Find and inspect a risk
- Check the selected company scope, then open Risk register.
- Review the summary cards for Active risks, High and critical, Overdue treatment and Accepted risks. Use table filters and pagination to find a record; do not equate one visible page with the full register.
- Open a row or its View details action. Review its statement, likelihood, impact, category, status, owner, target date and treatment plan.
- For a compliance-derived risk, follow Open source to inspect the underlying finding. Review available linked PSA tickets, Planner work and evidence before deciding what to do. A strategic risk can exist without a source compliance failure.
- Review dependency relationships, occurrence history and Audit history where available. Client access to linked records is checked separately; a visible risk does not grant unrestricted source access.
Promote a compliance gap
- As an MSP writer, open Unaddressed gaps and inspect the failed check and company.
- Select Add to risk register. The editor is prefilled from the finding; nothing is saved by opening it.
- Review title, statement, category, likelihood, impact, owner, treatment plan and target date. Check criticality is a starting signal for impact; priority describes remediation urgency. Only likelihood × impact sets the risk score.
- Review Visible to company users explicitly. A promoted gap can inherit its source finding’s visibility choice, so do not assume this switch starts off.
- Optionally select Use this category for future failures. Saving then also updates this compliance check’s category default; it is broader than this individual risk.
- Select Add risk. Reopen the saved risk and verify the assessment before approving client visibility.
Add a strategic risk
MSP writers can select Add strategic risk in the register to record a business risk without a failed check. Choose the company, enter a title and risk statement, select a category and review likelihood/impact. Add an owner, target date and treatment plan as appropriate. Strategic drafts begin internal-only. Where offered, Dependencies lets you choose upstream risks from the same company. Select Save changes to create the risk; Cancel discards the draft. An empty dependency picker does not mean there are no risks anywhere in the tenant: it is limited to eligible risks for the selected company. Dependency links are relationships to review, not automatic treatment completion or score propagation.Scoring and treatment
Likelihood and impact each range from 1 to 5. The score is their product.Approve and share with Company users
Client visibility requires both Visible to company users and a recorded MSP approval, along with the client’s Compliance permission and company scope.- Create and review the risk internally.
- Edit it, enable Visible to company users when intended, set Status to Approved, and save.
- Verify access with the intended Company role before relying on the client view. An MSP preview is not proof of that user’s access.
- To withdraw sharing, turn Visible to company users off and save.
Categories and AI assistance
Categories are tenant-wide. Risk settings covers adding, renaming, coloring, reordering and archiving them. Archiving a category preserves existing risk references. The risk matrix is fixed; category colors do not change severity.
An MSP administrator's unsaved category editor. Category configuration is separate from an individual risk assessment.
Reporting
Enabled risk tracking exposes risk reporting options such as Risk Summary, Risks by Category, Risk Matrix, Risk Exposure Trend, and Risk Register. Report and dashboard availability can differ. Review the selected company, reporting period, visible scope and block configuration before sharing a report. A dashboard summary is not the complete list, and an empty result does not prove that no risks exist outside the permitted scope.Troubleshooting and related guides
If Risks is missing, check feature enablement and permissions. If a client cannot see a risk, check visibility, recorded approval and company access. If editing is unavailable, check whether it is Closed and whether the current user is an MSP writer. If a save fails, keep the draft details, reopen the record and verify what persisted before retrying.FAQs
Can I create a risk without a failed compliance check?
Can I create a risk without a failed compliance check?
Can Company users create or approve risks?
Can Company users create or approve risks?
Will changing Approved to Mitigating make the risk private?
Will changing Approved to Mitigating make the risk private?
Are promoted compliance gaps always internal-only?
Are promoted compliance gaps always internal-only?
What calculates risk severity?
What calculates risk severity?
Does Use this category for future failures affect only this risk?
Does Use this category for future failures affect only this risk?
Does dismissing a gap pass its check?
Does dismissing a gap pass its check?
Can I edit a Closed risk?
Can I edit a Closed risk?
Does a compliant source automatically close a risk?
Does a compliant source automatically close a risk?
Does receiving an AI assessment add it to the register?
Does receiving an AI assessment add it to the register?
Does assigning an owner send a notification or create work?
Does assigning an owner send a notification or create work?