Skip to content
Notifications
Clear all

Showcase: Custom metric showing 'risk debt' across business units.

1 Posts
1 Users
0 Reactions
26 Views
(@elliotv)
Reputable Member
Joined: 3 months ago
Posts: 380
Topic starter   [#19860]

In our ongoing effort to operationalize risk posture, we identified a gap in the standard ServiceNow GRC reporting: a consolidated view of accumulating, unaddressed risk that hasn't yet manifested as a loss. We term this "risk debt," analogous to technical debt. It represents the aggregate exposure from accepted risks, deferred mitigation actions, and overdue control assessments, weighted by their inherent severity.

The objective was to create a custom metric that rolls this debt up by business unit, providing a single, comparable figure that reflects not just the count of open risk items, but their potential impact and age. This moves beyond simple backlog counting to a more nuanced, quantitative view of risk accumulation.

The implementation centers on a new table (`u_risk_debt_metric`) and a suite of scripted metrics. The core calculation for a given business unit involves three primary data sources:

1. **Accepted Risks:** From `sn_grc_risk_response`, where `state` is 'Accepted' and `effective_risk_rating` is populated.
2. **Deferred Mitigation Tasks:** From `sn_grc_task`, linked to mitigation plans, where `state` is 'Deferred' or 'Pending'.
3. **Overdue Assessments:** From `asmt_assessment_instance`, where `state` is 'Overdue'.

The debt score is a weighted sum. We apply time-based multipliers to increase the score for aged items, emphasizing stagnation.

```javascript
// Example Calculation Script (Server-side, Business Rule or Scheduled Job)
// This is a simplified illustrative snippet.

function calculateRiskDebt(businessUnitId) {
var debtScore = 0;
var riskGr = new GlideRecord('sn_grc_risk_response');
riskGr.addQuery('state', 'accepted');
riskGr.addQuery('business_unit', businessUnitId);
riskGr.query();

while (riskGr.next()) {
var baseRating = riskGr.effective_risk_rating.getDisplayValue(); // e.g., "High"
var baseScore = mapRatingToScore(baseRating); // e.g., High=10
var ageInDays = (new GlideDateTime() - riskGr.opened_at) / (1000 * 60 * 60 * 24);
var ageMultiplier = Math.min(1.5, 1 + (ageInDays / 365)); // Caps at 1.5x
debtScore += baseScore * ageMultiplier;
}

// Similar logic for deferred tasks (weighted by linked risk rating) and overdue assessments...
return Math.round(debtScore);
}
```

The metric is visualized on a custom dashboard for GRC managers and business unit leaders. Key components include:

* A bar chart comparing the risk debt score across all business units.
* A trend line for each BU showing debt accumulation over the last 12 months.
* A breakdown widget showing the debt composition (e.g., 60% from accepted risks, 30% deferred tasks, 10% overdue assessments) for a selected unit.

**Pitfalls & Considerations:**

* **Data Quality:** The metric is only as reliable as the underlying GRC data. Inconsistent risk rating scales or poor task/assessment hygiene will distort the score.
* **Weighting Schema:** The initial mapping of risk ratings to base scores (e.g., High=10, Medium=5, Low=1) required significant calibration with our risk committee to ensure it reflected organizational appetite.
* **Performance:** The initial roll-up calculation, if run synchronously, can be heavy. We offloaded it to a scheduled scripted metric calculation that populates the custom table nightly, and the dashboard reads from this aggregate.
* **Change Management:** Introducing a "debt" score can be politically sensitive. Clear communication that this is a management tool, not a performance indictment, was crucial. We positioned it as a leading indicator to prioritize resources.

This custom metric has provided a more dynamic and actionable view of latent risk exposure, shifting conversations from "how many open items" to "where is our exposure accumulating most rapidly." The next phase involves integrating it with our API gateway to expose risk debt scores to downstream enterprise dashboards, allowing for correlation with operational performance data.


null


   
Quote