Risk registry and catalog

View and manage every risk flagged across your assessments, track mitigations, and customize the risk types your organization uses.

The risk registry is your single view of every risk flagged across your privacy, vendor and AI assessments. The risk catalog is the list of risk types your teams choose from when they flag a risk. Together, they keep risk tracking consistent across your organization, so you can see your overall risk position and decide where to act first.

What the risk registry shows

DetailWhat it means
RiskThe risk type, from your risk catalog
AssessmentThe assessment where the risk was flagged
SystemsThe data sources linked to that assessment
Inherent risk levelIts severity before mitigations
MitigationsThe controls in place or planned
Residual risk levelWhat remains after mitigations

View your risk registry

In the left navigation, under Governance, select Risks.

Risks can't be created directly in the registry. Every risk starts in an assessment, so it's always connected to the context it came from. See Flagging risks in assessments.

You can also see the risks for a single system on its data source page, in the Risks tab.

Manage a risk

You can update a risk either in the original assessment or directly from the registry.

  1. In the risk registry, select a risk to open its details pane.
  2. Update its details, such as the inherent risk level, mitigations or residual risk level.
  3. Click Save.

As mitigations are put in place, reassess the residual risk, so the registry reflects your current position. Changes made in the registry also appear in the original assessment. [confirm: changes sync both ways]

Export your risk registry

Export the registry to share your risk position with leadership, auditors or other teams.

  1. In the risk registry, filter the list to the risks you need.
  2. Click on the three dots and Export table

Customize your risk catalog

The risk catalog is the list of risk types available in every assessment. Keeping it aligned with your organization's risk framework, such as ISO 31000 or your internal risk taxonomy, means everyone describes risks the same way.

MineOS risks

MineOS includes a set of predefined risks that cover common privacy, security, vendor and AI scenarios, so you can start flagging risks right away.

If a MineOS risk isn't relevant to your organization, hide it. Hidden risks no longer appear when flagging a risk, but stay in place in assessments where they're already used.

Add a custom risk

Create custom risks for concerns specific to your organization. Once added, a custom risk is available in every assessment type.

  1. Open the risk catalog.
  2. Click New risk
  3. Enter the risk's name and details, and save.

Edit a custom risk

You can edit a custom risk at any time. Your changes apply when the risk is flagged next, and don't change risks already flagged in assessments.

Tips

  • Set up your catalog before rolling out assessments, so teams flag risks consistently from the start.
  • Hide MineOS risks you don't use, to make the list easier to choose from.
  • Review the registry regularly, for example monthly or before leadership reporting, and update residual risk as mitigations are completed.

Related articles


Did this page help you?