the way that servicenow intends to provide business context around each of the risks um and the way that these data points go on here is through sending out a risk assessment um all right so the other thing from here you can also change the risk assessment methodology you can focus in on a specific entity um you can change it from inherent to residual and then you can also search so let's just say you're looking for anything that has to do with vulnerabilities so all the rest have to do with vulnerabilities will show here so you could click on it look at the risk Trend and you've just saved yourself a ton of time instead of going through all the Assessments in Excel and you can go go right into it and the idea is instead of collating this information waiting weeks or days and then um you know putting in a PowerPoint the idea is you know your board of directors or managers or business unit wants to know the risks for their area just hop right into the risk heat map um so all right so that is the risk heat map and um so again similar to what John was showing the list of tasks risk tasks so I'm the risk manager so it's only showing the risk tasks sorry it's really slow but it's not that exciting so I'm just gonna move on um and then here's issue management um again what's nice is this little thing right here which tells you what the new issues are in the last 30 days so you can take a look at those and then obviously all the nice sort of uh graphs and charts that you can um follow up on um here are evidence request tasks uh those come from the audit side so you can take a look at anything there um and then here are your lists so all the lists so this is your common risk Library um the control library and then one specific to you that that you own as a risk owner um all right so that's it for risk um one thing you can do from here also is schedule a risk assessment or go ahead and create a risk statement a risk a ton of stuff here I'll create a control or perform a control test um let's see if this loads I just wanted to show a risk assessment if we could if we have enough time if not we'll do it in in office hours oh this this might take a while all right so let's just go to audit real quick so this is the audit workspace so basically you go to workspaces and then audit workspace down here um it'll take you to this screen here so again similarities you'll see the tasks the issues overview and then the lists again here so audits uh the way that they work is almost like projects um like many project plans which we call engagements um and so you'll see that here you'll uh it's a good way to look at you know engagements that you have planned over time total engagements here any overdue doing in 30 days and any that are upcoming that way because we know that audits can be very time intensive so if you want to Pace them out like John was saying you kind of the second line usually gets hit pretty hard with providing multiple pieces of information over and over um so you can schedule it out over time right so your ISO your socks make sure not everybody's hit at the same time and then just the tracking information here to look at what tasks are are open whether it's an interview a walk-through control testing um and any sort of other activities that are needed like opening you know getting a report together closing an audit that's what the sort of more of generic activities are as well um all right so these are this the specific engagements or audits um if we take a look at one like this year in stocks Financial one um you can see who's involved so entities are the scope uh meaning so there's Finance sap accounting and people financials are the folks that are the uh that are part of this audit here um so there's a lot more to know here but I just wanted to give you a high level overview of what Henry yeah before you leave that can you click on 360 view real quick yeah so here I really love this part so and it happens with all the difference so you can do a 360 view from an audit engagement you can do it from a risk assessment you could do it from uh even a control assessment and the cool thing is based on that engage so in this case we're talking about Auto engagement So based on this engagement it'll show you all of the relational data that is associated with that engagement right so from risk to entities to controls it'll tell you it's part of one plan it's got audit tasks control test issues evidence requests that are pending so if you wanted to know everything about this single engagement the 360 View kind of gives you that the cool thing is if you do it in a risk assessment it's the same thing the risk assessment will show you all the controls and risks that are associated with the entities to that actual risk assessment right so just depending on what task or what activity you're doing the 360 view can give you all of that information yep um and just a quick tip for folks um if you're if you haven't gone to the training there is on now learning a nice little mod module that focuses just on audit because audit is not covered in the regular in-person in-person training there's not enough time but there is a specific module that kind of goes into audit in a lot more detail on on now learning yes and thank you Aisha for putting that site in all right so we've got a little bit of time left let's go ahead and wrap things up all right did I miss anything John I think we're good yeah yeah I think we did everything on the demo this was the example of a racy that we were talking about from an engagement perspective for somebody you know if you've heard of a racy before it's really an acronym for responsible accountable consulted and informed parties so you could think about from a project perspective if I'm working on phase one I'm in the planning stage or I'm on the design stage these are the different contributing uh persons or stakeholders right an analyst a project manager your CIO maybe Chief risk officer your leads me and then uh each letter represents what their response or what their uh accountable for or what their role is within that space of the project right so you can see when we're doing our planning on analysts is really consulted about information that they need but the plan the the the the CIO or the cro may be the one that's responsible and accountable for that plan to get put in Flight right or you know when you get to the design phase really the product specs the the responsible party at that point now becomes the analyst and maybe the accountable person is the leads me because the subject matter expert should know uh what that that product should be working and how it should be used but then the CIO and the CR will move to an informed uh level right so it just it's really important and I always stress it when we first start off our projects we love to do a stakeholder racing to kind of understand not only at the beginning who they need to be but this also starts to inform you from your change management perspective right this information this inform stuff how often should I communicate and how often and when and how do I need to communicate when we're out there already right yep absolutely and then one little trick that we like to do uh just because from the poll folks were saying they have a lot of stakeholder engagement um challenges um is take the same racy do what John was just saying and then do a color rating so if you're responsible person is engaged make that r a green if you're not exactly sure make that aura yellow if they aren't engaged make it a red once you get these letters colored it'll kind of give you an idea where you can get your early wins and where you might have to sort of uh unblock some roadblocks or even communicate to your leadership and say hey I know you want me to deliver this right but my engagement is red because these people while we did a racy they're not really engaged I've sent emails I've made phone calls and nobody getting back to me how do you want me to do this right so this should really help you inform and help you leverage uh the engagement piece that you need to pull from people it's it's a it's a it's a what do they call it a push and pull it really isn't it I gotta push sometimes and sometimes I gotta pull and it's just this activity that I got to do with engagement that's right um all right so a couple of key takeaways John yeah so real quick you know reality check the goals and breadth of your implementation right and sure all stakeholders have a voice so early on as Anne-Marie said if I only have one use case that's okay I may have a thousand use cases that's really hard to do but we really want to do a reality check and really understand where we're at on that right identify your key pain points and chat out uh chat the effort versus impact right like how can we determine um what is my low hanging fruit and what are the quick wins that I can catch on really quickly so that we can build in excitement right it's part of Engagement is excitement so if I can get some quick wins out there and people are excited about what's coming I can then get more engagement from them to build the harder things later uh know your csdm we talked about the common service data model right and leverage it right it's it's really important to understand how the the your your common data components influence the entities uh into the GRC space into the irm space document stakeholders and building engagement strategy we talked about the racy we gave you that example and then start governance as early as you can it's it's never too early to establish that really and the governance can be from uh you know if I've got a large scale Enterprise I may need to establish a portfolio level maybe program manager or assign a specific person that's responsible for engagement that kind of has this place going like just the the governance piece of it you can never start too early for it sometimes it may seem like man there's nobody involved I don't really need governance but even if it's just one single person involved starting the process of establishing the governance will really help and have the engagement that you need and really push your implementation along a lot further absolutely oh this is oh I did this wrong all right the title of this is wrong but the the time is right so we're having office hours this was our last webinar um the office hours for you know engagement is this Thursday at 8 30. it's a short 30 minute again that time is wrong I'm sorry I'll fix it on the PowerPoint before we send it out um and just a couple resources to then connect with us but before we go um there is a question in the chat um John from Dan um he's asking what's what's your experience with third line being prepared to commit to a controlled design up front um in such a way that they can use servicenow as a basis for independent assurance man that's a good question so uh as far as I'm being prepared to commit to a control design um again that really goes back to the governance aspect of it right if I if I get a third line representative I get my second line representative and then I may have some influencing articles whether it be from a regulator or something like that and we established that common design approach right whether it be um like I said itgc it'd be preventative manual detective like how am I going to document this control and once we can all come in an agreement and there's a governance around that that's what the tool does it helps you implement that that that that that governance right for you because everybody's going to use the same control Library so the attributes that are assigned in your controls everybody's going to use it so when they go do a test in audit they're going to use the control Library that's already established there with the attributes and all that that control test information that is fed will now go to second line they use the same information the result the only difference is the test is now your operational piece of it where the design is what's coming from your attributes in the control Library so the control Library your risk Library a lot of these authoritative documents a lot of these items require you to spend a little time in coming together on what that should look like so that you can be able to build that uh uh that that common not or the common nomenclature that you're talking about but I do agree with you third line can sometimes be a little challenging um uh when it comes to this stuff because they want to here's the other thing to remember it's the Paradigm right audit will look at controls as a holistic approach to a program right and sometimes second line will look at controls specific to a process and that's all they're looking at just that one little piece and so sometimes there's a disconnect in how that control is documented because of the Paradigm of the assessment or the engagement if that makes sense is control design also asking about um Dan about ending like had a test like the actual control test in the servicenow world we call them indicators what are the steps yeah yeah so so when you yeah so when you do your when you when you design your control they'll also be a test script for it right that says this is how you should be testing it again if we love to use control indicators uh to do that for us so what I'll do is it'll say you go to this table and and in that table I want you to check these parameters these filters and give me my results we love to use indicators to help standardize that so that it moves away from the manual side of it because the manual piece of it is I can give the steps to an auditor of what to do but that's still human that's still human uh what do they call it they've got to interpret what you're saying right whereas if I set it up as an indicator it could pull the data automatically for me so there is some value in using the indicators for that awesome yeah and I was just showing here how um there's the the CIS indicators um essentially uh that can help and some of them are manual like you're saying or you can actually go ahead and leverage the data in the cmdb or in the platform right not sure and now that indicator now establishes it for both third line and second one yeah right so you try to take away a little bit of that ambiguity in in what they're trying to do in their design or their testing of the operational so these are accelerator packs that you can download and just sort of um get started so you know you can use also say servicenow these are the standard indicators you know um and it's just something for you and your control owners or risk owners to then look at and poke at to get their engagement and buy in into the the design that's right I hope you answered the question then yeah awesome okay well I think were there any other questions um okay oh Dan's got a couple others we still got time for our first line is it your experience that they have an adequately developed understanding of effective internal of effective internal control design to contribute to the development of the solution in servicenow no no that's hard right because they're not a risk professional they're not a compliance professional they're there to perform the duties of their job so for me to for me to for me to require them to understand how to adequately adequately develop an effective internal control design would mean that I would then probably want to promote them to be a controlling manager right so no so no but but but the cool thing about service now is that I can use things I can use a service portal to ask certain questions to drive that we can even use something called flow designer that can allow you to ask questions that then triggers what you need done right we also have something called predictive intelligence which can allow you to use uh something like clustering or or or or or it'll grab the information and then it'll say hey guess what all these people are talking about the same thing it's this one issue right that's called clustering so so we have tools in service now that help close the gap in the knowledge space between my first line user and what my risk professional or my compliance professional needs to perform their job that's really what happens there's a knowledge Gap there that creates tension and and servicenow what we try to do is we try to close that through tools that we can build within the service now or or that we can plug in [Music] awesome okay I love this to what extent to what extent do your customers calculate the compliance scores based on automated data extracts versus testing by asking specific questions control performers and reviewers okay um yeah it depends on the size of the organization then really I mean in some cases because you got to remember and this is just my experience working in risk and compliance I've got this fear that I don't trust anybody or anything but I always want to double check the Checker kind of thing so um we work really diligently to demonstrate the value uh uh in in the automated work of of automatically calculating some of these results and the way we do that is when we're implementing and we do tests we'll run multiple tests right in various ways to show like look the we're coming up with the same score we're we're we're we don't need to check the Checker every single time right so it's just it this is part of a a culture change uh that we need to kind of see on our own uh the risks that you are showing is this based on an assessment calculation of impact for each control in case of control failure per entity the risk of you are showing I think with the the risk heat map because it was kind of uh oh okay okay um the risk assessment is based on an assessment calculation um as well as impact and likelihood right so we can probably Deep dive into that on um on Thursday then you're able to come Authority uh appears several different places in the heat map is this because this same risk applies for different controls yes because it's the same risk for different entities and it could be for multiple controls so there's a many-to-many relationship between risks and controls right because the same control can can help mitigate different risks potentially um all right next one um from Bola our team is in the process of capturing our controls um and control testing in servicenow is they're trained to get out there to get us started on how to best set this up yes there is a ton of information um now learning um Aisha has put that link um go to nowlearning.com there's a ton of on-demand courses you can take there's also virtual training that you can take uh and then they're also also if you go to knowledge our training team our talking team they are awesome so they're doing some trainings and some Labs at knowledge so definitely check those out can I add one little piece memory yeah I will tell you this and this is something that we look at in every implementation what I did not see in your question uh Ebola is entities where's it at here did I miss it no and entities could be is a service now word so it is it is in advance but it's a very cool thing like entities can be frustrating but they're also the secret magic to making risk and components work that's right so when you say we're working on capturing all of our controls on our control testing that's great all I would say is associated to what that's where entities come in what are my controls my controller what are what are they Associated to is an application a process an organization a function right like just keep that in mind is when you're establishing patrols and control objectives and you know your control tests and all that is as it's Associated to what that's that's the only Avatar is and so yes entities is a servicenow nomenclature but it's the power of GRC for us absolutely all right did I miss anything I think Dan was celebrating okay oh it's about educating first line absolutely a lot of it and and that's with any project as well right you're educating them on you know that's part of that organizational change management stuff um but using the racy understanding who's engaged you know the red yellow green and who who's not um will help you craft your messages a lot more clearer yeah um yep workload is important my experience is that Tessa completeness is a concept that is not really well understood even second line function yeah I test of completeness again I think it depends on the parameters of what you're establishing and what you're looking on your test right I mean you're right Tesla completeness as a whole it could mean a lot of things because of the different um because because of the different what do you call it the different industries that we're working with right for for in the healthcare industry okay test the completeness it's probably going to be 100 like you cannot fail or somebody dies right but in an operational perspective you know from a bank well you know test completeness could be at 90 and I'm good I'm gonna I'm gonna I'm gonna accept that risk right and so just that's why it just the list completeness when you say testing and verifying that I totally agree Dan I I think it varies it varies by industry it can vary by process it could vary by area a function it could be I mean yes I think that's why test of completeness can be very vague and very gray for a lot of people uh it's how they that's how they interpret what they're doing and what they're looking at okay all right yeah okay so Bola said that their entities are associated to applications and so and a lot of folks do this which is I like that answer because that's the easiest thing to get usually oh yeah list of business applications which is part of the the csdm model right um if we go back to and we have just a couple minutes this slide here right so your list of applications here um but work with someone um it gets a little confusing but once you understand it it's not there's application services and applications and then there's also business applications in the csdm model the easiest list of applications is to get business applications so as you're just starting out you can use business applications which is just sort of a logical model not the actual executable files right or instances of an application right so those are all accounted for in the csdm model but you can bring those in and that's the most common and easiest list to get you don't have to have every application listed in your application entity list but just the ones that you want to manage controls and risks against to get started so start with what you know and I know I know we're talking irm right but when we start working with applications you know we really try to plug in itam right information on application management and using the discovery tools so there's a lot of great benefits with some of these other ones yep yep absolutely all right any other last minute questions I think I think we're good okay well thank you everybody uh for your time thank you John for uh co-hosting with me this was a lot of fun again hope to see you guys on Thursday for our follow-up um office hours thank you have a good day

View original source

https://www.youtube.com/watch?v=X9bCfixwgdw