App navigation: Risk → Risk Register → [open a risk] → Response
A risk response defines how your organization will handle an identified risk – whether by mitigating, accepting, avoiding, or transferring it.
Step 1 – Open a Risk #
- Navigate to Risk → Risk Register.
- Find the risk you want to respond to and open its detail view.
Step 2 – Create a Response #
- In the risk detail view, navigate to the Response section and select + Create.
- The Risk Response wizard opens with the following steps.
Response Strategy #
- Select the Response Strategy:
- Accept – formally acknowledge the risk without further action.
- Avoid – eliminate the activity or condition that creates the risk.
- Mitigate – implement controls to reduce the likelihood or impact.
- Transfer – shift the risk to a third party (e.g., via insurance or a vendor contract).
- Link a Treatment Plan from the predefined plans in Company Setup.
Treatment Plan #
- Describe the Approach and Supporting Rationale for the selected strategy.
- Set the Response Timeline and Due Date.
- Link related Assets, Policies, and Controls to the response.
Residual Risk(s) #
- After defining the response, document the expected Residual Risk – the remaining risk after the response is implemented.
- Set the residual Impact and Probability scores.
[Screenshot: Risk Response wizard showing the Response Strategy step]
Step 3 – Review and Approve #
- Submit the response for review. Assigned reviewers and approvers are notified.
- Once approved, the response is linked to the risk record and the Response Status column in the Risk Register updates accordingly.
