Vendor assessment failures, LiveThreat breach alerts, SBOM CVE matches, privacy DSAR breaches, internal control deficiencies, SOC report CUEC gaps — all land in one risk register with shared data model.
Identified → Assessed → Treated → Accepted / Mitigated / Transferred / Avoided → Closed / Re-Opened, with configurable transition gates.
Tenant-configurable Probability × Impact matrix. Inherent at identification, residual updates as treatment tasks close.
Per-category appetite statements. Acceptances exceeding appetite require elevated approval — board-level for material risks.
Key Risk Indicators with green/amber/red thresholds. Breach triggers auto-create risks or escalate via Teams Adaptive Cards.
Risk scores update from LiveThreat's daily intelligence refresh, so the register reflects reality rather than a once-a-year reassessment.
Assessment findings, breach alerts, CVE matches, control deficiencies and privacy gaps all land in the register automatically with full context.
Key risk indicators with green/amber/red thresholds and trend lines; a breach can auto-create a risk and escalate to the risk function.
Operational owners, the risk function and internal audit each carry scoped permissions that enforce the governance model.
Verisq's RiskOps · Enterprise Risk Management is part of the Trust Operations Platform — one data model, one audit trail, one auditor seat.