Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a risk using the GRC: Workbench

Risk managers can create risks directly from the GRC: Workbench.

Before you begin

Role required: sn._risk.admin or sn.risk.manager

Procedure

  1. Navigate to https://myCompany.service-now.com/$grc_workbench.do.

  2. Select the Risk Dependencies tab at the top, then select the Relationships tab below it.

  3. On the left, in the Risks section, click Create Risk.

  4. On the form, fill in the fields.

FieldDescription
NameName for the risk. Field is auto-populated if the risk is generated from a risk statement, but can be changed without affecting the relationship between the risk and risk statement.
NumberUnique identification number. This field is automatically populated.
State

Risk state. Possible choices are: - Draft In this state, all risk users can modify the risk. Only available when creating a one-off control. One-off controls are possible but not recommended. - Attest When the risk is created from a risk statement, controls are in this state.

Note: When a risk is set back to draft, the assessment is canceled.

  • Review Risks are automatically moved to review from the assessment phase.
  • Monitor In this state, all risk managers can move the risk from review to monitor.
  • Retired Risk managers or administrators can move a risk from Monitor to Retired. Indicators do not run when the risk is in this state.

Note: When a risk is retired, any assessment associated with it is canceled.

Owning groupOwning group for the risk.
CategoryCategory of risk which applies to the profile. - Legal - Financial - Operational - Reputational - Legal/Regulatory - Credit - Market - IT Field is auto-populated if risk is generated from a risk statement.
OwnerOwner for the risk.Note: The owner is always added as a respondent.
StatementStatement this risk is associated with.
EntityEntity related to the risk. Note: Only active entities are shown.
DescriptionDescription of the risk and how it is a threat to the organization.
Additional InformationMore details that help others understand the risk record.
  1. Click the Assessment tab.

  2. On the form, fill in the fields.

FieldDescription
AssessmentAssessment to attach to this risk.
Assessment respondentsUsers assigned to the assessment of this risk.Note: Only a user with the sn_grc.user role can be added as a respondent.
When both the **Assessment** and **Assessment respondents** fields are set, assessments are created when you click **Assess**.
  1. Click the Scoring tab.

  2. On the form, fill in the fields.

    FieldDescription
    Inherent SLEMonetary value of a risk if it occurs before any mitigation strategies are in place.
    Residual SLEMonetary value of a risk if it occurs after all mitigation strategies are in place.
    Inherent AROProbability that a risk occurs in any given year before any mitigation strategies are in place.
    Residual AROProbability that a risk will occur in any given year after all mitigation strategies are in place.
    Inherent ALEAnnualized loss expectancy ALE = SLE x ARO before any mitigation strategies are in place.
    Residual ALEAnnualized loss expectancy ALE = SLE x ARO after all mitigation strategies are in place.
    Inherent scoreThe score of the risk before any mitigation strategies are in place.
    Residual scoreThe score of the risk after all mitigation strategies are in place.
    Calculated ALEAnnualized loss expectancy based off all calculations.
    Calculated scoreThe corresponding score for the calculated ALE.
  3. Click the Response tab.

  4. On the form, fill in the fields.

FieldDescription
Response- Accept - Avoid - Mitigate - Transfer
JustificationEnter a reasonable justification for the selected response
  1. Click the Monitoring tab.

    FieldDescription
    Control compliancePercentage of compliant controls
    Control non-compliancePercentage of non-compliant controls
    Control failure factorSum of failed controls weighting divided by total controls weighting
    Indicator failure factorUses the last result of each associated indicator. Number of last results failed divided by total number of indicators associated.
    Calculated risk factorThis value is calculated from (Indicator failure factor + Control failure factor) / 2.
  2. Click the Activity Journal tab.

  3. Enter additional comments, as necessary.

  4. Click Submit.

    The risk is created and centered in the middle of the page. Also, the risk is selected on the right.

Parent Topic:Use entity and risk dependencies using the GRC: Workbench