Risk Register
Governance → Risks is the company's risk register. Each risk is scored on a 5×5 matrix of how likely it is and how bad its impact would be (the ISO 31000 approach), given an owner and a next review date, and tracked through mitigation actions until it is closed. You need the Governance access permission to open it.
The Risk Register currently runs on sample data held in your browser session. The sample risks, categories and owners you see are examples; anything you create or change lasts only until the page is reloaded and is not stored on the server or shared with colleagues. Treat it as a preview of the screens and of the scoring method.
Scoring a Risk
Likelihood and impact are each rated 1 to 5. The score is the two multiplied, and the score decides the level.
| Score | Level |
|---|---|
| 1–4 | Low |
| 5–9 | Medium |
| 10–14 | High |
| 15–25 | Extreme |
| Rating | Likelihood | Impact |
|---|---|---|
| 1 | Rare | Insignificant |
| 2 | Unlikely | Minor |
| 3 | Possible | Moderate |
| 4 | Likely | Major |
| 5 | Almost Certain | Catastrophic |
| LikelihoodLikely | 4 | |
|---|---|---|
| ImpactMajor | × | 4 |
| Inherent scoreExtreme (15 or more) | = | 16 |
The Risk List
Four cards summarise the register: Total Risks, Extreme, High and Open (risks not yet closed). Below them, filters narrow the list by category, status or level; Clear resets them and the search box matches the risk title. A toggle switches between two views:
- Table — one row per risk with its title, category, owner, a From meeting tag if it began as a meeting issue, how many mitigations are done out of the total, the likelihood × impact score with its level, the Residual score when there is one, and a status badge.
- Matrix — the Risk Heatmap: a 5×5 grid with Likelihood on one axis and Impact on the other, coloured from low to extreme, with each risk placed in its cell. Click a risk to open it.
The header has Manage Categories (opens Risk Categories) and New Risk.
A risk's status is one of Identified, Assessing, Mitigating, Monitoring or Closed.
Creating a Risk
New Risk opens a dialog that scores the new risk on the 5×5 matrix.
- Describe the riskTitle*A short name, for example Data breach via phishing attack. Required.CategoryThe risk domain (Strategic, Operational, Financial, Compliance and so on).DescriptionWhat could happen and how it might affect the company.
- Assess the inherent risk
Pick the Likelihood and Impact (both start at 3, Possible and Moderate). The dialog shows the Inherent Score as you choose.
- Optionally capture the residual risk
Tick Also capture residual risk (after current mitigation) if controls are already in place, then set the Residual Likelihood and Residual Impact. The Residual Score is shown the same way.
- Ownership and reviewOwner*The person responsible for the risk. Required.StatusStarts at Identified.Next ReviewWhen the risk should be looked at again; defaults to 90 days from today.
Create Risk adds it to the register. The dialog can also open as Promote Issue to Risk, prefilled from a meeting issue and starting at Assessing, which marks the risk From meeting.
The Risk Page
Click a risk to open it. The header shows the title and description, a status selector (changing it saves immediately) and Delete, which permanently removes the risk with its mitigations and review history after a confirmation. A risk promoted from a meeting shows a Promoted from meeting issue note with the original issue.
- Inherent Risk card — shows likelihood × impact = score and the level. Click a different number under Likelihood or Impact to re-score; each re-score adds an entry to Review History with the previous and new values.
- Residual Risk card — shown when a residual rating was recorded: the risk after current controls are applied.
- A details card with the Category, Owner, Next Review and Last Updated.
- Mitigation Actions — the things being done to reduce the risk. Use Add, describe the action, and optionally pick an owner and a due date. Click the status of an action to cycle it Open → In Progress → Done. An action that is not done also offers Create Task, which is meant to hand it to the Task module; in this preview it only shows a confirmation message and does not create a task.
- Review History — every re-score with who did it and when.
Re-score a risk whenever circumstances change, rather than editing the title or description: the history then shows how its rating moved over time.
How It Connects
The Risk Register is self-contained in this release: it does not yet read from or feed other screens. The screens are built for a risk to be promoted from a meeting issue and for each mitigation action to become a task (see Live Session and All Tasks), but neither link is live today.
Set up first
- Risk Categories — every risk is filed under a category, so define the domains you use first.