Turn findings into action.
A risk register built around ICT third-party findings, with owners, severity, mitigation plans, due dates and a complete audit history.
Risk Register
7 high risks · 18 open · linked to assessments, evidence and contracts
| ID | Risk | Provider | Severity | Status | Owner |
|---|---|---|---|---|---|
| RSK-311 | DR testing evidence not provided | AWS | High | Mitigation Planned | S. Martin |
| RSK-318 | Exit strategy absent from contract | Microsoft | High | Open | T. Weber |
| RSK-324 | Subcontractor countries incomplete | Stripe | Medium | In Review | L. Dubois |
| RSK-327 | Pen test older than 12 months | Snowflake | Medium | Open | S. Martin |
| RSK-330 | No documented incident SLA | Temenos | Low | Accepted | M. Rossi |
Capabilities
What you get
Create risk from findings
Assessments, evidence gaps and contract clauses feed the register.
Ownership
Each risk has a named owner and reviewer.
Severity and appetite
Score probability and impact against your risk appetite.
Mitigation plans
Document actions, due dates and progress.
Acceptance
Record accepted risks with rationale and approval.
History
Every status change is captured in the audit trail.
Traceable back to the source.
Each risk keeps its link to the assessment answer, evidence document or contract clause that produced it.
- Source reference on every risk
- Comment thread with decisions
- Heat map for executive reporting
- Remediation status in the readiness score
AI Finding
Confidence 94%Disaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
Workflow
How the workflow runs
Get your ICT third-party risk under control.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.