Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

4
  • Signing In
  • Understanding the Dashboard
  • Navigation
  • Roles and Permissions

Common Workflows

9
  • Create and Approve a Policy
  • Complete an Assessment
  • Upload Artifacts
  • Review AI Artifact Analysis
  • Record and Assess a Risk
  • Create a Risk Response
  • Test a Control
  • Import Vulnerabilities
  • Complete a Vendor Assessment

Governance

6
  • Policy Center
  • Document Inventory
  • Third-Party Inventory
  • Company Setup
  • Process
  • Exception

Risk

5
  • Risk Register
  • Controls
  • Vulnerabilities
  • Assets
  • Threats

Compliance

3
  • Assessments
  • Cross Reference
  • Audit Inventory

Administration

5
  • Reports
  • Users and Roles
  • Framework Configuration
  • Notifications
  • Application Settings

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Common Workflows
  • Create a Risk Response

Create a Risk Response

1 min read

App navigation: Risk → Risk Register → [open a risk] → Response

A risk response defines how your organization will handle an identified risk – whether by mitigating, accepting, avoiding, or transferring it.

Step 1 – Open a Risk #

  1. Navigate to Risk → Risk Register.
  2. Find the risk you want to respond to and open its detail view.

Step 2 – Create a Response #

  1. In the risk detail view, navigate to the Response section and select + Create.
  2. The Risk Response wizard opens with the following steps.

Response Strategy #

  • Select the Response Strategy:
    • Accept – formally acknowledge the risk without further action.
    • Avoid – eliminate the activity or condition that creates the risk.
    • Mitigate – implement controls to reduce the likelihood or impact.
    • Transfer – shift the risk to a third party (e.g., via insurance or a vendor contract).
  • Link a Treatment Plan from the predefined plans in Company Setup.

Treatment Plan #

  • Describe the Approach and Supporting Rationale for the selected strategy.
  • Set the Response Timeline and Due Date.
  • Link related Assets, Policies, and Controls to the response.

Residual Risk(s) #

  • After defining the response, document the expected Residual Risk – the remaining risk after the response is implemented.
  • Set the residual Impact and Probability scores.

[Screenshot: Risk Response wizard showing the Response Strategy step]

Step 3 – Review and Approve #

  1. Submit the response for review. Assigned reviewers and approvers are notified.
  2. Once approved, the response is linked to the risk record and the Response Status column in the Risk Register updates accordingly.
Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Record and Assess a RiskTest a Control
Table of Contents
  • Step 1 – Open a Risk
  • Step 2 – Create a Response
    • Response Strategy
    • Treatment Plan
    • Residual Risk(s)
  • Step 3 – Review and Approve

© 2026 ClearGRC User Guide

  • Documentation