What the Risk Module Does
Risk OS is the enterprise risk register at the centre of ActiveERM — the system of record for what could go wrong, what you are doing about it, and whether that is working.
It implements the ISO 31000 process directly: establish scope, context and criteria; identify, analyse and evaluate risk; treat it; and monitor, review and report throughout. Nothing about it is bolted on to a compliance tool as an afterthought.
Configurable Scales and Criteria
Risk criteria come first, and they are yours to define. Configure likelihood and impact scales with your own anchors — frequency bands with a stated time horizon for likelihood, and multi-dimensional consequence for impact across financial, regulatory, reputational, safety and operational categories.
A risk scores at the highest level it reaches on any dimension, never an average, so a severe regulatory exposure with negligible financial cost cannot average itself into invisibility.
Scales are versioned. When criteria change, the register records which version a score was made under, so trend comparison stays honest.
Inherent and Residual Scoring
Every risk carries both an inherent assessment (before controls) and a residual assessment (after them), on the same scale. The gap between them is what your control environment is actually buying you — and it is the number most boards have never been shown.
Because controls live in the shared GRC control library, attaching or strengthening a control moves the residual score. The heat map is generated from the register rather than maintained beside it, so it reflects the current state instead of the last workshop.
Treatment and Ownership
Each risk carries a treatment decision — treat, tolerate, transfer or terminate — with rationale, a named owner, a target residual position, and a review date.
Two rules are enforced structurally rather than by discipline. A risk without an owner surfaces in the overdue view rather than sitting quietly. And a treatment plan requires a target residual score, because a plan with no target cannot be evaluated as successful.
Key Risk Indicators
Scheduled review tells you what happened. Key risk indicators tell you what is happening.
Define indicators with thresholds, attach them to risks, and a breach triggers review rather than waiting for the next quarterly cycle. Indicators can be updated manually, imported, or fed through the API from source systems. Our KRI guide covers how to choose indicators that actually predict.
Incidents and Events
Incidents are logged against the risks they realise, which closes the loop most registers leave open: an event that occurs is evidence your likelihood assessment was wrong, and the platform surfaces that rather than filing it separately.
Incident records carry impact, root cause, actions and closure evidence, and feed both risk reassessment and audit.
AI-Assisted Risk Work
Every tenant includes an isolated AI sandbox that can read your risk data and help with the parts that are laborious rather than analytical — drafting mitigation options for a described risk, summarising a register for a board pack, spotting risks whose reviews have lapsed, and answering questions about the register in natural language. Personal data is excluded from AI-accessible output by design. See AI integrations.
Reporting
Role-based dashboards show each owner what is theirs and what is overdue. Board and committee reporting is generated from the register — heat maps, movement since last period, treatment progress, overdue reviews, and indicator status — so the pack reflects the data on the day it is produced.
Who It Suits
Organisations running ERM across multiple functions where a spreadsheet has stopped scaling: usually at the point where more than one person maintains risks, more than one framework applies, or a board committee has started asking for trend rather than a snapshot.
If a single team maintains twenty risks reviewed annually, a spreadsheet is genuinely adequate and we will say so.
Related
- Risk matrices and ISO 31000 scoring — how to build scales that discriminate
- ISO 31000 and risk registers — what the standard asks for
- Top challenges in ERM — where programmes stall
- GRC Cloud — the control library the register scores against
Request a demo to see the register, heat map and indicator workflow with your own scales configured.