Risk management
Learn how MineOS helps you identify, evaluate and mitigate risks across your privacy, vendor and AI assessments.
Risk management in MineOS connects every risk to the assessment that identified it and the systems it affects. Risks are flagged while you complete privacy, vendor and AI assessments, then tracked in a single registry through to mitigation, so you can see your organization's overall risk position and decide where to act first.
How risks are tracked in MineOS
Each risk moves through a simple lifecycle:
- Identified. A risk is flagged while completing an assessment, based on factors such as the data types involved, international transfers, consent, access, security or anything you deem a risk.
- Evaluated. The risk is given an inherent risk level, which is its severity before any controls are applied.
- Mitigated. Your team records the mitigations in place or planned, such as encryption, data minimization or access restrictions.
- Reassessed. The residual risk level shows what remains after mitigation. Your team decides whether that's acceptable.
| Term | What it means |
|---|---|
| Inherent risk | The risk level before mitigations are applied |
| Mitigation | A control or action that reduces the risk |
| Residual risk | The risk level that remains after mitigations |
| Risk catalog | The list of risk types available across all your assessments |
| Risk registry | The central list of every risk identified in your assessments |
This approach follows common risk management practice, such as ISO 31000 and the NIST frameworks, so it fits alongside your existing risk program.
Risk management features
| Feature | What it does | Learn more |
|---|---|---|
| Flagging risks in assessments | Add risks while completing an assessment, with suggestions based on your answers and inventory | Flagging risks in assessments |
| Risk registry | Review and manage every risk in one place, and track mitigations | Risk registry and catalog |
| Risk catalog | Standardize the risk types your organization uses | Risk registry and catalog |
| Business impact analysis | Identify which systems are most critical to your business | Running a business impact analysis |
Where risks appear
- In the risk registry: under Governance, select Risks.
- On a data source page: the Risks tab lists the risks tied to that system, with their inherent risk level, mitigations and source assessment.
- In the assessment itself: risks stay attached to the assessment that identified them.
Updated about 1 hour ago
Did this page help you?
