Assessing a risk

Step 2 of the Add Risk wizard. Concepts are on Risk scoring explained; this page is how to do it.

Inherent — before any controls

Answer the factor questions for each dimension. Every factor shows its weight, so you can see what is driving the number, and the score updates as you answer.

The most common mistake in the whole app. People score inherent risk too low, because they unconsciously credit the controls they already have. Inherent means if we did nothing at all. If your inherent and residual scores are always close, this is why — and it makes your control library look worthless.

Residual — with the controls you have

Attach your existing controls first (step 3), then come back. Four tiles help you judge it:

Tile Tells you
Existing controls How many are attached and their total effectiveness.
Risk mitigation The reduction from inherent — for example 24 down to 15.
Control health Whether those controls are tested and passing, or overdue.
Appetite gap How far the residual score sits above or below appetite.

A large mitigation claimed by controls that are failing their tests is not a reduction — it is a finding. That is what the control health tile is for.

Target — with the controls you plan

Attach planned controls and the target score shows where the risk lands if you deliver them. Two shortcuts help:

  • Auto-calculate from controls — derive the target from the planned coverage.
  • Reset to inherent — start again.

If the target is still above appetite after every control you can think of, the risk needs a formal acceptance decision rather than another plan.

Manual overrides

Where the app calculates a score, you can override it per dimension. The override is marked on the record with a chip and recorded in the audit log.

Overriding is legitimate — models do not know everything. Overriding silently is not, which is why the marker cannot be removed.