What the register shows
The register is a flat list/table, one row per risk. A header summarises your totals and the split of risks across their statuses, with a By Group breakdown.
Each row displays:
Risk: its name
Scope: the group or committee the risk belongs to
Source: Adopted (from the scenario library) or Custom, with the framework name
Inherent: the rating before controls
Residual: the rating after controls
Status: its current lifecycle state (Draft → Identified → Assessing → Treating → Monitoring → Closed)
Open any row to see the risk's full detail and its assessment.
Searching, filtering, and sorting
Use the search bar to find a risk by name, and the Filter and Sort controls to narrow and order the list (for example by status, source, or hierarchy level).
Adding risks
There are two routes into the register:
Explore the scenario library: adopt pre-built scenarios mapped to your active frameworks. See Adopting risks from the scenario library.
Create a custom risk: a new risk with its own assessment. See Conducting a risk assessment.
Multi-level identification
Risks are scoped to a group when they're created: a team, site, division, or the whole organisation. Group-scoped risks roll up into the organisation-wide register, so an organisation admin sees everything while a group-scoped manager sees their group's risks.
Linking risks to other work
A risk in the register can be linked to:
Incidents that materialised the risk
Investigations that found contributing factors
Controls that mitigate it
Evidence (Records) that supports the rating
Consultations that informed the assessment
These links surface on each risk's detail page and feed the audit trail.
