Risk management

Risk register

A living risk register with a real likelihood × impact heat map, not a spreadsheet that goes stale.

Start free See pricing
Risk register walkthrough
app.keelgrc.com/risks
Risk
Risk register
18
Open risks
11
Treated
3
High / critical
2
Review due
RiskCategoryInherentResidualOwner
Vendor data breachThird partyHighMediumA. Rivera
Unpatched serversOperationsHighLowIT team
Account takeoverPeopleMediumLowS. Chen
Single cloud regionAvailabilityMediumMediumM. Lin

Auditors for SOC 2 and ISO 27001 expect a risk assessment you actually maintain. Keel gives you a living register: score each risk on a 5×5 likelihood × impact scale, watch it land on a colour-coded heat map, assign an owner and a treatment, and link it to the controls that bring it down, so your risk story stays current without a quarterly spreadsheet scramble.

The spreadsheet risk register always rots

A risk tab in a workbook is fine the week you make it and useless three months later: no owners, no scoring discipline, no line back to the controls that treat each risk. When the auditor asks “show me how you manage risk,” you’re rebuilding it from memory.

What risk register does

Likelihood × impact heat map

Every open risk is scored and plotted on a 5×5 matrix (Rare→Almost certain by Insignificant→Severe), banded Low / Guarded / Elevated / High. The map uses your effective (residual, where assessed) score, so mitigated risks move down where they belong.

Treatments and owners

Assign each risk a treatment (mitigate, accept, transfer, avoid), an owner, and a status. The register tracks open vs. treating and flags unmitigated high risks so nothing severe sits unattended.

Linked to your controls

Tie a risk to the controls that mitigate it. Because Keel crosswalks controls across frameworks, the same mitigation counts everywhere it applies, and your risk-to-control story is audit-ready.

AI risk drafting

Describe your business, or just name your framework, and Keel drafts a set of concrete, pre-scored risks to seed the register: each an editable starting point you accept or discard, never boilerplate you’re stuck with.

At-a-glance posture

Summary tiles show total risks, how many are high, how many are open/treating, and how many high risks remain unmitigated, the numbers a board or auditor asks for first.

Why it matters

  • Walk into an audit with a risk assessment that’s current, scored, and owned
  • See your riskiest exposures instantly on the heat map
  • Prove each risk is being treated, and by which control
  • Seed a real register in minutes with AI instead of a blank page

Get audit-ready, and prove it

Risk register is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

Does Keel’s risk register support residual (post-treatment) risk?

Yes. Where you’ve assessed a residual score, the heat map uses that effective score, so a well-mitigated risk visibly moves out of the high band.

Can I link risks to controls and evidence?

Yes. Link a risk to the controls that mitigate it. Those controls carry their own evidence, so the whole chain from risk to control to proof holds together.

Is the AI risk drafting going to invent risks I don’t have?

It drafts candidates from your context as a starting point; you review, edit, and keep only the ones that apply. Nothing is added to your register without you accepting it.

Which frameworks expect a risk register?

SOC 2 (CC3), ISO 27001 (clause 6 / 8.2), NIST CSF, and most others treat risk assessment as a core requirement. One register in Keel feeds all of them.