Risk management

Create and edit risks

Assess a risk with the full form, generate treatment suggestions, and record residual risk.

RolesViewerEditorAdminRoute/risk/register/[id]Shown toAll organizations

What it is

The quick-create dialog on the register captures a title and four chips. The full create page and the detail page are where a risk becomes useful: an owner and assignee, a due date, departments, a mitigation strategy and contingency plan, a treatment plan with post-treatment scores, and links to controls, an asset, policies, and findings. AI can draft treatment suggestions for you; scoring stays manual.

Where to find it

Risk ManagementRisk RegisterAdd risk

The full form lives at /risk/register/create; clicking any row in the register opens /risk/register/[id].

The Create Risk page with the Risk and Advanced tabs and the treatment plan sectionThe Create Risk page with the Risk and Advanced tabs and the treatment plan section
The create page. The Advanced tab holds departments and the free-text plans.

Key actions

Create a risk with the full form

Open /risk/register/create. The breadcrumb reads Create Risk and the form area Risk Details.
On the Risk tab, fill Title, Description, Status, Category, Likelihood, and Impact.
Set Owner (Optional), Assignee (Optional), and Due Date (Optional). The owner is accountable; the assignee does the work.
On the Advanced tab, add Mitigation Strategy (Optional), Contingency Plan (Optional), Additional Notes (Optional), and Departments (Optional).
Save. Controls cannot be linked until the risk exists ("Please create the risk first, then you can link controls").

Department chips are IT, Security, Finance, HR, Legal, Operations, Sales, Marketing, Customer Support, Executive, Procurement, Compliance, Risk Management, and Internal Audit.

Generate treatment suggestions with AI

In the Risk Treatment Plan section, click Generate. The button reads "Generating AI-powered treatments..." while it runs.
Review each suggested action. Edit the text, set Post-Treatment Likelihood and Post-Treatment Impact, and assign an Owner and Due Date.
Delete any suggestion that does not fit. Nothing is saved until you save the risk.

Add a treatment manually

Each treatment row has Action, Post-Treatment Likelihood, Post-Treatment Impact, Owner, Due Date, Status, and Evidence Requirement ID (Optional) ("e.g., E-SG-52"). The evidence id ties the treatment to the evidence item an auditor will ask for.

Record the residual assessment

Residual risk is not a field you type. It is derived from the treatments: fill in post-treatment likelihood and impact on each one and the residual level updates. Leaving them empty applies a flat reduction, which is rarely what you mean.

Risk detail page with Risk assessment, Properties, Asset, Controls, and Policies panels and the treatments listRisk detail page with Risk assessment, Properties, Asset, Controls, and Policies panels and the treatments list
The detail page. Links are added from the side panels; findings are linked from the finding side.
RelationshipWhere
ControlsControls panel ("Link controls to track coverage.")
AssetAsset panel ("Link an asset from the register."); one asset per risk
PoliciesPolicies panel
FindingsFrom a finding: Link Risk to Finding, or bulk Link Findings to Risk on the findings list

On the detail page the title and description edit inline, Risk assessment holds Likelihood and Impact, and Properties holds Status, Category, Owner, Assignee, and Due date. The treatments list starts empty ("No treatments yet. Generate suggestions or add one manually."); each entry shows its action, Likelihood, Impact, Status, and evidence id.

Delete a risk

Click Delete risk in the header and confirm in the Delete Risk dialog. Treatments go with it; linked findings, controls, and the asset are not deleted.

Statuses and fields

FieldWhat to enter
Title, DescriptionA scenario, not a category: "Laptop with customer data lost in transit", not "Data loss"
StatusWhere the risk is in its life; see the register
Likelihood, ImpactThe inherent assessment, before treatments
Owner, AssigneeAccountable member and the person doing the work
Due DateWhen the treatment plan should be complete
Mitigation StrategyWhat you will do to reduce likelihood or impact
Contingency PlanWhat you will do if it happens anyway
DepartmentsWho is affected; used for filtering and reporting

Treatment statuses:

StatusMeaningSet by
PlannedplannedAgreed, not started.You
In Progressin_progressBeing implemented.You
CompletedcompletedDone; evidence should exist.You
CancelledcancelledDropped; it still counts toward the residual calculation.You

Tips and gotchas

Write titles as scenarios with a cause and a consequence. Generated treatments are only as good as the description they read, and auditors read the title first.

Generated treatments are suggestions drafted from the risk text and your organization context. They are not scored, not validated against your controls, and not saved until you save the risk. Review every one.

Create first, link second. Controls, the asset, and policies can only be attached once the risk has an id, which is why the create page shows the "create the risk first" notice under Linked Controls.

What Noru does not do

There is no AI-assisted scoring. Likelihood and impact are whatever a person entered; AI only drafts treatment text. Noru does not chase treatment owners or move a treatment to Completed when its due date passes, and it does not verify that the evidence id you typed exists. Change history is recorded but there is no history panel on this page; read it through the MCP server if you need it.

Last updated on