Skip to main content

Risk Details

Manage individual risk fields, ratings, owner, categories, linked controls, and review cycles.

Written by James Ross

Overview

The risk detail page is where you manage an individual risk — its description, ratings, owner, categories, linked controls, cause, consequence, and review cycle. This article covers all the fields and actions available on a risk.

Risk Header

The top of the risk detail page displays:

  • Title — click to edit via an inline modal. Changes save without a full page reload.

  • Description — click to edit via an inline modal

  • Status badge — colour-coded (Active, Inactive, Draft)

Risk Ratings

Quick Steps

  • Open a risk detail page

  • Two rating cards are displayed: Inherent Risk and Residual Risk

Inherent Risk Rating

  • Click the inherent risk rating card to open the rating modal

  • Select a likelihood and impact level

  • The score preview updates in real time (e.g. Likely × Major = 16)

  • Save — the card updates with the new likelihood, impact, score, and a colour-coded risk level badge

Residual Risk Rating

  • Click the residual risk rating card

  • The modal includes likelihood, impact, and treatment strategy selectors

  • Select values (e.g. Possible × Moderate, treatment "Reduce")

  • Score preview updates in real time

  • Save — the card updates with the residual score and treatment

Risk Fields

Several field cards are available on the risk detail page. Click each card to open a modal and enter or edit the value:

  • Cause — text field describing the root cause of the risk (e.g. "Inadequate access controls")

  • Consequence — text field describing the potential impact (e.g. "Data breach and regulatory fines")

  • Owner — user picker to assign a risk owner. Can be cleared to "No owner assigned".

  • Business Area — group picker to assign the risk to a business area. Shows the selected group path.

  • Categories — category picker with checkboxes. See Configuring Risk Categories.

Linked Controls

The controls section shows controls linked to this risk:

  • Click Link Controls to open a modal showing available (unlinked) controls

  • Select one or more controls and save

  • Linked controls appear with their title, status, and an unlink button

  • Click unlink on a control to remove the link (the control itself is not deleted)

  • The control count updates automatically after linking or unlinking

Review Cycle

  • The review field shows the current review date and cycle

  • Click the review date field to open the review modal

  • Set a cycle (e.g. "Quarterly") and save

  • The next review date is auto-calculated (e.g. quarterly = approximately 3 months from the last review)

Sign-Off

When a review is due, a sign-off button appears:

  • Click sign-off to record the review

  • The next review date advances based on the cycle

  • The sign-off appears in the review history

If you are not eligible for sign-off, the button is disabled or hidden with an explanation.

Activation

  • Activate — requires title, description, rating, and owner. Validation errors appear if required fields are missing (e.g. rating is required).

  • Deactivate — changes status to Inactive. Risk data is not deleted.

Current Task Card

The overview panel displays a current task card showing:

  • Task title, due date, assigned to, status chip, timing chip

  • A View task button to open the task sidebar

  • For Draft risks: "Scheduled after activation" with expected first review date

  • For risks with missing tasks: "Missing" status with a Recreate task button

Further Information

For health indicators, see Risk Health. For the risk summary table, see Managing Risks. For linking controls, see also Control Details.

Did this answer your question?