Skip to content

Complete a Risk Lifecycle

This tutorial walks you through the full lifecycle of a risk — from creation to closure.

Click the Add Risk button in the Risk Register. A new risk record appears at the top of your register. Populate the Title and Description fields with enough detail for accurate scoring. See Creating Risks for all creation methods.

Click AI Suggest Score to have the platform assess the risk. The AI will:

  • Assign Likelihood and Impact ratings.
  • Assign relevant Threat Objectives with appropriate correlation levels.
  • Provide reasoning in the Comments field.

Review the proposed scores and reasoning. Adjust if needed. See Scoring Risks for details on how AI scoring works.

If your organization has the Jira integration configured, create a ticket directly from the risk detail view. Otherwise, use the Assigned To field to assign the risk to a team member and document the remediation task in the Remediation Task field.

As remediation work progresses, move the risk status through the lifecycle:

  • Remediation — Work is underway.
  • Closure Proposed — Remediation is complete and awaiting validation.

See Risk Fields — Status for all status definitions.

Write a Control Statement documenting what was done to address the risk. Set the status to Closed. See Risk Fields — Control Statement for guidance on writing effective control statements.