Three connected modules support the operational risk process: Demands, Risks and Remediation. Shared catalogs, evidence and workflow settings keep their records consistent.

Demands

A demand collects the request, business context and assessment scope. Create a draft, complete its information, then submit it to the review process. The register shows status, due date, current responsibility, tags, risks and owners.

The detail page combines the demand, its risk assessments and a flow diagram linking the resulting remediation plans. View status opens the workflow drawer and the actions available at the current stage.

Risk assessments and the register

Assess each scenario through its profile, inherent risk, current risk, recommended controls, target risk and response. The Risks register consolidates the resulting records for monitoring, ownership and lifecycle management. Assessment content is edited from the related demand.

Remediation

Remediation plans describe the work needed to implement a mitigation. Each plan has its own responsibility, deadline, supporting material and delivery status. Its lifecycle remains distinct from the demand's assessment status.

Collaboration and review

Use comments and evidence to support decisions. Invite stakeholders to a particular demand where that access is appropriate. Workspace permissions, the configured review process and the current workflow stage determine what each participant can see or change.

Choose Direct, Analyst review or Analyst + assurance in the risk-demand settings. Check the current approval round before interpreting which reviews remain outstanding.