RiskABC ISO RiskABC Gov

User Guide

Everything you need to get up and running. Step-by-step walkthroughs for both the ISO and Gov platforms.

Both Platforms

Signing Up & Subscription

Self-service signup happens at onboard.risk-abc.com. Pick the standards you need, set up your seats, accept the legal documents, and you're in. Renewals are managed from the same surface.

1 Create your organization

1
Go to onboard.risk-abc.com
The signup page asks for your name, work email, company name, and a short URL slug for your org.
2
Verify your email
We send a confirmation link. Click it to activate your account. The link expires after 24 hours — request a fresh one from the signup page if needed.
3
Pick at least two frameworks
Choose any two from the 12 supported standards. The remaining frameworks are available in your account at no extra charge — turn them on whenever you're ready.
4
Accept the legal documents
Review and accept the Terms of Service, Privacy Policy, and Data Processing Addendum.
5
Set up your subscription
Enter your seat count and billing details. We invoice annually. Mid-year seat additions are prorated to your renewal date.

2 Managing seats & renewals

  • Add seats mid-year — prorated to your renewal date, no need to wait
  • Invite users by email — they receive a one-click activation link
  • Renewal notice 30 days before your renewal date with the upcoming amount
  • Annual term is locked in once paid — no mid-term cancellations. Downsizes and cancellations take effect at your next renewal date
  • Free auditor seats — read-only access for external auditors doesn't consume a seat
ℹ️
Need to talk to a human first? Skip the self-serve flow and book a demo — we'll set up a sandbox org so you can explore the platform with your real frameworks before you commit.
Both Platforms

Getting Started

Both RiskABC and RiskABC Gov use the same single sign-on (SSO) system. One account gives you access to every platform your organization is subscribed to.

1 Logging In

1
Go to your platform URL
Navigate to sso.risk-abc.com — the single sign-on portal for both platforms. After login you'll choose which platform to enter.
2
Enter your email address
Type in your work email and click Continue. Your account is tied to your organization's domain.
3
Enter your password
Type your password. If you've forgotten it, click Forgot password to receive a reset link by email.
4
Complete MFA (if enabled)
If your organization has MFA enabled, open your authenticator app (Google Authenticator, Authy, etc.) and enter the 6-digit code shown.
5
You're in — Dashboard loads automatically
On first login, your controls are automatically loaded in the background. The dashboard shows your current compliance posture immediately.
risk.risk-abc.com / login
RiskABC
Sign in to RiskABC
Use your organization email
Email
you@organization.com
Password
••••••••
Sign In
Forgot password?
💡
First time? Your Org Admin will have set up your account. Check your inbox for a welcome email with a one-click magic link to sign in — no password to remember.
💡
The "What's New" window — The first time you sign in after a release, a What's New window opens with a highlight grid of recently added features (Vendor Management, Questionnaire Builder, SOA Approvals, Tasks, BIA Settings, Support). Click Open the User Guide to jump here, or Explore RiskABC (or the ✕) to dismiss it — it won't return until the next update. It appears once per person, so consultants managing several client orgs see it a single time, not once per org.
Both Platforms

Dashboard

The dashboard gives you an instant snapshot of your compliance posture — control completion, risk exposure, and items needing attention.

risk.risk-abc.com / dashboard
Dashboard
Controls
Risk Register
Assets
93
Total Controls
24
Implemented
8
High Risk
12
Risks Open
Implementation by Domain
A.5 Org
65%
A.6 People
40%
A.8 Tech
28%

What each stat means:

  • Total Controls — Total controls in the selected framework
  • Implemented — Complete with evidence; shows "of N applicable" on SOA frameworks, "of N total" otherwise
  • In Progress — Controls partially implemented
  • Not Started — Controls not yet begun
  • High/Extreme Risks — Open risks scoring in your top severity tiers
  • Policies Due Review — Policies past their review date (shown in purple)

Charts:

  • Implementation by Domain — A bar chart showing progress per control domain or theme
  • Control Implementation — A donut with your overall completion % in the center, split Implemented / In Progress / Not Started / Exceptions
  • Risk Register — A donut breaking open risks down by severity tier (plus a "Not Assessed" slice), with total and open counts in the header
ℹ️
Compliance Overview button — The Compliance Overview button in the top-right opens a single page showing every framework your organization subscribes to side by side, so you can compare posture across ISO 27001, SOC 2, TISAX, etc. without switching the framework selector.

1 At a Glance

A grid of clickable shortcuts — Information Assets, Open Risks, Policies, Evidence Items, and Exceptions (plus N/A Controls on SOA frameworks). Each tile shows a live count and opens that module.

2 Third-Party Risk panel

When vendors exist, the dashboard shows a Third-Party Risk panel — Total Vendors, Open Findings, Overdue Assessments, and Certs Expiring (30d) tiles, plus a Vendors by Criticality Tier breakdown. If any vendor findings are open in the risk register, a red alert banner appears at the top of the panel. View all vendors jumps to the Vendors module.

3 Frameworks grid

Cards for every framework available to you. Click a licensed framework to select it and jump to its Controls. Frameworks not in your plan appear locked; clicking one opens a Contact Sales prompt. If your org also has RiskABC Gov, a CMMC 2.0 card opens it in a new tab, signing you in automatically. If no frameworks are enabled, the dashboard shows No Frameworks Configured with a Contact Sales button.

Both Platforms

Controls & Statement of Applicability

Controls are the heart of both platforms. Each control maps to a specific requirement in the selected framework. You track status, add evidence, and manage applicability here.

1 Browsing Controls

risk.risk-abc.com / controls
Dashboard
Controls
Risk Register
🔍 Search controls…
Domain ▾
Status ▾
IDControlStatusRiskEvid
A.5.1 Policies for info security Implemented 6 — Low 3
A.5.2 Information security roles In Progress 9 — Mod 1
A.5.3 Segregation of duties Not Started 17 — High 0
1
Open Controls from the sidebar
Click Controls in the left sidebar. All controls for your active framework load in a paginated table.
2
Filter by Domain or Status
Use the Domain dropdown to narrow to a specific area (e.g. Access Control, Audit). Use Status to show only Not Started or In Progress controls.
3
Search by keyword
Type any word in the search box to filter controls by name in real time.
4
Click a row to open the detail panel
Clicking any control row slides open a detail panel on the right with the full description, scoring, evidence, and edit options.
⚠️
Gov platform: the Domain filter lists the 14 CMMC / NIST 800-171 domains by two-letter code — AC Access Control, AT Awareness & Training, AU Audit & Accountability, CA Security Assessment, CM Configuration Management, IA Identification & Auth, IR Incident Response, MA Maintenance, MP Media Protection, PE Physical Protection, PS Personnel Security, RA Risk Assessment, SC Sys & Comms Protection, SI System & Info Integrity.

2 Updating a Control's Status

1
Open the control detail panel
Click any control row in the table to open it.
2
Click Edit
In the detail panel, click the Edit button (pencil icon) to enter edit mode.
3
Set the Status
Choose from: Not StartedIn ProgressImplemented. Use Exception for controls that cannot be implemented.
4
Assign an owner (optional)
Select the team member responsible for this control from the Assigned To dropdown. Assigning a control to a team member sends them a Task Assigned email automatically.
5
Score the control's risk (Applicable controls)
For Applicable controls the detail panel shows a Risk Score Calculator — set Probability and Impact (1–5) and, on CIA frameworks, Confidentiality / Integrity / Availability (0–3). The score is RS = I × P + (C + I + A) (or RS = I × P where CIA doesn't apply) and drives the color-coded tier badge in the Risk column. Not Applicable controls aren't scored unless an admin enables Settings → Score Not Applicable controls.
6
Save
Click Save Changes. The dashboard stats update immediately.
💡
Best practice: Don't mark a control Implemented until at least one piece of evidence is attached. This keeps your SOA audit-ready.

3 Adding Evidence to a Control

1
Open the control detail panel
Click the control you want to attach evidence to.
2
Scroll to the Evidence section
The lower portion of the detail panel shows all attached evidence and an Add Evidence button.
3
Choose evidence type and add a title
Select from: Policy Doc · Screenshot · Artifact · Text Description · Test Result · Certificate. Enter a clear, descriptive title.
4
Policy Doc — link or upload
Choosing evidence type Policy Doc gives two paths: pick an existing policy from the dropdown to link it (the title fills in from the policy name automatically), or leave the dropdown empty and upload a new policy file. Other file types (Screenshot, Artifact, Test Result, Certificate) always upload a file; Text Description needs only a title and description.
5
Attach a file (optional)
Click Choose File to upload a document, screenshot, or certificate. Uploaded files are stored securely for integrity.
6
Save the evidence
Click Add. The evidence count on the control row updates immediately.

4 Statement of Applicability (SOA)

The SOA declares which controls are applicable to your organization and why. Required for ISO 27001 certification.

1
Open the control detail panel
Find the control you want to mark as not applicable.
2
Set Applicability
Applicability has three values — Applicable, Not Applicable, and Not Assessed (the default until you decide); you can also filter the table by any of them. Setting Not Applicable reveals an Exclusion Reason dropdown: Legal/Regulatory, Contractual, Risk Assessment, Business Requirement, Workforce Headcount, or Outsourced (the last two are ISO-27001-specific).
3
Add the justification
Click the Exclusion Justification (or Inclusion Justification) field — it opens a full-width editor. Enter your rationale; it is required (red asterisk) and Save is blocked until it's filled. Notes is a separate, optional field. The justification — not Notes — is what appears on the SOA export.
4
Justify Applicable controls too
When Applicability = Applicable, an Inclusion Reason dropdown (Legal/Regulatory, Contractual, Risk Assessment, or Business Requirement — a shorter list than the exclusion reasons) and an Inclusion Justification field appear. Both are required — Save rejects Applicable controls with either left blank.
5
Generate your SOA report
Go to Reports & SOA → click Export SOA to download a CSV or view it on-screen. All applicable/not applicable decisions are included.
⚠️
Gov platform — CMMC mandate: When a CMMC framework is active, a notice at the top of the Controls page states that all 110 CMMC practices are mandatory and cannot be excluded — the Applicability field is display-only. Accepted risks require a Plan of Action & Milestones (POA&M) and must be remediated within agreed timelines; an accepted risk is not a permanent state, and risk avoidance by discontinuing operations is not a compliant option.

5 SOA Approval & Versioning

Formally sign off and version-number your SOA — a common auditor requirement. An org admin chooses the approval mode in SettingsSOA Approval Mode.

1
Choose your approval mode
In SettingsSOA Approval Mode, pick Blanket sign-off (default — one approval covers the whole SOA) or Per-control sign-off (each control is reviewed and approved individually).
2
Blanket mode: Submit for Review
On the Controls page, open the SOA Approval & Versioning panel at the top. A reviewer (Org Admin, Compliance Officer, or Privileged Consultant) clicks Submit for Review and enters a short change summary.
3
Blanket mode: Approve & stamp a version
A different approver (Org Admin or Privileged Consultant) clicks Approve. This stamps a version — starting at 1.0, with a minor bump when controls have changed. The approver can force a major bump instead.
4
Per-control mode: Mark Reviewed, then Approve
Open a control's detail panel and find the Sign-off section. Click Mark Reviewed, then a different approver clicks Approve or Reject. The top panel becomes a progress view ("X / N controls approved").
5
Per-control mode: version stamps automatically
Once every control is approved, the SOA version stamps automatically — there's no separate finalize step. Editing an already-approved control sends just that control back for re-approval ("changes pending"); once all are approved again, the next version stamps.
💡
Segregation of duties: the approver must be a different person than the reviewer. For a solo or small org, an admin can enable owner self-approval in SettingsApproval — Separation of Duties so the same person may approve — this is the same toggle that governs policy approval.
💡
Change detail & version history: the panel and the SOA export show the actual value changes (e.g. "A.5.3 — Applicability: Applicable → Not Applicable"). Every approved version generates a PDF snapshot of the SOA, downloadable from the version-history list or from the Exports page via the panel's View in Exports button.
⚠️
Gov platform note: In RiskABC Gov, this document is labeled SOA / POA&M. The approval workflow is identical.
Both Platforms

Risk Register

The Risk Register captures every identified risk, links it to assets and threats, scores it, and tracks treatment. RiskABC Gov adds POA&M enforcement for high risks.

1 Creating a New Risk

risk.risk-abc.com / risks
Dashboard
Controls
Risk Register
12 risks + Add Risk
Risk NameScoreStatusTreatment
Unauthorised access to CUI 17 — High In Treatment Mitigate
Data breach via phishing 26 — Ext Open Mitigate
1
Click Add Risk
Open the Risk Register from the sidebar and click the + Add Risk button in the top right.
2
Enter a risk name and description
Give the risk a clear, specific name. Example: "Unauthorized access to customer records via weak passwords".
3
Link to an Asset (optional)
Select the asset this risk targets from the dropdown. If the asset doesn't exist yet, add it in the Asset Inventory first.
4
Link to a Threat (optional)
Select the threat that could exploit this risk (e.g. External Attacker, Insider Threat). Available on both platforms. If the threat you need isn't listed, click + New threat to add it inline — enter a name, optional category/source/description, and at least one vulnerability. It's saved to your Threat Library and auto-selected for this risk.
5
Scope the risk (optional)
By default a new risk belongs to the framework you're viewing. Tick Global risk to apply it across all frameworks — global risks show a violet Global badge and appear regardless of the selected framework. You can toggle this later from the risk's detail panel.
6
Assign an owner and save
Set the risk owner — the person responsible for treatment. Click Create Risk.
ℹ️
Bulk delete — Org Admins and Privileged Consultants can click Select multiple to check several risks and delete them in one action (up to 500 at a time). Bulk deletes are recorded in the Audit Trail.

2 Scoring a Risk

Risk scores are calculated automatically from the values you enter. The formula is: (Probability × Impact) + (C + I + A).

Score
Result
=
P × I
Probability × Impact
+
C + I + A
CIA Impact
Probability & Impact (P/I)

Scale: 1–5

  • 1 = Very Unlikely / Negligible
  • 3 = Possible / Moderate
  • 5 = Almost Certain / Catastrophic
CIA Scores

Confidentiality · Integrity · Availability

  • ISO: 0–3 per dimension
  • Assets: 1–3 per dimension
  • Max total CIA = 9
  • Gov: the CIA term is scored as impact to CUI (Controlled Unclassified Information) — 0 = N/A, 1 = Low, 2 = Medium, 3 = High per dimension
ℹ️
CIA applies only to frameworks that use it — For frameworks without a CIA model (ISO 9001, ISO 22301, ISO 20000, SOC 2) the score is simply Probability × Impact, the CIA selector is hidden, and the tier bands scale down. The (C + I + A) term and the 0–9 CIA range apply only to CIA-based frameworks (ISO 27001, Gov).
ℹ️
CIA from a linked asset — If you link the risk to an asset, its Confidentiality/Integrity/Availability ratings are copied from that asset and locked (shown as copied from asset). For a standalone risk with no asset, you set C/I/A directly. Residual scores reuse the same CIA values as the inherent score.

Risk levels (default):

Low · 0–8 Moderate · 9–16 High · 17–25 Extreme · 26+

An org_admin can rename tiers, change their score ranges, and recolor them in Settings — the register badges, the Risk Level Key, and the level filter all follow your org's configured tiers. The acceptable-risk threshold is a separate org setting.

3 Risk Treatment & POA&M

1
Open a risk and click Edit
Click any risk in the register to open its detail panel, then click Edit.
2
Choose a Treatment
Select one:
Mitigate — Implement controls to reduce the risk
Accept — Accept the risk as-is (requires justification if above threshold)
Transfer — Transfer risk to a third party (e.g. insurance)
Avoid — Remove the activity causing the risk (ISO only)
3
Enter treatment notes
Describe the specific actions being taken. This text is included in risk reports and audit exports.
4
Set residual risk scores
After treatment, enter the expected Residual Probability and Residual Impact to show the risk level after controls are applied.
💡
Treatment gives residual credit: the residual score isn't just Residual P × Residual I + CIA — each treatment subtracts a credit before the floor of 0: Mitigate −4, Transfer −3, Avoid −2, Accept −1. The detail panel shows the live formula (e.g. 3 × 2 + (2+2+2) − 4 (Mitigate) = 8) so the math is never hidden.
⚠️
Threshold enforcement (both platforms) — Your org sets an Acceptable Risk Score in Settings (default 16). If a risk's inherent score is above it and you set status to Accepted, RiskABC blocks the save until you enter a treatment note justifying acceptance. On the Gov platform this same gate is surfaced as the POA&M banner. The Avoid strategy remains ISO-only.
💡
Needs action flag — Risks scoring above the acceptable threshold that are still Open or In Treatment show a ⚠ Needs action marker in the register, and their detail panel shows an amber banner ("This risk exceeds the acceptable threshold…"). The flag clears once the risk is Accepted (with justification) or Closed.
💡
Automatic remediation task — When you create or edit a risk whose residual score is above your org's acceptable threshold, RiskABC auto-creates a task titled "Residual risk above threshold: <risk name>", its priority set from the residual risk level. Lowering the residual score (or accepting/transferring the risk) below the threshold removes the still-open auto-task; completed tasks are kept as history. Note the trigger uses the residual score, not the inherent score.
ℹ️
Evidence on a risk — From a risk's detail panel you can link supporting evidence — pick an existing Evidence Library item, unlink it, or create a new evidence item (attached to a control) linked to this risk in one step. Linked evidence is counted in the panel heading and flows into risk reports.
Both Platforms

Asset Inventory

The asset inventory catalogs everything your organization relies on — hardware, software, data, people, and services. Assets link directly to risks so you always know what's at stake.

1
Open Assets from the sidebar
Click Assets. The full asset list loads with type icons, classification badges, and CIA scores.
2
Click + Add Asset
Click the button in the top right to open the new asset form.
3
Set the asset type and classification
Type: Hardware · Software · Data/Information · People · Service · Facility · Cloud
Classification: the dropdown lists your organization's configured classification tiers (labels/colors set in Org Settings; defaults are Public, Internal, Confidential, Restricted). The same tiers drive the classification filter and each card's colored badge.
4
Score CIA impact (1–3 each)
Set Confidentiality, Integrity, and Availability scores. These feed directly into any risk linked to this asset.
5
Add optional metadata
The Inventory Details section captures Hostname, Serial Number, Manufacturer, Model, Building/Room, Geo Location, Assigned To, Managed By, Asset Category, and Specialized Type — all optional, shown on the detail view when filled.
ℹ️
Gov platform: For CMMC frameworks, Hardware assets get an additional CMMC Asset Category field with options: CUI Asset · Security Protection Asset · Contractor Risk-Managed Asset · Specialized Asset. This is required for CMMC scoping and only appears on Hardware-type assets.
💡
Software assets can link to a vendor: when Type is set to Software, extra fields appear — Vendor (pick from your Vendors catalog), Deployment Model (SaaS, On-Premise, Desktop, Cloud, Other), and Outage Workaround. This ties the asset inventory directly to third-party risk. You don't have to leave the form to add a missing vendor — click + Add vendor next to the Vendor dropdown, enter a name, and it's created in your Vendors catalog and selected on this asset immediately.
ℹ️
Assets shared from Gov — Assets synced from the Gov platform show a purple From Gov badge and are read-only (the detail view shows "From Gov — read-only"; Edit, Delete, and bulk-select are hidden). Manage them on the Gov platform where they originate.
ℹ️
Bulk delete — Org Admins and Privileged Consultants can click Select multiple to check several assets and delete them in one action (up to 500 at a time); From-Gov cards can't be selected. Bulk deletes are recorded in the Audit Trail.
Both Platforms

Threat Library

The Threat Library is a catalog of threat actors and scenarios you face. Linking threats to risks makes your risk register more accurate and your reports more meaningful.

1
Open Threats from the sidebar
Click Threat Library. You'll see a list of all threats with their category, source, and how many risks reference them.
2
Click + Add Threat
Enter a name for the threat (e.g. "Ransomware attack", "Supply chain compromise").
3
Set category and source
Category: Cyber · Physical · Human · Environmental · Operational · Legal/Compliance
Source: Internal · External · Both
4
Link at least one vulnerability
Every threat requires at least one linked vulnerability — pick an existing one from the library or type a new name to add it on the fly. From an existing threat's detail view, use + link existing vuln to attach more, or unlink one (it stays in the library, just detached from this threat).
5
Link the threat to risks
Go to the Risk Register and select this threat when creating or editing a risk. Linked risks appear in the threat's detail view.
ℹ️
Vulnerabilities live in their own library. The header shows a live count and link — e.g. "12 vulnerabilities in library" — that jumps straight to the Vulnerability Library, where the same vulnerability can be reused across many threats.
ℹ️
Bulk delete — Org Admins and Privileged Consultants can click Select multiple to check several threats and delete them in one action (up to 500 at a time). Bulk deletes are recorded in the Audit Trail.
Both Platforms

Vulnerability Library

The Vulnerability Library is the shared catalog of weaknesses your threats exploit — the "how" that pairs with the Threat Library's "who/what." Every vulnerability tracks how many threats currently reference it.

1 Browsing & usage tiers

Vulnerabilities are grouped into usage tiers based on how many threats link to them, so you can spot orphaned or over-used entries at a glance:

Unused · 0 threats Light · 1–2 Moderate · 3–4 High · 5–6 Critical · 7+

Click a tier card to filter the grid to just that tier. Use the search box and the sort dropdown (Most used, Least used, Name A→Z/Z→A, Newest) to find what you need.

2 Adding, editing & deleting

1
Click + New Vulnerability
Enter a Name (e.g. "Inadequate authentication mechanism") and an optional Description.
2
Open a card to view detail
Click any vulnerability card to see its usage tier, linked threats (each links back to Threat Library), and added date.
3
Edit
Click Edit Vulnerability to change the name or description. If it's in use, a note reminds you the edit propagates to every threat that references it.
4
Delete
Click Delete Vulnerability. If it's unused, it's removed immediately. If threats still reference it, you're asked to pick a replacement vulnerability for each affected threat before the delete completes — nothing is left dangling.
⚠️
No replacement available? If this is the only vulnerability in the library, add a second one first — you can't delete the last vulnerability out from under threats that reference it.
Both Platforms

Vendors & Third-Party Risk (TPRM)

The Vendors module tracks every third party your organization relies on — from onboarding through offboarding — with an inherent-risk questionnaire, expiring documents, contract renewals, and due-diligence assessments all in one place. It exists in both RiskABC and RiskABC Gov; the workflow is identical.

1 Creating a vendor & the profile

1
Click + Add Vendor
Open Vendors in the sidebar and click the button in the top right. Fill in Vendor Name (required), Service / Product, contact name/email/phone, and notes.
2
Open the vendor to see the full profile
Click any row to open a tabbed detail modal: Profile · IRQ · Assessments · Documents · Contracts · Risks/CAPA.
3
Fill out the Profile tab
Owner — the person responsible for this vendor
Lifecycle StageProspective · Onboarding · Active · Under Review · Offboarding · Terminated
StatusPending · Approved · Restricted
Geography, Website, and a free-tag Data Types Accessed list (e.g. PII, Financial Records)
4
Offboarding a vendor
Set Lifecycle Stage to Offboarding to reveal a 5-item checklist (data returned, data destroyed, access revoked, certificate of destruction, final obligations — each with an optional note). Save Checklist as you go; Complete Offboarding permanently moves the vendor to Terminated and cannot be undone.

2 IRQ & criticality tier

The Inherent Risk Questionnaire (IRQ) scores a vendor across six dimensions, each 0 (None) to 4 (Critical): Data Sensitivity, System Access Level, Business Dependency, Regulatory Scope, Data Volume, and Geography Risk.

1
Open the IRQ tab and score each dimension
A live score preview updates as you pick answers — it's the sum of your six answers as a percentage of the maximum possible (24).
2
Suggest IRQ (optional)
Click Suggest IRQ to pre-fill the six dimensions from the vendor's profile (data types accessed, geography, service, etc.). This is a deterministic, rule-based suggestion — no AI — shown as a draft with a short rationale line per dimension. Nothing is saved: review and adjust each value, then click Save IRQ to apply.
3
Click Save IRQ
The saved score derives a Criticality Tier automatically: Low (0–24) · Moderate (25–49) · High (50–74) · Critical (75–100). Tier thresholds and labels are configurable in Org Settings.
4
Override the tier manually (optional)
Toggle Set tier manually to pin a tier regardless of the IRQ score — useful when a qualitative factor (e.g. a breach history) should override the math. Turn it back off and save to clear the override.
Low · 0–24 Moderate · 25–49 High · 50–74 Critical · 75–100

3 Documents & Contracts

📄 Documents tab
  • Title, Document Type (SOC2, ISO27001, PCI-AOC, PenTest, Insurance, DPA, Other)
  • Effective Date + Expiry Date, with a configurable expiry alert buffer (default 30 days)
  • Attach a file directly, or add it later
  • Status pill: Valid · Expiring Soon · Expired
📝 Contracts tab
  • Title, Start / End / Renewal dates
  • Auto-renew toggle and Annual Value ($)
  • SLA / KPI Terms and free-text notes
  • Edit or delete any contract from the row
💡
Expiry & renewal reminders — a scheduled scan flags documents nearing their expiry buffer and contracts approaching renewal so you're never surprised by a lapsed cert or an auto-renewing contract.

4 Risks/CAPA tab

ℹ️
Coming soon: the Risks/CAPA tab is reserved for a roll-up of every risk and corrective/improvement action raised against this vendor — reachable today from a failed assessment finding (see below), but not yet aggregated in-tab. Use the Risk Register and CA / CI pages directly in the meantime.
Both Platforms

Questionnaire Builder

Build and manage the due-diligence questionnaires you send to vendors. RiskABC ships with system templates you can use as-is or clone to customize.

1 System templates

  • VSAQ, CAIQ, and AI Vendor Questionnaire ship pre-built and marked System
  • System templates are read-only — you can View their questions, but not edit or delete them
  • Click Clone to customize to make an editable copy in your org's Custom Templates list
💡
Explain-on-No — any Yes/No or Yes/No/N/A question now shows a required "Please explain" text box whenever the vendor answers No or N/A, so they justify the answer inline. This cuts down the follow-up "needs more info" back-and-forth.

2 Editing a custom template

1
Click Edit on a custom template
Or + New Template to start from scratch — Name (required), Description, Version.
2
Click + Add Question
Domain and Ref Code (e.g. IAM-01) group and label the question
Prompt (required) and optional Help Text
Answer Type — Yes/No, Yes/No/N/A, Single choice, Multi-select, Free text, Number, File upload
Risk Direction — Yes = Good or No = Good (which answer lowers risk)
Weight (1–10) and Required
3
Add answer options (Single / Multi only)
Each option has a stored Value, a displayed Label, and an optional Score.
4
Set up conditional branching (optional)
Pick a Parent question and a trigger value — this question only appears to the vendor when the parent's answer matches.
5
Add Framework References (optional) & reorder
Pick a Framework from the dropdown of your configured frameworks (a select — not free text), then type the Control ref (e.g. A.9.1.1) for traceability. Add several with + Add reference. Use the up/down arrows to reorder questions within a domain.
⚠️
Can't delete a template? A template in use shows: "Cannot delete: this template is used by N assessment(s). Delete or reassign those assessments first." Clear out or reassign the assessments, then delete.
Both Platforms

Vendor Assessments

An assessment is one filled-out questionnaire tied to one vendor — the full due-diligence cycle from send to score to Finished.

1 Create & send

1
From a vendor's Assessments tab, click + New Assessment
Pick a Template (required), an optional Title, the vendor's email (needed for the external portal), and a Due Date. Click Create & Fill — the assessment starts as Draft.
2
Fill it yourself, or send it to the vendor
Fill / View opens the assessment for your team to answer internally. Send link emails the vendor a magic link into an external vendor portal so they can answer it themselves — no account required.
3
Status moves to Answered
The first saved answer (from either side) auto-advances DraftIn Progress. Once the vendor submits, the status shows Answered (stored internally as Submitted).

2 Reviewing answers

1
Set a per-answer verdict
For each question, choose Pass · Fail · N/A · Needs info. Choosing Fail reveals a Severity field (Low / Moderate / High / Extreme) and a reviewer note.
2
Click Save Reviews
Any vendor clarification text appears read-only under the question once they've responded.
3
Request info if you flagged Needs info
Click Request info (enabled once at least one saved verdict is Needs info) to re-mint the vendor's magic link and email them a clarification request. Status moves to Info Requested until they respond.

3 Raising a Risk / CAPA from a finding

1
+ Raise Risk (appears once a saved verdict is Fail)
Creates a risk that carries the vendor, the question and its ref code, the vendor's answer, and your reviewer note as its description. Severity maps to inherent Probability/Impact; treatment is always Mitigate.
2
+ Raise CAPA (appears once a risk has been raised)
Creates a linked corrective/improvement action from the same finding detail. Once raised, the question shows Risk raised / CAPA raised chips instead of the buttons.

4 Recording a decision

1
Review the suggestion
After Compute Score, a Decision panel shows a Suggested Risk Level (Low / Moderate / High / Critical) and a Suggested Outcome (Pass / Fail / Review) with a bulleted list of reasons.
2
You make the call
The suggestion is advisory only — it is never applied automatically. The suggested option is emphasized as the primary button.
3
Record the outcome
Optionally type a note (rationale or conditions), then click Pass or Fail. The recorded decision is stamped with the outcome, who recorded it, and when, and shows the note — an audit trail of the sign-off.
ℹ️
"Score first" / "Unscored" appears until the assessment has been scored.

5 Scoring & Finished

1
Click Compute Score
Derives per-domain scores plus an overall residual score and residual tier from the saved verdicts.
2
Set Override (optional)
Enter a score (0–100) and a required Justification, plus optional Approved By and Expiry. A self-approval warning appears if you name yourself as approver.
3
Auto-advances to Finished
Once a residual score exists and every question has a saved, non-blank, non-Needs info verdict, the assessment automatically promotes to Finished (shown in green) — no manual step needed.
💡
Higher score = more residual risk — same convention as the vendor's IRQ score and criticality tier.
Both Platforms

Vendor Management Portal

The Vendors page is split into three lifecycle-driven views — a live portfolio overview, vendors you already work with, and vendors you're still evaluating — each organized and scored differently so you can manage the full third-party lifecycle from shortlist to onboarding.

1 Portfolio Dashboard

The Dashboard tab is a live portfolio overview of your active vendors.

  • Total Vendors
  • Critical / Top-Tier count (red when > 0)
  • Reassessments Overdue
  • Docs Expiring in ≤ 60 days (with an "expired" sub-count)
  • Contracts Renewing in ≤ 60 days
  • Assessments In Progress

Below the KPIs: a Vendors by Criticality donut (hover a slice or legend row to swap the center readout) paired with a criticality detail panel (per-tier proportion bars + a one-line concentration insight); a Critical / Top-Tier Vendors highlight table; and a full portfolio table grouped by category (Uncategorized last) with columns for Criticality, IRQ, Latest Assessment, Next Reassessment (turns red and shows "(overdue)" when past due), Docs (expired/expiring badges), and Next Renewal.

ℹ️
Until a vendor is added (or a prospective candidate is moved to Active), the Dashboard shows a "No active vendors yet" empty state.

2 Dashboard, Existing & Possible tabs

The Vendors page opens on a Dashboard tab and has three top tabs — Dashboard, Existing, Possible. Dashboard is the live portfolio overview above. Existing lists your active, onboarded vendors grouped by category. Possible lists prospective vendors you're still evaluating — a candidate shortlist. Switching between Existing and Possible filters the register by lifecycle stage (Active vs Prospective) rather than showing a separate list.

3 Categories & Evaluation Groups

🗂️ Categories (Existing tab)
  • Sort existing vendors into categories like IT, HR, Security, etc.
  • Category is a combobox — pick an existing category or type a new one; free entry is always allowed
  • The Existing table groups rows by category, with an Uncategorized group shown last, plus a Category column
🥊 Evaluation Groups (Possible tab)
  • Prospective vendors are organized into evaluation groups
  • Evaluation Group is a dropdown of groups already created, and always allows creating a new group by typing
  • When setting up a group, choose the assessment template to send to its candidates — falls back to the built-in VSAQ template if none is chosen

4 Scorecards & the fighting ring

Each candidate in an evaluation group shows a scorecard so you can compare potential vendors side by side and pick the best fit for your needs and risk acceptance — nicknamed the fighting ring.

  • Assessment completion — answered vs. total questions
  • Residual risk score and tier
  • Count of risk flags
  • Count of critical flags (high-weight risk answers)
💡
Lowest score wins — the best-fit candidate (lowest residual risk score) is highlighted, and a recommendation banner calls it out. Same convention as elsewhere: a lower residual score means a better, lower-risk candidate.

5 Running a preliminary assessment

1
Start the assessment from a candidate
One click sends the group's chosen questionnaire — or VSAQ by default if the group didn't set one.
2
Scorecard populates once scored
Completion, residual score/tier, and flag counts fill in on the candidate's card as answers come back and get reviewed.
3
Record a decision
Choose Select or Reject on each candidate. Decision states: Pending · Selected · Rejected · Deferred.
Both Platforms

Policies

Track your organization's security policies with version control, review dates, and direct links to the controls they support.

1
Click + Add Policy
Open Policies in the sidebar and click the add button.
2
Fill in the basics
Enter the policy Name, select its Document Kind (Policy, Procedure, Standard, Guideline, Work Instruction, Framework, Plan), and its Topic Area (e.g. Information Security, Access Control, Supplier Security).
3
Set the owner and review date
Pick an Owner (by job title) and a Review Date. The system emails a reminder when the review date approaches.
4
Attach the document (optional)
Drag & drop or click to upload the policy file (PDF, DOCX, XLSX). Once saved, anyone with access can download it from the detail panel via Download document.
5
Link to controls
Use the Linked Controls picker to associate this policy with the specific controls it satisfies. Linked policies appear in the control detail panel.
⚠️
Policies migrated from a prior system may show a file name with no downloadable binary — delete and re-attach the file to fix this.
💡
Policy lifecycle: Policies move through DraftUnder ReviewApprovedExpired. Expired policies show as a warning on the dashboard. The header summarizes counts by status (Draft, Under Review, Approved, Expired) plus how many are due for review within 30 days. Review dates are color-coded: red = overdue, orange = ≤ 30 days, yellow = ≤ 90 days. A red in SoD violation pill counts any policy currently approved by its own owner.

2 Reviewers & the Approve / Reject flow

A policy can't be dragged into Approved from the status dropdown — that status is only ever set by a formal decision.

1
Assign reviewers
In the policy detail modal, pick one or more Reviewers from your org's user list. Changes save immediately — no Save button needed.
2
Approve or Reject
An assigned reviewer, an Org Admin, or a Privileged Consultant can click Approve or Reject. Approving records the approver's name and today's date and moves the status to Approved automatically.
⚠️
Segregation-of-duties check: a policy's owner cannot approve their own policy — approving flags a red "Segregation of duties violation" banner unless your org has enabled owner self-approval in Org Settings. Re-approve with a separate approver, or re-enable the override.

3 Version history

Every policy carries a version number (set on creation, e.g. 1.0). The detail panel's Document version history section lists all uploaded versions and lets editors Upload a new version — the newest becomes the current file while prior versions remain on record for audit. The list and detail show the current version label.

Both Platforms

Evidence Library

The Evidence Library is a central store of all proof that your controls are implemented. Every piece of evidence is linked to one or more controls, and uploaded files are stored securely for integrity.

risk.risk-abc.com / evidence
Controls
Evidence
Policies
18 evidence items + Upload
TypeTitleControlDate
Policy Doc Information Security Policy v2.1 A.5.1 Apr 2026
Screenshot MFA enabled — all admin accounts A.8.5 Apr 2026
Artifact Pen test report Q1 2026 A.8.8 Mar 2026
1
Click + Upload Evidence
From the Evidence page or directly from a control detail panel.
2
Enter a title and choose the type
Title is required. Choose from: Policy Doc · Screenshot · Artifact · Text Description · Test Result · Certificate. The type determines the color badge shown.
3
Select the linked control
Use the control picker to link this evidence to one or more controls. This is what makes the evidence count go up on the Controls page.
4
Upload a file (optional)
Attach a PDF, image, or document. Uploaded files are stored securely for integrity. The detail panel shows the file name, size, and type.
5
Validate the evidence
Assign one or more Reviewers in the detail panel (saves immediately). An assigned reviewer, an Org Admin, or a Privileged Consultant can then click Validate, which stamps their name and date. Validation can later be undone with Revoke validation. Validated evidence carries more weight in audits.

1 What evidence can connect to

A single piece of evidence can support more than controls — it can also attach to Risks (from the Risk Register), CA/CI items, and Tasks. The detail panel lists every Connected Control, Risk, CA/CI, and Task, and editors can Unlink any of them here. Attach evidence to a risk/CA-CI/task from that item's own detail panel; it then appears back on the evidence record.

2 Version history

Evidence files are versioned — the detail panel's Document version history lets editors upload a newer file while keeping earlier versions on record. The most recent upload becomes the current downloadable file.

Both Platforms

Business Impact Analysis (BIA)

The BIA module captures recovery requirements for each critical business process. Use it to feed your continuity planning and meet ISO 22301 and CMMC requirements.

ℹ️
Six-tab editor — The Add/Edit Process modal is split into six tabs: Overview (identity, RTO/RPO/MTD, tier), Continuity (recovery strategies + SPOFs), Impact Matrix (impact by time window), Dependencies (applications, inputs, outputs), People & Vendors (key personnel + supplier contacts), and Gaps. Fill the tabs that apply; only Process Name is required to save. The list page also shows summary cards — Total Processes, Tier 0 / Tier 1 counts, and Avg RTO.
1
Open BIA from the sidebar
Click BIA. You'll see any existing business process entries and an + Add Process button.
2
Set the process identity on the Overview tab
On the Overview tab set the process Name (required) plus Description, Department, Owner, Frequency (Daily/Weekly/Monthly/Quarterly/Ad-hoc), who it Serves, normal FTE count, FTEs needed during a disaster, and whether it can be performed remotely.
3
Set the Criticality Tier
Choose from Tier 0 (Mission Critical) down through Tier 3 (Deferrable) — defaults are Tier 0: Mission Critical, Tier 1: Essential, Tier 2: Important, Tier 3: Deferrable. Tier names can be customized in Org Settings.
4
Set RTO, RPO, and MTD
RTO — Recovery Time Objective: how fast you must recover (hours)
RPO — Recovery Point Objective: how much data loss is acceptable (hours)
MTD — Maximum Tolerable Downtime: longest acceptable outage (hours)
5
Document recovery strategies
On the Continuity tab, record your Current recovery strategy plus alternatives for four scenarios: loss of applications, loss of building/power, loss of phones, and loss of staff. List Known single points of failure (SPOFs).
6
Rate the impact matrix
On the Impact Matrix tab, rate disruption impact across five categories (Financial, Compliance, Operations, Reputation, Information Security) for four time windows (0–4h, 4–24h, 1–3 days, 3+ days). Each cell is None / Low / Medium / High / Very High, color-coded. These ratings drive automatic risk generation and, on import, auto-derive the criticality tier.
7
Add dependencies and key personnel
Use the Dependencies tab (Applications section) and the People & Vendors tab to list what this process depends on. Pick a cataloged application (from Asset Inventory) or vendor (from the Vendors catalog) from the dropdown to live-link it and auto-fill its details, or type a free-text entry. A linked row shows a Linked to catalog badge. If you manually edit an auto-filled field, your edit is preserved as an override even when the underlying asset/vendor changes; unedited fields re-sync from the source each time you reopen the process. Clearing the name so it no longer matches a catalog entry drops the link.
8
Log gaps
On the Gaps tab, record any gaps between current capability and your recovery targets. Each gap has a Description, Action item, Assignee, Due date, and Status (Open / In Progress / Closed). Every open gap automatically spawns a Task (assigned to its assignee, with the due date) and a linked corrective action in CAPA. Setting the gap to Closed removes the Task; the CAPA is kept.
💡
Blank recovery strategy raises a risk — Leaving Current recovery strategy (on the Continuity tab) blank auto-raises a risk in the Risk Register.
💡
Auto-generated risks — Saving a process opens a linked Risk Register entry when either any impact-matrix cell is Medium or higher, or no current recovery strategy is defined. The risk is named [BIA] <process name>, set to Mitigate/Open with a 90-day review date, and its impact scales with the matrix severity. Deleting the BIA process removes the auto-risk (and its tasks).
💡
Completeness flagging — A process missing core recovery essentials (RTO, RPO, MTD, current recovery strategy, criticality tier, owner, or an all-None impact matrix) raises a single "Complete BIA process: <name>" Task for the owner, listing which fields are blank; it clears once every field is filled. Turning on Comprehensive BIA flagging in Org Settings also requires application dependencies, process inputs, outputs, key personnel, vendors, and at least one alternative recovery strategy.

9 Bulk-loading processes from XLSX

If you've already documented your processes in a spreadsheet — or you're migrating from another tool — skip the manual entry and use the import flow.

1
Click Import on the BIA page
A modal opens explaining how the import works.
2
Download the template (first-timers)
Click ↓ Download Template to get a pre-formatted XLSX with every supported sheet and column. Fill it in offline.
3
Choose your file and upload
Click Choose File… and select your XLSX. The parser reads the Business Processes and RTO sheet to create processes, then walks the other sheets (Standard Applications, Vendors, Key Personnel, Process Inputs/Outputs/Impacts) to attach data to each process by name.
4
Cross-sheet matching is automatic
If your workbook has a wider Critical Processes and RTOs sheet, RPO and MTD values from there are pulled in by matching Business Unit + Application Name — handy when process names diverge between sheets.
5
Review the import summary
After upload you see how many processes were created and any warnings — e.g. a row in the Vendors sheet that didn't match an existing process. Fix the spreadsheet and re-import, or add the missing process manually.
6
Criticality tier is auto-derived
If you don't set a tier, the parser walks the impact matrix and assigns one — Very High → Tier 0, High → Tier 1, Medium → Tier 2, otherwise Tier 3. You can override it later from the process detail screen.
💡
Made a mistake? Use the Select button on the BIA list, tick everything you want to remove, then click the Delete button (it shows the count of selected items). Bulk delete cascades — auto-generated risks and their open tasks disappear with the parent process. Restricted to Org Admin and Privileged Consultant.
Both Platforms

Tasks

Tasks are the platform's work queue. Some are entered manually; others appear automatically when a risk crosses your acceptable threshold.

1 Where tasks come from

  • Auto from risks — any risk with a residual score above your org's acceptable threshold opens a task automatically. An auto-flagged task inherits the risk's tier as its priority and shows it in that tier's color, so the queue mirrors your heat-map bands. Bring the residual back below threshold and the task closes itself.
  • Manual — click + New Task on the Tasks page to create one yourself: title, description, assignee, priority (the dropdown lists your organization's configured risk tiers, so a task's priority reads in the same language as your risk register), due date.
  • From CA / CI — closing a corrective or improvement action linked to a task auto-completes that task (Done if Closed, Dismissed if Cancelled).

2 Working a task

1
Open Tasks from the sidebar
Status filter pills run across the top — Open / In Progress / Done / Dismissed.
2
Click any row to edit
Update assignee, priority, due date, or move the status forward. Status changes log to the audit trail.
3
Use Re-sync from risks if needed
If you've changed your acceptable threshold and want every existing risk re-evaluated, click this once — the system opens new tasks for any risk now above threshold and dismisses tasks for risks now below.
Overdue badge — any Open or In Progress task past its due date shows the due date in red with a bold Overdue pill in the Due column, so a stale task never blends into the list.
ℹ️
Evidence on a task — Open any saved task and scroll to the Evidence section. Link existing library items or add a new one inline (title, type e.g. Text Description, optional control link) so the proof the work was done travels with the task. Only editors can add or unlink evidence.
📧
Two email touchpoints, not one — a consolidated assignment digest fires within hours of being assigned multiple tasks (no flood of one-per-task emails). Separately, a daily task-digest email goes out each morning to every user who has at least one Open or In Progress task: a single email listing all of them, with any overdue task called out.
Both Platforms

CA / CI — Corrective & Improvement Actions

Where Tasks track the work, CA / CI tracks the investigation behind the work. Use it to document root cause, the fix, and the proof that the fix held.

1 Corrective vs. Improvement

🛠 Corrective Action (reactive)
  • Triggered by an incident, audit finding, or non-conformity
  • Aim: stop the bleeding, then prevent recurrence
  • All five narrative fields usually filled in
📈 Continuous Improvement (proactive)
  • Triggered by an idea, KPI miss, or routine review
  • Aim: improve a process that already works
  • Containment + root cause may not apply

2 Filling out an action

1
Open CA / CI from the sidebar
Sits directly under Tasks. Click + New CA / CI.
2
Pick the kind
Corrective or Improvement. The form is the same — just labels for filtering.
3
Fill the five narrative fields
Root cause — what really caused it
Containment — what you did immediately to limit damage
Corrective action — what you're doing to fix it
Preventive action — what you're doing so it doesn't happen again
Effectiveness check — how you'll prove the fix held
4
Link a Task (optional)
Pick an existing task to tie this CA / CI to it. Closing the action will auto-complete the linked task; cancelling it dismisses the task.
5
Move through the statuses
Open → In Progress → Pending Verification → Verified → Closed. To Close, both Corrective Action and Effectiveness Check must be filled in.
6
Attach the proof
The Evidence section at the bottom of a saved action lets you link existing library evidence or create a new item inline. This backs your Effectiveness Check: attach the test result, screenshot, or memo showing the fix held, so the closed record is audit-ready on its own.
7
Verifier signs off
Once status is Verified, the page shows a green "Verified by … on …" banner. That's your audit-ready record that the effectiveness check passed.

The workflow row on each action captures:

  • Process Owner — free-text role accountable for the process (e.g. CISO, QMS Manager); distinct from the assignee
  • Assignee — the platform user doing the work
  • Priority — Low / Moderate / High / Extreme (a fixed four-level scale, not your configured risk tiers)
  • Target Date — when close-out is due
ℹ️
Who can close? Closing requires Compliance Officer or higher. In RiskABC ISO this is tighter than the edit permission — Risk Manager can edit a CA / CI but not close it.
Both Platforms

Reports & Export

Two related but separate places: Reports & SOA is a live, on-screen dashboard of your current posture; Exports is where you generate a downloadable, timestamped snapshot to hand to an auditor.

1 Reports & SOA — on-screen only

1
Open Reports & SOA from the sidebar
Three tabs run across the top: Statement of Applicability (labeled POA&M in CMMC frameworks), Risk Report, and Executive Summary.
2
Everything here is live and on-screen
Charts and tables update in real time as your data changes. There's no export button on this page — for a downloadable, dated file, use Exports (below).

2 Exports — downloadable PDF snapshots

Open Exports in the sidebar to generate a timestamped PDF you can hand to an auditor or file away — every export is preserved as a point-in-time record.

📦 Available export types
  • Statement of Applicability (SOA)
  • Risk Assessment (full register, inherent + residual)
  • CA / CI Register
  • Asset List
  • Business Impact Analysis (BIA)
  • Overall Compliance Report
  • Vendor Portfolio Report
🗂 History
  • Click Generate on any type — it's added to the History table below
  • Each row shows type, framework, file name, row count, size, generated-by, and date
  • Generating an export requires an edit role — Org Admin, Compliance Officer, Risk Manager, Consultant, or Privileged Consultant. Read-only/auditor and viewer roles can download and view existing exports but Generate is disabled
  • Filter History by export type using the dropdown above the table (defaults to All types)
  • Download any past export at any time
  • Delete is restricted to Org Admin and Privileged Consultant

What's in the Overall Compliance Report (framework-scoped):

  • Readiness Overview — overall implementation % (Implemented / Applicable) plus Total / Applicable / Implemented / In Progress / Not Started stat cards
  • Control Status & Approval breakdowns — Implemented / In Progress / Not Started / Exception, and Approved / Pending Review / Not Reviewed / Rejected
  • Implementation by Domain — per-domain completion table
  • Risk Posture — in-scope risks bucketed by your configured severity tiers, a Treatment Status breakdown, and the Top 8 risks by score
  • Policies & Approvals — every policy with owner, approver, reviewers, current version, approval and review-due dates
  • Document Version History — every policy document version with uploader, date, and note

It respects the Settings "Score Not Applicable controls" toggle — N/A is shown as a separate count unless the toggle is enabled.

What's in the Vendor Portfolio Report (organization-wide):

  • Portfolio KPI cards — Total Vendors, top-tier count, Reassessments Overdue, Docs Expired/Expiring, Contracts Renewing ≤60d, Open Vendor Findings
  • By Criticality Tier breakdown
  • Critical Vendors table
  • Vendor Roster — full roster grouped by category

Covers active vendors only — prospective and terminated are excluded — and criticality is derived from each vendor's IRQ score.

ℹ️
SOA and Overall Compliance Report are framework-specific — they export whichever framework is selected in the sidebar. To export a different standard, switch frameworks first, then click Generate. The other export types (Risks, CA/CI, Assets, BIA, Vendor Portfolio) are organization-wide. The History table's Framework column reflects which framework each SOA/Overall snapshot was for.
⚠️
Export metadata stays in History permanently, but the underlying PDF can be pruned from server storage over time. If Download returns "Export file no longer on disk — re-generate to retain a snapshot", click Generate again. For long-term auditor evidence, download and archive the PDF yourself.

3 Automation — scheduled, emailed exports

Automated exports let you schedule recurring reports instead of generating them by hand. Set up schedules in SettingsAutomation.

1
Open Settings → Automation
Settings is available to Org Admins and Privileged Consultants.
2
Add a schedule
Pick an export type (SOA, BIA, Overall Compliance, Risks, CAPA, Assets, or Vendor Portfolio), a framework (for SOA / Overall), a cadence (Weekly, Monthly, or Quarterly), one or more recipients (yourself and/or other org members), and toggle the schedule active.
3
The report arrives on schedule
On each cadence, the platform generates the export automatically and emails every recipient a secure, login-required link to the Exports page — the file itself isn't attached, recipients sign in and download it. It also lands in Exports History like any other export.
💡
Audit tip: Auditors often want to see the evolution of your compliance posture over time, not just the current state — so keep your SOA and Overall Compliance Report exports in History rather than deleting old ones. Set up SettingsAutomation to generate and email these monthly automatically, no manual effort required.
Both Platforms

Audit Trail

Every meaningful action in the platform is recorded. The audit trail is append-only — nothing can be edited or deleted once written.

1 What gets logged

  • 10 action types — CREATE, UPDATE, DELETE, LOGIN, LOGOUT, EXPORT, UPLOAD, APPROVE, REJECT, VIEW
  • Who — user name and email
  • When — timestamp to the second
  • Where from — source IP address
  • Result — success or failure with reason

The top of the page shows four at-a-glance counters — Total Events, Failures, Logins in the last 24 hours, and Changes in the last 24 hours (creates, updates, deletes). Failed events are also highlighted with a red row.

2 The diff modal — what changed and what it was

UPDATE rows go beyond "X edited Y." Click any update row and you see a side-by-side, field-level table of what changed — old value in red on the left, new value in green on the right.

1
Open Audit Trail from the sidebar
You'll see a paginated table of every action. Filter by action type, resource type, or user; narrow to just Success or Failure results; or type in the search box to match across event description, user, and resource type. Filtering also updates the event count at the top of the table.
2
Click an UPDATE row
A modal opens showing the field-by-field diff. Only fields that actually changed are listed.
3
Read the diff
Old value highlighted in red on the left, new value in green on the right. Empty or unset values show as an em dash (—).
🔒
Who can see diffs? The diff modal is restricted to Org Admin and Privileged Consultant — the rest of the audit trail is visible to everyone with audit access. Entries with nothing to show (pre-migration rows, or actions like LOGIN/VIEW/DELETE that don't snapshot field state) display "No diff captured for this entry."
Both Platforms

Org Settings

Settings lets Org Admins customize the platform to match your organization's terminology and risk appetite.

ℹ️
Subscription & Billing — Settings opens with a Subscription & Billing card. Click Manage Subscription to jump to the Onboard portal (onboard.risk-abc.com) to add seats, manage users, and handle billing/renewals.
  • Review Reminders — Choose the document-review buffer (15, 30, 45, 60, 75, or 90 days; default 30). Document owners are notified this many days before a policy's review date
  • Risk Severity Tiers — Define 2–6 tiers with custom labels, colors, and contiguous score ranges. The lowest tier starts at 0, the top is open-ended; scores run 0–34
  • Risk Acceptance Threshold — Risks scoring above this value are auto-flagged (a Task in RiskABC, POA&M in Gov). Default 16; set to 100 to disable flagging. Changing it immediately re-scans all risks and adds/removes flags
  • Asset Classification Tiers — Define 2–6 sensitivity tiers (least → most sensitive) with labels and colors; existing assets keep their stored value
  • BIA Criticality Tiers — Define 2–6 tiers with labels and colors; Tier 0 (first) is the most critical
  • Editing tiers — Add or remove tiers with + Add / ; every tier picks a color swatch
  • Vendor Criticality Tiers — Customize the labels, colors, and IRQ score cutoffs for Low / Moderate / High / Critical vendor tiers
  • Asset sharing — Share your asset inventory read-only with your Gov workspace
  • Approval — Separation of Duties — Toggle whether the same person may approve their own submission, covering both policy approvals and SOA approvals (document-level and per-control); off by default (see Policies and SOA Approval & Versioning)
  • Score Not Applicable controls — Toggle whether Not Applicable controls can still be scored and count in dashboard stats
  • Comprehensive BIA flagging — Off (default) checks only core recovery fields — RTO, RPO, MTD, recovery strategy, criticality tier, owner, and impact matrix. On also flags empty dependency, input, output, key-personnel, vendor, and alternative-strategy sections (cross-links to BIA)
  • SOA Approval Mode — Choose Blanket sign-off (one approval for the whole SOA) or Per-control sign-off (each control approved individually); see SOA Approval & Versioning
  • Export Branding — cover-page logo — Upload a PNG or SVG (max 2 MB); it renders ~140×60 pt on the export cover, so use a wide-format logo. Remove it any time to revert to the RiskABC logo
  • Export Branding — use the document title as the bold header — Replaces and hides the "RiskABC Export" line
  • Export Branding — hide the tool line — A separate toggle that removes the "Tool: RiskABC ISO 27001+ Platform" line. Branding applies to every PDF export
  • Automation — Set up scheduled, emailed recurring exports (see Reports & Export → Automation)
ℹ️
Who can change settings? Settings can be edited by Org Admins and Privileged Consultants. Other roles see the values read-only ("You do not have permission to change these settings").
Both Platforms

Users & Roles

New user invitations happen centrally in the Onboard portal. Day-to-day role and job-title changes for existing users happen in-app, on the User Management page. Each user is assigned a role that controls what they can see and do within each platform.

1
Open User Management from the sidebar
Visible to Org Admin only. Role cards across the top show a live headcount per role. The table below lists every user with email, job title, role, MFA status (Enabled or Off), and last login time — so you can spot users without MFA at a glance. Click a user to open a detail panel showing when they joined, last login, and MFA status, plus role and job-title controls.
2
Click a user to change their role or job title
Pick a new role from the dropdown and click Update Role. Job title is edited separately and saves immediately — pick from your org's existing titles or add a new one.
ℹ️
Inviting a brand-new user still happens on the Onboard portal — there's no in-app "create user" button. Once invited and activated, that user shows up on User Management for role and title changes.
Role View Edit Controls Edit Risks Upload Evidence Manage Users Change Settings
Org Admin
Compliance Officer
Risk Manager (ISO only)
Consultant
Evidence Owner (Gov only)
Privileged Consultant
Auditor
ℹ️
Consultant vs Privileged Consultant — day-to-day the two look alike: both can view and edit controls, risks, and evidence. The difference is elevation. A Privileged Consultant can also change Settings, review and approve the SOA, and bulk-delete records — the admin-level role for a consultant who runs a client's program end to end. A plain Consultant does the hands-on work but none of those.
ℹ️
Changing roles — Only your Org Admin can set account types and role assignments from the in-app User Management page.
Both Platforms

Support & Feedback

Report a bug, share feedback, or request a feature — it goes straight to the RiskABC team.

1
Open Support & Feedback
Click Support & Feedback in the sidebar.
2
Pick a type
Choose Bug report, Feedback, or Feature request from the segmented toggle.
3
Write it up
Enter a Subject (required, up to 200 chars) and a Message (required, up to 5000 chars — a live character counter is shown).
4
Send
Click Send. On success you see a confirmation and a Send another button.
ℹ️
Submissions are tied to your account and org automatically — you don't need to identify yourself. When you file a bug report, you pick which page you were on when you saw it, so the team can reproduce it.