For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Record a risk against the asset, project or other record it affects, then explain the current assessment and intended improvement.
Use a contextual Risks tab. This guide does not depend on the separately gated risk-portfolio page.
Before you start
Identify the affected record and agree who understands the risk. Gather the cause, potential consequences, existing safeguards and relevant evidence. Use the organisation's available likelihood and impact scales rather than inventing a numerical system.
Create the risk
- Open the affected record and its Risks tab.
- Check the existing risks for duplicates, then select Add Risk.
- Give the risk a clear title. Describe the Cause and Impact separately: what could happen, why and to whom?
- Select the appropriate category and any applicable assessment category shown.
- Choose Current Likelihood and Current Impact based on the present evidence. If recording target values, keep them distinct from today's position.
- Explain the assessment rationale. Record the mitigation plan, current status, tolerance and next review date where applicable.
- Select Create Risk, then reopen it from the parent record.
Record a later assessment
Use Record assessment when new evidence changes the position. Review the current likelihood and impact, target position, Assessment rationale and Effective at time.
Select the supporting evidence offered. If failed application checks are shown, address each relevant check with its disposition and rationale. Do not hide a failed safeguard by simply reducing a risk score.
Save the assessment and read it back in the history.
Check it worked
Confirm the risk remains linked to the intended parent. Compare current and target positions and inspect the assessment timestamp and rationale. Make sure the planned mitigation has an owner and actionable follow-up, not only a paragraph of intent.
If something goes wrong
| Problem | Next action |
|---|---|
| Add Risk is missing | Check the parent feature and risk-creation permission |
| A concurrent-update warning appears | Use Load latest assessment, compare the new evidence and reassess |
| Evidence does not support a lower score | Keep the supported position and record the missing work |
| The same risk affects another record | Review the available relationship controls rather than creating conflicting copies |
Human judgement matters
A target score is an aspiration, not a measured result. Acceptance of a risk is a separate accountable decision, not another word for assessment or mitigation.
What next?
For the wider context, see Manage risks and incidents.
Link the relevant controls and tasks, then review the risk when evidence or circumstances change, not only when the scheduled date arrives.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.