Risk management
Risk decisions with the assets and controls behind them.
A register with structured assessment, treatment plans and formal acceptance, review reminders and a cost-of-risk view — every risk linked to what it threatens and what protects it.
| Risk · linked to | L | I | Score | Treatment |
|---|---|---|---|---|
| Payment gateway outage→ Payment gateway API | 4 | 5 | 20 | In treatment |
| Backup restore untested→ pg-primary | 3 | 4 | 12 | Plan due |
| Provider concentration→ Acme Cloud B.V. | 3 | 3 | 9 | Accepted |
| Stale access review→ Card tokenisation | 2 | 4 | 8 | In treatment |
Likelihood × impact, 1–5 each
Score 1–25, snapshotted per assessment. 26 open · 3 accepted with expiry · next review 2026-09-15.
Capabilities
What the module does
- 01
Register & assessment methods
A CIS RAM-inspired semi-quantitative method ships: likelihood 1–5 × impact 1–5, score 1–25, accept / treat / escalate thresholds. The method version is snapshotted on every assessment.
- 02
Treatment & acceptance
Treatment plans with owners and dates; acceptance is approval-gated through the workflow engine — submit, approve, reject, revoke — and every step lands in the decision log.
- 03
Linked to assets & third parties
Each risk names the assets and vendors it concerns, so criticality and ownership come from the record, not from memory.
- 04
Review reminders
An on-demand reminder scan with daily de-duplication and ownership-aware targeting; per-target reminder history on the dashboard and detail pages. Scheduled runs and email delivery are on the roadmap.
- 05
Cost of risk
Put a number on exposure and on treatment so prioritisation is a conversation about money, not adjectives.
- 06
Dashboard
Open risks by score band, overdue reviews, treatments in flight — computed on demand from the register, never a stale rollup.
One data model
How it connects to the rest of the workspace
CMDB →
Assets and their criticality feed the assessment; a change in the CMDB shows up on the risk.
Compliance →
Findings and failed controls point at the risks they raise; requirements and risks share vocabulary.
Third parties →
Supplier risk lives in the same register, linked to the vendor record and its assets.
Questions we get asked
Which assessment method do you use?
A CIS RAM-inspired semi-quantitative method (1–5 × 1–5) ships today; the methodology catalog is platform-governed and versioned, so new methods arrive without rewriting old assessments.
Can leadership see the picture without logging in daily?
The dashboard is computed on demand from the register, and the reports module generates a risk register report and a cross-module executive summary — immutable snapshots you can hand to the board or an auditor.
How is risk acceptance recorded?
As a formal, time-bounded decision with an accountable owner. It expires, it is reviewed, and it is in the audit trail.
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.