Risk register
Risk Management → Risk Register
The register is the organisation's single list of risks. Everything else in the risk module — engagements, treatments, KRIs — hangs off it.
Adding a risk
New Risk, then record:
| Field | Notes |
|---|---|
| Title / Title (Arabic) | What could go wrong. |
| Category | Groups the register for reporting. |
| Likelihood / Impact | 1–5 each. Their product is the inherent score (1–25). |
| Owner | The person accountable. Not the person doing the work. |
| Source | Where the risk came from — assessment, incident, workshop, regulator. |
Inherent, assessed, residual
Three scores, three meanings. Keeping them apart is the point of the module.
- Inherent — the risk before any controls. Set on the register.
- Assessed — what an engagement concluded when it looked.
- Residual — what remains after controls and treatments.
A blank residual means nobody has assessed it yet. It does not mean zero, and the platform will not fill it in for you.
Status
identified → assessed → treating → monitored → closed, with accepted for
risks knowingly carried. Transitions are validated — you cannot jump from
identified to closed without the steps in between.
Treatments
A treatment is what you are doing about a risk: mitigate, transfer, avoid or accept. Each has an owner, a due date and a target residual score. Treatments appear in the engagement report and on the dashboard, with overdue ones flagged.
Accepting a risk records who accepted it and when, and can carry an expiry so it comes back for review. Use it deliberately — an accepted risk with a named owner is defensible; an ignored one is not.