Skip to content
English
  • There are no suggestions because the search field is empty.

Add a risk

Learn how to add a risk to the Risk register in Logiqc.

Adding a risk records what could happen, the controls already in place, how the risk is rated, and who is responsible for managing and approving it. Once submitted, the risk moves through the Manage and Approve stages before it becomes a formal identified enterprise risk on the register.

The Risk register helps your organisation maintain a clear view of risk exposure and the controls in place to manage it.

Risks can be linked to controls in other registers, mitigation actions, and related adverse events such as incidents, complaints, improvements, and repairs.

When a new risk is submitted, it moves to the Risk manager and then to the Risk owner for checking and approval.

Q: Who can add a risk?

A: Users need the Add risks permission. The minimum licence type required is Action.

Q: What happens after I submit a risk?

A: The risk moves into the Manage stage so the Risk manager can review it before approval.

Q: Can I save a risk before submitting it?

A: Yes. Use Save as draft when you need to come back and complete the details later.

Before you start

Check the following:

  • You have the Add risks permission (minimum licence type required: Action).
  • You know the risk dimension, risk category, risk name, contributing factors, and potential consequences.
  • You know who should be assigned as the Risk manager and Risk owner.
  • You have any supporting records or linked controls ready, if they are available.

Step 1: Open the Risk register

Go to the Risk register and start a new risk.

Governance › Risk
 

Open the Risk register, then select + Add risk to open the Add risk page.

Select + Add risk at the top right of the Risk register to open the Add risk page.

The Risk register with the + Add risk button at the top right

Select + Add risk at the top right of the Risk register to open the Add risk page.

Step 2: Complete the Risk details section

Use Risk details to describe the risk clearly enough for other users to understand what may happen and why it matters. This is the risk identification stage.

FieldWhat to enter
Risk dimension and Risk categoryUse Risk dimension for the highest-level classification, such as strategic or operational, then select the Risk category that best fits the risk.
Risk nameEnter a short, recognisable name, such as Disruption to essential services.
Contributing factorsDescribe what can lead to the risk occurring.
Description of riskExplain the risk in plain language.
Potential consequencesDescribe the likely impact if the risk occurs.
Risk review dateSet when the risk assessment and controls should be reviewed. Revisit the risk after significant changes and normally at least annually.
Record physical location (optional)Enter a specific location where the risk could occur, when location is relevant.
Additional comments (optional)Add useful context that should remain visible in Action history as the risk moves through the workflow.
Tip: Check the Draft tab on the Risk register for preconfigured example risks that you can use as a starting point, if available on your platform.
The Risk details section of the Add risk page

Complete Risk details before moving on to controls and assessment.

Step 3: Add risk controls

Controls are the measures, processes, policies, and practices implemented to manage identified risks. Their purpose is either to reduce the likelihood of a risk event occurring or to minimise the impact if it does occur.

Use Risk controls to describe the controls already in place and link related items from other registers.

Controls can include policies, procedures, audits, training, contracts, records, assets, maintenance, licences, suppliers, and other register items that help manage the risk.

The Risk controls section with linked register items

Link existing controls from other registers to show what already manages the risk.

You can also link a control from the Related items tab. Select Add new item to create a new register item and link it in one step, or Link items to link an existing one.

The Related items tab with Add new item and Link items highlighted

Link a control from the Related items tab using Add new item or Link items.

Items linked this way appear automatically in Risk controls, so you don't need to add them twice. To remove or change a linked control, go back to Risk controls — links can't be removed from the Related items tab.

Note: Feedback, Improvement, Incident, and Repair items can't be linked as risk controls. Use Related adverse events (Step 6) to track how these affect the risk instead.

Step 4: Assess the risk

Risk assessment is the overall process of identifying, analysing, and evaluating risks to determine their severity and decide on appropriate responses.

Use Risk assessment to rate the risk from three perspectives.

Uncontrolled risk: the initial rating before existing controls are considered.

Controlled risk: the rating after existing controls are taken into account.

Target risk: the level of risk your organisation would be comfortable with.

Note: Uncontrolled, Controlled, and Target risk ratings are required before the risk can be submitted.
The Risk assessment section showing uncontrolled, controlled, and target ratings

Rate the risk from all three perspectives before adding mitigation actions.

Step 5: Treat the risk

In Risk treatment, evaluate your current controls and check for related adverse events. If they are insufficient to lower the risk rating to an acceptable level, create specific risk mitigation actions designed to reduce either the risk's likelihood or its impact.

When you add a mitigation action, describe the action, choose the Action type that reflects whether the work is intended to change the likelihood or consequence of the risk, assign it to a user, and set the due date. Use Action open for newly assigned work, Action ongoing for work in progress, Action complete for completed work, or Action cancelled if the work will not proceed.

Step 7: Assign ownership

In Assign, select who is responsible for managing and overseeing the risk.

  • Related business area: Select the business area responsible for the risk.
  • Related meeting: Select a meeting to provide governance oversight, if relevant.
  • Risk manager: Select the user responsible for day-to-day management of the risk.
  • Risk owner: Select the user accountable for the risk.
  • Notify users by email: Select any users who need an email notification. Make sure they also have viewing access to the risk.

Step 8: Set access control

In Access control, choose who can access the risk.

Select All users can access to allow all users to view the risk.

To restrict access, select Specify who can access, then select the required Teams and Individual users.

Use Who can view? to check who has access.

Step 9: Save or submit the risk

Use Attach records if supporting files or links need to be attached. Attached records remain available only to users with the relevant access.

If follow-up work should begin in another register, select Create a related item and choose the register. After the final workflow action, Logiqc creates the related item and adds a link in System event history.

Select Save as draft to continue later. If you are the Risk owner and Quick publish is available, it skips the Manage and Approve stages and publishes the risk immediately. Otherwise, select Submit to move the risk into the workflow.

The Assign section with Risk manager, Risk owner, and Submit options

Assign the Risk manager and Risk owner, then save, quick publish, or submit.

Troubleshooting

"Quick publish is not available"

  • Check whether you are selected as the Risk owner.
  • Confirm the required risk sections have been completed.
  • Use Submit instead if the risk needs to move through the Manage and Approve stages.

What happens next

 

The risk is saved to the Risk register

Draft risks stay available for completion, while submitted risks move into the workflow.

 

The Risk manager reviews it

The Risk manager checks the details, controls, ratings, related events, and any mitigation work required.

The Risk owner approves it

Once approved, the risk is available on the Risk register with its next review date and current rating.