Skip to content

Risks

Risks are potential events that may threaten your objectives — strategic, operational, financial or compliance-related.

A risk carries a category (e.g. IT/Cyber, Compliance), a probability, an impact, and a status along the mitigation lifecycle. Through MITIGATED_BY you link the risk to a mitigating measure.

Cards with category badge, risk-matrix indicator (probability × impact) and status. Filter by category, status and severity.

List view

  • MITIGATED_BY (Risk → any measure) — “is mitigated by” / “mitigates”. The measure can be a value stream, role, policy or project — the constraint is only defined on the source side (Risk).
  • OWNS (Person → Risk) — risk owner
  • AFFECTS (Risk → anything) — what is threatened

Details: Relationship Types.

{
"type": "object",
"properties": {
"riskCategory": {
"type": "string",
"title": "Risk category",
"enum": ["Strategic", "Operational", "Financial", "Compliance", "Reputational", "IT/Cyber"]
},
"probability": {
"type": "string",
"title": "Probability",
"enum": ["Low", "Medium", "High", "Very high"]
},
"impact": {
"type": "string",
"title": "Impact",
"enum": ["Low", "Medium", "High", "Very high"]
},
"status": {
"type": "string",
"title": "Status",
"enum": ["Identified", "Assessed", "Under mitigation", "Mitigated", "Accepted", "Closed"]
},
"mitigation": { "type": "string", "title": "Mitigation strategy" },
"rootCause": { "type": "string", "title": "Root cause" },
"reviewDate": { "type": "string", "title": "Next review", "format": "date" }
},
"required": ["riskCategory"]
}

Extension ideas: numeric riskScore, residualRisk, responseStrategy (avoid/mitigate/transfer/accept), affectedAssets as array. Details: JSON Schema for Entity Types.

  • Category and status badges
  • Risk matrix (probability × impact)
  • Root cause analysis (rootCause)
  • Mitigation strategy as lead text
  • Linked mitigation measures via MITIGATED_BY
  • Review date — Next review is marked as a deadline out of the box and reminds those accountable

Detail view