Risk Management

Turn findings into action.

A risk register built around ICT third-party findings, with owners, severity, mitigation plans, due dates and a complete audit history.

app.northstar-dora.eu/risks

Risk Register

7 high risks · 18 open · linked to assessments, evidence and contracts

IDRiskProviderSeverityStatusOwner
RSK-311DR testing evidence not providedAWSHighMitigation PlannedS. Martin
RSK-318Exit strategy absent from contractMicrosoftHighOpenT. Weber
RSK-324Subcontractor countries incompleteStripeMediumIn ReviewL. Dubois
RSK-327Pen test older than 12 monthsSnowflakeMediumOpenS. Martin
RSK-330No documented incident SLATemenosLowAcceptedM. Rossi

Capabilities

What you get

Create risk from findings

Assessments, evidence gaps and contract clauses feed the register.

Ownership

Each risk has a named owner and reviewer.

Severity and appetite

Score probability and impact against your risk appetite.

Mitigation plans

Document actions, due dates and progress.

Acceptance

Record accepted risks with rationale and approval.

History

Every status change is captured in the audit trail.

Traceable back to the source.

Each risk keeps its link to the assessment answer, evidence document or contract clause that produced it.

  • Source reference on every risk
  • Comment thread with decisions
  • Heat map for executive reporting
  • Remediation status in the readiness score

AI Finding

Confidence 94%

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept FindingDismissRequest ClarificationCreate Risk

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

Workflow

How the workflow runs

Finding
Create risk
Assign owner
Mitigate
Resolve or accept

Get your ICT third-party risk under control.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.