Enabling Risk Tracking
Risk tracking is off by default. To enable it:1
Open Risk Settings
Go to Settings > Compliance and open the Risk tab.
2
Choose a Category Starter
Turn on Enable risk tracking. You’ll be asked to choose a category starter preset:
3
Customize Categories
In the Risk categories section, add, rename, recolor, reorder, or archive the categories used across the register and reports.
Disabling risk tracking hides the feature without deleting existing data. Re-enable it at any time to pick up where you left off.
Scoring Matrix
Every risk uses likelihood × impact on a fixed 5 × 5 scale. The scoring matrix in settings is a read-only reference showing the four severity bands:Accessing the Risk Register
Once risk tracking is enabled, a Risks tab appears in the Compliance workspace alongside Tree view and List view. Click Compliance in the sidebar, then select the Risks tab. The Risk Register page shows four summary cards: Active risks, High and critical, Overdue treatment, and Accepted risks, above two tabs:- Risk register: All tracked risks with filters for company, category, severity, status, owner, and target date.
- Unaddressed gaps (internal users only): Failed compliance checks that have not yet been promoted to a risk or dismissed.
Viewing risks requires compliance read access. Creating and editing risks requires compliance write access and is limited to internal MSP users. Client company users only see the Risk register tab, and only risks you have marked visible to them.
Working with Gaps
Risks are created from compliance findings, so the register always traces back to evidence. On the Unaddressed gaps tab, each failed check offers two actions:Add to Risk Register
Click Add to risk register to open the risk editor pre-filled from the failed check. The gaps tab includes a guidance banner explaining how the fields work together: criticality is evidence for impact, priority is remediation urgency, likelihood is company-specific probability, and only likelihood × impact determines the risk score.Dismiss
Click Dismiss to record why a failed result does not need to become a risk. A reason is required. If the check fails again later, it appears as a new gap.Risk Fields
When promoting a gap, you can also turn on Use this category for future failures to save the selected category as that compliance check’s default.
Viewing a Risk
Click any row in the register to open the risk detail. Alongside the core fields, the detail shows:- Source compliance finding with an Open source link back to the originating check
- Linked remediation work: the PSA ticket, Planner items, and evidence files attached to the source finding
- Failure occurrences: how many times the source check has failed (repeat failures increment the count instead of creating duplicates)
- Risk history: a field-by-field change log of every edit
- A Source is now compliant badge when the underlying check has since passed
Compliance AI and Risks
The Compliance AI assistant (the floating button on the Compliance page) can help with risk work when risk tracking is enabled:- Use the Find risk candidates prompt to rank confirmed compliance gaps that deserve human risk review.
- The assistant can produce a Risk assessment proposal with a drafted title, statement, category, likelihood, impact, and treatment plan.
Risk Reporting Blocks
Five risk blocks are available in the report builder (and dashboards, where supported) once risk tracking is enabled:Troubleshooting
Related Resources
Compliance
Manage compliance runs, checks, and evidence
Reporting
Build client reports with risk blocks