Add a risk
In this article:
Learn how to add a risk to the Risk register in Logiqc.
Adding a risk records what could happen, the controls already in place, how the risk is rated, and who is responsible for managing and approving it. Once submitted, the risk moves through the Manage and Approve stages before it becomes a formal identified enterprise risk on the register.
The Risk register helps your organisation maintain a clear view of risk exposure and the controls in place to manage it.
Risks can be linked to controls in other registers, mitigation actions, and related adverse events such as incidents, complaints, improvements, and repairs.
When a new risk is submitted, it moves to the Risk manager and then to the Risk owner for checking and approval.
Q: Who can add a risk?
A: Users need the Add risks permission. The minimum licence type required is Action.
Q: What happens after I submit a risk?
A: The risk moves into the Manage stage so the Risk manager can review it before approval.
Q: Can I save a risk before submitting it?
A: Yes. Use Save as draft when you need to come back and complete the details later.
Before you start
Check the following:
- You have the Add risks permission (minimum licence type required: Action).
- You know the risk dimension, risk category, risk name, contributing factors, and potential consequences.
- You know who should be assigned as the Risk manager and Risk owner.
- You have any supporting records or linked controls ready, if they are available.
Step 1: Open the Risk register
Go to the Risk register and start a new risk.
Navigation path
Open the Risk register, then select + Add risk to open the Add risk page.
Select + Add risk at the top right of the Risk register to open the Add risk page.

Select + Add risk at the top right of the Risk register to open the Add risk page.
Step 2: Complete the Risk details section
Use Risk details to describe the risk clearly enough for other users to understand what may happen and why it matters. This is the risk identification stage.
| Field | What to enter |
|---|---|
| Risk dimension and Risk category | Use Risk dimension for the highest-level classification, such as strategic or operational, then select the Risk category that best fits the risk. |
| Risk name | Enter a short, recognisable name, such as Disruption to essential services. |
| Contributing factors | Describe what can lead to the risk occurring. |
| Description of risk | Explain the risk in plain language. |
| Potential consequences | Describe the likely impact if the risk occurs. |
| Risk review date | Set when the risk assessment and controls should be reviewed. Revisit the risk after significant changes and normally at least annually. |
| Record physical location (optional) | Enter a specific location where the risk could occur, when location is relevant. |
| Additional comments (optional) | Add useful context that should remain visible in Action history as the risk moves through the workflow. |

Complete Risk details before moving on to controls and assessment.
Step 3: Add risk controls
Controls are the measures, processes, policies, and practices implemented to manage identified risks. Their purpose is either to reduce the likelihood of a risk event occurring or to minimise the impact if it does occur.
Use Risk controls to describe the controls already in place and link related items from other registers.
Controls can include policies, procedures, audits, training, contracts, records, assets, maintenance, licences, suppliers, and other register items that help manage the risk.

Link existing controls from other registers to show what already manages the risk.
You can also link a control from the Related items tab. Select Add new item to create a new register item and link it in one step, or Link items to link an existing one.

Link a control from the Related items tab using Add new item or Link items.
Items linked this way appear automatically in Risk controls, so you don't need to add them twice. To remove or change a linked control, go back to Risk controls — links can't be removed from the Related items tab.
Step 4: Assess the risk
Risk assessment is the overall process of identifying, analysing, and evaluating risks to determine their severity and decide on appropriate responses.
Use Risk assessment to rate the risk from three perspectives.
Uncontrolled risk: the initial rating before existing controls are considered.
Controlled risk: the rating after existing controls are taken into account.
Target risk: the level of risk your organisation would be comfortable with.

Rate the risk from all three perspectives before adding mitigation actions.
Step 5: Treat the risk
In Risk treatment, evaluate your current controls and check for related adverse events. If they are insufficient to lower the risk rating to an acceptable level, create specific risk mitigation actions designed to reduce either the risk's likelihood or its impact.
When you add a mitigation action, describe the action, choose the Action type that reflects whether the work is intended to change the likelihood or consequence of the risk, assign it to a user, and set the due date. Use Action open for newly assigned work, Action ongoing for work in progress, Action complete for completed work, or Action cancelled if the work will not proceed.
Step 6: Set tolerance for related adverse events
Use Related adverse events to link incident and feedback sub-categories to the risk. Matching adverse events are counted automatically. The section shows counts for Incidents, Complaints, Repairs, Non-conformance, and the Total so you can compare them with the review threshold.
Set the number of adverse events that can occur before the risk is automatically brought under review.

Set how many related adverse events can occur before the risk is brought under review.
Step 7: Assign ownership
In Assign, select who is responsible for managing and overseeing the risk.
- Related business area: Select the business area responsible for the risk.
- Related meeting: Select a meeting to provide governance oversight, if relevant.
- Risk manager: Select the user responsible for day-to-day management of the risk.
- Risk owner: Select the user accountable for the risk.
- Notify users by email: Select any users who need an email notification. Make sure they also have viewing access to the risk.
Step 8: Set access control
In Access control, choose who can access the risk.
Select All users can access to allow all users to view the risk.
To restrict access, select Specify who can access, then select the required Teams and Individual users.
Use Who can view? to check who has access.
Step 9: Save or submit the risk
Use Attach records if supporting files or links need to be attached. Attached records remain available only to users with the relevant access.
If follow-up work should begin in another register, select Create a related item and choose the register. After the final workflow action, Logiqc creates the related item and adds a link in System event history.
Select Save as draft to continue later. If you are the Risk owner and Quick publish is available, it skips the Manage and Approve stages and publishes the risk immediately. Otherwise, select Submit to move the risk into the workflow.

Assign the Risk manager and Risk owner, then save, quick publish, or submit.
Troubleshooting
"Quick publish is not available"
- Check whether you are selected as the Risk owner.
- Confirm the required risk sections have been completed.
- Use Submit instead if the risk needs to move through the Manage and Approve stages.
What happens next
The risk is saved to the Risk register
Draft risks stay available for completion, while submitted risks move into the workflow.
The Risk manager reviews it
The Risk manager checks the details, controls, ratings, related events, and any mitigation work required.
The Risk owner approves it
Once approved, the risk is available on the Risk register with its next review date and current rating.