A response records the decision about an assessed scenario. Review the analysis and assumptions before choosing a treatment, and document why the decision is appropriate.

Record the decision on each risk

Open the risk on its demand and complete Risk response and Response justification. The available responses are:

ResponseDecision to describe
MitigateImplement measures to reduce likelihood or consequences
AvoidStop or change the activity that gives rise to the scenario
AcceptRetain the assessed exposure under an authorised decision
TransferArrange for another party to bear a specified part of the consequences

Transfer does not automatically remove the organisation's accountability or every residual exposure. Explain what an agreement or insurance arrangement covers and what remains.

Save each risk's response. Establish accountable ownership through the risk's owner controls and create suitable remediation work for mitigation decisions.

Return the response for review

In an enforced round, use View status to provide the demand's risk response after the individual risks have been reviewed. The demand moves to Response provided, where analysts perform the configured review and may request changes.

An analyst can perform response actions on the requester's behalf where authorised. The permitted response fields remain separate from the assessment fields, and the approval checklist governs what is needed to finish the round.

Selecting a response and closing a risk are separate actions. Review the risk's lifecycle instead of assuming that a response automatically completes it.