Skip to content
  • There are no suggestions because the search field is empty.

Get started with Enterprise Risk Management

The order to do things in when you set up the add-on for the first time.

Enterprise Risk Management brings your risk work into one place, whether you are working with GDPR, NIS2, the AI Act, information security or an area you define yourself. Instead of separate spreadsheets that each live their own life, you get one shared risk overview where assessments turn into action plans and action plans turn into decisions.

Setting it up follows a fixed order, because each step depends on the one before it.

  1. Create a risk area. A risk area is one compliance or security domain you assess risk within.
  2. Set up the scale and the risk matrix. Decide how many levels the area uses, what they are called, and which risk level each combination of consequence and probability produces.
  3. Set the risk appetite. Define the highest risk level the area accepts, and set a global appetite across all areas.
  4. Add risk scenarios. Import them from the catalogue or build your own, along with consequences and security measures.
  5. Add the entities the area covers. Processes, assets and systems, and suppliers.
  6. Assess. Add risk scenarios to your entities and set consequence and probability, one at a time or in bulk.
  7. Decide and plan. Accept, avoid or mitigate each assessed risk.
  8. Report. Use the risk overview for day-to-day work and the management report for the board.

Repeat steps one to five for each risk area you need. Areas are independent of each other, so a second area does not have to use the same scale or the same appetite as the first.