Skip to content

Manage Risks & Mitigations

This guide explains how to identify, score, and manage risks in the Risk Register (/risks).


Step 1: Registering a New Risk

  1. Navigate to Risk Management > Risk Register (/risks).
  2. Click + New Risk.
  3. Fill in the risk details:
    • Risk Title: E.g., Unauthorized Access via Stale Privileged Credentials.
    • Category: E.g., Cybersecurity, Operational, Third-Party, Regulatory.
    • Inherent Severity & Likelihood: Rate on a 1–5 scale based on your organization's risk matrix.
    • Risk Owner: Assign the accountable risk manager or domain lead.
  4. Click Create Risk. The system issues an identifier (e.g., RSK-2026-0033).

Step 2: Linking Mitigating Controls & Calculating Residual Risk

  1. Click on the newly created risk to open its detail drawer.
  2. In the Mitigating Controls section, click + Add Mitigating Control.
  3. Select relevant active controls (e.g., CTL-2026-0004 Quarterly Privileged Access Review).
  4. OrviQ recalculates the Residual Risk Score based on the effectiveness and coverage of the linked controls.
  5. Select the Treatment Strategy: Mitigate, Transfer, Avoid, or Accept.

OrviQ Enterprise Governance, Risk & Compliance Platform