Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a risk manually

Risk administrators can create risk records when they see a potential for a gain or loss of value.

Before you begin

Role required: sn_risk.user

Procedure

  1. Navigate to All > Risk > Risk Register > Create New.

  2. On the form, fill in the fields.

FieldDescription
NumberUnique identification number. This field automatically populated.
Inherit from risk statementOption to create a risk independent of risk statement.
ActiveOption to indicate if the risk is active.
NameName for the risk. Field is auto-populated if the risk is generated from a risk statement, but can be changed without affecting the relationship between the risk and risk statement.
DescriptionDescription of the risk and how it is a threat to the organization.
Risk StatementRisk statement this risk is associated with.
CategoryCategory of risk which applies to the profile. - Legal - Financial - Operational - Reputational - Legal/Regulatory - Credit - Market - IT If the risk is generated from a risk statement, the field is automatically populated/
EntityEntity related to the risk. Note: Only active entities are shown.
Sync with entity ownerOption to assign the entity owner as the owner of this risk record. When selected, if the entity owner changes, the risk owner is updated automatically. This option is set to True by default.
Owning groupOwning group for the risk.
Risk relevanceExplanation of how this risk applies to you. Note: This field only appears when the Inherit from risk statement option is selected.
OwnerOwner for the risk.Note: The owner is always added as a respondent.
  1. Select the Assessment Summary tab.

    This tab is only visible if you have the Advanced Risk plugin activated. The scores of the risk assessment methodology selected as the primary are displayed in the risk scoring section. If the Advanced Risk plugin is not activated, then the following sections for classic risk appear.

  2. To fill in the fields for the risk appetite section, see Define the risk appetite for a risk.

  3. On the form, fill in the fields.

FieldDescription
Note: These fields appear for classic risk.
AssessmentAssessment to attach to this risk.
Assessment respondentsUsers assigned to the assessment of this risk.Note: Only a user with the sn_grc.user role can be added as a respondent.
When both the **Assessment** and **Assessment respondents** fields are set, assessments are created when you select **Assess**.
  1. Select the Scoring tab.

  2. On the form, fill in the fields.

FieldDescription
Note: These fields appear for classic risk.
Inherent SLEMonetary value of a risk if it occurs before any mitigation strategies are in place.
Residual SLEMonetary value of a risk if it occurs after all mitigation strategies are in place.
Inherent AROProbability that a risk occurs in any given year before any mitigation strategies are in place.
Residual AROProbability that a risk will occur in any given year after all mitigation strategies are in place.
Inherent ALEAnnualized loss expectancy `ALE = SLE x ARO` before any mitigation strategies are in place.
Residual ALEAnnualized loss expectancy `ALE = SLE x ARO` after all mitigation strategies are in place.
Inherent scoreThe score of the risk before any mitigation strategies are in place.
Residual scoreThe score of the risk after all mitigation strategies are in place.
Calculated ALEAnnualized loss expectancy based off all calculations.
Calculated scoreThe corresponding score for the calculated ALE.
  1. Select the Response tab.

  2. On the form, fill in the fields.

FieldDescription
Response- Accept - Avoid - Mitigate - Transfer
JustificationEnter a reasonable justification for the selected response
  1. Select the Monitoring tab.

    FieldDescription
    Control compliance percentagePercentage of compliant controls
    Control non-compliance percentagePercentage of non-compliant controls
    Control failure factorSum of failed controls weighting divided by total controls weighting
    Indicator failure factorUses the last result of each associated indicator. Number of last results failed divided by total number of indicators associated.
    Calculated risk factorThis value is calculated from (Indicator failure factor + Control failure factor) / 2.
  2. Select the Activity Journal tab.

  3. Enter additional comments, as necessary.

  4. Select Submit.

Parent Topic:Using Risk Management