Enterprise Risk Management Platform

CASE STUDY DETAILS
Windy City Health – Enterprise Risk Management
Project Type
Enterprise Platform Implementation
Challenge
Decentralized Risk Management
Domain
Healthcare / Risk Management & Governance
Impact
Centralized Enterprise Risk Visibility

OVERVIEW
Windy City Health operates a complex healthcare IT environment spanning 50 hospitals with interconnected clinical systems, medical devices, and network infrastructure serving over 15,000 employees. The organization needed a centralized Enterprise Risk Register to identify, assess, score, and monitor organizational risks — from cybersecurity threats targeting patient data to operational risks threatening clinical system uptime.
We implemented a comprehensive Risk Management solution on ServiceNow IRM — creating 8 enterprise risks with standardized scoring methodology, risk response plans, and a suite of executive dashboards including heat maps, state distribution charts, and priority-ranked risk views that give leadership continuous visibility into the organization’s risk posture.
Problem Statement
Windy City Health faced significant challenges in managing and monitoring organizational risks across its healthcare operations, resulting in:
The challenge was to establish a centralized and structured risk management solution that could standardize risk assessment, prioritize organizational risks, track mitigation activities, assign ownership, and provide leadership with clear visibility into enterprise risk exposure.
- No centralized view of organizational risks across IT, clinical, and compliance teams.
- Inconsistent risk tracking through spreadsheets, documents, and informal processes.
- No standardized methodology for evaluating risk likelihood and impact, making prioritization and mitigation investment difficult.
- Risk response plans lacked structured ownership, deadlines, and progress tracking.
- Leadership required extensive manual effort to identify and aggregate the organization’s top risks.
- Limited ability to demonstrate active risk monitoring and mitigation to auditors and the board.
Solutions
To address these challenges, we designed and developed a comprehensive enterprise risk management solution:

1. Enterprise Risk Register with Standardized Scoring
- Created 8 enterprise risks across Operational, Security, Compliance, and Financial domains.
- Implemented a standardized 5×5 Likelihood × Impact risk scoring matrix.
- Classified risks from Low (1–4) to Critical (17–25) based on calculated scores.
- Assigned each risk a designated owner, owning group, and Windy City Health entity for clear accountability.
3. Risk Response Plans & Mitigation Tracking
- Configured risk response strategies including Mitigate, Accept, and Transfer.
- Documented justification for each risk response decision.
- Created mitigation tasks with assigned owners and defined 90-day due dates.
- Tracked mitigation progress against defined milestones and response objectives.
5. Executive Risk Dashboards
- Built an Enterprise Risk Heat Map to visualize risk distribution by owner.
- Created category-based reporting for Operational, Security, and Compliance risks.
- Developed a High Priority Risks report sorted by calculated risk score.
- Created entity-based reporting to provide leadership with a consolidated view of organizational risks.
2. Healthcare-Specific Risk Scenarios
- Documented 8 real-world healthcare IT risk scenarios covering EHR downtime, PHI breaches, medical device cybersecurity, staffing shortages, and regulatory compliance.
- Included disaster recovery, third-party vendor dependencies, and aging network infrastructure risks.
- Assessed each scenario based on its potential operational, security, financial, and compliance impact.
- Prioritized risks using standardized likelihood and impact scoring.
4. Risk State Management
- Implemented a structured risk lifecycle from Draft → Open → Assess → Mitigating → Closed.
- Enabled teams to monitor risks throughout their lifecycle.
- Maintained active governance through ongoing monitoring and remediation tracking.
- Provided visibility into risks currently being monitored, mitigated, or under response.
APPROACH
Our Approach
Risk Framework Design
- Defined a standardized 5×5 risk scoring matrix for likelihood and impact assessment.
- Established likelihood levels from Rare to Almost Certain and impact levels from Negligible to Catastrophic.
- Defined score thresholds for Low, Medium, High, and Critical risk classifications.
Risk Identification Workshop
- Identified 8 priority risks based on Windy City Health’s clinical IT environment.
- Evaluated patient safety risks including EHR downtime and medical device security.
- Assessed regulatory, operational resilience, and organizational sustainability risks.
Platform Configuration
- Activated GRC and Risk Management plugins.
- Created the Windy City Health entity profile and risk statement definitions.
- Configured all 8 risks with complete ownership, category, entity, likelihood, impact, score, state, and response information.
- Added risk relevance narratives to provide context for each identified risk.
Response Planning & Monitoring
- Created risk response tasks with defined mitigation actions, owners, and due dates.
- Configured risk state workflows to support continuous monitoring and governance.
- Tracked mitigation activities as risks progressed through their lifecycle.
Reporting & Visualization
- Designed 4 complementary reports covering risk priority, category distribution, ownership, and risk states.
- Created leadership views to identify highest-priority risks and areas of concentrated risk exposure.
- Provided visibility into risk ownership and active mitigation activities.
Tools & Technologies
Salesforce Development & Integration:
- Platform: ServiceNow (Zurich 2025)
- Modules: Integrated Risk Management (IRM) — Risk Management
- Plugins: com.sn_grc (Governance, Risk, and Compliance), com.sn_risk (Risk Management)
- Framework: 5×5 Likelihood × Impact Risk Scoring Matrix
- Reporting: Heat Maps, Pie Charts, Donut Charts, Priority Lists, Risk Dashboards
- Entity Management: GRC Profile, Risk Definitions, Risk Statements





success and impact
What the Client Achieved
- Centralized risk register — 8 enterprise risks in a single system of record with consistent scoring
- Standardized methodology — 5×5 matrix eliminates subjective, incomparable risk assessments
- Active governance — Multiple risk states (Open, Mitigating, Respond) demonstrate ongoing management
- Clear accountability — Every risk has a designated owner, owning group, and entity assignment
- Mitigation tracking — Response tasks with due dates and assigned owners drive action
- Executive visibility — 4 dashboard reports provide instant answers to board-level risk questions
Business Impact
- Risk visibility went from “weeks of manual aggregation” to real-time dashboards
- Consistent scoring methodology enables cross-department risk comparison and investment prioritization
- Active risk state management demonstrates governance maturity to auditors and the board
- Mitigation tasks ensure risk response plans are executed, not just documented
- Audit-ready evidence of risk identification, assessment, response, and monitoring lifecycle
- Healthcare-specific risk scenarios align IT risk management with patient safety priorities
Services we offered
Phone
+1 (224) 209-9860Address
1600 McConnor Parkway,
Suite 125, Schaumburg, IL 60173

Schedule a free consultation
Phone
+1 (224) 209-9860Address
1600 McConnor Parkway,
Suite 125, Schaumburg, IL 60173


