Risks
The risk register is where everything the platform observes comes together as decisions. Risks arrive two ways: your team raises them by hand, and the rest of SolveGRC sends them in — cloud posture findings promoted into register entries, vendor escalations from TPRM, gap signals from your framework assessments, and external drift picked up by continuous monitoring. Each risk carries a lifecycle status, an owner, a treatment plan, links to the controls that mitigate it, and — where you add a quantification profile — a dollar exposure figure with an explainable breakdown.
This guide covers the register in three moves, one page each.
The lifecycle at a glance
- Raise and treat. Create a risk, classify it, score it, and plan its treatment.
- Promote from signals. Turn what the platform observes — findings, gaps, escalations — into register entries with their provenance intact.
- Quantify in dollars. Add a quant profile so a risk reads as a dollar range, not just a color.
A risk moves through six statuses: Draft → Open → Mitigating → Monitoring → Closed, with Reopened for a closed risk that recurs. Mitigating means treatment actions are in progress; Monitoring means the risk has been accepted or transferred and is being watched rather than worked. Each risk also carries a review date, and the dashboard counts the reviews coming due in the next seven days so nothing goes stale quietly.
How this connects
The register consumes from most of the platform and feeds the layers above it:
- In: risks you raise, promoted posture and cloud findings, vendor risk escalations from TPRM, and framework gap signals.
- Out: the risk register with treatment plans, and quantified exposure in dollars where profiled.
- Feeds: executive reporting, board-level portfolio views, and control mitigation links back into your control register.
One automation runs through it all: Monte-Carlo simulation turns profiled risks into dollar ranges, on the same engine for every risk regardless of where it came from.
Before you start
You can run the register entirely by hand, but its value compounds when the rest of the platform feeds it. Connected cloud accounts, active vendor assessments, and activated frameworks all generate the signals that keep the register honest about what is actually happening.
You will also need:
- Access to the module. Risks appears in the sidebar only if your role has read permission for it, and creating risks or acceptances needs create permission. If you do not see it, ask an administrator.
- An active subscription. The module is gated behind your plan.
If you are new to the module, the page header offers a guided tour, Track and treat a risk, that walks through creating, classifying, linking, and treating a risk in place.