A risk register your team can keep current

Risk work only helps when it is readable and owned. Record the risk, who is responsible, what the treatment decision is and which control or task reduces it.

Who this is for: For teams building an ISO 27001-style risk process without maintaining a separate spreadsheet.

Write risks in plain English

Capture the scenario, owner, likelihood, impact and treatment decision in language the business can understand.

  • Risk owner
  • Likelihood and impact
  • Treatment status

Show what is being done

Link risks to controls, evidence and remediation tasks so treatment work does not disappear after the register is created.

Keep decisions reviewable

Accepted risks, open treatment work and changed risk levels should be visible before management review or audit preparation.

Common questions

Do we still need an auditor?

Yes. We help you prepare the work: scope, owners, policies, risks and evidence. An auditor still decides what is acceptable for certification, and legal interpretation stays with qualified advisers.

Which integrations are available today?

The current evidence sources are GitHub, Google Workspace and AWS. Jira can be used for remediation work. Other systems should be treated as manual evidence unless they are scoped separately.

What can AI help with?

AI can prepare drafts, summarise notes and suggest first-pass wording. Scope, evidence approval, legal interpretation and customer-facing statements still need owner review.

Which standards should we lead with?

ISO 27001 and GDPR are the strongest starting points. SOC 2, NIS2 and DORA can be handled as preparation or mapping work once the exact scope is agreed.