Build a defensible risk register
Capture risks, score them consistently, treat them, and export a register your auditor and your biggest customer will both accept.
Step-by-step
- 1
Open the Risk Register
From the sidebar, go to Risks. If you're new, click 'Seed sample risks' to load a starter set aligned to ISO 27001 Annex A — you can edit or delete them freely.

The risk register with heatmap, filters and one-click seed data. - 2
Add a risk
Click 'New risk'. Give it a short, plain-language name (e.g. 'Loss of laptop with client data'). Pick a category, an owner, and set inherent likelihood and impact on the 1–5 scale. The heatmap updates instantly.
- 3
Choose a treatment
Set the treatment (Mitigate, Accept, Transfer, Avoid) and describe the specific action. Link the controls that reduce the risk — this is the join between your register and your Statement of Applicability.
- 4
Attach evidence
In the Evidence tab of the risk drawer, upload the artifact that proves the treatment works — an MFA report, a signed policy, a backup test. Auditors accept the same file that buyers accept.

Upload once, reuse across risks, controls, audits and Trust Center. - 5
Set the review cadence
Every risk needs a review date. High risks: quarterly. Everything else: annually. The register colour-codes anything overdue so nothing slips.
- 6
Export for auditors and buyers
Use Export → PDF for the auditor's file, or CSV for buyer questionnaires. Both are timestamped and carry your workspace branding.

- "Do you maintain a documented risk register reviewed at least annually?"
- "Are risks scored with a defined methodology (likelihood × impact)?"
- "Are risk owners named individuals, not teams or job titles?"
- "Can you show treatment status and residual risk for the top ten risks?"
What this workflow produces: A signed, dated risk register PDF plus the last review record — attach both to any SIG-Lite or CAIQ response.
FAQ
No. ISO-STANDARD.app maps each risk to every applicable standard (27001, 9001, 42001, SOC 2, GDPR) so one register serves them all.
Use the built-in 1–5 likelihood × 1–5 impact scale. It matches ISO 31000 and the risk methodologies most enterprise buyers expect.
Yes — Import → CSV in the Risks page. Column headers match the export format so round-tripping is safe.
Set residual likelihood and impact after treatment. The register stores both inherent and residual scores and shows movement in the heatmap.
A named individual with authority to act — not 'IT' or 'the CTO'. Buyers and auditors both flag generic ownership as a weakness.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
