TrustPoint

Risk Management

A live register wired to controls, treatment and the board.

What it does

Most risk registers are a spreadsheet that gets updated the week before a board meeting. This one is wired into the controls that actually reduce the exposure, so residual score moves when control effectiveness moves.

You assess against a matrix you configure, score in three layers, treat what sits above appetite, and formally accept what you choose to carry. Every one of those steps leaves a record with an owner and a date.

The heatmap is the board view. Cells above your declared appetite are called out, so the conversation starts at the exposure that matters instead of at the methodology.

Risk assessments

Scoped assessments that produce risk scenarios against the matrix you chose, attached to a perimeter from Governance.

Scenarios beat one-line risk titles. An assessment records the threat, the asset and the consequence, so two people reading the register understand the same thing.

Configurable risk matrices

Three by three, four by four and five by five matrices, configurable per tenant, with named levels and colour bands you define.

Your methodology is already approved by your own risk committee. The platform adapts to it rather than asking you to re-approve a vendor default.

5x5 · Almost certain / Catastrophic

Three-layer scoring

Three scores for each risk: inherent, controlled and residual. An explicit manual-override path lets an owner disagree with the calculated score on the record.

Residual risk that nobody can explain is worthless in a board pack. Here the number has a derivation, and a disagreement with it is itself recorded rather than argued in email.

Inherent 20 · Residual 8

Risk register

The canonical list: owner, category, scenario, all three scores, treatment status and a stable risk identifier.

One register, one ID. When Audit raises a finding against a risk, it points at the same record Risk is managing.

RSK-0142

Illustrative interface. Not customer data.

Risk treatment plans

Treatments with milestones, progress logs, attached evidence items, success criteria and scheduled stakeholder review.

A treatment without a success criterion never closes. Writing down what "done" means at the start is what makes the register shrink.

Risk acceptances

Formal acceptance through an approval workflow with segregation-of-duties enforcement, governed by an acceptance matrix that defines who may accept what.

Accepting a risk is a decision with a name on it. The matrix stops a risk owner quietly accepting an exposure above their authority.

Risk appetite and thresholds

Set appetite per risk category. Breaches surface automatically rather than waiting for someone to notice them.

Appetite that lives in a board minute changes nothing. Appetite encoded as a threshold changes what the register shows you on a Monday morning.

Key risk indicators

KRIs tracked against defined thresholds, so movement in an indicator is visible before it becomes movement in a score.

A risk score is a lagging view. An indicator moving in the wrong direction is the earliest warning you get.

Heatmap

The board view of the register, plotted on your matrix, with above-appetite cells called out.

It is the one artefact a board actually reads. Making it a live view of the register instead of a rebuilt slide removes a whole reporting cycle.

Illustrative interface. Not customer data.

Risk transfer

Record insurance and contractual transfer against a risk, with its cost and coverage amount.

Transfer is a treatment option like any other. Keeping it in the register stops the insurance conversation happening somewhere the risk team cannot see.

Executive risk dashboard

Risk level history, trend over time, and top exposures, scoped to whichever folder you are looking at.

The question is never only "what is our exposure" but "which way is it moving". Trend answers the second one.

How a day looks

A KRI on third-party concentration crosses its threshold overnight. The risk owner opens the register, sees the residual score has moved because a compensating control was marked ineffective in its last review, and opens a treatment with two milestones and a named owner. The acceptance matrix will not let them accept the exposure at its current level, so it routes to the risk committee instead. None of that involved an email attachment.

Roles that live here

  • Risk Manager
  • Risk Owner
  • Chief Risk Officer
  • Business Unit Head
  • Executive

Drawn from sixteen built-in roles, each scoped along the org tree. Access control

Related frameworks

See Risk Management on your matrix.

A 45-minute working session focused on the frameworks and requirements that matter to your organization.