Skip to main content

Hello!

New to EA and LeanIX. I’m looking for thoughts around performing general risk management (associated with EA) within LeanIX.

Risk management typically involves listing specific risks, with description, likelihood, and impact score attributes, and calculates risk scores based off of them.

As far as I can tell, LeanIX (even with the Risk and Compliance module) allows us to store aggregated obsolescence specific risk via the lifecycle attribute but it doesn’t provide this general risk management capability.

I’ve found a documentation example which seems to use tags to augment fact sheets with additional sunset status/risk, but that’s not quite what I had in mind. I’ve also found this example where custom fact sheet attributes are created and populated with similar fields (but not as a separate risk object):

https://docs-eam.leanix.net/reference/calculate-risk-scores-based-survey-responses

Has anyone created custom objects and custom relationships to implement this sort of risk register functionality?

Is this sort of customisation advisable? (generally tool customisations incur a maintenance cost when tools change)

Thoughts? 

Hi @AliB,

SAP LeanIX’s standard risk management features are designed to address aggregated obsolescence risks related to the underlying IT components that enable an application to function. This approach ensures that organizations can easily identify and mitigate potential disruptions caused by outdated or unsupported infrastructure elements that may impact application stability and performance.

However, SAP LeanIX’s true strength lies in its highly flexible and powerful metamodel. This metamodel provides organizations with the opportunity to customize and extend their risk management framework beyond just obsolescence. For example, you can expand the metamodel to capture a wider range of IT and architectural risks, such as security vulnerabilities, data privacy concerns, integration dependencies, or compliance-related threats.

Moreover, the metamodel’s adaptability allows for the inclusion of controls to manage and mitigate these broader risks. This means you can create a comprehensive risk management strategy that encompasses not only the identification and assessment of risks but also the implementation and monitoring of effective controls. By tailoring the metamodel to meet your organization's unique needs, you can align risk management more closely with enterprise architecture practices and drive proactive risk mitigation throughout your IT landscape.

Please feel free to reach out for further details.

 


Many thanks Mobin,

Customising the meta model is a way forward although it looks like I’d have to implement the automation for calculated risk attributes myself.

I’m wondering if you have partners that have already implemented such automation or something similar?


Hi @AliB,

Sure, please reach out to LeanIX Support with this use case and they will link you with our Professional Services team for further assistance. 


Reply