Skip to main content

Risk engagements

Risk Management → Risk Engagements

An engagement is a scoped exercise to assess a set of risks — an annual review, a project assessment, a regulator-driven exercise.

1. Create and scope

Create the engagement, then Scope Risks to pull risks in from the register. Optionally scope assets so the report shows what was in view.

2. Assess each risk

For each scoped risk, record assessed likelihood and impact, the residual after controls, and a risk response (mitigate, transfer, avoid, accept, no action).

Assessing inside an engagement does not silently overwrite the register. The engagement holds its own assessment; the register is updated through a controlled event when the engagement closes.

3. Divergence

If someone edits a risk directly in the register after it was scoped in, the engagement flags it as diverged — the engagement is now working from a stale picture. Reload that risk or reset it before relying on the result.

4. Close

Closing writes the engagement's conclusions back to the register, checks the results against your risk appetite, and raises breach notifications where thresholds are exceeded.

Appetite thresholds

If the engagement has an appetite threshold, the report lists every risk above it. With no threshold set, that section shows nothing — it is not a clean bill of health, it means the question was never asked.