Use the Risk Assistant, AI score suggestions and the assessment AI to draft risks, score them, plan mitigation and connect other modules, and know what each can and cannot save.
AI in RMS proposes, drafts and explains. Scores, statuses, owners, acceptance and approval stay with the people responsible. Each entry point below states what it can save.
Product location: /rms/chat. Open Risk Assistant under Analysis.
Open Risk Assistant under Analysis. The page, Risk Management AI Assistant, talks to the RMS Risk Specialist. Start a new conversation or continue one from the list.
It can:
find similar risks and read a risk's full context, trends and the register summary;
list risks due for review and overdue actions;
explain the methodology's scales and suggest factor scores with reasons;
recommend mitigating actions;
summarise material for a review;
analyse a document you point it to;
propose which framework requirements a risk relates to.
Example requests:
“Which of our risks have overdue reviews, and which of those are High or Critical?”
“Suggest likelihood and impact for RISK-OPS-2026-0014 and explain each score against our scale.”
“Recommend mitigating actions for the cold-chain gateway risk that would move its residual to Low.”
“Prepare a summary of what changed in our top ten risks for next week's management review.”
Product location: /rms/chat. Open Risk Assistant under Analysis.
The assistant can make two kinds of change, each within your own permissions:
Create a draft risk with a title, description, context and scope, root causes, notes, categories and objectives. The risk is saved as Draft without scores. Open it, score it and add the owner in the risk form.
Update one descriptive field of an existing risk: title, description, context and scope, root causes, notes or review frequency. It shows the change and asks for your explicit confirmation before saving.
It does not change scores, status, owner or acceptance, and does not delete risks. Do those in the risk record.
Product location: /rms/risks/{riskId}/edit (fallback: /rms/risks). Choose Ask AI, or Get AI suggestions in Framework mapping on the risk.
Open a risk and choose Ask AI in its editor, or Get AI suggestions in Framework mapping. The conversation opens Anchored to a specific risk, so the assistant works from that record. Choose Clear context to continue without it.
Framework suggestions are proposals. Add the requirements you agree with through Add link manually.
Product location: /rms/risks/new. Use AI score suggestions on the form.
On the risk form, AI score suggestions proposes factor scores once the description has at least 30 characters, or when you edit a saved risk. Choose the Score type, Inherent or Residual, then Suggest scores. Each factor comes with a suggested value and the reasoning.
Choose Apply for a factor or Apply all, then check the values against the scale guidance. Applied values only fill the form; nothing is saved until Save Risk. Dismiss discards the suggestions. For residual suggestions, describe the controls operating today in Controls already in place (scoring note).
Product location: /rms/assessments
Risk Assessment Companion: helps answer an assessment submission by explaining questions, suggesting answers from what is known and checking before you submit. It only writes into the form when you choose Use this answer. See run a risk assessment.
Risk identification: after the first approval, AI proposes risks from the answers. Nothing enters the register until someone accepts each proposal.
Reconciliation: after a re-submission is approved, AI proposes new, updated, reaffirmed and closed risks for your decision.
Assessment Template Assistant: builds and, after your confirmation, publishes assessment templates. See author an assessment template.
Product location: /rms/onboarding/policies. After the required policies, choose Open the AI assistant.
When the required risk policies are complete, policy onboarding offers Connect with other modules and Open the AI assistant. The assistant reviews your organisation's forms, for example incident, supplier-review or change-request forms, and proposes output rules so a submission can create or link a risk automatically. It saves a new rule only after you explicitly agree. See form output rules.
For example: “When an incident report is submitted with severity High, create a risk from the incident description with initial status Pending Review.” A Pending Review risk waits for a person to confirm and activate it; see the risk record. The rule can also create Draft or Active risks.