What the risk register is for
Every organization faces risks — data breaches, service outages, vendor failures, regulatory changes. Compliance frameworks like SOC 2 (CC3.1–CC3.4), ISO 27001 (A.8), and HIPAA require you to formally identify these risks, assess their likelihood and impact, decide how to handle them, and track them over time. The Risk Register centralizes this process so your team can manage risks collaboratively and auditors can see that risk management is active and ongoing.Viewing your risks
The risk register shows all identified risks with:
Click any risk to open its detail panel, which has Risk Score, Controls, and Treatment tabs, plus an Owner row you can assign from.
Adding a new risk
- Navigate to Data Library → Risk in the sidebar.
- Click New Register. A Risk Scenario sheet opens.
- Fill in Risk Scenario Name and Description — be specific about what could go wrong and what would be affected.
- Under Risk Scenario Details, enter an Estimated Cost in USD.
- On the Risk Score tab, score likelihood and impact under both Inherent Risk Score and Residual Risk Score.
- On the Treatment Plan tab, pick one option under Risk Treatment Options:
- Mitigate — “Identify controls to put in place or tasks to be done that will reduce the risk score.”
- Transfer — “Move risk outside of your organization’s set of responsibilities.”
- Avoid — “Stop doing the activity which is causing the risk to your organization and its assets.”
- Accept — “Decide to live with the risk and take no further actions.”
- Click Save. Close discards the sheet.
Risk scoring
Likelihood and impact are each scored from 1 to 5 on a segmented rating control, labeled:- 1 Very low impact
- 2 Low impact
- 3 Medium impact
- 4 High impact
- 5 Very high impact
Risk Library
The second tab, Risk Library, is a pre-built catalog of common risks. It lists each one with Risk Scenario, Category, and a Status of Active or Inactive. Click the + button on an inactive row to add that risk to your register. DSALTA creates the risk record, sets its treatment plan to Mitigate, and links the controls the library entry maps to. Category exists on library entries only. Once a risk is in your register it has no category field, which is why the register has no Category column.Reviewing risks
Risks should be reviewed regularly — quarterly at minimum, or whenever your environment changes significantly. During a review:- Assess whether the likelihood or impact has changed, and re-score the risk if so.
- Verify that treatment plans are being executed and that the linked controls are passing.
- Delete risks that are no longer relevant.
- Add new risks identified since the last review.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)