Skip to main content
Audience: MSP staff managing risks, and Company users reading risks shared with them. Compliance read access and enabled risk tracking are required. Only internal MSP users with Compliance write/manage access can create, edit, approve or dismiss findings. Company users do not manage the register or see Unaddressed gaps. Open Compliance > Risks. If risk tracking is disabled, an MSP administrator can configure it under Settings > Compliance > Risk. See Risk tracking and categories.

Find and inspect a risk

  1. Check the selected company scope, then open Risk register.
  2. Review the summary cards for Active risks, High and critical, Overdue treatment and Accepted risks. Use table filters and pagination to find a record; do not equate one visible page with the full register.
  3. Open a row or its View details action. Review its statement, likelihood, impact, category, status, owner, target date and treatment plan.
  4. For a compliance-derived risk, follow Open source to inspect the underlying finding. Review available linked PSA tickets, Planner work and evidence before deciding what to do. A strategic risk can exist without a source compliance failure.
  5. Review dependency relationships, occurrence history and Audit history where available. Client access to linked records is checked separately; a visible risk does not grant unrestricted source access.
A Source is now compliant badge describes the source finding. It does not mean that the business risk has been reviewed, its treatment completed or its status automatically closed.

Promote a compliance gap

  1. As an MSP writer, open Unaddressed gaps and inspect the failed check and company.
  2. Select Add to risk register. The editor is prefilled from the finding; nothing is saved by opening it.
  3. Review title, statement, category, likelihood, impact, owner, treatment plan and target date. Check criticality is a starting signal for impact; priority describes remediation urgency. Only likelihood × impact sets the risk score.
  4. Review Visible to company users explicitly. A promoted gap can inherit its source finding’s visibility choice, so do not assume this switch starts off.
  5. Optionally select Use this category for future failures. Saving then also updates this compliance check’s category default; it is broader than this individual risk.
  6. Select Add risk. Reopen the saved risk and verify the assessment before approving client visibility.
Dismiss is a separate action for findings that should not become risks. Enter a meaningful reason and confirm the dismissal; the reason needs at least three characters. Dismissing does not mark the underlying check passed. A later failure can produce a new gap.

Add a strategic risk

MSP writers can select Add strategic risk in the register to record a business risk without a failed check. Choose the company, enter a title and risk statement, select a category and review likelihood/impact. Add an owner, target date and treatment plan as appropriate. Strategic drafts begin internal-only. Where offered, Dependencies lets you choose upstream risks from the same company. Select Save changes to create the risk; Cancel discards the draft. An empty dependency picker does not mean there are no risks anywhere in the tenant: it is limited to eligible risks for the selected company. Dependency links are relationships to review, not automatic treatment completion or score propagation.

Scoring and treatment

Likelihood and impact each range from 1 to 5. The score is their product. Use the editor’s Status for Open, Approved, Mitigating, Accepted or Closed. New risks start Open; subsequent edits persist with Save changes. An owner or target date records accountability and timing; it does not itself send a ticket, assign Planner work or notify that person. Closed risks are read-only. Review the assessment before closing it. A later failed run creates a new gap rather than reopening the closed record. Repeat occurrences on an existing risk should be reviewed against the source evidence rather than treated as independent risks by default.

Approve and share with Company users

Client visibility requires both Visible to company users and a recorded MSP approval, along with the client’s Compliance permission and company scope.
  1. Create and review the risk internally.
  2. Edit it, enable Visible to company users when intended, set Status to Approved, and save.
  3. Verify access with the intended Company role before relying on the client view. An MSP preview is not proof of that user’s access.
  4. To withdraw sharing, turn Visible to company users off and save.
Approval is recorded when an MSP user first changes the status to Approved. Moving the status later to Mitigating, Accepted or another state does not clear that recorded approval. Do not use a status change alone to make a previously approved visible risk private.

Categories and AI assistance

Categories are tenant-wide. Risk settings covers adding, renaming, coloring, reordering and archiving them. Archiving a category preserves existing risk references. The risk matrix is fixed; category colors do not change severity.
Create risk category dialog with a blank name and default teal color.

An MSP administrator's unsaved category editor. Category configuration is separate from an individual risk assessment.

Where Compliance AI offers a Risk assessment proposal, Use this assessment opens the standard editor with a draft. Review every field and the affected company. The proposal is not saved merely by receiving it or opening the editor. Select Add risk deliberately after reviewing; a draft is not confirmed evidence or client approval. See Compliance AI.

Reporting

Enabled risk tracking exposes risk reporting options such as Risk Summary, Risks by Category, Risk Matrix, Risk Exposure Trend, and Risk Register. Report and dashboard availability can differ. Review the selected company, reporting period, visible scope and block configuration before sharing a report. A dashboard summary is not the complete list, and an empty result does not prove that no risks exist outside the permitted scope. If Risks is missing, check feature enablement and permissions. If a client cannot see a risk, check visibility, recorded approval and company access. If editing is unavailable, check whether it is Closed and whether the current user is an MSP writer. If a save fails, keep the draft details, reopen the record and verify what persisted before retrying.

FAQs

An MSP writer can use Add strategic risk, select a company and save a business-risk assessment.
No. Company users read eligible shared risks. MSP writers handle creation, edits and approval.
No. It also needs recorded MSP approval, Compliance access and the correct company scope.
No. The recorded approval remains. Turn Visible to company users off and save to withdraw sharing.
No. Their draft visibility can inherit the source finding. Review the switch before saving.
Likelihood multiplied by impact, each from 1 to 5. Priority and category color do not directly set the score.
No. Saving with it selected also changes the source compliance check’s category default.
No. Dismissal records why the finding is not being promoted. It does not change the source check result.
No. Closed risks are read-only; a later failure creates a new gap.
Do not assume it does. Review the source badge separately from the risk assessment and treatment status.
No. Review the proposed assessment in the editor and deliberately select Add risk.
The risk editor records ownership. It does not itself create a ticket or Planner task, or notify the owner.