Help Centre workspace

Risk Management

Assess Asset-related exposure qualitatively or with FAIR, incorporate manual and scanner-derived technical evidence, then govern treatment, exceptions, reassessment and linked Controls or third parties.

Start with the workflow

From context to a governed Risk decision

Risk assessment links Asset value, threats, vulnerabilities, operating Controls, treatment and formal acceptance while preserving lifecycle history.

1
Identify

Start from an Asset and define threats, manual weaknesses and linked technical exposure.

2
Evaluate

Assess likelihood/impact or quantify one FAIR threat scenario.

3
Treat

Plan mitigation, transfer, avoidance, monitoring, escalation or acceptance.

4
Decide

Evaluate residual exposure against appetite and govern any exception.

5
Reassess

Create a new assessment version when conditions materially change.

Assessment paths

Choose the assessment that fits the decision

Qualitative assessment supports consistent register prioritisation; FAIR quantifies one specific threat scenario financially.

Implementation documentation

Plan the rollout and operate the module

Download the practical implementation handbook or the detailed technical reference for this module.

Important operating rules

Keep Risk semantics separate from connected module scores

Asset value, TPRM tier, Control implementation and Compliance status can inform Risk context, but they are not substitutes for the Risk assessment and its current/residual result.

  • Qualitative assessments can consider multiple threats; FAIR scenarios analyse one specific threat at a time.
  • Current Controls should reflect what is operating, while treatment actions represent planned changes.
  • Rejected Risk exceptions return the exposure to treatment/reassessment rather than silently accepting it.
  • Third-party and Control relationships provide context without transferring ownership of the Risk calculation.
  • Scanner findings are linked as technical evidence and assessed in grouped form; they do not automatically become one Risk per finding.
  • Download the Risk Management First-Time Implementation Handbook for rollout guidance and the Technical Documentation for architecture/operations detail.