Risk Management guide

Complete a qualitative risk assessment

Identify vulnerabilities and threats, evaluate exposure against appetite and tolerance and document the selected treatment.

Risk Manager or authorised assessor Approximately 20–40 minutes Updated 27 July 2026

Outcome

Complete a qualitative assessment for an asset, identify vulnerabilities and threats, consider existing controls, compare the result with appetite and tolerance and select an appropriate treatment.

1. Identify vulnerabilities and threats

Open the asset in the Risk Register and continue to Identification. Add vulnerabilities from the CVE catalogue or use non-CVE entries such as shadow IT, missing encryption or weak change control.

Likelihood, current controls and uncertainty can be recorded for each selected vulnerability, changing the emerging risk score.

Add relevant threats and advanced persistent threats. Qualitative assessment can consider several threats together, unlike FAIR scenarios which analyse a specific threat individually.

2. Record existing controls

Add implemented controls that currently change the risk scenario. PurpleWASP can link framework controls and policies already held elsewhere in the platform.

Existing policies and framework controls can be linked directly to the risk, demonstrating how platform modules connect.
Do not record proposed work as an existing control. Planned improvements belong in treatment so the current exposure is not understated.

3. Evaluate against appetite and tolerance

The platform calculates the assessment score and compares it with organisation thresholds.

The evaluation view shows the current score, appetite, tolerance and recommended response.
Within appetiteThe organisation is generally prepared to operate at this level, subject to its acceptance criteria.
Above appetite but within toleranceTreatment is expected. If residual exposure remains above appetite, an exception decision is required.
Above toleranceThe exposure requires urgent escalation and treatment according to organisation rules.

4. Apply treatment

Select the recommended or justified strategy: mitigate, transfer, avoid, monitor, escalate or accept. Use presets where useful, but adjust assumptions when the preset does not fit the scenario.

Treatment changes the current or residual score. Additional strategies can be added when one treatment does not reduce the risk sufficiently.

Add controls or actions that support the selected response and continue to Review.

5. Review the assessment

The review brings together inherent score, evaluation, treatment strategies, controls and residual position before completion.

Confirm that the narrative, score, treatment and evidence describe the same scenario. Complete the assessment when residual exposure is within the allowed decision rules, or continue to the exception process.

Common problems

The score increases during identification

This can be expected as likelihood, control strength and uncertainty replace the initial asset-derived baseline with scenario-specific information.

Controls do not appear after selecting a domain

Confirm that the framework has controls in that domain and that the control record is active and accessible.