You are here:
Configure Risk Management for IT Compliance
Configure the features for risk management workflows in IT Compliance and turn on the default scoring expression set so every risk your team registers gets an automatic inherent and residual score.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service. |
| User Permissions Needed | |
|---|---|
| To enable foundational services, activate Risk Management, and assign permission sets: | Compliance Admin permission set |
Risk scoring gives your team a standardized, quantitative way to measure the severity of threats facing your organization. Each risk gets an inherent risk score (the raw threat level before any safeguards) and a residual risk score (the threat level that remains after mitigating controls are applied).
Enable the Business Rules Engine
Turn on the Business Rules Engine so Salesforce can automatically calculate inherent and residual risk scores from the criteria you define.
- From Setup, in the Quick Find box, enter Expression Sets, and then select Expression Sets.
- Confirm that the Expression Sets list view is accessible. If it isn't, the Business Rules Engine isn't enabled in your org yet.
- To enable the Business Rules Engine, follow the steps in Get Started with Business Rules Engine.
Enable Context Services
Turn on Context Services so the Business Rules Engine can pull the right risk data into each scoring calculation.
- From Setup, in the Quick Find box, enter Context Service, and then select Context Service.
- Turn on the Context Service toggle, and then refresh your browser.
- Confirm that a Context Definitions tab now appears in your org.
Activate Risk Management in Salesforce Go
Turn on Risk Management and Risk Scoring in Salesforce Go, activate the default risk scoring expression set, and assign permission sets so your admins and compliance team can start managing risks.
- On the Salesforce Go page, click the Features tab, and then search for and select Accelerate Trust with Unified Risk and Compliance.
- Next to Risk Management, click Set Up.
- Turn on the Risk Management toggle.
- Click Manage User Access, and then assign the IT Compliance permission sets to the administrators who configure risk scoring and to the compliance users who manage the risk lifecycle.
- Turn on the Risk Scoring toggle.
- From Setup, in the Quick Find box, enter Expression Sets, and then select Expression Sets.
- Open the default risk scoring expression set, open its version, and click Activate.
- Return to the Risk Management settings in Salesforce Go and refresh the page so Salesforce picks up the active expression set.
- Configure the risk scoring parameters to match your business requirements.

