Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

4
  • Signing In
  • Understanding the Dashboard
  • Navigation
  • Roles and Permissions

Common Workflows

9
  • Create and Approve a Policy
  • Complete an Assessment
  • Upload Artifacts
  • Review AI Artifact Analysis
  • Record and Assess a Risk
  • Create a Risk Response
  • Test a Control
  • Import Vulnerabilities
  • Complete a Vendor Assessment

Governance

6
  • Policy Center
  • Document Inventory
  • Third-Party Inventory
  • Company Setup
  • Process
  • Exception

Risk

5
  • Risk Register
  • Controls
  • Vulnerabilities
  • Assets
  • Threats

Compliance

3
  • Assessments
  • Cross Reference
  • Audit Inventory

Administration

5
  • Reports
  • Users and Roles
  • Framework Configuration
  • Notifications
  • Application Settings

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Risk
  • Risk Register

Risk Register

3 min read

App navigation: Risk → Risk Register

The Risk Register is the central record of all formally identified and assessed risks in your organization. It uses the ATVEC methodology (Asset-Threat-Vulnerability-Exploit-Control) to build risks from your existing inventories, providing an auditable chain of evidence for every risk score.

Screen Layout #

Navigate to Risk → Risk Register to open the Risk Summary screen. It shows: Total Risks, breakdown by Risk Level, breakdown by Status (Draft, Under Review, Active, Awaiting Approval), and a Review Due panel. The inventory grid includes: Actions, Status, Treatment Status, Response Status, Name, Residual Risks, Severity, and Owner.

[Screenshot: Risk Register screen showing summary panel and grid]

Risk Lifecycle #

Status Meaning
Draft Risk identified but not yet submitted for review.
Under Review Submitted to reviewers.
Awaiting Approval Reviews complete, pending approver sign-off.
Active Approved and formally tracked in the register.

Recording a Risk #

Prerequisites #

  • At least one Asset, Threat, and Vulnerability should exist before building an ATVEC-mapped risk (recommended for full traceability).
  • Owner, Reviewer, and Approver users must be configured.

Step 1 – Open the Create Risk Wizard #

  1. Navigate to Risk → Risk Register.
  2. Select + on the toolbar to open the Create Risk wizard.

Step 2 – Identification #

  • Enter the Title (required) and Description.
  • Set Source (Internal Audit, Manual Entry, TPRA, Residual Risk, or Others), Identified By, and Identified On date.
  • Set Risk Classification (Inherent or Residual).
  • Assign Owner, Reviewer(s), and Approver(s).

[Screenshot: Risk wizard – Identification step]

Step 3 – ATVEC Mapping #

  • Link the risk to specific Assets, Threats, Vulnerabilities, Exploits, and Controls from your existing inventories.
  • This creates an auditable chain of evidence for how the risk was derived.
  • Use the Add Threat and Add Exploit toolbar buttons to link additional items.

Step 4 – Evaluation #

  • Set Impact and Probability scores to calculate the overall risk severity.
  • The risk score is derived from the Risk Matrix configured in Company Setup → Risk Profile.
  • Select Complete to submit the risk for review.

Step 5 – Review and Approve #

  1. The risk moves to Under Review. Assigned reviewers submit their decisions.
  2. Approvers provide final sign-off. The risk status changes to Active.

Creating a Risk Response #

For each active risk, one or more responses can be created to define how the organization will handle it.

Step 1 – Open the Response Wizard #

  1. Open a risk from the Risk Register.
  2. Navigate to the Response section and select + Create.

Step 2 – Response Strategy #

  • Select the Response Strategy:
    • Accept – formally acknowledge the risk without further action.
    • Avoid – eliminate the activity or condition that creates the risk.
    • Mitigate – implement controls to reduce the likelihood or impact.
    • Transfer – shift the risk to a third party (e.g., via insurance or a vendor contract).
  • Link a Treatment Plan from the predefined plans in Company Setup.

Step 3 – Treatment Plan #

  • Describe the Approach and Supporting Rationale.
  • Set the Response Timeline and Due Date.
  • Link related Assets, Policies, and Controls to the response.

Step 4 – Residual Risk(s) #

  • Document the expected Residual Risk – the remaining exposure after the response is implemented.
  • Set the residual Impact and Probability scores.

Step 5 – Review and Approve the Response #

  1. Submit the response for review. Assigned reviewers and approvers are notified.
  2. Once approved, the Response Status column in the Risk Register updates accordingly.

Residual Risk #

After a risk response is implemented, the Residual Risk column reflects the remaining risk exposure. Residual risks can themselves be tracked as new risk entries (Source: Residual Risk) for complete traceability.

Tip: The Top 5 Highest Risks table and Active Risks trend chart on the GRC Executive Dashboard are populated from Risk Register data. Keeping risks reviewed and up to date ensures the dashboard reflects your current exposure accurately.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
ThreatsControls
Table of Contents
  • Screen Layout
  • Risk Lifecycle
  • Recording a Risk
    • Prerequisites
    • Step 1 – Open the Create Risk Wizard
    • Step 2 – Identification
    • Step 3 – ATVEC Mapping
    • Step 4 – Evaluation
    • Step 5 – Review and Approve
  • Creating a Risk Response
    • Step 1 – Open the Response Wizard
    • Step 2 – Response Strategy
    • Step 3 – Treatment Plan
    • Step 4 – Residual Risk(s)
    • Step 5 – Review and Approve the Response
  • Residual Risk

© 2026 ClearGRC User Guide

  • Documentation