Help center

Help center

All collectionsRisk (RMS)Register and risk recordsWork with a risk record

Work with a risk record

Read a risk's overview, move it through its treatment stages, keep evidence and history, and set it obsolete, reactivate or delete it.

Read a risk's overview, move it through its treatment stages, keep evidence and history, and set it obsolete, reactivate or delete it.

Open a risk

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.

Open Risk Register and select a risk. The header shows its number and title, its status and its Domain, which determines the risk number's prefix. The actions available depend on the status:

Status

Actions

Draft or Active

Edit, Set Obsolete, Delete

Pending Review

Review, Delete

Obsolete

Reactivate, Delete

The page has three tabs: Overview, Treatment and History.

Read the Overview

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.

The Overview tab collects everything recorded about the risk:

Panel

What it shows and what you can do

Source context

The module and record that created the risk, for example a form submission or assessment, with a link while that module is enabled.

Score

Inherent Risk and Residual Risk with score, level, Factor Breakdown and Recommended Action. Mitigation Impact shows how far the residual is below or above the inherent score. Not assessed means no score has been recorded.

Risk Categories, Affected Objectives

The classification chosen when the risk was logged or edited.

Mitigating Actions

The planned and completed actions for this risk; see treatment work.

Evidence Documents

Files that support the risk's assessment and its actions.

Details

Context & Scope, Root Causes and Notes.

Treatment & acceptance

The treatment proposal, acceptance documentation and review frequency.

Framework mapping

The standard requirements this risk relates to (requires Quality). Get AI suggestions opens the Risk Assistant for this risk to propose mappings; Add link manually records a standard and requirement with an optional note.

Referenced by processes

QMS processes, or specific process steps, that reference this risk (requires Quality).

Controls

Linked controls, their effectiveness, how much of the risk each covers and how much each counts; see controls and residual challenges.

Residual vs controls

Whether the recorded residual is supported by the controls' evidence.

Risk in money

Before- and after-controls loss estimates; see monetary estimates.

What the controls are worth

The yearly loss the linked controls avoid, overall and per control.

Shared with other risks

Common dependencies this risk shares with other risks; see concentration.

Lifecycle History

When the risk was set obsolete, reactivated or deleted, by whom and why.

Keep supporting evidence

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.

In Evidence Documents, choose Upload to open Upload Evidence:

  1. Drag a file onto the drop zone or browse to it. Files can be up to 100 MB: documents (PDF, Word, HTML, text, Markdown), images, video or audio.

  2. Enter a Title and choose a Document Type: Incident Report, Root Cause Analysis, Photo / Image, Policy / Procedure, Test / Verification Report, Implementation Evidence, Correspondence or Other.

  3. Optionally choose Link to Action (optional) to attach the file to one mitigating action instead of the risk as a whole, and add Notes.

  4. Upload the file.

Capture from screen asks your browser which screen, window or tab to share, takes one image of it and uses AI to pre-fill the upload's title, type and notes. The image becomes the file to upload. Review the pre-filled values before you upload; if the analysis fails, the fields stay empty and you can still upload the image.

The table shows each file's type, what it is linked to, who uploaded it and when. AI Status shows whether the file has been read for AI use: Pending, Processing, Indexed or Failed. Use Retry AI processing for a failed file. Preview shows images, PDFs and text files, Download retrieves the original, and Delete removes the file after confirmation.

Move the risk through its treatment stages

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the Treatment tab.

On Treatment, Current stage shows where the risk is in its workflow: Assessment, Treatment, Periodic Review or Closed. The button moves it on one stage: Advance to Treatment, Advance to Periodic Review, Close Risk, or Reopen for a closed risk, which returns it to Periodic Review. Stages apply to Draft and Active risks.

Treatment proposal records the intended response. Choose Edit, write the proposal and Save proposal. A proposal is required when the inherent level is Medium or higher.

Under Residual scoring & acceptance, choose a Residual value for each factor. The Calculated residual score and Residual band update as you choose. When the residual band is Medium or higher, enter Acceptance documentation: who accepts the remaining risk and why. Choose Save residual.

Treatment plans created from a form, for example a supplier corrective-action request, appear on the Treatment tab. Each shows its treatment option, owner, target date, cost estimate, source submission and status. Move a plan through its lifecycle there: approve, start, complete or cancel it.

Score the residual on the controls that operate today, not on planned work. If your methodology derives residual scores from control effectiveness, a nightly check recalculates them; see controls and residual challenges.

Read the history

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open the History tab.

History lists each approved assessment submission that touched this risk: when it was created, reaffirmed as Still applicable, Updated or Closed. It also shows whether the change was AI suggested, the close reason and the changed values. Open submission opens the assessment submission behind the change.

Review a risk created by another module

Product location: /rms/risks/{riskId}/review (fallback: /rms/risks). Choose Review now in the register, then Review on the pending risk.

A form or another module can create a risk that waits as Pending Review. The register then shows how many risks await review, and Review now filters to them.

Choose Review to open Review pending risk. Check the Source context, then confirm or adjust the owner, categories, objectives, the suggested inherent scores, the title and the descriptive fields. Leave a factor blank to skip it.

  • Confirm and activate saves your changes and makes the risk Active.

  • Reject sets the risk obsolete with the reason you give.

Link controls after activation.

Set a risk obsolete, reactivate or delete it

Product location: /rms/risks/{riskId} (fallback: /rms/risks). Open Risk Register and select the risk.

  • Set Obsolete retires a risk that no longer applies but should stay on record. Enter the Reason. The dialog warns if mitigating actions remain open. The risk and all its data are kept, and it leaves the heatmap and active figures.

  • Reactivate returns an obsolete risk to the active register and clears the obsolete reason and date.

  • Delete permanently removes a risk recorded in error. In Permanently delete risk, type the risk title exactly to confirm, then choose Delete Permanently. Its actions, scores, links and evidence records are removed. Evidence files are purged after a recovery period (30 days by default), and the lifecycle entry remains. See retention status.

Prefer Set Obsolete to deletion for anything that was a real risk. It keeps the history an auditor or reviewer may need.

Did this answer your question?
😞
😐
😁