Risk registry and catalog
View and manage every risk flagged across your assessments, track mitigations, and customize the risk types your organization uses.
The risk registry is your single view of every risk flagged across your privacy, vendor and AI assessments. The risk catalog is the list of risk types your teams choose from when they flag a risk. Together, they keep risk tracking consistent across your organization, so you can see your overall risk position and decide where to act first.
What the risk registry shows
| Detail | What it means |
|---|---|
| Risk | The risk type, from your risk catalog |
| Assessment | The assessment where the risk was flagged |
| Systems | The data sources linked to that assessment |
| Inherent risk level | Its severity before mitigations |
| Mitigations | The controls in place or planned |
| Residual risk level | What remains after mitigations |
View your risk registry
In the left navigation, under Governance, select Risks.
Risks can't be created directly in the registry. Every risk starts in an assessment, so it's always connected to the context it came from. See Flagging risks in assessments.
You can also see the risks for a single system on its data source page, in the Risks tab.
Manage a risk
You can update a risk either in the original assessment or directly from the registry.
- In the risk registry, select a risk to open its details pane.
- Update its details, such as the inherent risk level, mitigations or residual risk level.
- Click Save.
As mitigations are put in place, reassess the residual risk, so the registry reflects your current position. Changes made in the registry also appear in the original assessment. [confirm: changes sync both ways]
Export your risk registry
Export the registry to share your risk position with leadership, auditors or other teams.
- In the risk registry, filter the list to the risks you need.
- Click on the three dots and Export table
Customize your risk catalog
The risk catalog is the list of risk types available in every assessment. Keeping it aligned with your organization's risk framework, such as ISO 31000 or your internal risk taxonomy, means everyone describes risks the same way.
MineOS risks
MineOS includes a set of predefined risks that cover common privacy, security, vendor and AI scenarios, so you can start flagging risks right away.
If a MineOS risk isn't relevant to your organization, hide it. Hidden risks no longer appear when flagging a risk, but stay in place in assessments where they're already used.
Add a custom risk
Create custom risks for concerns specific to your organization. Once added, a custom risk is available in every assessment type.
- Open the risk catalog.
- Click New risk
- Enter the risk's name and details, and save.
Edit a custom risk
You can edit a custom risk at any time. Your changes apply when the risk is flagged next, and don't change risks already flagged in assessments.
Tips
- Set up your catalog before rolling out assessments, so teams flag risks consistently from the start.
- Hide MineOS risks you don't use, to make the list easier to choose from.
- Review the registry regularly, for example monthly or before leadership reporting, and update residual risk as mitigations are completed.
Related articles
- Flagging risks in assessments: add risks while completing an assessment
- Managing risk: understand the risk lifecycle in MineOS
Updated about 2 hours ago
