Risk Management
A live register wired to controls, treatment and the board.
What it does
Most risk registers are a spreadsheet that gets updated the week before a board meeting. This one is wired into the controls that actually reduce the exposure, so residual score moves when control effectiveness moves.
You assess against a matrix you configure, score in three layers, treat what sits above appetite, and formally accept what you choose to carry. Every one of those steps leaves a record with an owner and a date.
The heatmap is the board view. Cells above your declared appetite are called out, so the conversation starts at the exposure that matters instead of at the methodology.
Risk assessments
Scoped assessments that produce risk scenarios against the matrix you chose, attached to a perimeter from Governance.
Scenarios beat one-line risk titles. An assessment records the threat, the asset and the consequence, so two people reading the register understand the same thing.
Configurable risk matrices
Three by three, four by four and five by five matrices, configurable per tenant, with named levels and colour bands you define.
Your methodology is already approved by your own risk committee. The platform adapts to it rather than asking you to re-approve a vendor default.
5x5 · Almost certain / Catastrophic
Three-layer scoring
Three scores for each risk: inherent, controlled and residual. An explicit manual-override path lets an owner disagree with the calculated score on the record.
Residual risk that nobody can explain is worthless in a board pack. Here the number has a derivation, and a disagreement with it is itself recorded rather than argued in email.
Inherent 20 · Residual 8
Risk register
The canonical list: owner, category, scenario, all three scores, treatment status and a stable risk identifier.
One register, one ID. When Audit raises a finding against a risk, it points at the same record Risk is managing.
RSK-0142
Risk register
New risk| ID | Scenario | Inh | Res | Status |
|---|---|---|---|---|
| RSK-0142 | Single cloud provider concentration | 20 | 8 | Treatment in progress |
| RSK-0139 | Unreviewed privileged access | 16 | 4 | Within appetite |
| RSK-0151 | Third-party data leakage | 25 | 15 | Above appetite |
| RSK-0128 | Core banking outage | 20 | 9 | Treatment in progress |
Risk treatment plans
Treatments with milestones, progress logs, attached evidence items, success criteria and scheduled stakeholder review.
A treatment without a success criterion never closes. Writing down what "done" means at the start is what makes the register shrink.
Risk acceptances
Formal acceptance through an approval workflow with segregation-of-duties enforcement, governed by an acceptance matrix that defines who may accept what.
Accepting a risk is a decision with a name on it. The matrix stops a risk owner quietly accepting an exposure above their authority.
Risk appetite and thresholds
Set appetite per risk category. Breaches surface automatically rather than waiting for someone to notice them.
Appetite that lives in a board minute changes nothing. Appetite encoded as a threshold changes what the register shows you on a Monday morning.
Key risk indicators
KRIs tracked against defined thresholds, so movement in an indicator is visible before it becomes movement in a score.
A risk score is a lagging view. An indicator moving in the wrong direction is the earliest warning you get.
Heatmap
The board view of the register, plotted on your matrix, with above-appetite cells called out.
It is the one artefact a board actually reads. Making it a live view of the register instead of a rebuilt slide removes a whole reporting cycle.
Risk heatmap
ExportRisk transfer
Record insurance and contractual transfer against a risk, with its cost and coverage amount.
Transfer is a treatment option like any other. Keeping it in the register stops the insurance conversation happening somewhere the risk team cannot see.
Executive risk dashboard
Risk level history, trend over time, and top exposures, scoped to whichever folder you are looking at.
The question is never only "what is our exposure" but "which way is it moving". Trend answers the second one.
How a day looks
A KRI on third-party concentration crosses its threshold overnight. The risk owner opens the register, sees the residual score has moved because a compensating control was marked ineffective in its last review, and opens a treatment with two milestones and a named owner. The acceptance matrix will not let them accept the exposure at its current level, so it routes to the risk committee instead. None of that involved an email attachment.
Roles that live here
- Risk Manager
- Risk Owner
- Chief Risk Officer
- Business Unit Head
- Executive
Drawn from sixteen built-in roles, each scoped along the org tree. Access control
Related frameworks
See Risk Management on your matrix.
A 45-minute working session focused on the frameworks and requirements that matter to your organization.