Complete a Risk Lifecycle
This tutorial walks you through the full lifecycle of a risk — from creation to closure.
1. Create a manual risk
Section titled “1. Create a manual risk”Click the Add Risk button in the Risk Register. A new risk record appears at the top of your register. Populate the Title and Description fields with enough detail for accurate scoring. See Creating Risks for all creation methods.
2. Score with AI
Section titled “2. Score with AI”Click AI Suggest Score to have the platform assess the risk. The AI will:
- Assign Likelihood and Impact ratings.
- Assign relevant Threat Objectives with appropriate correlation levels.
- Provide reasoning in the Comments field.
Review the proposed scores and reasoning. Adjust if needed. See Scoring Risks for details on how AI scoring works.
3. Assign remediation
Section titled “3. Assign remediation”If your organization has the Jira integration configured, create a ticket directly from the risk detail view. Otherwise, use the Assigned To field to assign the risk to a team member and document the remediation task in the Remediation Task field.
4. Track progress
Section titled “4. Track progress”As remediation work progresses, move the risk status through the lifecycle:
- Remediation — Work is underway.
- Closure Proposed — Remediation is complete and awaiting validation.
See Risk Fields — Status for all status definitions.
5. Close the risk
Section titled “5. Close the risk”Write a Control Statement documenting what was done to address the risk. Set the status to Closed. See Risk Fields — Control Statement for guidance on writing effective control statements.