Risk Register#
The risk register holds scored risks following ISO 31000. Each risk carries a likelihood, an impact, a treatment and a review cadence.
Risks can be linked to tasks, and tasks can be filtered by risk item, so the audit and corrective work addressing a risk can be listed.
The matrix#
The 5x5 matrix shows likelihood as rows and impact as columns, colored by score. Each sector states how many risks fall in it.
Select a sector to filter the register beneath it. Select the indicator above the table to clear the filter.
The axes#
| Likelihood | Impact |
|---|---|
| Rare | Insignificant |
| Unlikely | Minor |
| Possible | Moderate |
| Likely | Major |
| Almost certain | Severe |
The score is likelihood multiplied by impact, from 1 to 25. Each axis value is 1 to 5 in the order listed.
The register#
| Column | Content |
|---|---|
| Risk | The title. |
| Score | The risk band, on the same color scale as the matrix. |
| L×I | The likelihood and impact behind the band. |
| Treatment | The selected treatment. |
| Management system | The management system it belongs to. |
The register is sorted by score, highest first, and is paged. Use Prev and Next at the bottom to move between pages.
Select a row to edit the risk.
Add a risk#
Select + New risk and complete:
| Field | Notes |
|---|---|
| Title | Required. |
| Likelihood | Required. |
| Impact | Required. The drawer shows the resulting score and band. |
| Treatment | Accept, Mitigate, Transfer or Avoid. |
| Owner | The person accountable. |
| Management system | The domain it belongs to. |
| Description | Optional. |
| Review every (days) | The review cadence. |
The risk is saved automatically once title, likelihood and impact are set.
Treatments#
| Treatment | Meaning |
|---|---|
| Accept | The risk is tolerated at its current score. |
| Mitigate | Reduce the likelihood, the impact, or both. |
| Transfer | Move the consequence elsewhere, for example by insurance or contract. |
| Avoid | Stop the activity that creates the risk. |
Link risks to work#
Set the Risk item field on a task to link it to a risk. In Tasks, filter by risk item to list all work linked to it.
Findings raised during an audit inherit the audit's risk item.
Delete a risk#
Select Delete on the row. The risk moves to the Trash.
Notes and limits#
- The 5x5 matrix is fixed, including its labels and the score calculation.
- Review cadence is recorded, not enforced. No review task is created and no reminder is sent when a review falls due.
- A risk is scoped to a management system, not to a site or an area.