Incidents Risks And Response

Use This Doc For

Purpose

Risk assessments describe a plausible hazard, its likelihood and severity, the inherent risk, and the residual risk after mitigation. Incident records capture what actually occurred. Linking both to controls and corrective actions keeps response work connected to the broader compliance record.

Assess A Risk

  1. Describe the hazard and scope precisely.
  2. Record likelihood, severity, and inherent risk before relying on controls.
  3. Link the controls that mitigate the risk and add mitigation notes where needed.
  4. Record residual risk only after considering how those controls operate.
  5. Assign the assessor and next review date.

The platform displays linked incidents on the risk detail. A risk with no incidents is not automatically low risk, and an incident does not by itself prove the linked control failed.

Risk assessment List, Grid, and Board views all begin with active assessments. In Grid or Board, choose All assessments beside the view controls to inspect inactive history. The scope is retained in the URL.

Respond To An Incident

  1. Address safety, containment, service continuity, and required escalation through the organization’s incident procedures first.
  2. Create the incident with occurrence and detection times, severity, category, description, reporter, and related risk where known.
  3. If it may be regulator-notifiable, mark that fact and record the notification deadline. When an employee context and deadline are available, the platform creates a compliance calendar event.
  4. Track investigation and root cause separately from immediate containment.
  5. Create corrective actions for longer-term remediation, with owners and due dates.
  6. Record notification time only after the external notification has actually occurred.

Decisions And Consequences

What To Watch

Recovery

If severity, category, timing, or linkage is wrong, correct the record promptly and explain the change in notes or the audit trail. If an incident was closed too early, return it to an active response state where the interface permits and assign the missing work. Never delete or hide an incident merely to improve posture; preserve the event and correct its interpretation.