Create a risk

Creating a risk requires the Risk.Submit capability, which lets you create and save drafts and submit them for formal review. Most users have it, but organizations can also create view-only or view-and-approve roles that intentionally leave it out.

Before you begin

Gather a clear description of the uncertain event, where it came from, its possible impact, relevant dates, and any supporting files. Use an existing template if your organization has one for this type of risk.

You don't choose a risk owner while creating a risk. The owner is named after the risk has been submitted, usually by the reviewer, so the owner field on the Create page is read-only. See Who can be a risk owner.

Create and save a draft

  1. Open Risk Register and select New Risk, or select Create Risk on the Dashboard.
  2. Complete the visible Discovery fields. A title is enough to save a draft; the description is required when you submit.
  3. Add a category, dates, and other available context.
  4. Add existing mitigations when known.
  5. Use Files / Links / Tags to stage attachments, related risks, and tags. Jira linking becomes available after the risk exists and reaches an eligible state.
  6. Select Save draft. You can also use Ctrl+S or Cmd+S on the Create page.
  7. Confirm that a permanent reference such as RR26-00042 appears after creation. The number is the two-digit year followed by a number that restarts at 1 each year.

Image needed: Create Risk page with section navigation, Save draft, Submit for Review, and Files / Links / Tags highlighted.

The exact sections depend on your workflow. Later phases can add Assessment, Compliance Frameworks, Risk Tolerance, Treatment Plan, Effectiveness Review, Residual Risk, Monitoring, Reassessment, and Closure.

A draft is visible only to you until you submit it. If you no longer need it, you can delete it permanently from the register's row actions (see Deleting and restoring risks).

Understand the field-progress count

The phase rail and the Now/Next bar show a small “filled / total” count for the current phase, such as 0/12. It shows how much of the phase you have filled in. It does not decide whether you can save or submit; the required-field rules below do that.

Identified Date and Identified By are pre-filled with today's date and your name. While the risk is a draft, they are left out of the count and its total, so a new form starts at 0 rather than 2. They join the count when you submit, so the Risk Intake total rises by two at that point (for example, 10/12 becomes 12/14). That is expected.

Apply a template

  1. Open the Templates menu on the Create page.
  2. Select an available personal, shared, or system template.
  3. Review every populated section. A template can replace values, not merely add missing ones.
  4. Make the content specific to this risk before saving.

Eligible content can be saved as a personal template and managed from My Account.

Submit for review

  1. Review every visible section for accuracy.
  2. Make sure the description is complete.
  3. Save any outstanding changes.
  4. Select Submit for Review.
  5. Read and correct any prerequisite message.
  6. Confirm the risk leaves Draft.

Submission first moves the risk to Submitted. If automatic reviewer assignment is on, a reviewer is assigned right away and the risk moves to Under Review. Otherwise it waits in Submitted until someone with the Risk.AssignAnalyst capability, usually a Risk Manager, assigns a reviewer.

Required information changes over time

Administrators can configure additional required fields and state-specific rules. Fields that were optional during intake may also become required before a later action. Common examples include:

  • likelihood and impact before validation;
  • a tolerance justification and approver before recommending that a risk is within tolerance, and the justification again before that recommendation is approved;
  • a treatment plan before plan approval and before treatment starts;
  • effectiveness notes and residual scores before monitoring.

Completing treatment doesn't require a completion date. If nobody has entered one, RiskVault records today's date.

RiskVault names missing prerequisites when an action cannot continue. Save the relevant section after correcting them.