Read a risk's overview, move it through its treatment stages, keep evidence and history, and set it obsolete, reactivate or delete it.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.
Open Risk Register and select a risk. The header shows its number and title, its status and its Domain, which determines the risk number's prefix. The actions available depend on the status:
Status | Actions |
|---|---|
Draft or Active | Edit, Set Obsolete, Delete |
Pending Review | Review, Delete |
Obsolete | Reactivate, Delete |
The page has three tabs: Overview, Treatment and History.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.
The Overview tab collects everything recorded about the risk:
Panel | What it shows and what you can do |
|---|---|
Source context | The module and record that created the risk, for example a form submission or assessment, with a link while that module is enabled. |
Score | Inherent Risk and Residual Risk with score, level, Factor Breakdown and Recommended Action. Mitigation Impact shows how far the residual is below or above the inherent score. Not assessed means no score has been recorded. |
Risk Categories, Affected Objectives | The classification chosen when the risk was logged or edited. |
Mitigating Actions | The planned and completed actions for this risk; see treatment work. |
Evidence Documents | Files that support the risk's assessment and its actions. |
Details | Context & Scope, Root Causes and Notes. |
Treatment & acceptance | The treatment proposal, acceptance documentation and review frequency. |
Framework mapping | The standard requirements this risk relates to (requires Quality). Get AI suggestions opens the Risk Assistant for this risk to propose mappings; Add link manually records a standard and requirement with an optional note. |
Referenced by processes | QMS processes, or specific process steps, that reference this risk (requires Quality). |
Controls | Linked controls, their effectiveness, how much of the risk each covers and how much each counts; see controls and residual challenges. |
Residual vs controls | Whether the recorded residual is supported by the controls' evidence. |
Risk in money | Before- and after-controls loss estimates; see monetary estimates. |
What the controls are worth | The yearly loss the linked controls avoid, overall and per control. |
Shared with other risks | Common dependencies this risk shares with other risks; see concentration. |
Lifecycle History | When the risk was set obsolete, reactivated or deleted, by whom and why. |
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.
In Evidence Documents, choose Upload to open Upload Evidence:
Drag a file onto the drop zone or browse to it. Files can be up to 100 MB: documents (PDF, Word, HTML, text, Markdown), images, video or audio.
Enter a Title and choose a Document Type: Incident Report, Root Cause Analysis, Photo / Image, Policy / Procedure, Test / Verification Report, Implementation Evidence, Correspondence or Other.
Optionally choose Link to Action (optional) to attach the file to one mitigating action instead of the risk as a whole, and add Notes.
Upload the file.
Capture from screen asks your browser which screen, window or tab to share, takes one image of it and uses AI to pre-fill the upload's title, type and notes. The image becomes the file to upload. Review the pre-filled values before you upload; if the analysis fails, the fields stay empty and you can still upload the image.
The table shows each file's type, what it is linked to, who uploaded it and when. AI Status shows whether the file has been read for AI use: Pending, Processing, Indexed or Failed. Use Retry AI processing for a failed file. Preview shows images, PDFs and text files, Download retrieves the original, and Delete removes the file after confirmation.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the Treatment tab.
On Treatment, Current stage shows where the risk is in its workflow: Assessment, Treatment, Periodic Review or Closed. The button moves it on one stage: Advance to Treatment, Advance to Periodic Review, Close Risk, or Reopen for a closed risk, which returns it to Periodic Review. Stages apply to Draft and Active risks.
Treatment proposal records the intended response. Choose Edit, write the proposal and Save proposal. A proposal is required when the inherent level is Medium or higher.
Under Residual scoring & acceptance, choose a Residual value for each factor. The Calculated residual score and Residual band update as you choose. When the residual band is Medium or higher, enter Acceptance documentation: who accepts the remaining risk and why. Choose Save residual.
Treatment plans created from a form, for example a supplier corrective-action request, appear on the Treatment tab. Each shows its treatment option, owner, target date, cost estimate, source submission and status. Move a plan through its lifecycle there: approve, start, complete or cancel it.
Score the residual on the controls that operate today, not on planned work. If your methodology derives residual scores from control effectiveness, a nightly check recalculates them; see controls and residual challenges.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the History tab.
History lists each approved assessment submission that touched this risk: when it was created, reaffirmed as Still applicable, Updated or Closed. It also shows whether the change was AI suggested, the close reason and the changed values. Open submission opens the assessment submission behind the change.
Product location: /rms/risks/{riskId}/review (fallback: /rms/risks). Choose Review now in the register, then Review on the pending risk.
A form or another module can create a risk that waits as Pending Review. The register then shows how many risks await review, and Review now filters to them.
Choose Review to open Review pending risk. Check the Source context, then confirm or adjust the owner, categories, objectives, the suggested inherent scores, the title and the descriptive fields. Leave a factor blank to skip it.
Confirm and activate saves your changes and makes the risk Active.
Reject sets the risk obsolete with the reason you give.
Link controls after activation.
Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.
Set Obsolete retires a risk that no longer applies but should stay on record. Enter the Reason. The dialog warns if mitigating actions remain open. The risk and all its data are kept, and it leaves the heatmap and active figures.
Reactivate returns an obsolete risk to the active register and clears the obsolete reason and date.
Delete permanently removes a risk recorded in error. In Permanently delete risk, type the risk title exactly to confirm, then choose Delete Permanently. Its actions, scores, links and evidence records are removed. Evidence files are purged after a recovery period (30 days by default), and the lifecycle entry remains. See retention status.
Prefer Set Obsolete to deletion for anything that was a real risk. It keeps the history an auditor or reviewer may need.