Core workflows

Build a defensible risk register

Capture risks, score them consistently, treat them, and export a register your auditor and your biggest customer will both accept.

8 min read · updated July 2026

Step-by-step

  1. 1

    Open the Risk Register

    From the sidebar, go to Risks. If you're new, click 'Seed sample risks' to load a starter set aligned to ISO 27001 Annex A — you can edit or delete them freely.

    The risk register with heatmap, filters and one-click seed data.
    The risk register with heatmap, filters and one-click seed data.
  2. 2

    Add a risk

    Click 'New risk'. Give it a short, plain-language name (e.g. 'Loss of laptop with client data'). Pick a category, an owner, and set inherent likelihood and impact on the 1–5 scale. The heatmap updates instantly.

  3. 3

    Choose a treatment

    Set the treatment (Mitigate, Accept, Transfer, Avoid) and describe the specific action. Link the controls that reduce the risk — this is the join between your register and your Statement of Applicability.

  4. 4

    Attach evidence

    In the Evidence tab of the risk drawer, upload the artifact that proves the treatment works — an MFA report, a signed policy, a backup test. Auditors accept the same file that buyers accept.

    Upload once, reuse across risks, controls, audits and Trust Center.
    Upload once, reuse across risks, controls, audits and Trust Center.
  5. 5

    Set the review cadence

    Every risk needs a review date. High risks: quarterly. Everything else: annually. The register colour-codes anything overdue so nothing slips.

  6. 6

    Export for auditors and buyers

    Use Export → PDF for the auditor's file, or CSV for buyer questionnaires. Both are timestamped and carry your workspace branding.

    Export for auditors and buyers
What corporate buyers look for
  • "Do you maintain a documented risk register reviewed at least annually?"
  • "Are risks scored with a defined methodology (likelihood × impact)?"
  • "Are risk owners named individuals, not teams or job titles?"
  • "Can you show treatment status and residual risk for the top ten risks?"

What this workflow produces: A signed, dated risk register PDF plus the last review record — attach both to any SIG-Lite or CAIQ response.

FAQ

Do I need one register per standard?

No. ISO-STANDARD.app maps each risk to every applicable standard (27001, 9001, 42001, SOC 2, GDPR) so one register serves them all.

What scoring scale should I use?

Use the built-in 1–5 likelihood × 1–5 impact scale. It matches ISO 31000 and the risk methodologies most enterprise buyers expect.

Can I bulk-import from a spreadsheet?

Yes — Import → CSV in the Risks page. Column headers match the export format so round-tripping is safe.

How do I show residual risk?

Set residual likelihood and impact after treatment. The register stores both inherent and residual scores and shows movement in the heatmap.

Who should own a risk?

A named individual with authority to act — not 'IT' or 'the CTO'. Buyers and auditors both flag generic ownership as a weakness.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation