Risk Details
Understanding the risk detail view and managing individual risks.
Risk Details
The risk detail view provides comprehensive information about a single risk. This guide explains each section and how to effectively manage risks.
Opening Risk Details
Access the detail view by:
- Clicking a risk in the Risk Registry or Priority Queue
- Direct URL - Each risk has a unique URL for bookmarking/sharing
- From related items - Click risk links from gaps, workflows, or dashboards
Detail View Layout
Header
The header shows:
- Risk title - Primary identification
- Severity badge - Color-coded severity
- Status badge - Current status
- Priority score - AI-calculated priority
- Actions menu - Edit, workflow, delete options
Key Metrics
Quick-view metrics:
- Risk Score - Likelihood × Impact
- Days Open - How long since creation
- Related Gaps - Count of linked gaps
- Mitigation Progress - If a workflow exists
Information Sections
Overview
Primary risk information:
| Field | Description |
|---|---|
| Description | Full risk explanation |
| Category | Security, Compliance, etc. |
| Likelihood | 1-5 probability rating |
| Impact | 1-5 business impact rating |
| Risk Score | Calculated L × I score |
| Owner | Assigned responsible person |
| Created | Date risk was added |
| Last Updated | Most recent modification |
Assessment Details
Risk assessment information:
| Field | Description |
|---|---|
| Inherent Risk | Risk without controls |
| Residual Risk | Risk after controls |
| Control Effectiveness | How well controls work |
| Treatment | Mitigate, Transfer, Accept, Avoid |
Related Items
Connected items:
| Item Type | Description |
|---|---|
| Gaps | Linked compliance gaps |
| Controls | Controls that mitigate this risk |
| Workflows | Remediation workflows |
| Documents | Related evidence/policies |
Activity
Complete history:
- Status changes
- Property edits
- Comments
- Workflow updates
- System events
Managing Risk Status
Status Options
| Status | When to Use |
|---|---|
| Open | Risk identified, not addressed |
| Mitigating | Active work underway |
| Mitigated | Risk reduced to acceptable level |
| Accepted | Formally accepted with approval |
| Closed | No longer relevant |
Changing Status
Click Status Badge
Opens status change dialog.
Select New Status
Choose the appropriate status.
Add Notes
Document why the status is changing.
Save
Status updates and is logged in history.
Status changes are logged in the audit trail. Always add meaningful notes explaining the change.
Editing Risk Properties
What Can Be Edited
- Title and description
- Category
- Likelihood and impact
- Severity
- Owner
- Related items
- Custom fields
Edit Process
- Click "Edit" button in header
- Modify desired fields
- Review changes
- Click "Save"
Bulk Editing
For multiple risks:
- Select risks in Registry view
- Click "Bulk Edit"
- Choose fields to update
- Apply changes
Risk Assessment
Initial Assessment
When adding a risk:
- Assess inherent risk (without controls)
- Identify existing controls
- Evaluate control effectiveness
- Calculate residual risk
- Determine treatment approach
Reassessment
Periodically reassess risks:
- Quarterly for high/critical risks
- Annually for medium/low risks
- After significant changes
- Following incidents
Assessment Documentation
Record in the risk:
- Assessment date
- Who conducted it
- Methodology used
- Findings and reasoning
- Recommended actions
Risk Treatment
Treatment Options
| Treatment | Description | When to Use |
|---|---|---|
| Mitigate | Reduce likelihood or impact | When controls can lower risk |
| Transfer | Shift risk to third party | Insurance, outsourcing |
| Accept | Acknowledge and live with | Low risk or cost prohibitive |
| Avoid | Eliminate the risk source | Change approach entirely |
Documenting Treatment
Record your treatment decision:
- Open risk details
- Edit treatment field
- Add treatment rationale
- Link mitigation activities
Creating Workflows from Risks
For risks requiring remediation:
Click "Create Workflow"
Opens workflow creation from risk context.
Configure Workflow
Set name, tasks, and assignments.
Link to Risk
Workflow automatically links to the risk.
Start Workflow
Begin remediation activities.
Risk Comments
Adding Comments
- Scroll to Comments section
- Type your comment
- @mention team members
- Click "Post"
Comment Uses
- Discuss risk with team
- Document decisions
- Share updates
- Ask questions
- Record meeting notes
Viewing History
Activity Timeline
The Activity tab shows:
- All status changes
- Property modifications
- Comments added
- Workflow updates
- Who made each change
- When changes occurred
Audit Trail
For compliance purposes:
- Every action is logged
- Timestamps are recorded
- User identity captured
- Changes cannot be deleted
Risk Scoring Deep Dive
Score Components
| Component | Calculation |
|---|---|
| Inherent Score | Likelihood × Impact (no controls) |
| Control Factor | % reduction from controls |
| Residual Score | Inherent - (Inherent × Control Factor) |
| Priority Boost | AI factors (age, gaps, audit) |
Score Interpretation
| Score | Risk Level | Action Required |
|---|---|---|
| 17-25 | Critical | Immediate action |
| 10-16 | High | Prompt action |
| 5-9 | Medium | Planned action |
| 1-4 | Low | Monitor |
Linking Items
Adding Gaps
- Click "Link Gap" in Related Items
- Search for gaps
- Select relevant gaps
- Save links
Adding Controls
- Click "Link Control"
- Search for controls
- Select relevant controls
- Note how they mitigate
Adding Documents
- Click "Link Document"
- Select from document library
- Or upload new document
- Explain relevance
Linking items creates a complete picture of the risk context and helps demonstrate due diligence during audits.
Exporting Risk Details
Export for reporting:
- Open risk details
- Click "Export"
- Choose format (PDF, CSV)
- Download file
Export includes:
- All risk properties
- Assessment details
- Related items list
- Activity history
Common Questions
Can I delete a risk?
You can, but it's not recommended. Instead:
- Mark as "Closed" with explanation
- Archive if feature available
- Keep for audit trail
How do I transfer ownership?
- Edit the risk
- Change the Owner field
- Notify the new owner
- Document the transfer reason
What if I disagree with the assessment?
- Add a comment explaining your view
- Discuss with the risk owner
- Request reassessment if needed
- Document the final decision
Next Steps
- Crypto Risks - Cryptocurrency-specific risks
- Workflows - Create remediation plans
- Priority Queue - View AI prioritization