Risk register
A living risk register with a real likelihood × impact heat map, not a spreadsheet that goes stale.
| Risk | Category | Inherent | Residual | Owner |
|---|---|---|---|---|
| Vendor data breach | Third party | High | Medium | A. Rivera |
| Unpatched servers | Operations | High | Low | IT team |
| Account takeover | People | Medium | Low | S. Chen |
| Single cloud region | Availability | Medium | Medium | M. Lin |
Auditors for SOC 2 and ISO 27001 expect a risk assessment you actually maintain. Keel gives you a living register: score each risk on a 5×5 likelihood × impact scale, watch it land on a colour-coded heat map, assign an owner and a treatment, and link it to the controls that bring it down, so your risk story stays current without a quarterly spreadsheet scramble.
The spreadsheet risk register always rots
A risk tab in a workbook is fine the week you make it and useless three months later: no owners, no scoring discipline, no line back to the controls that treat each risk. When the auditor asks “show me how you manage risk,” you’re rebuilding it from memory.
What risk register does
Likelihood × impact heat map
Every open risk is scored and plotted on a 5×5 matrix (Rare→Almost certain by Insignificant→Severe), banded Low / Guarded / Elevated / High. The map uses your effective (residual, where assessed) score, so mitigated risks move down where they belong.
Treatments and owners
Assign each risk a treatment (mitigate, accept, transfer, avoid), an owner, and a status. The register tracks open vs. treating and flags unmitigated high risks so nothing severe sits unattended.
Linked to your controls
Tie a risk to the controls that mitigate it. Because Keel crosswalks controls across frameworks, the same mitigation counts everywhere it applies, and your risk-to-control story is audit-ready.
AI risk drafting
Describe your business, or just name your framework, and Keel drafts a set of concrete, pre-scored risks to seed the register: each an editable starting point you accept or discard, never boilerplate you’re stuck with.
At-a-glance posture
Summary tiles show total risks, how many are high, how many are open/treating, and how many high risks remain unmitigated, the numbers a board or auditor asks for first.
Why it matters
- Walk into an audit with a risk assessment that’s current, scored, and owned
- See your riskiest exposures instantly on the heat map
- Prove each risk is being treated, and by which control
- Seed a real register in minutes with AI instead of a blank page
Get audit-ready, and prove it
Risk register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
Does Keel’s risk register support residual (post-treatment) risk?
Yes. Where you’ve assessed a residual score, the heat map uses that effective score, so a well-mitigated risk visibly moves out of the high band.
Can I link risks to controls and evidence?
Yes. Link a risk to the controls that mitigate it. Those controls carry their own evidence, so the whole chain from risk to control to proof holds together.
Is the AI risk drafting going to invent risks I don’t have?
It drafts candidates from your context as a starting point; you review, edit, and keep only the ones that apply. Nothing is added to your register without you accepting it.
Which frameworks expect a risk register?
SOC 2 (CC3), ISO 27001 (clause 6 / 8.2), NIST CSF, and most others treat risk assessment as a core requirement. One register in Keel feeds all of them.
Related features: Controls & crosswalk · Vendor risk management · AI tools
Works with: SOC 2 · ISO/IEC 27001 · NIST Cybersecurity Framework