Skip to content

Risk management

Risks you can follow. From the first assessment to the next review.

Trustbird keeps one risk register for every standard you carry. Each risk is linked to the systems, processes and suppliers it affects and to the controls that treat it, so you can always see why a risk exists and what you are doing about it.

  • Every risk linked to what it affects
  • Risk acceptance by a named person
  • Periodic review with reminders

A register that reflects how your organization works

A risk register is useful when it starts from real things: the systems you run, the data you hold and the suppliers you depend on. Trustbird builds the register on that picture of your organization.

One risk register

Record risks once and use them for ISO 27001, NEN 7510 and ISO 9001. No separate lists per standard.

Linked to your organization

Link each risk to the assets, processes and suppliers it concerns. When something changes there, you see which risks need another look.

Likelihood and impact

Assess each risk on likelihood and impact with a method you define. The outcome shows which risks need attention first.

Treatment plans

Decide how to treat each risk, link the controls that reduce it and assign actions with an owner and a due date.

Acceptance by a named person

A remaining risk is accepted only by the person you designate. The decision is recorded with name, date and reasoning.

Periodic review

Set how often each risk is reviewed. Owners get a reminder in time, and every earlier assessment remains visible in the history.

How it works

  1. 01

    Describe what matters

    Answer plain questions about your systems, data, processes and suppliers. Trustbird uses the answers as the basis for the register.

  2. 02

    Identify and assess

    Record the risks that apply to you and assess likelihood and impact. Ask yourself questions like: what happens if this supplier is unavailable for a week?

  3. 03

    Decide on treatment

    Link controls, plan actions and have the designated person accept what remains.

  4. 04

    Review on schedule

    Trustbird reminds owners when a review is due and keeps the full history for the auditor.

Frequently asked questions

Can I use my own risk assessment method?
Yes. You define the scales for likelihood and impact and what level of risk is acceptable to you. Trustbird applies that method consistently across the register.
Can the AI accept a risk?
No. The AI can suggest risks and point out inconsistencies, but only a named person in your organization can accept or close a risk.
Do I need a separate risk register per standard?
No. One register serves every standard you carry. Where a standard asks for something specific, Trustbird shows it as an addition to the same register.

See what Trustbird does for your organization

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.