Risk Management
Identify, assess, and treat every risk in one register
SecureSlate scores every risk scenario for likelihood and impact against scales you write yourself, so a number means the same thing whoever picked it. Every risk can then be mapped to the controls that reduce it, each carrying the framework clause it satisfies, so the register you hand your auditor arrives with its own reasoning attached.
Why risk management matters
A risk score nobody can explain is a number, not an assessment.
Everyone scores differently
One person's high is another person's medium. Without written definitions for each level, the register records who filled in the row rather than how much risk the business is actually carrying.
The register and the controls drift apart
Risks live in a spreadsheet and controls live in the compliance tool. Nothing connects the mitigation to the thing it mitigates, so nobody can show that the treatment was more than an intention.
It gets done once, for the audit
The assessment is built the month before fieldwork and then left alone for a year. By the next audit the business has changed, the risks have changed, and the document describes a company that no longer exists.
Score it, treat it, and show your working
Scoring scales you define, inherent and residual scored separately, every risk mapped to the controls that reduce it, and an AI pass your team approves.
Let AI Draft the Assessment
Confirm your company details and SecureSlate AI recommends inherent and residual scores, a treatment plan, and supporting notes for each scenario, taking roughly two minutes a risk. It prefills from your company profile and scores likelihood, impact, and treatment together. Nothing is applied until you approve it, so the register stays your team's judgement rather than the model's.

Scoring Scales You Write Yourself
Every level on the likelihood and impact scales carries a score, a label, and a written definition, so a three means the same thing to your engineer and your CFO. Set the bands that turn a combined score into low, medium, high, or critical, and add your own categories. This is what makes the number defensible when an auditor asks how you arrived at it.

Inherent and Residual, Side by Side
The register shows each scenario with its inherent score, its residual score, how many controls are mapped to it, who owns it, and where it sits between incomplete, in progress, needs approval, and approved. Scoring residual separately rather than deriving it means the register reflects a judgement about what the controls actually achieve.

Map Every Risk to the Controls That Reduce It
Every scenario takes one of the four treatments: mitigate, avoid, transfer, or accept, each with a plain description so the choice is deliberate. Then map the controls that reduce the residual score, and each one carries the framework clause it satisfies, such as ISO 27001:2022 A.8.26, so the line from risk to control to clause is visible in one place.

Where the Risk Actually Sits
The overview pairs a status donut, showing how much of the register is approved against what still needs sign-off, with a heatmap of inherent risk across likelihood and impact. One glance tells you whether your exposure clusters in the top right corner or spreads thinly, and how much of the assessment is genuinely finished.

Start From a Library, Not a Blank Page
The risk library holds prewritten scenarios grouped by category, from operations security and access control through business continuity, privacy, fraud, and vendor relationships, each arriving with recommended controls already mapped. Add the ones that apply, then write your own for whatever is specific to your business.

Resources
Read up before your next assessment.
Practical guides to risk registers and assessments, from building the matrix to turning a rating into something a team will actually act on.
FAQs
Risk management questions answered.
The record of the risks your organisation has identified, what each one could cost you, who owns it, what you decided to do about it, and what is left after your controls. SOC 2 and ISO 27001 both expect one, and ISO 27001 in particular expects the method behind the scoring to be written down rather than improvised.
Inherent risk is the exposure before your controls do anything about it. Residual risk is what remains once they are working. SecureSlate scores each one separately on its own likelihood and impact, rather than calculating residual from a formula, so the second number reflects a judgement about what your controls genuinely achieve.
Yes, and you should. Set the score, the label, and a written description for every level of both the likelihood and impact scales, define the bands that map a combined score onto low, medium, high, and critical, and add your own risk categories. The heatmap and the register follow whatever you configure.
Because they are what make scores comparable. If likelihood four says the threat is expected to occur and the actor is strongly motivated, two different owners assessing two different risks apply the same test. Without that, a register is a collection of opinions, and an auditor asking why something is a three has nothing to read.
You confirm your company details and it recommends inherent and residual scores, a treatment plan, and notes for each scenario, in roughly two minutes a risk, drawing on your company profile. Every recommendation waits for a person. Nothing is applied until you approve it, so it removes the blank page rather than the judgement.
No. The risk library has prewritten scenarios grouped by category, covering the ground most organisations share, and each arrives with recommended controls already mapped. Add what applies, adjust the scoring to your business, then write custom scenarios for the risks nobody else would have.
Map controls directly to the scenario they reduce. Each mapped control shows the framework clause it satisfies, so a risk points to a control and the control points to ISO 27001:2022 A.8.26 or its equivalent. That chain is what turns a treatment decision into evidence instead of an intention.
Every scenario carries an owner and moves through incomplete, in progress, needs approval, and approved. The status is visible in the register and counted on the overview, so an assessment that is half finished looks half finished rather than appearing complete because every row has something written in it.
Both require a documented risk assessment, and ISO 27001 requires a repeatable method producing comparable results. A register with defined scales, per-level definitions, separate inherent and residual scoring, named owners, recorded treatments, and controls mapped to clauses answers that directly, because the reasoning is attached to each row.
At least annually, and after anything that changes your exposure, such as a new product, a new market, a significant vendor, or an incident. The practical trigger is the status view: if most of the register has not been touched since the last audit, it is describing a company you no longer are.
Build a register that survives the question
Set your scoring scales, pull the scenarios that apply from the library, and let AI draft the first pass for your team to approve.
