Risks
A risk register your team actually keeps up to date
Write down what could go wrong, score it by likelihood and impact, decide how to treat it and link the controls that reduce it. The heat map shows where to act first, and reviews come back on their own.

How it works
Record the risk
Name it, describe it, choose a category and an owner. Every risk gets a number such as R-7 that is never reused.
Score and treat it
Pick likelihood and impact for a score from 1 to 25, choose reduce, accept, transfer or avoid, and write the treatment plan.
Keep it reviewed
Set the next review. It appears in Tasks and the owner gets one reminder when it is due.
What changes for you
See your biggest risks at a glance
The 5x5 heat map of open risks is on the risk page and on the Overview.
Show the risk after treatment
Record likelihood and impact after treatment, so the remaining risk is clear to management and auditors.
Proof for every change
Every change is kept in the history and the audit log, and the register downloads for Excel.
What it covers
- NIS2 21(2)(a)
- ISO 27001 6.1.2
- ISO 27001 6.1.3
- ISO 27001 8.2
Works together with
Questions
Can members add risks?
Yes. Members see the register and can add risks they notice. Changing and deleting risks needs an owner or admin, or a custom role with that permission.
How do risks connect to controls?
On a control's page you choose the risks it treats. The risk's page then lists those controls, so you see how each risk is handled.
Start your risk register today
Add your first risks in minutes; the heat map fills in as you go.
