Overview
Risk Manager is a dedicated module in ProcessPro for identifying, assessing, and managing organisational risks and their controls. It provides a structured framework for risk identification, rating, treatment, and ongoing review — separate from your process maps and workflows.
What Can You Do with Risk Manager?
Identify risks — create risk records with titles, descriptions, causes, and consequences
Assess risks — rate risks using likelihood × impact scoring for both inherent and residual risk
Define treatments — assign treatment strategies (Avoid, Reduce, Transfer, Accept)
Manage controls — create controls, link them to risks, track evidence and assurance
Monitor health — automated health indicators flag risks and controls that need attention
Track reviews — review cycles and assurance tasks keep your risk register current
Visualise risk — heat maps show your risk profile at a glance
Export data — download risk and control summaries as CSV
Accessing Risk Manager
Quick Steps
Risk Manager is accessible from the sidebar navigation
Click Risk Manager to open the module
The default landing page is the Overview tab with heat maps
Risk Manager Tabs
The module has four main tabs:
Overview — heat maps and metric cards showing your risk profile
Risks — risk summary data table with all risks for your company
Controls — control summary data table with all controls
Reviews & Assurance — task data table for review and assurance tasks
Permissions
Risk Manager access is controlled at the company level:
A company admin can enable or disable Risk Manager via a toggle in company settings
When enabled, the Risk Manager link appears in the sidebar for all users in that company
When disabled, the link is hidden and navigating to /risk returns a 403 Forbidden response
Each company's setting is independent — enabling it for one company does not affect others
Important: Risk Manager must be enabled before any risk or control data can be created. Contact your company admin if you don't see the option.
Risks and Controls Are Not Processes
Risks and controls are stored as distinct object types — they do not appear in the process list. You will not see them alongside your processes, value streams, or other process-type objects.
Further Information
For configuring risk categories and rating scales, see Configuring Risk Categories and Configuring Risk Rating Scales. For creating and managing risks, see Managing Risks.