Adding and managing controls

After a risk is identified and validated, the next step is to plan mitigation actions. In Risk Manager, you do this by creating and assigning controls.

Controls are preventive, detective, or corrective measures that your organization implements to reduce the likelihood or impact of an identified risk.

Effective controls can:

  • Reduce the likelihood of a risk occurring.

  • Lessen the impact if the risk materializes.

  • Provide documented assurance to auditors and stakeholders.

  • Strengthen your organization's overall risk posture and resilience.

Add a control to Risk Manager

You can use Risk Manager to add and manage controls and track key information for each one.

Example

Scenario

You've identified and validated the risk Supply Chain Disruption. Now, you want to add a control to mitigate that risk.

Process

Open the Risk Manager app, create a new control (for example: Dual-Sourcing Strategy), and save it.

For detailed steps, see Working with controls

Result

The control is saved with the status Draft.

What's next?

After adding controls, you need to link them to the relevant risks to complete the mitigation framework. To continue, see Creating risk relationships.