From Manual to Automated: Advanced Risk Assessments
hi everyone um I'm dear talikai I'm an advisory solution consultant in breast resilience and ESG here at service now based in London UK my expertise is financial services where I provide guidance and support to diverse range of clients I've been conducting a series of webinars focusing on integrated risk management GRC this is I think is this is the fourth session uh throughout this webinar series we explore how servicenow platform goes beyond the traditional boundaries of GRC and how it can Empower organizations to transform their risk management and compliance processes today we will demonstrating Advanced risk assessment how you can do data driven assessment or automated risk assessments with me I have the pleasure of being joined by my Stephanie merakovich and I will hand over to Steph to introduce herself as well good morning good afternoon depending on where you're joining from good evening my name is Stephanie merakovich and I'm a Solutions consultant within our risk business unit based out of Canada so I cover all of our customers across Canada spanning all the different Industries I'm really excited for this assessment because as you start to think through what your program maturity and your roadmap can look like and especially looking at you know the current state of what's going on in the world and you know being able to to think about how we can not only make lives of people easier but do it in a way that's going to reduce costs it's a it's a really important topic I think to start looking at how your program can mature and so I'm really excited to to show you what's available in terms of those Advanced risk assessments to support you as you continue to mature your program now just before we get started a couple of housekeeping items everyone on the line is kept on mute but if you have any questions please use the Q a feature we're going to take a look at those as best as we can as we go through the session we'll either answer them live or directly in the chat and want to make sure that of course you're able to get your questions answered as you're seeing things and we're going through the solution today's session will be recorded and shared through the community after at the end of the session you'll be prompted to fill out a survey if you don't mind just sharing your feedback that would be fantastic we want to be able to ensure these sessions are delivering value to you um and so anything that you can share with us in terms of feedback would be wonderful now in terms of the agenda today we want to just set the stage a little bit in terms of what embedding risk and resilience across the Enterprise can look like and and what we're seeing from you know other customers that we're working with as well from there we'll talk about what are the key features of the advanced risk assessments what do we mean when we say Advanced risk assessment so we'll give you some insight into what those capabilities are and then from there we'll dive right into the demonstration I want to make sure that we get a lot of time to show you those workflows the different options for what that could look like so from there we'll dive through that and then of course if there are any other q and A's that we haven't gone through as we've gone through the session today I will leave some time as well for Q a at the end and again for Q a just make sure that you're using that q a feature the chat helps if you just want to kind of commute communicate but if you have specific questions q a will ensure that we don't miss that and that we can actually answer your question all right so as we start to think about you know what risk and resilience looks like across the organization I think it's important to think through what that framework looks like what the ecosystem looks like and how that actually can be integrated in a platform like servicenow you know a lot of you who are on the line today are probably familiar a bit with servicenow in terms of your organization might already use it for Solutions like it ticketing or customer service management HR management for example or other it workflows the servicenow platform is is quite a flexible platform that serves many different use cases and what that means from a risk and resilience perspective is that there's actually a common data model that allows you to tap into that and leverage that information from a risk and resiliency perspective so what do I mean by that if we think through an example um you know traditional I.T use case you might have certain it assets defined within servicenow those become you know entities or elements that we can sort of valuating risk against or compliance against or for example when we start thinking through something like security operations that's information that can feed into understanding how our risks our risk scores might change over time from a you know a vulnerabilities perspective or perhaps in terms of you know managing your different employees and the different departments and bus you want to be able to evaluate risk against those or understand what your control compliance looks like against your different business processes a lot of this information may actually already be available in your servicenow instance today and so you get to start using that as you build your framework from a risk perspective the other thing that's important to highlight too that you see here on the screen is that when we talk about risk and resilience we actually have several different use cases under that umbrella so at the center you'll see Enterprise and operational risk but in order to really have that beefed up program you want to be able to understand what is the risk posture in terms of the third parties the vendor suppliers that we're working with or what are we doing from a corporate compliance perspective the different internal policies that we have that we need to align with and as well as any regulatory Frameworks whether it be something like niss or ISO or from a privacy perspective maybe gdpr as an example of course all of these become important to understand holistically what our risk and resilience looks like and so this is what we start to think through a true integrated solution can be to actually have those different data points not just across what data might be in service now or across your organization but as well in terms of these different structures within risk and resilience whether we're talking about operational risk Enterprise risk third party risk business continuity this all feeds into ensuring you can stay resilient and actually mitigate and manage risk now in order to really make that seamless it's important to be able to ensure that the user experience for everyone is smooth right for yourselves on the line as you're managing your risk program you want it to be simple and easy and for it to be able to easy to manage right but also as you start to engage your different risk stakeholders the owners for example it's empowering for them to be able to to actually see the risks that they own or the controls that they own to understand what is the state what are the items that I have to remediate so servicenow is really good at really connecting um that user experience for those different stakeholders so that you can shift to have that more risk-aware Culture by embedding risk into everyday workflows where people might not even know that they're doing something related to risk but they know that they are managing or or supporting or providing information that'll help the organization more broadly as we start to think through that crawl walk run with any program around risk you can start to to on uh I'm sure you kind of started thinking about what that next phase might look like and so we often see customers start shifting into more continuous monitoring of risks and controls of course it's great to be able to send out risk assessments and engage stakeholders but when we want to think through securing our organization the more that we can do to be more proactive instead of reactive is going to help so if you can start to continuously monitor those risks and monitor those controls you can identify if there's any gaps or if your risk scores are increasing or if there's been a spike in something like vulnerabilities that could impact your risk scores right you want to be able to catch that in near real time so that you can remediate that and not months down the line when maybe it's a little bit too late and there's already been some detriment or a negative impact to the organization so thinking through what that maturity could look like by introducing more continuous monitoring and automation we talked a little bit about contextualizing risk for business stakeholders so not only actually engaging them in a way that's easy for them but what about being able to give them insight into the status of those risks of course that's going to be important and then finally to be able to connect and manage risk and compliance through tools of an automation let me ask you this imagine that you know as a stakeholder you were able to receive not maybe an email notification or teams notification maybe you don't actually do risk assessments or control assessments very often once a year twice a year so you receive this notification through the tools you're already using email teams what have you and there's a link that brings you directly to the assessment and the assessment has information for you about what were the recent results are there any open issues what's the guidance how do you actually go through this assessment and if you had any questions what if you could actually connect directly to that risk team that's sending out these assessments so the more that we can really connect risk across the organization by using tools that you exist and allow servicenow to be that system of of action that allows you again to shift more towards that risk aware culture and also set you up for success in terms of maturing your program and introducing more automation now as you think through what risk assessments look like today across your Enterprise important to understand that there's many different types of risk assessments that could be happening either your group might actually be doing a couple of different types of risk assessments um or or perhaps the different like Risk groups might so Florida can you tell us a little bit more about what that that could look like from a servicenow perspective uh yeah definitely and uh before we dwell into the examples that we have prepared for the webinar today we want to set the scene of like you know what risk assessments are like what you can do with you know what's the art of possible within service now with risk assessment and how you can spend those across Enterprise so um servicenow offers a very flexible framework when it comes to risk assessments um so it can enable the organizations to effectively manage all types of Assessments across the Enterprise so as you can see here you can have different type of assessment that's currently are in the screen hence uh this you know with risk assessments you have that comprehensive Suite of features that can provide the centralized management and configurable methodologies to enable organizations to align and optimize the assessment process for different risk domain compliance requirements and different industry standards so hence that's why um with the advanced risk assessment that we have within servicenow we provide that flexibility where you can Define multiple risk assessment methodologies and each one can have its own set of factors its own scoring logic and rating criteria so like when it comes to you know risk and controlled self-assessments and protest risk assessment application risk assessment you can Define like how those assessments are going to look like you can Define their factors the scoring Logic the rating their metrics is maybe your operational risk one can look five by five while your application risk one or process response Matrix is a three by three so this is this is like the difference in like you know the flexibility that you have in service now because you can assess a type of rest let's say operational risk and you can dwell into the details like Factor levels uh to evaluate the associated risk on the other hand if you evaluate something else like application education risk or project risk you can have a different set of factors that may be considered to measure the level of risk accurately and hence the flexibility the flexibility is there not only you can do like that risk but if you for example you want to have the ability to assess um risk with any sort of objects let's say new regulation is coming you want to know what's the impact this is where you can do object risk assessment rather than just doing risk-based assessment when you evolve into the granular level of risk within the organization hence that's like it allows you to assess you know different sets different areas of the organization can that can be um risk associated with a particular business unit with a particular division or a business application or it can be with a specific area like as I mentioned a project a regulatory requirement an exception if you want to measure the impact on the risk that that might have and if we move down Stephanie then we will we should be able to see uh factors uh as well so uh factors are an essential component of any risk assessment what does that mean um it it's basically the piece that you have to capture the information so like simply putting this here if uh consists of questions and the corresponding responses that you you will provide during the risk assessment process so these factors can either be answered manually such as for example what is the financial what is the legal or what is the reputational impact of the risk or automatically through automated risk factors um so what what are the those those can be number of open vulnerabilities for an asset if you do those you know application risk assessment revenue of the business number of certain requests and so on so this is this is for absolutely you can move from doing those manual assessment to completely data-driven assessments so you can automate parts or you can automate the whole process of risk assessments if you for example let's say you had your controls already assessed by different teams and those controls are being used to mitigate the risk you're own and you're currently assessing rather than assuming that controls are effective you you have this information coming automatically from the teams that they're on the control and you can use it to fully automate your control and residual environments this is what we want to show later on in one of the examples how you can leverage uh data that you already have in the platform as the evidence of you know the uh the app control or residual assessment that you're you're going to be performing so the shift towards data driven assessment and automation will Empower organizations to improve risk management practices because this can enhance the decision making you have how the data is your evidence you can have a real-time view on your rest program and control program because you're continuously monitoring your risks and your controls and rather than being reactive you can be very proactive when it comes to manage risking controls so uh later on we will show two examples one of them is going to be half automated and the other one is going to be fully automated how you can be very proactive when it comes to managed certain risks that you have within the organization and if we move to the next slide before we just jump to the examples we do have the key features just for you to see here what are the key features of advanced risk assessment I already mentioned that you can have multiple assessment methodologies for different type of risk and different type of objects that you have within the organization you can combine manual and automated assessment to assess risk so like you know some organization might not be there yet but they can start like small like having um having some Automation in some of their risk assessment it's highly configurable everything that you do on these Advanced risk assessment is something that you can configure and all the features of the risk assessments essentially like you know just assessing the risk is like you can assess the risk qualitatively you can do that quantitatively as well you can Define what's how the risk Roll Up is going to look like if you want like you know average minimize maximize um so that automatically while you're assessing the risk you can see how this is affecting the risk hierarchy and risk taxonomy and your business hierarchy as well and then lately on we've released the risk appetite feature as well which where you can basically while assessing the risk you can see if you're impacting your you know the thresholds that you've set up for your appetite intolerances that you have around certain types of risks that you're defining we have a couple of questions in the chat one of them is actually asking around that risk roll up that you were just speaking to and how from like an organizational perspective how people can actually see their overall risk posture across their organization even though um maybe today risk roll-up is happening within a specific risk assessment methodology or or maybe they have a few different methodologies yeah and when it comes when you have different methodologies and let's say you you're using same risks and you have different methodologies you have um a drop down when you can basically select with methodology you want for example let's say you have one for operational risk you can see with operational risk how you assess risk your score in certain way but if you have you know another methodology that basically you abuse that risk or that risk of being assessed with that methodology as well you should be able to you know with through the drop down that you have on a certain risk or in a certain organizational unit to see the level of the risks that you have there absolutely uh we had another question just on that screen that had all the different risk assessments uh one question about where is the third party risk assessments um if if I'm not sure if like what it meant by third party risk assessment if it's the inherent third-party risk assessment or the tiering assessment meant here but uh basically this is something that you know um when uh you can definitely use the same you know the same technology to do the third party risk assessment for your if you want to define the inherent risk or in risk-based areas um because as mentioned earlier you can basically use object risk assessment rather than risk assessments to do this type uh this type of assessments awesome all right so in terms of the demonstration for today there's two key use cases that we'd like to show you um and the first one is going to be more around the data driven assessments um the second one is going to be what the experience could look like in terms of what we would call a frictionless assessment so with that let's go ahead and dive into the demonstration now in terms of any of those stakeholders that might be coming in and supporting you we talked a little bit about shifting to that risk-aware culture what we're looking at here is the employee Center portal so you're probably familiar with servicenow already if it's a place that you might go to submit something like an IT ticket or a request there you can actually enable components of of risk and compliance in that same portal and what that allows is for your different stakeholders to be engaged and to have that One-Stop shop to be able to complete things like Risk assessments issue remediations risk response tasks for example control attestations and and more now if we look through an example of a specific risk assessment here I want to take you through the experience of what it would be like to complete this so in this example we've sent a risk assessment to one of our our stakeholders or owners and so they would receive a notification maybe that's by email or through teams for example the notification will bring them directly to the portal to kick off their risk assessment so right off the bat they can either click to get started if you want you can enable them to assign these out reassign them or even to be able to review the previous results now let's go ahead and click to get started I'm going to actually copy over the previous assessment example here just as a note this is a configuration change and when we speak about configuration we mean like there's drop down options drag and drop interfaces you you know particularly for this one it's a check box do you want to allow them to copy over so you don't need to know how to to code everything in service now is going to be no code or no code low code and really is a simple experience so taking a look at this risk assessment we're going to actually copy over those results here okay now as this loads up let me just refresh and make sure I'm still signed on here give me one moment I've had my tab open for just a couple of minutes so I want to make sure that this is still logged in as this loads I think it's important to understand that when it comes to like defining your risk assessments as you saw from what blurta was showing there's different ways that you can set up your risk assessment methodology and configuring that is also very easy in terms of selecting check boxes and whatnot so here's an example of a risk assessment in this case we're starting off with the inherent assessment then we'll move into the control assessment the residual and then the response task now when we talk about how configurable this is you can absolutely turn on or off these different phases depending on the type of risk assessment you're doing whether we just care about the inherent or if we want to do maybe a full rcsa you also have full abilities to adjust the different factors so in this example we're looking at a simple impact and likelihood and we're actually using a four-point scale again you can adjust the point scale the options you can provide guidance for the stakeholders so that they understand what does it mean to have low versus high impact and then as well the actual factors itself you can Define so some customers will do impact and likelihood others might have five factors for impact that rolls into their over impact so really it's an opportunity to kind of match your process and bring that into service now in terms of how you're conducting your risk assessment today now as the stakeholder who's coming in here I have a lot of contextual information to help me as I'm going through and completing this assessment so I can actually see on the right hand side some reference information how many issues do we currently have open for risk are there any risk events that are currently raised if you're tracking any key risk indicators have there been any breaches or have you crossed crossed any of those thresholds and of course all of this information you can actually drill down so if I wanted to double click into one of these items I could actually see what is the open issue for this risk and that's going to help me understand what does this environment look like so that I can provide these responses to the best of my of my knowledge without having to swivel chair while I can have all this information in one place now as we complete our impact and our likelihood the solution is going to automatically score these results based on the calculation that you've inputted so again you can use a simple calculation an average or what have you or you can actually get a little bit more complex it's really up to you and if ever they need to override a particular score here they absolutely can change those computed scores and provide their justification or comments now as we move past the inherent assessment you'll notice that in the control assessment again we have a lot of contextual information so firstly in the middle here I can actually see what are the mitigating controls that are currently mapped to my risk and also what is the status of whether they are compliant or not sometimes these control tests are actually being done by a different person so if that's the case I can actually get that that information see what the status is if I need to I can actually click to open up that control specifically and see why the status is compliant or non-compliant but also I don't even need to necessarily drill in because all that information here how many issues are open for these controls or what were the results of those control tests we can actually see that being surfaced right here on that screen when it comes to doing your uh if the control assessment is kind of being done separately to this you'll notice that the factors for our control Effectiveness are actually getting automatically calculated this is being defined based on the statuses that you see here so again thinking through your maturity of your program right maybe your phase one is that somebody is coming in they're reviewing the results they need to actually input what they believe that control Effectiveness is but as your program continues to mature you can actually leverage more Automation and service now and use the data that exists in the platform in your organization to be able to have this type of risk assessment automatically inputted in terms of your control Effectiveness so we really don't even need to to to input a response here because the information is already in the solution okay again the solution will absolutely compute your control Effectiveness as you step through this and if we need to we can override with justification so now as we move into the residual risk in this example here everything is going to be automated as well of course depending on your methodology if you needed to have actual factors here for your residual assessment you can but in this case in thinking through that maturity again if that data already exists in the organization if we can automate it and have some of these scores calculated for us that's where we're going to be able to ensure that we're getting more clear and that we're actually capturing information doing these calculations appropriately and that we're saving some time and efforts in terms of someone you know kind of going through a residual when we already have the information of the inherent and the control Effectiveness here moving into that last phase as over here is where we can start to Define our risk response so how do we want to work through this do we want to accept it mitigate avoid or transfer it what happens when we select a risk response is it actually creates a task here so for this particular task we can actually make sure that this you know gets assigned to a plan that we see that there's an owner and a priority and this becomes a task that we can start to track as we move through um and actually remediate or mitigate or conduct our risk acceptance as part of this as well okay so this is one example of a risk assessment that we have here there's different ways again that you can set up your your risk assessment methodology um and if I just take a quick look back to uh our tasks here as well you'll notice that I as a user have a few different risk assessments so you know there's different ways that you can start to to set this up um in in terms of of completing this maybe we want to take a look at at another example here for a different risk about unauthorized trading you can actually start to Define what those different risk assessments look like okay all right so that takes us through our first example um blurred I'll pause here just to see if there's anything else that you think would be important to add before we move on from here sorry classic and I was in mute um no I think that's uh basically covered you know the first example of how you some you know when you have the example when um second line is triggering those assessments and then someone from the first line has this on this unified task new completes half the data as evidence to support the assessment and also we saw the case of like uh if those controls are already being attested and evaluated and uh from different areas or different teams in the organization you can have that information coming automatically and you can you know you can agree with the results you can always have the option to override but essentially like um it's coming so already someone else in the organization have tested it and you can leverage that information to drive Automation in your assessment so this is what this was like uh the example of like you know those Hoth uh automated risk assessment um and this there are areas where you can and drive Automation and we were able to show that Automation and the control and the residual environment what I will be doing now I will be do something that's completely automatic and um something that uh you know one first line is is is logging into their computer and doing their daily activity tasks uh they would basically submitting requests without being aware that they're actually contributing in the overall risk and compliance management um piece I know that there are a lot of questions in the chat as well we'll be we'll be uh trying to answer those uh but let me jump on the second example first and then we can try to answer everything at the end so I'll be taking this screen now so if we um show this first before we jump into the platform this is basically astring like power risk can be part of the everyday uh word from everyone so like you know there are activities that we do perform but actually we are unaware of like how the you know this sort of the invisible risk that's being performed or like um the automation that's going to be we are going to use to drive uh Drive some of the activities like for example when we log into the PC we change our password we actually have a control update um or a control requirement that says that the password has to be changed every 90 days so US changing the password it's actually making that control be compliant or do we have like we have other examples that actually are something that we do within the day and we don't know that they're they're actually you know like an invisible area that um we don't see that manages or you know affects the risk and control environment what I'm going to do do today I'm basically going to show like how I'm going to raise the gifted request like basically I received a request from A supplier um I'm I know that it's a policy organization our organization has a policy that everything that I receive I need to go in and and and input that information in a form intake that we have somewhere in our portal that we use for everything but what I'm unaware of I that's you know there is like um there are thresholds uh within our risk environment that we should not go over this certain value that's something that I will be showing uh in this demonstration how exactly that works so if I go in and I basically impersonate like an employee I'm impersonating cereal here here it's the same portal that Stephanie was throwing earlier but basically has everything servicenow related so what I'm doing here I'm basically looking at um looking at the um going back to this one looking at like all the things that I can do in the employee Center I know that I need to go in and register request uh through a gift that I've just received so I go into the legal one I can look there is like uh gifts and meals um uh a requests here so like I can go in and I can start initiating this request so like once here I can look at the description of what the this request is and I can see like you know I'm requesting what's the purpose of this and then I can start uh making the changes so uh the information so before I do this I just want to show that now if I just switch back to from second line perspective just to show you this and the second line I do have this dashboard I do have all suppliers I can see all suppliers like you know how you know what's the gift value per supplier that I have because I do have some risks and controls that I've set up that we should not be we should not go through a certain threshold on the things like you know when we accept uh gifts so like this as you can see we have a ACME here that's almost five thousand and we have other suppliers as well and we have a list of all the employees and the total gifts values that every employee has registered if I just go and in the uh in the rest side when I manage risk I do have a methodology where I um uh I do have a methodology where I actually can look at you know you know Supply risk that I have so if I look at and I open this one I just want to show uh you know how this methodology looks like so uh I will essentially I will have this heat map and the heat map I need I I will see like exactly where um all sort of like you know the rest that I have where exactly every supplier sits in you know this is inherent risk so this is without having the controls in place so if I look the ones when we have the controls in place I'll see that everything is like you know in either medium or low so like I don't I don't have anything that I should maybe start actioning it so if I look at like for example the supplier is sending here I look at this I can see the details about this I can see where exactly this sits that's the the supplier if I want to look at exactly you know the information on the supplier and like what are the sort of controls that we are we are basically using to mitigate the risk for this supplier we can look at this uh this uh when I go to the controls I should be able to see you know what are those controls and like what are the um sort of uh measurement mechanism that we're using to to monitor this risk so if I just refresh this so this is where I want to sew that we have this risk and we have uh two controls that we basically are using to mitigate the risk of this in here and blurtle while this is loading um just a quick question on you know how out of the boxes is everything um that you're kind of we're going through and that we're showing today in the solution in terms of the risk assessments but also in terms of like the workflow that we're taking a look for the Second Use case so uh basically I would say that those are out of the box obviously you would Define your methodologies and I guess we've we've um we've we've used the methodology with uh automated structures that's something that you would need to build because like you would need to uh tell the platform what sort of factors you're going to use to mitigate for example that risk and that's something that you would need to additionally configure from what's what's there out of the box right and then just while you're talking about automated factors there was a question around if that's available um with Enterprise packages so yes automated factors specifically are available with Enterprise packages um but uh um the manual factors um are are going to be available with the professional level foreign yeah so like um uh here so I'm able to see the the supplier Acme in this case and I can see this supplier has two controls and these controls are like the number uh the supplier must not have more than five thousand and gives over the last 12 years or the a number of employees should not receive more than two uh two thousand years in gifts in the last uh 12 months so we do have these sort of controls that are mitigating the stress can make you look at the controls level as well you can look at like how we are mitigating the rest so like this is a control we have a mechanism of an indicator we can see that last time has passed so we have the information on this is basically how the system is looking is surfing for information is looking at this information so every time that we've we've we've looked at this we because we have a daily uh daily uh job that looks at the data into the platform we've seen that you know everything was like under five thousand hence we have not reached any thresholds and the controls are compliant hence that's why you know when we look at this specific um with specific supplier Acme when when it comes to the residual breasts we don't have we see that this is actually a place that Medium rather than being like you know somewhere even that the inherent risk was critical so this is I wanted to show first before we jump in and we show like after we make a change and we're actually for the Acme we put like something that goes over the threshold that we've set up how does this actually affect um our risk and compliance environment so if I go into the uh if I go into the uh the first line I'm going into here I'm just saying like you know what's the purpose of disclosure I'm just saying that actually I'm receiving a gift and then I can Pro I can basically look at the supplier in here find which which is the supplier I can provide the the details in here and I can say the total in value for example is 500 and then let's say that it's it's and then once I submit this like this information should get updated within uh within the system so like if I if I go back into the um the previous screen where I was in and I was seeing like uh almost like you know uh um 4 000 and something like I can see that now it's five five uh over uh five thousand so like what the system will like will do in this time was like based on the job frequency of like how we set up like you know how frequently we want to monitor the controls and we monitor the risk we'll look at the data we'll look at like if um if they're now instead of having you know the value that we just saw earlier that was like under uh uh four thousand if we do have the same value or this actually has changed because you know uh we do have data that supports that we have we've gone over uh over the threshold So like um so this is something that uh something that um how you you would uh set up um Automation in place because you can basically basically um put your uh put the automation put jobs in place to say I want to look at this let's say um every hour or every day based on the frequencies that you want to provide and the system based on those frequencies will look at your controls will look at the risks and we'll look at like you know if uh you've you've you've made uh you know that's uh sort of we you breach the thresholds that you've you've added for your controls and essentially uh if your controls that you're using to mitigate that risk are failing it means that your rest posture you know for that specific uh vendor will fail as well um are there any questions Stephanie we need to um answer before we jump into the second part of this demonstration yeah there's a couple of of general questions with regards um to the assessment in the heat map so um you were just showing the heat map workbench So Lisa has a question can you use the heat map workbench to analyze risks with it change requests uh can you repeat the question again yeah can you use the the heat map workbench that we were looking at uh can you use that to analyze risks with it change requests uh definitely like I mean you would have those I I would assume you would have those risks and those risks could be linked at I.T assets and basically you can use the risk heat map based on you you know the factors that you've set up and you can see the trending you can see the analysis or like you know how the risk is trending how you're mitigating the risk where there's risk exactly sets you would be defining the methodologies around you know uh that type of risks awesome and then in terms of the risk assessments can they be triggered uh automatically based on like a condition set uh yes so basically this is what I'm doing right now uh those assessments are like the assessment that uh you know that's currently um for these suppliers I actually there is a job that runs that will trigger this and then you can Define the criteria of when that job should run so and basically um however that criteria is that will mean that you know it will run um in you know in that defined uh defined uh criteria awesome thanks for that okay so like now I what I want to show is basically the same heat map that I was showing earlier but you know the difference is that I do have the Acme supplier in the red and you know why it's in the red it's because like you know we know that we had a control that measures like you know looks at the threshold data that we have and that basically uh because that controls has failed uh the risk assessment the automatic risk assessment that we have in place for the suppliers have gathered that information and now instead of having the uh the this residual risk at uh low level or medium level we have it at high level because the our controls have failed so and then this is where it comes you know when you can drive that sort of Automation and you can say like you know look at my data not necessarily that that those data will be like you know controlled it can be something that's across the platform like you know the exam sample I just took with with gifts and then you can you know you can create your own methodologies and how you want to automatically assess the rest so now you can see uh the controls have the previously was in um was in um compliance now actually this control is non-compliant so like if I go and have a look at this control I should be able to see that we the the information that we have actually has failed the indicator has failed and why this has failed if I look at this information it will it will show that the previous state was passed but this actually the last time that this was run it has failed and the reason that it has failed is because this has gone over the 5 000 threshold that we've set in with set up in place so you were able to see that without me doing nothing I just entered a gift request like someone from the first line would do the system was able to recognize the change look at um monitor the controls continuously look at the if the control has you know the control that mitigates the risk is all on the threshold that it should be in the moment that this threshold was um over the control automatically is non-compliant and the risk changes status as well so this was the second example that we wanted we wanted to show that was it's completely uh automated so blurta for this one uh while this is uh completely automated if someone wanted to change the frequency of collection or in fact maybe they just wanted to run it on an ad hoc basis is that something we can do that's completely like you know I can either click execute here and run into the ads ad hoc basis but this approach would be rather reactive than proactive if you allow like you know you say you want to look at this daily like that's the frequencies you want to look as we have it in here that's the system will look daily if any changes in the data you had any changes in the data and if those changes are actually within the thresholds that you've set up as president compliance great and then just in terms of like um the values like if there are values in another table whether we're looking at that control evaluation that you were just showing or we're talking more from like a quantitative assessment that we might be doing can you refer to values or data that might exist in another table to support these workflows yeah and and definitely less the integrated approach because you can Leverage The platforms the data that you have in the platform but we recognize that some of the data might not be even in servicenow platform so with Advanced risk assessment you can gather that data integrate with the other platforms that you have and then bring the data uh in in servicenow to have automatically you know some of these metrics or indicators coming up as well so that should not if you don't have the data and service now that should not limit to have um automation as well as long as you identify uh where the the data that you need to support that that assessment relies on awesome thank you do we have uh more questions Stephanie um those were the key ones there was one uh response back just in terms of the risk responses where maybe the risk owner and the risk assessor are different personas um and whether we can support that I think the the initial question was related to the response tasks if I'm not mistaken okay uh yeah I saw that question before and I I think I've um I've said that you can decide who should be assessing the risk and now I can see that actually they have a different risk honor a different risk assessor in their approaches but still I would say that if you don't have a risk assessor but actually the risk owner is you're the risk assessor you can automatically you know whenever you create those risks you can automatically say whoever is the owner of the rest is the assessor of this risk as well so basically it's essentially is the same Persona I think we have left both there to allow for flexibility for organizations that they may have different personas when it comes to owning the risk and assessing the risk but if you have the same Persona you can automatically assign whoever is the owner to be the assessor as well awesome thanks perfect I think we're we're we're on on time so thanks everyone for joining I hope this uh session was helpful you can always reach to us or if you have any questions or if you you want to know more about of what we've shown today we're happy to answer all your questions so if you have any other questions feel free to pop those into the chat just while we give you a couple of minutes to um to to type in any last minute questions here perhaps we'll just do a quick recap on what we saw in terms of um like the solution and and the value here so just sharing my screen um really we were taking a look at how you can start to do those risk assessments and set them up to move more into an automated flow of course we recognize that there's like a journey that you go through and that you know many organizations that we speak with might still be in that kind of more manual phase and that's okay but thinking through what that maturity could look like for you um so that you can sort to get the value and benefits out of streamlining this right to be able to actually have that single solution where everything is in one place so that you don't have to swivel chair we saw that available in the risk assessments uh where you have that contextual information for example we talked about a unified view to eliminate silos there's different ways to report we saw the risk heat map as an example and you can actually enable a lot of those reports through the portal for your owners as well if you are looking to shift to that more ownership from the owners and get to that more risk aware culture in terms of modernizing communication and collaboration the risk assessment really does have that opportunity to capture comments and to be able to communicate back and and forth you know if they have any questions and to make it a little bit easier just so that we can ensure that you know we're reducing potential delays or that you know in case people might be inputting information that could actually impact what what our reporting is and and and see if there's any costly mistakes and then finally all of that is going to be happening in real time so the more that you can leverage data that exists within your organization to support in some of those assessments that you're doing whether it's looking at you know that gift workflow where we have information coming in and then that actually triggers um you know whether our control is effective or not and then even how that feeds into the risk assessment right by introducing more automation there that's what's going to give you more of that real-time reporting and tracking so that you can actually make decisions on the data you have today and not on the data that you had from a month or two ago so with that we'll take a look to see if there's any last minute questions here in the Q a um I think we have one round uh if uh control assessment results in a non-compliance or issue planning same months after the risk assessment is conducted will the risk automatically be adjusted so um if you've if you've set up like you know like a let's say like a job that will continuously look if there is a change in your risk and control environment yes that would be uh automatically like uh adjusted if not like you can always you know when there is a change that has affected the control there can be like um a notification sent to the risk owner then they should run an anthoc risk assessment so these are the possible options you can have if you don't you know continuously set up monitoring for the risk awesome for the YouTube uh uh video I think usually like it it's like a day or two days after the webinar is done so they can just like you know uh upload it so I think latest it should be it should be this this Friday all right I see there's also a questions around uh documentation on how to automatically trigger risk assessments um blurred do you have any um ideas or do we know if we have a specific doc on that or um what would be the best way to kind of support that question around how to get more information on triggering risk assessments automatically I think that yeah that that's more like Eva like a platform feature as well like so basically the way of how you can that's definitely it's a job and then you would just say like um I want this assessment to be triggered in case I have a change in the control or in case I have basically on the criteria not sure if there's like how there should be documentation online but how good this documentation is like I can't answer this at the moment perfect yeah I think that's a good one to take a look at and perhaps also your your servicenow team may also be helpful um just in terms of like because they're probably familiar as well with different ways to support that too um so I would also recommend uh chatting with your servicenow team thank you and then another question about if there's any KB pointers that are helpful um it's KB knowledge based articles that are helpful okay um yeah we can take a look it might be worth doing a quick search um within there like I guess in terms of the documentation we have there's a few different uh pages about like the indicators for example so we looked at the control indicators there's also some interesting documentation around the risk assessment factors and the different options that you have for that as well um and of course there's definitely other topics just depending on where specifically you want to take a look at but in terms of what might be helpful from what we saw today I'm probably taking a look at the risk assessment methodology and the different risk factors uh would be good and then around the key risk indicators or key control indicators cool all right I think with that looks like we've gone through all the questions um feel free to connect with us or here's a few ways that you absolutely can um as Laura mentioned we will be posting this uh recording as well and other than that just want to say thank you for your time and attention thanks everyone
https://www.youtube.com/watch?v=N5n-yX9xQDA