Risk management

Risk reports

Preview live reports, generate snapshots, and download PDFs for management and auditors.

RolesViewerEditorAdminRoute/risk/reportsShown toAll organizations

What it is

Risk reports turns the register, controls, corrective actions, and vendor records into five management-ready documents. Each report has a live preview that always reflects current data, and a Generate action that freezes a versioned snapshot you can download as a PDF. Snapshots are what you hand to a board, an auditor, or the external audit package builder.

Where to find it

Risk ManagementReports
Risk reports page with five report cards and the Generated Reports History tableRisk reports page with five report cards and the Generated Reports History table
The five report cards and the history of generated snapshots below them.

Key actions

Preview live data

Click any report card. A modal titled with the report name opens on Live Preview, rendered from the data as it stands right now. Nothing is stored by opening it.

The Risk Assessment Report modal showing the live preview with the executive summary and risk level distributionThe Risk Assessment Report modal showing the live preview with the executive summary and risk level distribution
A live preview. Generate to keep this version.

Generate a snapshot

Open the report and check the preview.
Click Generate. The toast "… generated successfully" confirms and a new row appears in Generated Reports History with the next version number.

Download the PDF

Click Download PDF in the modal, or "Download as PDF (.pdf)" on a row in the history table. Downloads work only for generated snapshots; the live preview refuses with "Can only download generated reports".

Delete a snapshot

Use Delete Report on the history row and confirm. This removes the snapshot and its PDF; the underlying risks are untouched.

Use a report as evidence

Each report card names the evidence item and controls it supports (table below), and those ids are printed in the PDF. Attaching the PDF to that evidence item is a manual step: download it, then upload it in the Evidence vault against the listed item. The external audit package builder is the exception: its Risk Reports step lets you pick a generated Risk Assessment and Risk Treatment snapshot directly, and can generate one in place.

Statuses and fields

ReportIDWhat it containsEvidence itemControls
Risk Assessment ReportNORU-REP-01Executive Summary, Risk Level Distribution, Risk Categories, Risk Register, RecommendationsE-RM-04RM-02
Risk Treatment Plan SummaryNORU-REP-02Treatment Plan Summary, Treatment Status Distribution, Risks with Treatment Plans, Risks Requiring Treatment Plans, RecommendationsE-RM-05RM-02, RM-08
Compliance Review SummaryNORU-REP-03Compliance Overview, Control Status Distribution, Controls by Domain, Control Implementation Details, Not Implemented Controls Requiring Attention, RecommendationsE-RM-07RM-04
Corrective Actions SummaryNORU-REP-04Corrective Actions Summary, Action Status Distribution, Overdue Actions Requiring Immediate Attention, Actions Due Within 7 Days, All Corrective Actions, RecommendationsE-RM-08RM-04, RM-09
Vendor Risk/Agreement SummaryNORU-REP-05Vendor Risk Overview, Risk Level Distribution, Agreement Status Distribution, High Risk Vendors Requiring Attention, Overdue Vendor Reviews, Complete Vendor Registry, RecommendationsE-TPM-19TPM-13, TPM-02

Cards carry a category badge (risk, compliance, or vendor). The history table lists Report Name, Type, Version, Generated Date, and Generated By ("System" when no user is recorded); it reads "No reports generated yet." until the first snapshot exists.

Tips and gotchas

Generate at governance points, not on a timer: before a management review, at quarter close, and when an auditor asks. Version numbers then map to meetings, which is what an auditor wants to see.

Live preview and snapshot can disagree. The preview is recomputed on every open; the snapshot is frozen. If a number looks wrong in a PDF, open the preview to see whether the data has since changed or the snapshot is what needs regenerating.

Deleting a snapshot is permanent. If the PDF was already shared with an auditor, keep the version they saw.

What Noru does not do

Generating a report does not create an evidence record, link the PDF to a control, or notify anyone. The evidence item and control ids are labels that tell you where the report belongs. The Recommendations section at the end of every report is generated from the counts in the report, not from a review of your program, and should be read as prompts rather than findings.

Last updated on