Skip to content

Risk management

Risk management is your workspace’s risk register. In a risk assessment, you list the risks your company faces, rate how severe and how likely each one is, and record how you’re responding to it. Once you finalize an assessment, Oneleet uses it as evidence for your risk assessment control and shows it to your auditors.

You’ll find it under Compliance > Risk management. Admins can create, edit, finalize, and reopen assessments, while members and auditors can only view them. Members still see most editing controls, but their changes don’t save. Your workspace can have one assessment in progress at a time.

On the Risk management page, click Start first assessment. The title defaults to the current month and year, such as “September 2026 Risk Assessment”. Change it if you like, then click Start assessment.

While an assessment is in progress, Risk management takes you to it. If you also have a finalized assessment, the page shows that one instead, with a Continue assessment button for the one in progress.

By default, a new assessment uses a 3×3 risk matrix. Impact is rated Minor, Moderate, or Major, likelihood is rated Unlikely, Likely, or Almost certain, and the two combine into a Low, Medium, or High rating. A 5×5 matrix adds Negligible and Devastating impact and Remote and Possible likelihood, and rates risks from Trivial up to Extreme.

You can change the size until you finalize the assessment. Open the Assessment actions menu on the assessment page, choose Edit, and pick a Risk matrix size. The menu only appears once the assessment has at least one risk.

You can’t switch from 5×5 back to 3×3 while any risk in your workspace uses a 5×5-only value, including archived risks and risks in past assessments. Since risks in finalized assessments can’t be edited, a 5×5-only value in an older assessment keeps your workspace on 5×5.

A first assessment you start yourself has no risks yet. Click Add from library or Add first risk to add risks. Once the assessment has a risk, use the Risk library and Add risk buttons at the top of the assessment instead.

The Oneleet risk library lists common risks by category. Pick a category or search, check the risks that apply to your company, and click Add risks (Add risk if you checked only one). Aim for the risks that matter most rather than every risk in the list. A library risk with the same title as one already in your assessment is dimmed.

To add a risk of your own, click Add risk, enter a Title and an optional Description, choose a Category, and click Add risk.

When an assessment has risks that still need assessing, click Start review on the assessment page (it reads Continue review once you’ve started). You can also open any risk from the register. Each risk has sections for its details, inherent risk, response, residual risk, and optional notes, and your answers save automatically as you go.

The bar at the bottom of the page lists anything still Needed for completion, and clicking an item scrolls to it. When you click Continue, Oneleet takes you to the next risk that needs assessing, or back to the assessment page after the last one.

A risk counts as assessed once it has an impact, a likelihood, a response with a description, and an answer to the residual risk question, plus a remaining impact and likelihood if that answer is Yes.

Under Risk details, check the category and choose an owner under Who’s responsible for this risk?. If the person isn’t on Oneleet yet, click Add now to add them on the People page.

For a risk carried over from a previous assessment, the category and owner appear only after you click Modify. If AI suggested every answer on a risk, they stay hidden even then, so set that risk’s owner from the Owner column in the register.

Inherent risk is the risk before you take any action to reduce it. Rate how severe the impact would be and how likely the risk is to occur, and Oneleet combines your two answers into the risk’s inherent rating.

Choose how you’re addressing the risk: Mitigate, Transfer, Avoid, or Accept. A follow-up question then asks you to describe how you’re doing it, or for Accept, why you’re accepting the risk. Your response also decides which group the risk appears under in the register.

To show which parts of your security program support the response, click Link controls and pick controls from the list. Linked controls appear on the risk and in the register your auditors see.

Residual risk is what’s left after your response. Answer Will any risk remain after implementing the response above? If you answer Yes, the remaining impact and likelihood start out matching your inherent answers, so adjust them to reflect the effect of your response. If you answer No, the risk’s residual rating is None.

Oneleet can add risks to your assessment with answers suggested by AI based on your company profile. When every field is filled in, the risk opens with a summary of the suggested assessment, including the reasoning behind most answers and a confidence level for the ratings. From there, you have three choices:

  • Accept: keep the suggested answers and mark the risk assessed.
  • Modify: open the full form to change the answers.
  • Not relevant: archive the risk and move on.

When AI filled in only some fields, the form says so and you complete the rest. Each suggested answer is labeled AI suggested, and if you change one, Revert to AI suggestion puts the original back.

The assessment page lists every risk with its owner, category, and inherent and residual ratings. Risks that still need assessing come first, followed by one group per response. You can change a risk’s owner directly from the Owner column.

Above the register, the Residual risk matrix counts your risks by remaining impact and likelihood, and hovering a cell lists the risks in it. Risk distribution shows how many risks you have in each category.

To download the register, click Export. The CSV contains the rows that match your current filters.

Archive a risk that’s no longer relevant to your company by choosing Archive from its row menu. Archived risks are hidden until you click Show archived risks, count as assessed, and aren’t copied into your next assessment. To remove a risk entirely, choose Delete from its row menu and then Really delete?.

To archive or delete several risks at once, check their rows and use the action panel that appears.

Once every risk is assessed, the assessment page shows Finalize assessment. Click it, then click Yes, finalize assessment. The assessment is marked Completed with your name and the date, and becomes the latest assessment on the Risk management page.

After finalizing, you can no longer add, edit, archive, or delete risks, though you can still edit each risk’s notes. To change anything else, reopen the assessment or make the change in your next assessment.

You can reopen the most recent assessment within 7 days of finalizing it. Open the assessment, click Reopen assessment, and confirm. You can also reopen it from the Forgot something? message on any of its risks.

The assessment returns to In progress, its completion date and “Completed by” name are cleared, and you finalize it again when you’re done.

When no assessment is in progress, click Start new assessment on the Risk management page, then confirm the title.

The new assessment copies every non-archived risk from your latest finalized assessment, including its answers, owner, and linked controls, and keeps the same matrix size. Each copied risk starts out needing assessment. When you review one, Oneleet shows its answers from the previous assessment, with the same three choices as an AI-suggested risk: Accept keeps them unchanged, Modify opens the form to change them, and Not relevant archives the risk. After you modify a risk, answers you didn’t change are marked Matches previous.

View past assessments lists every assessment, with a count of its risks for each response (archived risks included).

Your risk assessments support the Risk assessments performed control. Its monitor fails when your latest assessment was finalized more than 365 days ago, so finalize a new assessment at least once a year.

Workspaces with SOC 2 also have a check that your assessment includes at least one assessed risk in the Fraud category. This check looks at the assessment in progress, so while no assessment is in progress it shows No applicable assets.

Within about an hour of finalizing, Oneleet attaches the register as a CSV evidence file named “Risk register” followed by the assessment title to the Risk assessments performed control. If you reopen and finalize the assessment again, the file is regenerated. An assessment with no risks gets no evidence file.

Auditors see your latest finalized assessment on the Risk register tab of your audit in the auditor portal.