Skip to main content
Risk Management adds a risk register to the Compliance module. Failed compliance checks surface as gaps that you can promote into tracked risks, each with a likelihood and impact score, an owner, a treatment plan, and a target date. Risks feed dedicated reporting blocks so you can show clients their risk posture in reports and dashboards.

Enabling Risk Tracking

Risk tracking is off by default. To enable it:
1

Open Risk Settings

Go to Settings > Compliance and open the Risk tab.
2

Choose a Category Starter

Turn on Enable risk tracking. You’ll be asked to choose a category starter preset:
3

Customize Categories

In the Risk categories section, add, rename, recolor, reorder, or archive the categories used across the register and reports.
Disabling risk tracking hides the feature without deleting existing data. Re-enable it at any time to pick up where you left off.

Scoring Matrix

Every risk uses likelihood × impact on a fixed 5 × 5 scale. The scoring matrix in settings is a read-only reference showing the four severity bands:

Accessing the Risk Register

Once risk tracking is enabled, a Risks tab appears in the Compliance workspace alongside Tree view and List view. Click Compliance in the sidebar, then select the Risks tab. The Risk Register page shows four summary cards: Active risks, High and critical, Overdue treatment, and Accepted risks, above two tabs:
  • Risk register: All tracked risks with filters for company, category, severity, status, owner, and target date.
  • Unaddressed gaps (internal users only): Failed compliance checks that have not yet been promoted to a risk or dismissed.
Viewing risks requires compliance read access. Creating and editing risks requires compliance write access and is limited to internal MSP users. Client company users only see the Risk register tab, and only risks you have marked visible to them.

Working with Gaps

Risks are created from compliance findings, so the register always traces back to evidence. On the Unaddressed gaps tab, each failed check offers two actions:

Add to Risk Register

Click Add to risk register to open the risk editor pre-filled from the failed check. The gaps tab includes a guidance banner explaining how the fields work together: criticality is evidence for impact, priority is remediation urgency, likelihood is company-specific probability, and only likelihood × impact determines the risk score.

Dismiss

Click Dismiss to record why a failed result does not need to become a risk. A reason is required. If the check fails again later, it appears as a new gap.

Risk Fields

When promoting a gap, you can also turn on Use this category for future failures to save the selected category as that compliance check’s default.
Closed risks are read-only. If the same check fails again after a risk is closed, a new gap is created rather than reopening the closed risk.

Viewing a Risk

Click any row in the register to open the risk detail. Alongside the core fields, the detail shows:
  • Source compliance finding with an Open source link back to the originating check
  • Linked remediation work: the PSA ticket, Planner items, and evidence files attached to the source finding
  • Failure occurrences: how many times the source check has failed (repeat failures increment the count instead of creating duplicates)
  • Risk history: a field-by-field change log of every edit
  • A Source is now compliant badge when the underlying check has since passed

Compliance AI and Risks

The Compliance AI assistant (the floating button on the Compliance page) can help with risk work when risk tracking is enabled:
  • Use the Find risk candidates prompt to rank confirmed compliance gaps that deserve human risk review.
  • The assistant can produce a Risk assessment proposal with a drafted title, statement, category, likelihood, impact, and treatment plan.
AI never writes to the register directly. Clicking Use this assessment opens the standard risk editor pre-filled with the draft, flagged as an AI-assisted assessment. Review and edit every field; nothing is added until you click Add risk.

Risk Reporting Blocks

Five risk blocks are available in the report builder (and dashboards, where supported) once risk tracking is enabled:

Troubleshooting

Compliance

Manage compliance runs, checks, and evidence

Reporting

Build client reports with risk blocks