Skip to content
  • There are no suggestions because the search field is empty.

Risk assess an entity

Add a risk scenario to a process, asset or supplier and complete the assessment in one place.

How do you create a risk assessment

To create a risk assessment, open the relevant entity in your risk area, add a risk scenario, and set the consequence and probability levels with justifications. The risk level is then calculated automatically from the matrix belonging to that risk area.

 

  1. Go to your risk area and select the Operational overview.
  2. Find the entity you want to risk assess.
  3. Open the entity and click Add risk scenario.
  4. Select the risk scenario you want to assess against.
  5. Once the risk scenario is added to the entity, select the three dots to the right of the scenario and select Assess.
    risk handling menu
  6. Set the consequence level and select the specific consequences that apply.
  7. Write a justification for the consequence level.
  8. Set the probability level and select the security measures already in place. Security measures are controls or safeguards previously configured in your risk area. If none appear in the list, no security measures have been defined for this area yet — you can add them in the risk area settings before completing the assessment, or leave the selection empty and proceed.
  9. Write a justification for the probability level.
  10. Optionally add the risk exposure, meaning the estimated financial loss if the risk materialises.
  11. Click Save.

risk-exposure

The risk level is calculated and shown on the assessment. If it sits above the area's risk appetite, it is flagged as over appetite.

Please note:

Why do consequence and probability require a justification

Consequence and probability always require a justification because it creates an audit trail you can point to when someone later asks why a risk was rated the way it was.

 


Related Articles