Flagging risks in assessments

Flag risks while completing an assessment, review risks suggested by Mira AI with their evidence, and label risks so the right teams can act on them.

Identifying risks is the goal of most assessments. In MineOS, you flag risks directly inside the assessment you're completing, either by choosing from your risk catalog or by reviewing risks suggested by Mira AI from your answers and inventory. Every risk you flag is added to your risk registry automatically and linked to the systems it affects.

What a flagged risk includes

DetailWhat it means
RiskThe risk type, chosen from your risk catalog
DescriptionWhat the risk means
LabelsCategories such as security, privacy, legal or AI, so each team can find its risks
Inherent risk levelIts severity before mitigations
MitigationsThe controls in place or planned
Residual risk levelWhat remains after mitigations
EvidenceWhy the risk was flagged, for risks suggested by Mira

Before you start: add a risk question

Risks are flagged through a Risk question in the assessment. If the assessment's template doesn't include one, you won't be able to add risks to it.

To add a risk question to a template:

  1. Open the template in the template editor. See Building Templates.
  2. In the section where you want to capture risks, add a new question.
  3. Set the question type to Risk.
  4. Save the template.

Assessments created from the template from then on will include the risk question. Changes to a template don't apply to assessments already created from it. To flag risks in an existing assessment, add a Risk question directly in that assessment instead.

Flag a risk

  1. Open the assessment.
  2. Go to the Risk question.
  3. Select a risk from your risk catalog.
  4. Set the inherent risk level.
  5. Add any mitigations already in place, and set the residual risk level.
  6. Click Save.

The risk now appears in your risk registry, and on the Risks tab of each data source linked to the assessment.

Review suggested risks

MineOS suggests risks based on the assessment's template type, your answers and the connected inventory. For example, you may see suggested risks when an assessment involves sensitive data, international data transfers, or a vendor with a weak security posture.

Review each suggestion, then add it or dismiss it. Suggestions are a starting point. Make sure each risk you add reflects your organization's actual exposure.

Choosing the right risk level

LevelWhen to use it
Inherent riskRate the risk as if no controls were in place. Consider how sensitive the data is, how much of it there is, and the impact if something went wrong.
Residual riskRate what remains once your mitigations are in place, such as encryption, access restrictions or contractual safeguards.

If you don't have mitigations yet, you can add them later from the assessment or the risk registry, and update the residual risk then.

Tips

  • Add the Risk question to your templates once, so every new assessment is ready for risks.
  • Link the right data sources first. Flagged risks appear on the data sources linked to the assessment, and suggestions draw on them. See Linking assessments to other entities.
  • Use your organization's custom risks for recurring concerns, so the same issue is described the same way across assessments. See Risk registry and catalog.
  • Record existing mitigations when you flag a risk, so the residual risk is accurate from the start.

Related articles


Did this page help you?