Adding a risk is the first step in identifying and addressing a potential threat or vulnerability raised by a demand. Each risk lives on the demand and is automatically registered in the Risk Registry.
1. Steps to add a risk
- Open the demand and go to the Risk Assessment tab.
- Click the Add Risk button.
- Confirm in the "Create New Risk" drawer: the RSK_ID is generated automatically for the new entry.
Once the risk is added, you can begin analysing it through the risk tabs: Risk Profiling, Inherent Risk, Current Risk, Recommended Controls, Target Risk, Risk Response and Remediation Plan.
Note: Risks can only be added once the demand has been accepted and is In Progress: a draft or a demand still awaiting acceptance cannot receive risks, and neither can a closed demand. Creating risks also requires an active risk matrix configuration in your workspace settings.
2. Risk options overview
Each risk card offers management actions alongside the assessment tabs:
- Comments: discuss the risk with stakeholders.
- Evidences: attach supporting documents or links that substantiate the assessment.
- Owners: designate who is responsible for managing and mitigating the risk.
- Delete Risk: remove a risk that is no longer relevant (a confirmation is requested; this cannot be undone).
These options keep risks actively managed, tracked and documented throughout their lifecycle.
3. Where the risk appears
- On the demand: the flow diagram at the top of the demand links the demand to each of its risks and, later, to their remediation plans.
- In the Risk Registry: every risk is added to the registry, the centralised record that gives visibility, accountability and traceability across all identified risks. See the Risk Registry Module section for details.