Overview of Risk Register

Overview of Risk Register

The ComplyAssistant Risk Register allows you to track and manage security Threats and associated Controls across your organization. You can register a series of system-defined Threats and Controls or add and register your own.


In order to access the Risk Register, you must either be an Administrator or assigned a User Group with the Risk Register function. To manage Threats and Controls in the register, you must also be assigned the Threat and Controls Admin function.

Threats come with Inherent Risk Levels to your organization. This is calculated by degree of Impact and its Likelihood of occurring. We suggest Inherent Risk Levels, but you have the ability to modify them.


Controls come with a Likelihood Reduction Value which has the power to reduce a Threat’s Inherent Risk Level. You can assign a Control to one or more Threats. You can also assign more than one Control to a single Threat.



You can see the impact that Controls have on a Threat by viewing the Threat’s Residual Risk Level. The lower the Residual Risk, the better the Controls are at mitigating the Threat. 


Once you register a Threat, it appears on the Registered Threats table of the Risk Registry. Similarly, Controls appear under Registered Controls after being registered.

For a complete list of Threats that have and have not been registered, go to the Threat Library within Account Settings. Similarly, all Controls can be found in the Control Library.


The Risk Register aims to help you manage and reduce the overall risks associated with your organization. Risks can seldom be eliminated entirely but can almost always be reduced in scope or impact based on the Controls you implement.