Risk management

Learn how MineOS helps you identify, evaluate and mitigate risks across your privacy, vendor and AI assessments.

Risk management in MineOS connects every risk to the assessment that identified it and the systems it affects. Risks are flagged while you complete privacy, vendor and AI assessments, then tracked in a single registry through to mitigation, so you can see your organization's overall risk position and decide where to act first.

How risks are tracked in MineOS

Each risk moves through a simple lifecycle:

  1. Identified. A risk is flagged while completing an assessment, based on factors such as the data types involved, international transfers, consent, access, security or anything you deem a risk.
  2. Evaluated. The risk is given an inherent risk level, which is its severity before any controls are applied.
  3. Mitigated. Your team records the mitigations in place or planned, such as encryption, data minimization or access restrictions.
  4. Reassessed. The residual risk level shows what remains after mitigation. Your team decides whether that's acceptable.
TermWhat it means
Inherent riskThe risk level before mitigations are applied
MitigationA control or action that reduces the risk
Residual riskThe risk level that remains after mitigations
Risk catalogThe list of risk types available across all your assessments
Risk registryThe central list of every risk identified in your assessments

This approach follows common risk management practice, such as ISO 31000 and the NIST frameworks, so it fits alongside your existing risk program.

Risk management features

FeatureWhat it doesLearn more
Flagging risks in assessmentsAdd risks while completing an assessment, with suggestions based on your answers and inventoryFlagging risks in assessments
Risk registryReview and manage every risk in one place, and track mitigationsRisk registry and catalog
Risk catalogStandardize the risk types your organization usesRisk registry and catalog
Business impact analysisIdentify which systems are most critical to your businessRunning a business impact analysis

Where risks appear

  • In the risk registry: under Governance, select Risks.
  • On a data source page: the Risks tab lists the risks tied to that system, with their inherent risk level, mitigations and source assessment.
  • In the assessment itself: risks stay attached to the assessment that identified them.

Did this page help you?