Skip to main content

Development trial ยท sample information only

Manage risks and incidents

What you'll achieve

You will record a risk or incident, assign accountable owners, link supporting context and keep treatment or response evidence separate from optimistic status changes.

Who this is for

This guide is for an Organisation Collaborator with the permission or assigned action described below. If the navigation or action is missing, check the selected organisation, effective account level, feature state and role before assuming the product is unavailable.

Before you start

Check that you have:

  • A factual description and source evidence.
  • The correct organisation and affected records.
  • An accountable owner and escalation route.

1. Choose risk or incident

For a risk, open the relevant asset, policy, supplier relationship, project or other governed record and choose its Risks tab. The separate organisation-wide Risks portfolio is not part of the current active feature set. Use Incidents for an event that has occurred and needs coordinated response. Link the records when an incident changes the risk assessment.

2. Record facts first

Capture what is known, the source, affected scope and timing. Mark uncertainty openly instead of filling gaps with assumptions.

3. Assign accountability

Name the accountable owner and responsible contributors. Use the incident team or RACI surface where available; do not rely on a comment mention as ownership.

4. Assess and plan

For a risk, record assessment and treatment separately. For an incident, use the response, containment and communication workspaces. Link tasks, controls and evidence to the source record.

5. Reassess from evidence

Completing actions does not automatically reduce risk. Record a new assessment or incident outcome only when evidence supports the changed position.

Check it worked

  • The record distinguishes fact, uncertainty, impact and decision.
  • Owners and due actions are visible.
  • Linked evidence supports the current assessment or incident state.

If something goes wrong

What you see What to do
The event may be a reportable breach Escalate immediately through the privacy and incident process; do not wait for a perfect record.
No owner is available Escalate rather than assigning a name without agreement.
The score changed after tasks closed Check that a new evidence-based assessment was recorded.

Human judgement, security and privacy

Risk scoring and incident classification support a decision; they are not the decision. Regulatory, legal and communications judgements need the appropriate human owner.

What's next

Review the related controls and create a dated follow-up assessment after treatment or recovery evidence is available.

Need help?

Use your organisation's approved Backstory support route. Include the organisation, page and action that failed, but do not include passwords, invitation links, secret keys or unnecessary personal or confidential content.

Was this article helpful?