To create a risk, open Compliance then Risks in the sidebar and use the Create button. Record the risk’s details, score its inherent and residual exposure, assign an owner, and set a treatment plan. ISO Mate assigns a reference code automatically and computes the score and level band as you type.
Add a risk to the register
The risk register lives under the Compliance group in the sidebar. Open Risks to see the Risk Register, then click Create. The Create button is a split control, so opening its menu also offers Create with AI when AI creation is enabled for your account, which drafts the risk from a short description for you to review.
Describe the risk
- Title and description: name the risk and describe its context.
- Category: choose operational, security, compliance, financial, reputational, legal, or other.
- Status: set where the risk sits in its lifecycle, one of identified, assessed, treating, monitoring, or closed.
Score inherent and residual exposure
Rate likelihood and impact from 1 to 5 for both inherent exposure (before treatment) and residual exposure (after your controls). ISO Mate multiplies likelihood by impact to produce a score from 1 to 25 and assigns a level band automatically: 1 to 4 is low, 5 to 10 is medium, 11 to 15 is high, and 16 to 25 is critical. The score preview and level badge update live as you adjust the values. For more on the bands, see Interpreting the 5×5 Risk Matrix.
Assign an owner and a treatment plan
- Owner: assign the person accountable for the risk. The owner receives notifications about assignments, reviews, and escalations.
- Treatment strategy: choose accept, avoid, mitigate, or transfer.
- Treatment plan: document the planned actions in the rich text field.
- Review schedule: pick a review frequency of monthly, quarterly, annually, or ad hoc, and a next review date. See Running a Risk Review Cycle.
You can also record an optional target exposure, the level you expect the risk to reach once treatment is complete. See Setting Target Exposure on a Risk.
Link controls, frameworks, tasks, and incidents
Map the controls that treat the risk directly on the risk form. On the risk detail page you can also link the frameworks the risk relates to, the tasks that carry out the treatment, evidence, and any incident that realized the risk. A reference code such as RISK-0001 is assigned automatically when the risk is created.
Related articles
Ready to build your risk register? Start your free 14-day trial.