Skip to main content

Documentation Index

Fetch the complete documentation index at: https://help.dsalta.com/llms.txt

Use this file to discover all available pages before exploring further.

The Risk Register is where you document, assess, and monitor all identified risks to your organization. Compliance frameworks require you to maintain an active risk management process — this module provides the structure and audit trail.

What the risk register is for

Every organization faces risks — data breaches, service outages, vendor failures, regulatory changes. Compliance frameworks like SOC 2 (CC3.1–CC3.4), ISO 27001 (A.8), and HIPAA require you to formally identify these risks, assess their likelihood and impact, decide how to handle them, and track them over time. The Risk Register centralizes this process so your team can manage risks collaboratively and auditors can see that risk management is active and ongoing.

Viewing your risks

The risk register shows all identified risks with:
ColumnDescription
Risk NameShort description of the risk
CategoryOperational, Technical, Compliance, Financial, or Strategic
LikelihoodRare, Unlikely, Possible, Likely, or Almost Certain
ImpactNegligible, Minor, Moderate, Major, or Severe
Risk ScoreCalculated from likelihood × impact (Low, Medium, High, Critical)
TreatmentMitigate, Accept, Transfer, or Avoid
OwnerWho is responsible for managing this risk
StatusOpen, In Treatment, or Closed
Click any risk to view the full detail page with treatment plans, linked controls, and history.

Adding a new risk

  1. Navigate to Data Library → Risk Register in the sidebar.
  2. Click + New Risk.
  3. Enter the risk name and description — be specific about what could go wrong and what would be affected.
  4. Select the category, assess the likelihood and impact, and assign an owner.
  5. Choose a treatment strategy:
    • Mitigate — Implement controls to reduce the likelihood or impact
    • Accept — Acknowledge the risk and document the rationale for accepting it
    • Transfer — Shift the risk to a third party (e.g., insurance, outsourcing)
    • Avoid — Eliminate the activity that creates the risk
  6. If mitigating, document the specific controls or actions being taken.
  7. Click Save.

Risk scoring

DSALTA calculates a risk score by combining likelihood and impact. The scoring matrix produces four risk levels:
  • Low — Monitor periodically, no immediate action needed
  • Medium — Implement controls within your standard timeline
  • High — Prioritize remediation, assign an owner, set a target date
  • Critical — Immediate action required, escalate to leadership

Risk Library

DSALTA includes a pre-built risk library with common risks mapped to compliance frameworks. Instead of starting from scratch, browse the library and add relevant risks to your register with one click. Each pre-built risk includes suggested treatment strategies and control mappings.

Reviewing risks

Risks should be reviewed regularly — quarterly at minimum, or whenever your environment changes significantly. During a review:
  1. Assess whether the likelihood or impact has changed.
  2. Verify that treatment plans are being executed.
  3. Close risks that have been fully mitigated or are no longer relevant.
  4. Add new risks identified since the last review.
DSALTA logs every change to a risk (score updates, status changes, owner changes) with timestamps, creating the audit trail auditors expect to see.