Skip to content

Risks: what you record here and why

Last checked on

The Risks group is where you agree how to weigh risks, record what could go wrong and what you are doing about it, and see at a glance where your biggest risks sit.

Why this protects your organisation

A software supplier that does not know what could go wrong usually finds out when a customer calls. Recording each risk with an owner and a deliberate choice about how to handle it lets you spend time and money where it matters, and explain that reasoning to a customer or an auditor. ISO 27001 asks for this in clause 6.1: a consistent way of assessing risks and a conscious decision for each one.

Steps

  1. Open Risk assessment method and check that the default scales and thresholds suit your organisation. Then establish the method.
  2. Record what could go wrong under Risks, with an owner, the assets involved, and the likelihood and impact.
  3. Choose a treatment for each risk. For Reduce, add actions to the treatment plan and link the measures that make the risk smaller.
  4. Look at the Risk overview to see how your risks are spread across likelihood and impact.

The three screens in this group build on one another. The method decides how you weigh a risk, the register is where you keep the risks themselves, and the overview shows the result in one picture.

  • Risk assessment method: the scales for likelihood and impact, where low turns into medium and medium into high, and up to which score a risk may be accepted through the normal process.
  • Risks: the risk register, with an owner for each risk, the assets involved, the assessment, the treatment and a review date.
  • Risk overview: a matrix counting how many risks sit at each combination of likelihood and impact.

Whatever you do to shrink a risk is recorded as a measure in the Measures and evidence group. That way each risk shows the measures that address it, and each measure shows the risks it reduces.

If it does not work

I cannot choose a likelihood or impact on a risk

Those lists only work once a risk assessment method has been established. Open Risk assessment method and click Establish.

I cannot create or change anything in this group

An advisor can read along but not edit by default. The workspace owner can give an advisor edit rights for the Risks and controls module.

Read next