How-To: Manage Risks
Learn how to create risk statements, assign ratings, and link them to audit universe entities.
Prerequisites
- Entity must already exist in the Audit Universe
- You must have the Auditor, Manager, or CAE role
Adding Risks to an Entity
Step 1 — Open Entity Detail
Navigate to Universe → click the entity you want to assess.
Step 2 — Go to the Risks Tab
Click the Risks tab in the entity detail view.
Step 3 — Click "Add Risk"
Click + Add Risk to open the risk creation form.
Step 4 — Complete Risk Details
| Field | Required | Description |
|---|---|---|
| Risk Title | ✅ | Concise risk statement (e.g., "Unauthorized payment approvals") |
| Category | ✅ | Strategic, Operational, Financial, Compliance, IT, Reputational |
| Description | Recommended | Detailed explanation of the risk scenario |
| Likelihood | ✅ | 1 (Rare) to 5 (Almost Certain) |
| Impact | ✅ | 1 (Negligible) to 5 (Catastrophic) |
| Risk Owner | Recommended | Person accountable for managing this risk |
| Inherent Risk | Auto-calculated | Likelihood × Impact (before controls) |
| Residual Risk | Optional | Risk level after considering existing controls |
Step 5 — Save
Click Save. The risk is now attached to the entity and the entity's overall risk score is recalculated.
The risk appears in the entity's Risks tab with a color-coded badge showing the risk level (🟢 Low, 🟡 Medium, 🟠 High, 🔴 Critical). The entity's aggregate risk score in the universe list is updated accordingly.
AI-Assisted Risk Assessment
The AI companion can suggest risks based on:
- Industry standards — common risks for the entity type
- Historical findings — risks identified in past audits of similar entities
- Regulatory requirements — risks mandated by compliance frameworks (NCA, PDPL)
How to Use
- Open the entity detail → Risks tab
- Click AI Suggest Risks
- AI analyzes the entity and presents a list of suggested risks with pre-filled ratings
- Review each suggestion — Accept, Modify, or Reject
- Accepted risks are added to the entity
AI risk suggestions include confidence scores and source citations. All suggestions require explicit human approval before being applied. Every AI interaction is logged in the audit trail with full traceability.
Risk Categories
AIIA supports the following risk taxonomy:
| Category | Description | Examples |
|---|---|---|
| Strategic | Risks to long-term business objectives | Market disruption, M&A failure |
| Operational | Risks in day-to-day processes | Process errors, supply chain disruption |
| Financial | Risks to financial reporting and assets | Fraud, misstatement, asset impairment |
| Compliance | Regulatory and legal risks | NCA ECC non-compliance, PDPL violation |
| IT / Cyber | Technology and security risks | Data breach, system outage, ransomware |
| Reputational | Risks to brand and public trust | Media coverage, customer complaints |
Bulk Risk Operations
Bulk Import
- Navigate to Library → Risks
- Click Import → Download Template
- Fill in the CSV template with risk statements
- Upload and map risks to entities
Bulk Update
- Select multiple risks using checkboxes in the Risks tab
- Click Bulk Actions → select action:
- Update Ratings — adjust likelihood/impact for all selected
- Change Category — reassign category
- Archive — mark risks as inactive
Risk Heatmap
The risk heatmap provides a visual overview of all risks across the universe:
- Navigate to Executive dashboard
- View the Risk Heatmap widget
- Each cell shows the count of risks at that likelihood × impact intersection
- Click a cell to drill into the specific risks
Best Practices
- Use clear, actionable risk statements — "Unauthorized access to financial systems" is better than "Security risk"
- Be honest about ratings — avoid bias toward lower ratings
- Review quarterly — risk landscapes change; reassess ratings regularly
- Consider residual risk — assess risk after existing controls, not just inherent risk
- Link to controls — every risk should have at least one mitigating control mapped
Related Documentation
- Map Controls → — Link controls to these risks
- Field Reference → — Complete field documentation
- Annual Planning — risk scores drive planning priorities