Back to app
Risks

Risks

Exposures tracked with an owner, a severity, and a lifecycle that distinguishes mitigating from accepting.

Reviewed AdminVertiqa 1.46+

A risk is something that could go wrong, written down while there's still time to do something about it. Risks are the only Company State record type with a severity.

What a risk needs

Owner, severity, title, description, and status are all required. A due date is optional — use it when the exposure has a date attached, like a contract that lapses or a certification that expires.

The owner is picked from your team, so a risk always has a name against it.

Severity

Four levels: low, medium, high, critical.

Severity is not set-and-forget. The list has a Change severity action on each row and the detail page has the same control; both open a dialog that takes the new severity and an optional reason. That reason is worth writing — a risk that quietly moved from medium to critical with no explanation tells you nothing later.

Changing severity needs the edit permission.

The four statuses

  • Open — known, nothing being done yet.
  • Mitigating — actively being worked on.
  • Accepted — a deliberate choice to live with it.
  • Closed — no longer active.

Accepted and closed mean different things and the distinction is the point. Accepted says someone decided to carry this exposure; closed says it's gone. Closing an accepted risk to tidy the list erases the decision to accept it — if it was a real call, record it as a decision too.

Use Close risk on the detail page when it's genuinely over; it lets you capture a reason and needs the close permission.

Filtering

Status and severity filters plus an owner box are applied by the server. Search matches title, description, and owner. On the Company State landing page, the Risks card counts everything that isn't closed — including accepted ones.