Skip to content
  • There are no suggestions because the search field is empty.

Risk assess an entity

Add a risk scenario to a process, asset or supplier and complete the assessment in one place.

A risk assessment connects one entity to one risk scenario. You state consequence and probability, and the risk level is calculated automatically from the matrix belonging to that risk area.

 

  1. Go to your risk area and select the Operational overview.
  2. Find the entity you want to risk assess.
  3. Open the entity and click Add risk scenario.
  4. Select the risk scenario you want to assess against.
  5. Now the risk scenario is added to the entity. Select the three dots to the right of the scenario and select "assess"
    risk handling menu
  6. Set the consequence level and select the specific consequences that apply.
  7. Write a justification for the consequence level.
  8. Set the probability level and select the security measures already in place.
  9. Write a justification for the probability level.
  10. Optionally add the risk exposure, meaning the estimated financial loss if the risk materialises.
  11. Click Save.

risk-exposure

The risk level is calculated and shown on the assessment. If it sits above the area's risk appetite, it is flagged as over appetite.

Please note: consequence and probability always need a justification. This is what gives you an audit trail to point to when someone later asks why a risk was rated the way it was.