Skip to main content

Development trial ยท sample information only

Record and assess a contextual risk

For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.

What you will achieve

Record a risk against the asset, project or other record it affects, then explain the current assessment and intended improvement.

Use a contextual Risks tab. This guide does not depend on the separately gated risk-portfolio page.

Before you start

Identify the affected record and agree who understands the risk. Gather the cause, potential consequences, existing safeguards and relevant evidence. Use the organisation's available likelihood and impact scales rather than inventing a numerical system.

Create the risk

  1. Open the affected record and its Risks tab.
  2. Check the existing risks for duplicates, then select Add Risk.
  3. Give the risk a clear title. Describe the Cause and Impact separately: what could happen, why and to whom?
  4. Select the appropriate category and any applicable assessment category shown.
  5. Choose Current Likelihood and Current Impact based on the present evidence. If recording target values, keep them distinct from today's position.
  6. Explain the assessment rationale. Record the mitigation plan, current status, tolerance and next review date where applicable.
  7. Select Create Risk, then reopen it from the parent record.

Record a later assessment

Use Record assessment when new evidence changes the position. Review the current likelihood and impact, target position, Assessment rationale and Effective at time.

Select the supporting evidence offered. If failed application checks are shown, address each relevant check with its disposition and rationale. Do not hide a failed safeguard by simply reducing a risk score.

Save the assessment and read it back in the history.

Check it worked

Confirm the risk remains linked to the intended parent. Compare current and target positions and inspect the assessment timestamp and rationale. Make sure the planned mitigation has an owner and actionable follow-up, not only a paragraph of intent.

If something goes wrong

Problem Next action
Add Risk is missing Check the parent feature and risk-creation permission
A concurrent-update warning appears Use Load latest assessment, compare the new evidence and reassess
Evidence does not support a lower score Keep the supported position and record the missing work
The same risk affects another record Review the available relationship controls rather than creating conflicting copies

Human judgement matters

A target score is an aspiration, not a measured result. Acceptance of a risk is a separate accountable decision, not another word for assessment or mitigation.

What next?

For the wider context, see Manage risks and incidents.

Link the relevant controls and tasks, then review the risk when evidence or circumstances change, not only when the scheduled date arrives.

Get help

Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.

Was this article helpful?