Adding and editing risks
This page covers step 1 of the Add Risk wizard: describing what the risk actually is. Scoring is covered in Assessing a risk.
The identification fields
| Field | What to put in it |
|---|---|
| Title | The risk, not the subject. “Card processor outage during peak” beats “Card processor”. A good title contains a cause and a consequence. |
| Category | The risk taxonomy your organisation uses. Drives the category breakdown on the register. |
| Risk owner | Who is accountable — not who is fixing it. The owner answers for this risk at committee. |
| Asset type / Asset | What the risk is about. If asset lists are configured, this also feeds the scoring. |
| Threat | What could go wrong. |
| Vulnerability | The weakness that lets it happen. |
| Risk narrative | Context, cause and consequence in a few sentences. This is what somebody reads in two years when deciding whether the risk is still real. |
| Identification date | When the risk was first recognised. Defaults to today. |
| Risk status | The treatment stance: Mitigation, Transfer, Acceptance, Avoidance, Reduction. |
Which fields you see is decided by the layout your register uses, so your form may differ from this list. Required fields are marked, and some stages will not let you continue until they are filled.
Saving as a draft
Select Save as draft to keep a partially completed risk. Drafts are visible to you and are not counted in register totals until submitted.
Editing an existing risk
Open the risk and select Edit. What you may change depends on three things: your role, whether you own or are assigned the risk, and whether the current stage has been frozen. A field you cannot edit is shown read-only rather than hidden, so the value still reconciles with reports.
Every change is written to the audit log with your name and a timestamp.