RiskABC ISO RiskABC Gov

User Guide

Everything you need to get up and running. Step-by-step walkthroughs for both the ISO and Gov platforms.

Both Platforms

Signing Up & Subscription

Signup happens at onboard.risk-abc.com. Pick the standards you need, set your seat count, and accept the legal documents. We review each request and send an invoice; your account opens once that's settled. Renewals are managed from the same surface.

1 Create your organization

1
Go to onboard.risk-abc.com
Step 1 asks for three things - Company Name, Your Name, and Email Address. Use a work address: a personal domain (gmail.com and the like) raises a confirmation prompt before you can continue.
2
Choose your seats and frameworks
Step 2 sets your seat count and your starting frameworks. Pick at least two of the 11 supported standards - all 11 are included in the price, so the rest are yours to turn on at any time for free. The running annual total is shown as you go.
3
Review and accept the legal documents
Step 3 shows a summary of everything you've chosen alongside the Terms of Service and the End User License Agreement. Both must be accepted to submit. Signed copies are linked in your confirmation email and stay available from your account.
4
We review your request and invoice you
Submitting sends you a confirmation email straight away. Accounts are not opened automatically - we review each request and send an invoice for your first annual term. Reply to that email with any questions.
5
Activate your account
Once your account is opened you receive a Welcome to RiskABC email with a Set Password & Enable MFA button. That is a one-click activation link; it expires after 72 hours. Click it, choose a password (minimum eight characters), accept the Terms of Service and EULA if you have not already, then sign in. Next you enroll a passkey (Face ID, Touch ID, Windows Hello, or a security key) in Chrome, Edge, or Safari. Authenticator-app codes are not a fallback. If you cannot enroll a passkey, reach out to RiskABC Support at support@risk-abc.com.

2 Managing seats & renewals

  • Add seats mid-year - prorated to your renewal date, no need to wait
  • Invite users by email - they receive a one-click activation link
  • Renewal notice emailed to your Org Admins 30 days before your renewal date, with the seat count, any Gov add-ons and the total for the coming year. Accounts billed through a partner agreement don't receive this - your partner handles renewals.
  • Annual term is locked in once paid - no mid-term cancellations. Downsizes and cancellations take effect at your next renewal date
  • Free auditor seats - read-only access for external auditors doesn't consume a seat
ℹ️
Need to talk to a human first? Skip the self-serve flow and book a demo - we'll set up a sandbox org so you can explore the platform with your real frameworks before you commit.
Both Platforms

Getting Started

Both RiskABC and RiskABC Gov use the same single sign-on (SSO) system. One account gives you access to every platform your organization is subscribed to.

1 Logging In

1
Go to the sign-in portal
Open sso.risk-abc.com. The heading is Sign in to your account - one portal for both RiskABC and RiskABC Gov. Product apps you open while signed out send you here with a return link.
2
Enter your email address and password
Both go on the same form - type your work email and password, then click Sign in. There is no passkey button on this first screen. If you've forgotten the password, click Forgot password (see below).
3
Confirm it is you with a passkey
After the password succeeds, the portal asks you to confirm with a passkey if one is already enrolled - Face ID, Touch ID, Windows Hello, or a security key. Authenticator-app codes are not a fallback once a passkey exists, or after your enrollment deadline. Use Chrome, Edge, or Safari. If the device is gone, reach out to RiskABC Support at support@risk-abc.com to enroll again.
4
Choose your organization and product
You land on a chooser, not the product dashboard. Pick the organization, then RiskABC or RiskABC Gov. That launches the app. On first visit after a launch, controls load in the background so the dashboard has something to show.
sso.risk-abc.com
RiskABC
Sign in to your account
Use your organization email
Email
you@organization.com
Password
••••••••
Sign In
Forgot password?
💡
First time (new organization)? Your Org Admin's welcome email is the activation link: Set Password & Enable MFA, 72 hours, then a password on every later visit. Invited teammates get their own activation email from the Onboard portal (not a passwordless sign-in). After that first set-password click, everyone types email and password, then confirms with a passkey.
ℹ️
Forgot password - the page is titled Reset your password. Enter your email. The next screen always says Check your email (even if that address is unknown, so a stranger cannot probe who has an account). The link lasts 1 hour; check spam if it is missing. New password: minimum eight characters. If this is the first time you have set a password, you also tick the Terms of Service and EULA. Too many reset requests: wait 15 minutes. After the password is saved you are sent back to sign in, and MFA still applies for roles that require it.
ℹ️
How long a session lasts - the access token is 15 minutes. About 30 seconds before it expires, a banner in the bottom-right refreshes it for you (or you click Refresh now). Privileged, Gov, and consultant refresh cookies last 24 hours; everyone else 7 days. A failed refresh returns you to SSO. Log out still ends every session on every device.
💡
The release greeter - The first time you sign in after a release, a welcome window opens naming the release and highlighting what's new in it. For 2026-09 Boysenberry Bear that's Business Continuity, audit findings opening CA/CI, auto-filled Audit results in Management / Program Review, passkeys, dashboard widget sizes, vendor renewal dates, and files on CA/CI and BCP paperwork. Click Read the guide to jump here, or Take a look (or the ✕) to dismiss it - it won't return until the next release. It appears once per person, so consultants managing several client orgs see it a single time, not once per org.
Both Platforms

Dashboard

The dashboard gives you an instant snapshot of your compliance posture - control completion, risk exposure, and items needing attention.

risk.risk-abc.com / dashboard
Dashboard
Controls
Risk Register
Assets
93
Total Controls
24
Implemented
8
High Risk
12
Risks Open
Implementation by Domain
A.5 Org
65%
A.6 People
40%
A.8 Tech
28%

What each stat means:

  • Total Controls - Total controls in the selected framework
  • Implemented - Complete with evidence; shows "of N applicable" on SOA frameworks, "of N total" otherwise. On Gov this tile is named Completed and carries no sub-line.
  • In Progress - Controls partially implemented
  • Not Started - Controls not yet begun
  • High/Extreme Risks - Open risks scoring in your top severity tiers. On Gov this tile is named High Risk.
  • Policies Due Review - Policies past their review date (shown in purple). RiskABC only.
  • Gov Exceptions - Gov Key Metrics are six tiles: Total Controls, Completed, In Progress, Not Started, High Risk, and Exceptions. There is no applicable-count sub-line on those tiles.

Charts:

  • Implementation by Domain (RiskABC) - stacked bar of Implemented / In Progress / Not Started per domain.
  • Gov Completion by Domain - Completed vs Remaining (total minus completed). In Progress is not a separate series.
  • Control Implementation - A donut with your overall completion % in the center, split Implemented / In Progress / Not Started / Exceptions. On Gov this card is titled Overall Completion and its first slice reads Completed.
  • Risk Register - A donut breaking open risks down by severity tier (plus a "Not Assessed" slice), with total and open counts in the header. On Gov this card is titled Residual Risk Distribution. With no scored risks the Gov card unmounts; RiskABC shows No risks recorded.
ℹ️
Compliance Overview is a full workspace at /overview, not a poster. Org-wide roll-up tiles (implementation %, open risks, open tasks, open CA/CI), a Where to focus next list, then a card per subscribed framework sorted by lowest percent first, with jumps to Controls or Dashboard. Gov cards omit the Not Applicable / SOA chips that ISO cards show when the framework uses a Statement of Applicability. The dashboard Add widget item also named Compliance Overview is a compact percent list - a different surface. Open the real page from the Compliance Overview control on the dashboard, not from Preferences.

1 At a Glance RiskABC only

A grid of clickable shortcuts - Information Assets, Open Risks, Policies, Evidence Items, and Exceptions (plus N/A Controls on SOA frameworks). Each tile shows a live count and opens that module. Gov has no At a Glance grid; use the sidebar to reach the same modules.

2 Third-Party Risk panel

When vendors exist, the dashboard shows a Third-Party Risk panel - Total Vendors, Open Findings, Overdue Assessments, and Certs Expiring (30d) tiles, plus a Vendors by Criticality Tier breakdown. Click a criticality chip to expand that tier (the vendor list loads on first expand); each row opens Vendors. Click the same chip again to collapse it. If any vendor findings are open in the risk register, a red alert banner appears at the top of the panel. View all vendors jumps to the Vendors module.

3 Frameworks grid

Cards for every framework available to you. Click a licensed framework to select it and jump to its Controls. Frameworks not in your plan appear locked; clicking one opens a Contact Sales prompt. If your org also has RiskABC Gov, a CMMC 2.0 card opens it in a new tab, signing you in automatically. If no frameworks are enabled, the dashboard shows No Frameworks Configured with a Contact Sales button.

💡
Make it your dashboard - Customize lives on the Dashboard (look for the New badge), not under Preferences. Click it and every widget grows a drag handle, Move up / Move down arrows, and a hide button. Chart widgets also get a size control: one column, two columns, or full width (like stretching a home-screen widget). KPI strips, vendor tiles, and framework cards stay full width. The grid adds columns as the window widens, so a domain chart can sit in the same row as the pies. Add widget lists everything not currently on the page - Tasks Due Soon, Top Open Risks, Policy Status, Open CA / CI, Asset Summary, Evidence Summary, Threat Library Summary, Vulnerabilities Summary, BIA Summary, and the compact Compliance Overview widget - each labeled with the section it comes from. Reset to default is the widget reset (sizes included); sidebar Reset is on the Editing menu. Changes save automatically and are yours alone (per product). Customize also unlocks sidebar editing. Click Done when you're finished. Preferences stays Appearance, timezone, and reminder hour only.
Both Platforms

Controls & Statement of Applicability

Controls are the heart of both platforms. Each control maps to a specific requirement in the selected framework. You track status, add evidence, and manage applicability here.

1 Browsing Controls

risk.risk-abc.com / controls
Dashboard
Controls
Risk Register
🔍 Search controls…
Status ▾
Applicability ▾
IDControlStatusApplicabilityRiskEvid
A.5.1 Policies for info security Implemented Applicable 6 - Low 3
A.5.2 Information security roles In Progress Applicable 9 - Mod 1
A.5.3 Segregation of duties Not Started Not Assessed 17 - High 0
1
Open Controls from the sidebar
Click Controls in the left sidebar. All controls for your active framework load in a single table, with a running count of how many match your current filters.
2
Filter by Domain, Status, or Applicability
On RiskABC, domain tiles run across the top of the page showing implemented / total and a percentage for each area - click one to filter the table to it, click it again to clear. Below them, use All statuses to show only Not Started or In Progress controls, and All applicability to pull up everything still Not Assessed, or just your exclusions. On frameworks that use a Statement of Applicability the table carries its own Applicability column alongside Status.

On Gov the table columns are Control ID, Name, Domain, Status, Approval, Risk, Evidence, and Assigned To - there is no Applicability column. Filters: All Domains, All Statuses, Clear filters, plus search. Rows paginate. The Approval column is per-control sign-off, not the blanket SOA pill.
3
Search by keyword
Type any word in the search box to filter controls by name in real time.
4
Click a row to open the detail panel
Clicking any control row slides open a detail panel on the right with the full description, scoring, evidence, and edit options.
⚠️
Gov platform: the Domain filter lists the 14 CMMC / NIST 800-171 domains by two-letter code - AC Access Control, AT Awareness & Training, AU Audit & Accountability, CA Security Assessment, CM Configuration Management, IA Identification & Auth, IR Incident Response, MA Maintenance, MP Media Protection, PE Physical Protection, PS Personnel Security, RA Risk Assessment, SC Sys & Comms Protection, SI System & Info Integrity.

2 Updating a Control's Status

1
Open the control detail panel
Click any control row in the table to open it.
2
Edit in place
There is no edit mode to enter - if you have edit rights the panel's fields are live as soon as it opens. If you don't, the same fields render as read-only text.
3
Set the Status
Choose from: Not StartedIn ProgressImplemented. Use Exception for controls that cannot be implemented.
4
Assign an owner (optional) Gov only
Select the team member responsible for this control from the Assigned To dropdown. Assigning a control to a team member sends them a Task Assigned email automatically. The RiskABC control panel has no assignee field - track control ownership through Tasks there instead.
5
Score the control's risk (Applicable controls)
For Applicable controls the detail panel shows a Risk Score Calculator - set Probability and Impact (1–5) and, on CIA frameworks, Confidentiality / Integrity / Availability (0–3). The score is RS = I × P + (C + I + A) (or RS = I × P where CIA doesn't apply, in which case the CIA selector is hidden) and drives the color-coded tier badge in the Risk column. On RiskABC, Not Applicable controls aren't scored unless an admin enables Settings → Score Not Applicable controls; Gov has no such setting.
6
Save
Click Save Changes. The dashboard stats update immediately.
💡
Best practice: Don't mark a control Implemented until at least one piece of evidence is attached. This keeps your SOA audit-ready.

3 Adding Evidence to a Control

1
Open the control detail panel
Click the control you want to attach evidence to.
2
Scroll to the Evidence section
The lower portion of the detail panel shows all attached evidence and an Add Evidence button.
3
Choose evidence type and add a title
Select from: Policy Doc · Screenshot · Artifact · Text Description · Test Result · Certificate. Enter a clear, descriptive title. Gov offers the first four; Test Result and Certificate are RiskABC only.
4
Policy Doc - link or upload
Choosing evidence type Policy Doc gives two paths: pick an existing policy from the dropdown to link it (the title fills in from the policy name automatically), or leave the dropdown empty and upload a new policy file. Other file types (Screenshot, Artifact, Test Result, Certificate) always upload a file; Text Description needs only a title and description.
5
Attach a file (optional)
Click Choose File to upload a document, screenshot, or certificate. Uploaded files are stored securely for integrity.
6
Save the evidence
Click Add. The evidence count on the control row updates immediately.

4 Statement of Applicability (SOA)

The SOA declares which controls are applicable to your organization and why. Required for ISO 27001 certification.

1
Open the control detail panel
Find the control you want to mark as not applicable.
2
Set Applicability
Applicability has three values - Applicable, Not Applicable, and Not Assessed (the default until you decide); you can also filter the table by any of them. Setting Not Applicable reveals an Exclusion Reason dropdown: Legal/Regulatory, Contractual, Risk Assessment, Business Requirement, Workforce Headcount, or Outsourced (the last two are ISO-27001-specific).
3
Add the justification
Click the Exclusion Justification (or Inclusion Justification) field - it opens a full-width editor. Enter your rationale; it is required (red asterisk) and Save is blocked until it's filled. Notes is a separate, optional field. The justification - not Notes - is what appears on the SOA export.
4
Justify Applicable controls too
When Applicability = Applicable, an Inclusion Reason dropdown (Legal/Regulatory, Contractual, Risk Assessment, or Business Requirement - a shorter list than the exclusion reasons) and an Inclusion Justification field appear. Both are required - Save rejects Applicable controls with either left blank.
5
Generate your SOA report
Open Reports & SOA to read the full Statement of Applicability on screen - every applicable / not applicable decision with its justification. For a dated file to hand an auditor, go to Exports and generate the Statement of Applicability (SOA) PDF for the active framework.
⚠️
Gov by framework, not as one blob: Applicability is locked (display-only, every practice Applicable) only on CMMC 2.0. NIST SP 800-171 and HIPAA keep a live Applicability control and still produce SOA-titled reports. Gov scoring simply has no Not Applicable score option - that is not the same as every catalog being mandatory. On CMMC 2.0, accepted risks still need a Plan of Action & Milestones (POA&M) and must be remediating on a timeline; an accepted risk is not a permanent state.
💡
A head start on the justification - on frameworks that use a Statement of Applicability, opening a control with an empty justification drafts one for you from the control itself: its status and applicability, and the risks, evidence, and policies actually linked to it. A chip under the field says where the wording came from - Suggested · template, Suggested · precedent (reused from a similar control you've already justified, alongside an amber n% match chip), or Suggested · hybrid - next to Regenerate (rebuild it, e.g. after picking a different reason) and Clear. It only ever fills an empty field - anything you've typed is left alone - and the draft is always yours to edit before you save.

5 SOA Approval & Versioning

Formally sign off and version-number your SOA - a common auditor requirement. An org admin chooses the approval mode in SettingsSOA Approval Mode.

1
Choose your approval mode
In SettingsSOA Approval Mode, pick Blanket sign-off (default - one approval covers the whole SOA) or Per-control sign-off (each control is reviewed and approved individually).
2
Blanket mode: Submit for Review
On the Controls page, open the SOA Approval & Versioning panel at the top. Submit is available to Org Admin, Compliance Officer, Privileged Consultant, and Consultant. The change summary is required (cannot be empty). Click Submit for Review.
3
Blanket mode: Approve, Reject, or hold the version
Approve and Reject are Org Admin or Privileged Consultant only - a Compliance Officer cannot stamp. The approver must be a different person unless owner self-approval is on. Approve stamps 1.0 on the first approval. Later, if control values actually changed, you get a minor bump (or a major bump if the approver asks). If nothing changed, the last version is held and a major bump is ignored. Reject returns the SOA to draft with no new version.
4
Per-control mode: Mark Reviewed, then Approve
Open a control's detail panel and find the Sign-off section. Mark Reviewed is Org Admin, Compliance Officer, or Privileged Consultant - not Consultant. Then a different Org Admin or Privileged Consultant clicks Approve or Reject. The top panel becomes a progress view ("X / N controls approved"). Editing Status, Assigned To, Notes, or SOA fields on an already-approved control resets that row to Not Reviewed.
5
Per-control mode: version stamps automatically
Once every control is approved, the SOA version stamps automatically - there's no separate finalize step. Editing an already-approved control sends just that control back for re-approval ("changes pending"); once all are approved again, the next version stamps.
💡
Segregation of duties: the approver must be a different person than the reviewer. For a solo or small org, an admin can enable owner self-approval in SettingsApproval - Separation of Duties so the same person may approve - this is the same toggle that governs policy approval.
💡
Change detail & version history: the panel and the SOA export show the actual value changes (e.g. "A.5.3 - Applicability: Applicable → Not Applicable"). Every approved version generates a PDF snapshot of the SOA, downloadable from the version-history list or from the Exports page via the panel's View in Exports button.
⚠️
Gov document titles: on CMMC 2.0 the signed artifact is often labeled SOA / POA&M. On NIST SP 800-171 and HIPAA you still get SOA-titled reports and a live Applicability field. Do not treat every Gov catalog as CMMC POA&M rules.
TISAX only

ISA Assessment (TISAX)

When TISAX (VDA ISA) is your active framework, an extra ISA Assessment item appears in the sidebar - the VDA ISA 6.0.3 questionnaire, worked question by question and scored the way a TISAX assessor scores it.

1
Read the readiness card first
One Assessment Readiness card sits at the top. It reads N of M answered · P% with a progress bar, adds a red N below target count when you have gaps, and shows your cutback Score against the maximum on a second bar that runs red, amber then green as you close in on it. A Jump to next incomplete → button takes you to the first unanswered question. Below that, one chip per chapter shows that chapter's percentage - a ✓ when it's complete, a red ▾N when it has answers below target - and clicking a chip jumps to it.
2
Work a module at a time
Switch between Information Security, Prototype Protection, and Data Protection, and narrow further with Below target only and Unanswered only. Click a question to expand its answer form in place - no modal, so you can work straight down a chapter.
3
Rate the question
Set a Maturity level - 0 Incomplete, 1 Performed, 2 Managed, 3 Established, 4 Predictable, 5 Optimizing - and, if this question differs from the default, its own Target level. Tick Not applicable - excluded from scoring to drop it from the totals. The full level key is printed at the bottom of the page.
4
Fill in the assessor's four fields
Each question carries Implementation description, Reference documentation, Findings/Assessment result, and Measures/recommendations, plus responsible department, contact, date of assessment, and date of completion. Everything saves as you leave the field, and the question footer records who last assessed it and when.
5
Hand it over
Download questionnaire (.xlsx) gives you the filled ISA workbook in its original column layout. For a dated PDF of the same record, schedule the Maturity Assessment (ISA) export from Settings → Automation; it lands in Exports History like any other snapshot.
ℹ️
What "cutback" means - scoring above target on one question doesn't paper over a shortfall on another: results are capped at the target before they're averaged. The expanded question tells you when it happened ("counted as 3 after cutback to target") and flags anything below target in red.
Both Platforms

Risk Register

The Risk Register captures every identified risk, links it to assets and threats, scores it, and tracks treatment. RiskABC Gov adds POA&M enforcement for high risks.

1 Creating a New Risk

risk.risk-abc.com / risks
Dashboard
Controls
Risk Register
12 risks + Add Risk
Risk NameScoreStatusTreatment
Unauthorised access to CUI 17 - High In Treatment Mitigate
Data breach via phishing 26 - Ext Open Mitigate
1
Click Add Risk
Open the Risk Register from the sidebar and click the + Add Risk button in the top right.
2
Enter a risk name and description
Give the risk a clear, specific name. Example: "Unauthorized access to customer records via weak passwords".
3
Link to an Asset (optional)
Select the asset this risk targets from the dropdown. If the asset doesn't exist yet, add it in the Asset Inventory first.
4
Link one or more Threats (optional)
Use the Add threat(s)… picker to attach every threat that could realize this risk - it's a searchable multi-select, so a risk can carry several. The detail panel lists them all; on RiskABC the register's Threat column shows the first, while on Gov it lists every linked threat separated by commas. If the threat you need isn't there, click + New threat to add it inline - name, optional category/source/description, and at least one vulnerability. It's saved to your Threat Library and selected for this risk.
5
Scope the risk (optional)
By default a new risk belongs to the framework you're viewing. Tick Global risk to apply it across all frameworks - global risks show a violet Global badge and appear regardless of the selected framework. You can toggle this later from the risk's detail panel.
6
Assign an owner and save
Set the risk owner - the person responsible for treatment. Click Add Risk.
ℹ️
Bulk delete - Org Admins and Privileged Consultants can click Select multiple to check several risks and delete them in one action (up to 500 at a time). Bulk deletes are recorded in the Audit Trail.
ℹ️
Editing an existing risk - the detail panel lets you change the Risk Name, Description, Owner, linked threats, and the linked Asset after creation. Swapping the asset re-copies that asset's C / I / A scores onto the risk, so the score moves with it.

2 Scoring a Risk

Risk scores are calculated automatically from the values you enter. The formula is: (Probability × Impact) + (C + I + A).

Score
Result
=
P × I
Probability × Impact
+
C + I + A
CIA Impact
Probability & Impact (P/I)

Scale: 1–5

  • 1 = Very Unlikely / Negligible
  • 3 = Possible / Moderate
  • 5 = Almost Certain / Catastrophic
CIA Scores

Confidentiality · Integrity · Availability

  • ISO: 0–3 per dimension
  • Assets: 1–3 per dimension
  • Max total CIA = 9
  • Gov: the CIA term is scored as impact to CUI (Controlled Unclassified Information) - 0 = N/A, 1 = Low, 2 = Medium, 3 = High per dimension
ℹ️
CIA applies only to frameworks that use it - For frameworks without a CIA model (ISO 9001, ISO 22301, ISO 20000, SOC 2) the score is simply Probability × Impact, the CIA selector is hidden, and the tier bands scale down. The (C + I + A) term and the 0–9 CIA range apply only to CIA-based frameworks (ISO 27001, Gov).
ℹ️
CIA from a linked asset - If you link the risk to an asset, its Confidentiality/Integrity/Availability ratings are copied from that asset and locked (shown as copied from asset). For a standalone risk with no asset, you set C/I/A directly. Residual scores reuse the same CIA values as the inherent score.

Risk levels (default):

Low · 0–8 Moderate · 9–16 High · 17–25 Extreme · 26+

An org_admin can rename tiers, change their score ranges, and recolor them in Settings - the register badges, the Risk Level Key, and the level filter all follow your org's configured tiers. The acceptable-risk threshold is a separate org setting.

3 Risk Treatment & POA&M

1
Open a risk
Click any risk in the register to open its detail panel. If you have edit rights it opens ready to edit - there is no separate Edit button.
2
Choose a Treatment
Select one:
Mitigate - Implement controls to reduce the risk
Accept - Accept the risk as-is (requires justification if above threshold)
Transfer - Transfer risk to a third party (e.g. insurance)
Avoid - Remove the activity causing the risk (ISO only)
3
Enter treatment notes
Describe the specific actions being taken. This text is included in risk reports and audit exports.
4
Set residual risk scores
After treatment, enter the expected Residual Probability and Residual Impact to show the risk level after controls are applied.
💡
Treatment gives residual credit: the residual score isn't just Residual P × Residual I + CIA - each treatment subtracts a credit before the floor of 0: Mitigate −4, Transfer −3, Avoid −2, Accept −1. The detail panel shows the live formula (e.g. 3 × 2 + (2+2+2) − 4 (Mitigate) = 8) so the math is never hidden.
⚠️
Threshold enforcement (both platforms) - Your org sets an Acceptable Risk Score in Settings (default 16). If a risk's inherent score is above it and you set status to Accepted, RiskABC blocks the save until you enter a treatment note justifying acceptance. Gov enforces the same gate and surfaces it the same way - the identical amber "exceeds the acceptable threshold" banner on the risk. The Avoid strategy remains ISO-only.
💡
Needs action flag - Risks scoring above the acceptable threshold that are still Open or In Treatment show a ⚠ Needs action marker in the register, and their detail panel shows an amber banner ("This risk exceeds the acceptable threshold…"). The flag clears once the risk is Accepted (with justification) or Closed.
💡
Automatic remediation task - When you create or edit a risk whose residual score is above your org's acceptable threshold, RiskABC auto-creates a task titled "Residual risk above threshold: <risk name>", its priority set from the residual risk level. Lowering the residual (or accepting/transferring below the threshold) Dismisses still-Open or In Progress auto-tasks; it does not delete them. Completed or user-Dismissed tasks stay as history. Note the trigger uses the residual score, not the inherent score.
ℹ️
Evidence on a risk - From a risk's detail panel you can link supporting evidence - pick an existing Evidence Library item, unlink it, or create a new evidence item (attached to a control) linked to this risk in one step. Linked evidence is counted in the panel heading and flows into risk reports.
Both Platforms

Asset Inventory

The asset inventory catalogs everything your organization relies on - hardware, software, data, people, and services. Assets link directly to risks so you always know what's at stake.

1
Open Assets from the sidebar
Click Assets. The full asset list loads with type icons, classification badges, and CIA scores.
2
Click + Add Asset
Click the button in the top right to open the new asset form.
3
Set the asset type and classification
Type: Hardware · Software · Data/Information · People · Service · Facility · Cloud
Classification: the dropdown lists your organization's configured classification tiers (labels/colors set in Org Settings; defaults are Public, Internal, Confidential, Restricted). The same tiers drive the classification filter and each card's colored badge.
4
Score CIA impact (1–3 each)
Set Confidentiality, Integrity, and Availability scores. These feed directly into any risk linked to this asset.
5
Add optional metadata
The Inventory Details section captures Hostname, Serial Number, Manufacturer, Model, Building/Room, Geo Location, Assigned To, Managed By, Asset Category, and Specialized Type - all optional, shown on the detail view when filled.
ℹ️
Gov platform: For CMMC frameworks, Hardware assets get an additional CMMC Asset Category field with options: CUI Asset · Security Protection Asset · Contractor Risk Managed Asset · Specialized Asset · Out of Scope. This is required for CMMC scoping and only appears on Hardware-type assets. Specialized Type - IoT · OT · Restricted Information System · Test Equipment - records which kind of specialized asset it is. Both lists match the CMMC 2.0 Scoping Guide, so an inventory kept in a spreadsheet transfers across unchanged.
💡
Software assets can link to a vendor: when Type is set to Software, extra fields appear - Vendor (pick from your Vendors catalog), Deployment Model (SaaS, On-Premise, Desktop, Cloud, Other), and Outage Workaround. This ties the asset inventory directly to third-party risk. You don't have to leave the form to add a missing vendor - click + Add vendor next to the Vendor dropdown, enter a name, and it's created in your Vendors catalog and selected on this asset immediately.
ℹ️
Assets shared from Gov - Assets synced from the Gov platform show a purple From Gov badge and are read-only (the detail view shows "From Gov - read-only"; Edit, Delete, and bulk-select are hidden). Manage them on the Gov platform where they originate.
ℹ️
Bulk delete - Org Admins and Privileged Consultants can click Select multiple to check several assets and delete them in one action (up to 500 at a time); From-Gov cards can't be selected. Bulk deletes are recorded in the Audit Trail.
Both Platforms

Threat Library

The Threat Library is a catalog of threat actors and scenarios you face. Linking threats to risks makes your risk register more accurate and your reports more meaningful.

1
Open Threats from the sidebar
Click Threat Library. You'll see a list of all threats with their category, source, and how many risks reference them.
2
Click + Add Threat
Enter a name for the threat (e.g. "Ransomware attack", "Supply chain compromise").
3
Set category and source
Category (RiskABC): Cyber · Physical · Human · Environmental · Operational · Legal/Compliance
Category (Gov): Cyber · Physical · Insider · Supply Chain · Operational · Compliance
Source: Internal · External · Both
4
Link at least one vulnerability
Every threat requires at least one linked vulnerability - pick an existing one from the library or type a new name to add it on the fly. From an existing threat's detail view, pick from the Link existing vulnerability… dropdown and click Link to attach more, or unlink one (it stays in the library, just detached from this threat).
5
Link the threat to risks
Go to the Risk Register and select this threat when creating or editing a risk. Linked risks appear in the threat's detail view.
ℹ️
Vulnerabilities live in their own library. The header shows a live count and link - e.g. "12 vulnerabilities in library" - that jumps straight to the Vulnerability Library, where the same vulnerability can be reused across many threats.
ℹ️
Bulk delete - Org Admins and Privileged Consultants can click Select multiple to check several threats and delete them in one action (up to 500 at a time). Bulk deletes are recorded in the Audit Trail.
Both Platforms

Vulnerability Library

The Vulnerability Library is the shared catalog of weaknesses your threats exploit - the "how" that pairs with the Threat Library's "who/what." Every vulnerability tracks how many threats currently reference it.

1 Browsing & usage tiers

Vulnerabilities are grouped into usage tiers based on how many threats link to them, so you can spot orphaned or over-used entries at a glance:

Unused · 0 threats Light · 1–2 Moderate · 3–4 High · 5–6 Critical · 7+

Click a tier card to filter the grid to just that tier. Use the search box and the sort dropdown (Most used, Least used, Name A→Z/Z→A, Newest) to find what you need.

2 Adding, editing & deleting

1
Click + New Vulnerability
Enter a Name (e.g. "Inadequate authentication mechanism") and an optional Description.
2
Open a card to view detail
Click any vulnerability card to see its usage tier, linked threats (each links back to Threat Library), and added date.
3
Edit
Click Edit Vulnerability to change the name or description. If it's in use, a note reminds you the edit propagates to every threat that references it.
4
Delete
Click Delete Vulnerability. If it's unused, it's removed immediately. If threats still reference it, you're asked to pick a replacement vulnerability for each affected threat before the delete completes - nothing is left dangling.
⚠️
No replacement available? If this is the only vulnerability in the library, add a second one first - you can't delete the last vulnerability out from under threats that reference it.
Both Platforms

Vendors & Third-Party Risk (TPRM)

The Vendors module tracks every third party your organization relies on - from onboarding through offboarding - with an inherent-risk questionnaire, expiring documents, contract renewals, and due-diligence assessments all in one place. It exists in both RiskABC and RiskABC Gov. Write access: Org Admin, Compliance Officer, Consultant, and Privileged Consultant on both platforms; Risk Manager can create/edit/send/archive on RiskABC only - on Gov that role is read-only for vendors, questionnaires, and assessments. Auditors and other read-only roles can open Vendors and Fill/View assessments but never see + Add Vendor, Save Profile, Archive, Send link, Save IRQ, Save schedule, template edit, Save Reviews, or Pass/Fail.

1 Creating a vendor & the profile

1
Click + Add Vendor (or + Add Prospective Vendor)
On Dashboard or Existing, the button is + Add Vendor. Fill in Vendor Name (required), Service / Product, contact name/email/phone, notes, and a Category combobox (pick or type). On the Possible tab the button is + Add Prospective Vendor - extra fields are Evaluation Group (type to create) and Assessment to send (defaults to the built-in VSAQ). A preliminary send uses that template and the contact email.
2
Open the vendor to see the full profile
Click any row to open a tabbed detail modal: Profile · IRQ · Assessments · Documents · Contracts. Vendor-linked risks and CAPA items are tracked on the Risk Register and CA / CI pages (filter or search by vendor name).
3
Fill out the Profile tab
Owner - the person responsible for this vendor
Lifecycle Stage - Prospective · Onboarding · Active · Under Review · Offboarding · Terminated
Status - Pending · Approved · Restricted
Geography, Website, and a free-tag Data Types Accessed list (e.g. PII, Financial Records)
4
Offboarding a vendor
Set Lifecycle Stage to Offboarding to reveal a 5-item checklist (data returned, data destroyed, access revoked, certificate of destruction, final obligations - each with an optional note). Save Checklist as you go; Complete Offboarding permanently moves the vendor to Terminated and cannot be undone.

2 IRQ & criticality tier

The Inherent Risk Questionnaire (IRQ) scores a vendor across six dimensions, each 0 (None) to 4 (Critical): Data Sensitivity, System Access Level, Business Dependency, Regulatory Scope, Data Volume, and Geography Risk.

1
Open the IRQ tab and score each dimension
A live score preview updates as you pick answers - it's the sum of your six answers as a percentage of the maximum possible (24).
2
Suggest IRQ (optional)
Click Suggest IRQ to pre-fill the six dimensions from the vendor's profile (data types accessed, geography, service, etc.). This is a deterministic, rule-based suggestion - no AI - shown as a draft with a short rationale line per dimension. Nothing is saved: review and adjust each value, then click Save IRQ to apply.
3
Click Save IRQ
The saved score derives a Criticality Tier automatically: Low (0–24) · Moderate (25–49) · High (50–74) · Critical (75–100). Tier thresholds and labels are configurable in Org Settings.
4
Override the tier manually (optional)
Toggle Set tier manually to pin a tier regardless of the IRQ score - useful when a qualitative factor (e.g. a breach history) should override the math. Turn it back off and save to clear the override.
Low · 0–24 Moderate · 25–49 High · 50–74 Critical · 75–100

3 Documents & Contracts

Both RiskABC and RiskABC Gov have a Documents tab and a Contracts tab on every vendor. This is not an ISO-vs-Gov split.

  • Documents - Title; Document Type (SOC2, ISO27001, PCI-AOC, PenTest, Insurance, DPA, Other); Effective Date + Expiry Date with a configurable expiry alert buffer (default 30 days); attach a file now or later; status pill Valid / Expiring Soon / Expired
  • Contracts - Title; Start / End / Renewal dates; Auto-renew toggle and Annual Value ($); SLA / KPI terms and notes; edit or delete any contract from the row
💡
Expiry & renewal become Tasks - a daily 09:00 job upserts Vendor cert expiring: … (source vendor_cert_expiry) for documents inside their per-doc buffer, re-stamping every 5 days. A daily 11:00 job upserts contract-renewal Tasks (source vendor_contract_renewal) for contracts renewing within 30 days. Watch them on Tasks - this is not a silent flag.
ℹ️
Vendor risks and CAPAs - a failed assessment finding raises a risk or a CA / CI directly (see Vendor Assessments). Track them where they live: the Risk Register and the CA / CI page, both of which record the vendor the finding came from.

4 Archiving & deleting a vendor

Vendors are archive-only - there's no direct delete from the Existing or Possible view, for either lifecycle.

1
Click Archive
From a vendor's row or detail panel, click Archive. The vendor moves out of Existing/Possible and onto the Archived tab in the Vendor Management Portal.
2
Restore it if you archived by mistake
On the Archived tab, click Restore to bring the vendor back to wherever it came from - Existing or Possible.
3
Permanently delete (Archived only)
Once - and only once - a vendor is archived, a Delete permanently option appears. This is the only path to fully removing a vendor record, and it can't be undone.
ℹ️
The Archived tab tags each entry Existing or Possible so you know which lifecycle it returns to on Restore.
Both Platforms

Questionnaire Builder

Build and manage the due-diligence questionnaires you send to vendors. RiskABC ships with system templates you can use as-is or clone to customize.

1 System templates

  • VSAQ and the AI Vendor Questionnaire ship pre-built and marked System
  • System templates are read-only - you can View their questions, but not edit or delete them
  • Click Clone to customize to make an editable copy in your org's Custom Templates list
💡
Explain-on-No - any Yes/No or Yes/No/N/A question now shows a required "Please explain" text box whenever the vendor answers No or N/A, so they justify the answer inline. This cuts down the follow-up "needs more info" back-and-forth.

2 Editing a custom template

1
Click Edit on a custom template
Or + New Template to start from scratch - Name (required), Description, Version.
2
Click + Add Question
Domain and Ref Code (e.g. IAM-01) group and label the question
Prompt (required) and optional Help Text
Answer Type - Yes/No, Yes/No/N/A, Single choice, Multi-select, Free text, Number, File upload
Risk Direction - Yes = Good or No = Good (which answer lowers risk)
Weight (1–10) and Required
3
Add answer options (Single / Multi only)
Each option has a stored Value, a displayed Label, and an optional Score.
4
Set up conditional branching (optional)
Pick a Parent question and a trigger value - this question only appears to the vendor when the parent's answer matches.
5
Add Framework References (optional) & reorder
Pick a Framework from the dropdown of your configured frameworks (a select - not free text), then type the Control ref (e.g. A.9.1.1) for traceability. Add several with + Add reference. Use the up/down arrows to reorder questions within a domain.
⚠️
Can't delete a template? A template in use shows: "Cannot delete: this template is used by N assessment(s). Delete or reassign those assessments first." Clear out or reassign the assessments, then delete.
Both Platforms

Vendor Assessments

An assessment is one filled-out questionnaire tied to one vendor - the full due-diligence cycle from send to score to Finished.

1 Create & send

1
From a vendor's Assessments tab, click + New Assessment
Pick a Template (required), an optional Title, the vendor's email (needed for the external portal), and a Due Date. Click Create & Fill - the assessment starts as Draft.
2
Fill it yourself, or send it to the vendor
Fill / View opens the assessment for your team to answer internally. File questions can only be answered on the vendor portal - Fill/View says so. Send link requires a vendor email (otherwise the send returns 400). Send sets status to Sent and mints a ~14-day magic-link token (each send overwrites expires_at). The vendor needs no account. Expired or revoked links fail; an already-submitted assessment cannot be filled again. Answers autosave about every 1.5 seconds. A No answer that requires explanation must have that explanation before submit.
3
Status moves to Answered
The first saved answer (from either side) auto-advances DraftIn Progress. Once the vendor submits, the status shows Answered (stored internally as Submitted).

2 Reviewing answers

1
Set a per-answer verdict
For each question, choose Pass · Fail · N/A · Needs info. Choosing Fail reveals a Severity field (Low / Moderate / High / Extreme) and a reviewer note.
2
Click Save Reviews
Any vendor clarification text appears read-only under the question once they've responded.
3
Request info if you flagged Needs info
Click Request info (enabled once at least one saved verdict is Needs info) to re-mint the vendor's magic link and email them a clarification request. Status moves to Info Requested. The portal then shows only the needs_info questions plus reviewer notes. When they resubmit, status returns to Answered.

3 Raising a Risk / CAPA from a finding

1
+ Raise Risk (appears once a saved verdict is Fail)
Creates a risk that carries the vendor, the question and its ref code, the vendor's answer, and your reviewer note as its description. Severity maps to inherent Probability/Impact; treatment is always Mitigate.
2
+ Raise CAPA (appears once a risk has been raised)
Creates a linked corrective/improvement action from the same finding detail. Once raised, the question shows Risk raised / CAPA raised chips instead of the buttons.

4 Recording a decision

1
Review the suggestion
After Compute Score, a Decision panel shows a Suggested Risk Level (Low / Moderate / High / Critical) and a Suggested Outcome (Pass / Fail / Review) with a bulleted list of reasons.
2
You make the call
The suggestion is advisory only - it is never applied automatically. The suggested option is emphasized as the primary button.
3
Record the outcome
Optionally type a note (rationale or conditions), then click Pass or Fail. The recorded decision is stamped with the outcome, who recorded it, and when, and shows the note - an audit trail of the sign-off.
ℹ️
"Score first" / "Unscored" appears until the assessment has been scored.

5 Scoring & Finished

1
Click Compute Score
Derives per-domain scores plus an overall residual score and residual tier from the saved verdicts.
2
Set Override (optional)
Enter a score (0–100) and a required Justification, plus optional Approved By and Expiry. A self-approval warning appears if you name yourself as approver.
3
Auto-advances to Finished
Once a residual score exists and every question has a saved, non-blank, non-Needs info verdict, the assessment automatically promotes to Finished (shown in green) - no manual step needed.
💡
Higher score = more residual risk - same convention as the vendor's IRQ score and criticality tier.

6 Reassessment schedule

On the vendor's Assessments tab, the Reassessment schedule card holds when this vendor is due again. Completing an assessment sets Last assessed to today and advances Renewal date (next due) by the cadence.

  • Last assessed - date of the last finished assessment
  • Renewal date - next due date shown on the Dashboard (red + overdue when past)
  • Cadence - months between assessments. Leave blank to use the tier default: Critical 6, High 12, Moderate 24, otherwise 36
  • Exempt from reassessment - skips overdue KPIs and the Monday 10:00 Task Vendor reassessment due: <name>
  • Save schedule - persists the card
Both Platforms

Vendor Management Portal

The Vendors page is split into three lifecycle-driven views - a live portfolio overview, vendors you already work with, and vendors you're still evaluating - each organized and scored differently so you can manage the full third-party lifecycle from shortlist to onboarding, plus an Archived tab for vendors you've removed.

1 Portfolio Dashboard

The Dashboard tab is a live portfolio overview. It excludes Prospective and Terminated vendors. Onboarding, Active, Under Review, and Offboarding still count.

  • Total Vendors
  • Critical / Top-Tier count (red when > 0)
  • Reassessments Overdue
  • Docs Expiring in ≤ 60 days (with an "expired" sub-count)
  • Contracts Renewing in ≤ 60 days
  • Assessments In Progress

Below the KPIs: a Vendors by Criticality donut (hover a slice or legend row to swap the center readout) paired with a criticality detail panel (per-tier proportion bars + a one-line concentration insight); a Critical / Top-Tier Vendors highlight table; and a full portfolio table grouped by category (Uncategorized last) with columns for Criticality, IRQ, Latest Assessment, Next Reassessment (turns red and shows "(overdue)" when past due), Docs (expired/expiring badges), and Next Renewal.

ℹ️
Until a vendor is added (or a prospective candidate is moved out of Prospective), the Dashboard shows a "No active vendors yet" empty state. Terminated vendors do not appear here either.

2 Dashboard, Existing, Possible & Archived tabs

The Vendors page opens on a Dashboard tab and has four top tabs - Dashboard, Existing, Possible, Archived. Possible is Prospective only. Existing is every non-Prospective stage that is not archived: Onboarding, Active, Under Review, Offboarding, and Terminated - not Active-only. Dashboard excludes Prospective and Terminated (Onboarding / Under Review / Offboarding still count). Archived holds every vendor removed from Existing or Possible - see Archiving & deleting a vendor.

3 Categories & Evaluation Groups

Both platforms have categories on Existing and evaluation groups on Possible. This is not an ISO-vs-Gov split.

  • Categories (Existing tab) - sort vendors into groups like IT, HR, Security. Category is a combobox (pick or type). The Existing table groups rows by category, Uncategorized last, plus a Category column
  • Evaluation Groups (Possible tab) - prospective vendors are organized into evaluation groups. Type to create a group. When setting up a group, choose the assessment template to send; it falls back to the built-in VSAQ if none is chosen

4 Scorecards & the fighting ring

Each candidate in an evaluation group shows a scorecard so you can compare potential vendors side by side and pick the best fit for your needs and risk acceptance - nicknamed the fighting ring.

  • Assessment completion - answered vs. total questions
  • Residual risk score and tier
  • Count of risk flags
  • Count of critical flags (high-weight risk answers)
💡
Lowest score wins - the best-fit candidate (lowest residual risk score) is highlighted, and a recommendation banner calls it out. Same convention as elsewhere: a lower residual score means a better, lower-risk candidate.

5 Running a preliminary assessment

1
Start the assessment from a candidate
One click sends the group's chosen questionnaire - or VSAQ by default if the group didn't set one.
2
Scorecard populates once scored
Completion, residual score/tier, and flag counts fill in on the candidate's card as answers come back and get reviewed.
3
Record a decision
Buttons are Select and Reject only - there is no Deferred control. Confirming Select sets that winner to lifecycle Active + Selected and auto-Rejects every other candidate in the same evaluation group. Reject marks that row only. States you will see: Pending, Selected, Rejected.
Both Platforms

Policies

Track your organization's security policies with version control, review dates, and direct links to the controls they support.

1
Click + Add Policy
Open Policies in the sidebar and click the add button.
2
Fill in the basics
Enter the policy Name, select its Document Kind (Policy, Procedure, Standard, Guideline, Work Instruction, Framework, Plan), and its Topic Area (e.g. Information Security, Access Control, Supplier Security).
3
Set the owner and review date
Pick an Owner (by job title) and a Review Date. The system emails a reminder when the review date approaches.
4
Attach the document (optional)
Drag & drop or click to upload the policy file (PDF, DOCX, XLSX). Once saved, anyone with access can download it from the detail panel via Download document.
5
Link to controls
Use the Linked Controls picker to associate this policy with the specific controls it satisfies. Linked policies appear in the control detail panel.
⚠️
Policies migrated from a prior system may show a file name with no downloadable binary - delete and re-attach the file to fix this.
💡
Policy lifecycle: Policies move through DraftUnder ReviewApprovedExpired. Expired policies show as a warning on the dashboard. The header summarizes counts by status (Draft, Under Review, Approved, Expired) plus how many are due for review within 30 days. Review dates are color-coded: red = overdue, orange = ≤ 30 days, yellow = ≤ 90 days. A red in SoD violation pill counts any policy currently approved by its own owner.

2 Reviewers & the Approve / Reject flow

A policy can't be dragged into Approved from the status dropdown - that status is only ever set by a formal decision.

1
Assign reviewers
In the policy detail modal, pick one or more Reviewers from your org's user list. Changes save immediately - no Save button needed.
2
Approve or Reject
An assigned reviewer, an Org Admin, or a Privileged Consultant can click Approve or Reject. Approving records the approver's name and today's date and moves the status to Approved automatically.
⚠️
Segregation-of-duties check: a policy's owner cannot approve their own policy - approving flags a red "Segregation of duties violation" banner unless your org has enabled owner self-approval in Org Settings. Re-approve with a separate approver, or re-enable the override.

3 Version history

Every policy carries a version number (set on creation, e.g. 1.0). The detail panel's Document version history section lists all uploaded versions and lets editors Upload a new version - the newest becomes the current file while prior versions remain on record for audit. The list and detail show the current version label.

4 Bulk Upload

1
Drag & drop up to 50 files
Drop files directly onto the Policies page. A details modal opens for the batch.
2
Set the batch fields
Owner, Review Date, Version, and Status apply to every file in the batch.
3
Set per-file name and linked controls
Each file gets its own name and linked controls. With Decision Engine Suggestions (Beta) turned on, controls are auto-suggested per file.

5 Document Viewer

Click a policy's attached file to view it in-page - PDF, image, and text files all render inline, no download needed. Download document is still there if you want the file itself.

Both Platforms

Evidence Library

The Evidence Library is a central store of all proof that your controls are implemented. Every piece of evidence is linked to one or more controls, and uploaded files are stored securely for integrity.

risk.risk-abc.com / evidence
Controls
Evidence
Policies
18 evidence items + Upload
TypeTitleControlDate
Policy Doc Information Security Policy v2.1 A.5.1 Apr 2026
Screenshot MFA enabled - all admin accounts A.8.5 Apr 2026
Artifact Pen test report Q1 2026 A.8.8 Mar 2026
1
Click + Add Evidence
From the Evidence page, or directly from a control detail panel. To add several at once, use the Bulk upload evidence dropzone further down the Evidence page instead.
2
Enter a title and choose the type
Title is required. Choose from: Policy Doc · Screenshot · Artifact · Text Description · Test Result · Certificate. The type determines the color badge shown.
3
Select the linked control
Use the control picker to link this evidence to one or more controls. This is what makes the evidence count go up on the Controls page.
4
Upload a file (optional)
Attach a PDF, image, or document. Uploaded files are stored securely for integrity. The detail panel shows the file name, size, and type.
5
Validate the evidence
Assign one or more Reviewers in the detail panel (saves immediately). An assigned reviewer, an Org Admin, or a Privileged Consultant can then click Validate, which stamps their name and date. Validation can later be undone with Revoke validation. Validated evidence carries more weight in audits.

1 What evidence can connect to

A single piece of evidence can support more than controls - it can also attach to Risks (from the Risk Register), CA/CI items, and Tasks. The detail panel lists every Connected Control, Risk, CA/CI, and Task, and editors can Unlink any of them here. Attach evidence to a risk/CA-CI/task from that item's own detail panel; it then appears back on the evidence record.

2 Version history

Evidence files are versioned - the detail panel's Document version history lets editors upload a newer file while keeping earlier versions on record. The most recent upload becomes the current downloadable file.

3 Bulk Upload

1
Drag & drop up to 50 files
Drop files directly onto the Evidence page. A details modal opens for the batch.
2
Set at least one control per file
Evidence requires at least one linked control per file - the modal won't let you finish the batch without it. With Decision Engine Suggestions (Beta) turned on, controls are auto-suggested per file.

4 Document Viewer

Click an evidence file to view it in-page - PDF, image, and text files render inline without downloading.

Both Platforms

Business Impact Analysis (BIA)

The BIA module captures recovery requirements for each critical business process. Use it to feed your continuity planning and meet ISO 22301 and CMMC requirements. Once the processes are in, record the plans, checklist, and drills in Business Continuity.

ℹ️
Six-tab editor - The Add/Edit Process modal is split into six tabs: Overview (identity, RTO/RPO/MTD, tier), Continuity (recovery strategies + SPOFs), Impact Matrix (impact by time window), Dependencies (applications, inputs, outputs), People & Vendors (key personnel + supplier contacts), and Gaps. Fill the tabs that apply; only Process Name is required to save. The list page also shows summary cards - Total Processes, the two most-critical bands (RiskABC: Mission Critical / Essential; Gov: Critical / High), and Avg RTO. Write access: Org Admin, Compliance Officer, Consultant, and Privileged Consultant on both platforms; Risk Manager as well on RiskABC ISO, not Gov. Sign-off roles are narrower (see section sign-offs).
1
Open BIA from the sidebar
Click BIA. You'll see any existing business process entries and an + Add Process button.
2
Set the process identity on the Overview tab
On the Overview tab set the process Name (required) plus Description, Department, Owner, Frequency (Daily/Weekly/Monthly/Quarterly/Ad-hoc), who it Serves, normal FTE count, FTEs needed during a disaster, and whether it can be performed remotely.
3
Set the Criticality Tier
The two platforms number these differently, because their audiences do.

RiskABC runs Tier 0 (Mission Critical) down through Tier 3 (Deferrable) - Tier 0: Mission Critical, Tier 1: Essential, Tier 2: Important, Tier 3: Deferrable.

Gov runs Tier 1 (Critical) down through Tier 4 (Low) - Tier 1: Critical, Tier 2: High, Tier 3: Moderate, Tier 4: Low. Tier 1 as the most critical band is the convention in continuity planning and federal work, so Gov follows it.

On both platforms the most critical band is listed first, a new process starts in the least critical band, and tier names can be customized in Org Settings. The optional dashboard widget BIA Summary (off by default; add it from Customize) counts that most-critical band: Tier 0 (Mission Critical) on RiskABC, Tier 1 (Critical) on Gov, plus how many processes have an RTO set.
4
Set RTO, RPO, and MTD
RTO - Recovery Time Objective: how fast you must recover (hours)
RPO - Recovery Point Objective: how much data loss is acceptable (hours)
MTD - Maximum Tolerable Downtime: longest acceptable outage (hours)
5
Document recovery strategies
On the Continuity tab, record your Current recovery strategy plus alternatives for four scenarios: loss of applications, loss of building/power, loss of phones, and loss of staff. List Known single points of failure (SPOFs).
6
Rate the impact matrix
On the Impact Matrix tab, rate disruption impact across five categories (Financial, Compliance, Operations, Reputation, Information Security) for four time windows (0–4h, 4–24h, 1–3 days, 3+ days). Each cell is None / Low / Medium / High / Very High, color-coded. These ratings drive automatic risk generation and, on import, auto-derive the criticality tier.
7
Add dependencies and key personnel
Use the Dependencies tab (Applications section) and the People & Vendors tab to list what this process depends on. Pick a cataloged application (from Asset Inventory) or vendor (from the Vendors catalog) from the dropdown to live-link it and auto-fill its details, or type a free-text entry. A linked row shows a Linked to catalog badge. If you manually edit an auto-filled field, your edit is preserved as an override even when the underlying asset/vendor changes; unedited fields re-sync from the source each time you reopen the process. Clearing the name so it no longer matches a catalog entry drops the link.
8
Log gaps
On the Gaps tab, record any gaps between current capability and your recovery targets. Each gap has a Description, Action item, Assignee, Due date, and Status (Open / In Progress / Closed). Every open gap automatically spawns a Task (assigned to its assignee, with the due date) and a linked corrective action in CAPA. Setting the gap to Closed removes the Task; the CAPA is kept.
💡
Blank recovery strategy raises a risk - on first insert only - Leaving Current recovery strategy blank when you first create the process (Add Process or import) auto-raises a risk. Saving a name-only process first, then later leaving strategy blank, does not.
💡
Auto-generated risks - a linked Risk Register entry is created only on first insert (Add Process or import), and only if any impact-matrix cell is Medium or higher or no current recovery strategy is defined. Saving a name-only process first, then later adding a Medium+ impact or leaving strategy blank, does not open a risk. Editing an existing process never creates or updates the auto-risk. The risk is named [BIA] <process name>, set to Mitigate/Open with a 90-day review date, and its impact scales with the matrix severity. Deleting the BIA process still cascades the auto-risk and its tasks.
💡
Completeness flagging - A process missing core recovery essentials (RTO, RPO, MTD, current recovery strategy, criticality tier, owner, or an all-None impact matrix) raises a single "Complete BIA process: <name>" Task for the owner, listing which fields are blank; it clears once every field is filled. Turning on Comprehensive BIA flagging in Org Settings also requires application dependencies, process inputs, outputs, key personnel, vendors, and at least one alternative recovery strategy.
💡
Completeness, section by section - The process list carries a Completeness bar showing how much of a BIA has been filled in, with a Fix → link that opens it on the first section still missing something. Opening any process shows the same breakdown at the top: each unfilled item is named - RTO not set, reputation impact at 4-24h not rated, no key personnel recorded. RTO, RPO, MTD, criticality, and disaster FTE live on the Overview tab; Fix → still opens Continuity (recovery strategies + SPOF) for the recovery-time checks, and People & Vendors for disaster FTE - those jumps do not land on Overview. Tabs with anything outstanding carry a marker. This only checks that nothing was left blank; it does not review what you wrote. Gaps is the exception: a process with no gaps recorded counts as complete, since a process may genuinely have none - it is flagged only when a gap was raised without an action item or an assignee.
💡
The BIA as evidence for a risk - Every risk raised from a BIA is listed on that BIA, and each links back to the risk. From the other direction, any risk's detail panel has a Business Impact Analysis picker: link it to the BIA it came from and the link opens that BIA on its Gaps tab, where the remediation is tracked. Useful when the evidence that a risk is being handled lives in the BIA rather than in the Evidence register.

9 Section sign-offs: Reviewed → Approved

Each of the six tabs - Overview, Continuity, Impact Matrix, Dependencies, People & Vendors, Gaps - carries its own sign-off, tracked independently. The sign-off controls appear only after the process is first saved. Statuses: Draft, Pending Review, Approved, Rejected.

1
Mark a section Reviewed
Once a tab's content is accurate, click Mark Reviewed. That button is Org Admin, Compliance Officer, or Privileged Consultant. Risk Manager and Consultant can edit the BIA but cannot sign off.
2
A different person approves or rejects
Approve and Reject are Org Admin or Privileged Consultant only. The author cannot review their own section, and the reviewer cannot approve, unless owner self-approval is on in SettingsApproval - Separation of Duties. Rejected sections can be re-opened for review.
3
A material edit resets the section
Changing that tab's fields after sign-off returns the section to Draft. You sign it off again.

10 Bulk-loading processes from XLSX

If you've already documented your processes in a spreadsheet - or you're migrating from another tool - skip the manual entry and use the import flow.

1
Click Import on the BIA page
A modal opens explaining how the import works.
2
Download the template (first-timers)
Click ↓ Download Template to get a pre-formatted XLSX with every supported sheet and column. Fill it in offline.
3
Choose your file and upload
Click Choose File… and select your XLSX. The parser reads the Business Processes and RTO sheet to create processes, then walks the other sheets (Standard Applications, Vendors, Key Personnel, Process Inputs/Outputs/Impacts) to attach data to each process by name.
4
Cross-sheet matching is automatic
If your workbook has a wider Critical Processes and RTOs sheet, RPO and MTD values from there are pulled in by matching Business Unit + Application Name - handy when process names diverge between sheets.
5
Review the import summary
After upload you see how many processes were created and any warnings - e.g. a row in the Vendors sheet that didn't match an existing process. Fix the spreadsheet and re-import, or add the missing process manually.
6
Criticality tier is auto-derived
If you don't set a tier, the parser walks the impact matrix and assigns one. On RiskABC: Very High → Tier 0, High → Tier 1, Medium → Tier 2, otherwise Tier 3. On Gov: Very High → Tier 1, High → Tier 2, Medium → Tier 3, otherwise Tier 4. You can override it later from the process detail screen.
💡
Made a mistake? Use the Select button on the BIA list, tick everything you want to remove, then click the Delete button (it shows the count of selected items). Bulk delete cascades - auto-generated risks and their open tasks disappear with the parent process. Restricted to Org Admin and Privileged Consultant.
Both Platforms

Business Continuity (BCP)

The BIA says which processes matter and how fast they must come back. Business Continuity is how you actually recover them: the plans on file, the capabilities that make those plans real, and the tests that prove they work. Open Business Continuity in the sidebar - it sits next to BIA.

ℹ️
Three tabs - Paperwork (plans, runbooks, contact lists, and the files themselves), Implementation (backup, restore, people, and comms capabilities), and Testing (tabletops, walkthroughs, simulations, full interruption drills). Summary cards at the top count documents on file, implementation items done, and tests completed.
💡
BIA first, BCP second. Finish the process list and recovery targets in BIA, then record the documents and exercises here. When the Decision Engine is on, the BCP page shows BCP suggestions (advisory; Review opens the matching tab). Cards fire for: no document of type BCP; paperwork Draft / Review due / next-review past; empty implementation vs open Not started or In progress items; no tests; Partial/Fail completed with no future next-test date; a planned test past its scheduled date; last completed actual date older than 365 days. Finish-the-BIA cards are not on the BIA page - they live on Suggested Actions and Review deep-links only.

1 Paperwork - the documents, not a file path

1
Click + Add document
Give it a Title. Pick a Type - BCP, DRP, Restore runbook, Emergency contacts, Crisis comms, or Other - and a Status of Draft, Approved, or Review due. Optional: version, owner, last reviewed, and next review.
2
Attach the file
Use the File picker - PDF, Word, or spreadsheet - so the controlled copy lives on the record. This is not a path to a share drive. After save, the file name is a download link on the card. Re-edit to replace it. Notes are free text for anything the file itself doesn't say.

2 Implementation - make the plan real

The first time you open BCP, the platform seeds 10 items (Not started) across Backup, Restore, People, Comms, Workplace, Dependencies, and Governance - backup jobs, offsite copies, restore runbook, restore tested in 12 months, crisis roles, emergency contacts, crisis comms plan, alternate workplace, critical vendor/ICT dependencies from the BIA, and BCP review cadence. N/A counts as done in the top card. Each item has a title, owner, notes, and a status: Not started, In progress, Implemented, or N/A. Change status inline, or click Edit for the full row. + Add item for anything else. There is no Delete on implementation rows (unlike paperwork and tests). An "empty implementation" suggestion only appears if someone wiped the list via API.

3 Testing - prove it

1
Click + Log a test
Title plus Type: Tabletop, Walkthrough, Simulation, or Full interruption. Status starts at Planned and moves to Completed (or Cancelled). When it ran, set Result to Pass, Partial, or Fail.
2
Record dates, scope, and findings
Scheduled date, actual date, and next test date keep the calendar honest. Scope and findings are the narrative an auditor asks for. A Partial or Fail without a next-test date is the kind of gap Suggested Actions will call out.
ℹ️
Who can edit? Org Admin, Compliance Officer, Consultant, and Privileged Consultant on both platforms; Risk Manager as well on RiskABC ISO. Others can read the registers.
Both Platforms

Tasks

Tasks are the platform's work queue. Some are entered manually; others appear automatically when a risk crosses your acceptable threshold.

1 Where tasks come from

  • Auto from risks - any risk with a residual score above your org's acceptable threshold opens a task automatically. An auto-flagged task inherits the risk's tier as its priority and shows it in that tier's color, so the queue mirrors your heat-map bands. Bring the residual back below threshold and still-Open or In Progress auto-tasks are set to Dismissed (system auto_dismissed), keeping assignee, notes, and evidence. A task you already marked Done or Dismissed is left alone. If residual rises again, only those system-dismissed rows reopen; a person's Dismissed or Done stays. Changing the org threshold already re-scans; Re-sync from risks is catch-up.
  • Manual - click + New Task on the Tasks page to create one yourself: title, description, assignee, priority (the dropdown lists your organization's configured risk tiers, so a task's priority reads in the same language as your risk register), due date.
  • From CA / CI - closing a corrective or improvement action linked to a task auto-completes that task (Done if Closed, Dismissed if Cancelled).

2 Working a task

1
Open Tasks from the sidebar
Status filter pills run across the top - Open / In Progress / Done / Dismissed.
2
Click any row to edit
Update assignee, priority, due date, or move the status forward. Status changes log to the audit trail. Auditors and other non-editors cannot open the row at all, so they never see Evidence or CA/CI on the task.
3
Use Re-sync from risks if needed
If you've changed your acceptable threshold and want every existing risk re-evaluated, click this once - the system opens new tasks for any risk now above threshold and Dismisses still-Open/In Progress auto-tasks for risks now below. Changing the threshold in Org Settings already re-scans; this button is catch-up.
Overdue badge - any Open or In Progress task past its due date shows the due date in red with a bold Overdue pill in the Due column, so a stale task never blends into the list.
ℹ️
Evidence on a task - Open any saved task you can edit and scroll to Evidence. Link existing library items or add a new one inline - title, type (e.g. Text Description) and the control it attaches to, which is required. Editors can attach evidence on any saved task, including auto-generated ones. Delete of the task itself remains manual-only.
ℹ️
CA / CI on a task - A saved task's modal has a Corrective Action / Continuous Improvement block: list of linked records, Unlink, Link an existing CA/CI (only unlinked ones; one CAPA to one task), and + New CA / CI from this task (always kind Corrective, title and description copied, source task). Empty state: "No CA / CI linked yet." Closing a linked CA/CI marks the task Done; cancelling it dismisses the task. You can still start from the CA / CI form and pick a task the other way.
📧
Two email touchpoints, not one - a consolidated assignment digest fires within hours of being assigned multiple tasks (no flood of one-per-task emails). Separately, a daily task digest goes to every user who has at least one Open or In Progress task: a single email listing all of them, with any overdue task called out. It arrives at the hour you pick - set Reminder hour in Preferences, and the digest lands at that time in your own timezone.
Both Platforms

CA / CI - Corrective & Improvement Actions

Where Tasks track the work, CA / CI tracks the investigation behind the work. Use it to document root cause, the fix, and the proof that the fix held.

1 Corrective vs. Improvement

🛠 Corrective Action (reactive)
  • Triggered by an incident, audit finding (NC or Observation), or nonconformity
  • Aim: stop the bleeding, then prevent recurrence
  • All five narrative fields usually filled in
📈 Continuous Improvement (proactive)
  • Triggered by an idea, KPI miss, an audit Opportunity for Improvement (OFI), or a routine review
  • Aim: improve a process that already works
  • Containment + root cause may not apply

2 Filling out an action

1
Open CA / CI from the sidebar
Sits directly under Tasks. Click + New CA / CI.
2
Pick the kind
Corrective or Improvement. The form is the same - just labels for filtering.
3
Fill the five narrative fields
Root cause - what really caused it
Containment - what you did immediately to limit damage
Corrective action - what you're doing to fix it
Preventive action - what you're doing so it doesn't happen again
Effectiveness check - how you'll prove the fix held
4
Link a Task (optional)
Pick an existing task to tie this CA / CI to it. Closing the action will auto-complete the linked task; cancelling it dismisses the task.
5
Move through the statuses
Open → In Progress → Pending Verification → Verified → Closed. To Close, both Corrective Action and Effectiveness Check must be filled in.
6
Attach the proof
The Evidence section at the bottom of a saved action lets you link existing library evidence or create a new item inline. This backs your Effectiveness Check: attach the test result, screenshot, or memo showing the fix held, so the closed record is audit-ready on its own.
7
Verifier signs off
Once status is Verified, the page shows a green "Verified by … on …" banner. That's your audit-ready record that the effectiveness check passed.

The workflow row on each action captures:

  • Process Owner - free-text role accountable for the process (e.g. CISO, QMS Manager); distinct from the assignee
  • Assignee - the platform user doing the work
  • Priority - Low / Moderate / High / Extreme (a fixed four-level scale, not your configured risk tiers)
  • Target Date - when close-out is due
ℹ️
Who can close? Closing requires Compliance Officer or higher. In RiskABC ISO this is tighter than the edit permission - Risk Manager can edit a CA / CI but not close it.
💡
Opened from Internal Audit. Recording a finding on an audit opens a CA or CI for you unless you pick an existing one: OFI → Continuous Improvement; Major NC, Minor NC, and Observation → Corrective Action. There is no skip - Linked CA/CI defaults to auto-create. That does not also open a Task. Deleting the finding does not delete the CAPA. See Internal Audit.
Both Platforms

Reports & Export

Two related but separate places: Reports & SOA is a live, on-screen dashboard of your current posture; Exports is where you generate a downloadable, timestamped snapshot to hand to an auditor.

1 Reports & SOA - on-screen only

1
Open Reports & SOA from the sidebar
Tabs run across the top: Risk Report and Executive Summary are always there, and on a framework that uses a Statement of Applicability a third tab, Statement of Applicability, leads them (on CMMC frameworks it's labeled Plan of Action & Milestones (POA&M)). On frameworks without an SOA there are only the two tabs and the page is titled simply Reports.
2
Everything here is live and on-screen
Charts and tables update in real time as your data changes. There's no export button on this page - for a downloadable, dated file, use Exports (below).

2 Exports - downloadable PDF snapshots

Open Exports in the sidebar to generate a timestamped PDF you can hand to an auditor or file away - every export is preserved as a point-in-time record.

📦 The export catalog

Grouped into five color-coded sections. Each card shows how fresh your last snapshot is - green within a week, amber within a month, gray beyond that, or Never taken.

  • Compliance - Statement of Applicability (SOA), Overall Compliance Report, Policy Register Gov plus System Security Plan (SSP)
  • Performance Evaluation - ISMS Scorecard, Internal Audit, Management Review
  • Risk & Vendors - Risk Assessment (inherent + residual), Vendor Portfolio Report, Business Impact Analysis (BIA)
  • Libraries - Threat Library, Vulnerability Library, Asset List, Evidence Register
  • Improvement - CA / CI Register

Management Review exports one review at a time - pick it from the dropdown on that row before clicking Generate. Gov On Gov the same rows read SOA / POA&M and Program Review, and the SSP export also carries the CMMC L1 / L2 level.

🗂 History
  • Click Generate on any type - it's added to the History table below
  • Each row shows type, framework, file name, row count, size, generated-by, and date
  • Generating an export requires an edit role - Org Admin, Compliance Officer, Risk Manager, Consultant, or Privileged Consultant. Read-only/auditor and viewer roles can download and view existing exports but Generate is disabled
  • Filter History by export type using the dropdown above the table (defaults to All types)
  • Download any past export at any time
  • Delete is restricted to Org Admin and Privileged Consultant
ℹ️
Everything exports from one place - the Scorecard is generated here like every other export type. Exports are color-coded the same way the live pages are - status pills, risk tiers, and so on - so a printed PDF reads the same as the screen.

What's in the Overall Compliance Report (framework-scoped):

  • Readiness Overview - overall implementation % (Implemented / Applicable) plus Total / Applicable / Implemented / In Progress / Not Started stat cards
  • Control Status & Approval breakdowns - Implemented / In Progress / Not Started / Exception, and Approved / Pending Review / Not Reviewed / Rejected
  • Implementation by Domain - per-domain completion table
  • Risk Posture - in-scope risks bucketed by your configured severity tiers, a Treatment Status breakdown, and the Top 8 risks by score
  • Policies & Approvals - every policy with owner, approver, reviewers, current version, approval and review-due dates
  • Document Version History - every policy document version with uploader, date, and note

It respects the Settings "Score Not Applicable controls" toggle - N/A is shown as a separate count unless the toggle is enabled.

What's in the Vendor Portfolio Report (organization-wide):

  • Portfolio KPI cards - Total Vendors, top-tier count, Reassessments Overdue, Docs Expired/Expiring, Contracts Renewing ≤60d, Open Vendor Findings
  • By Criticality Tier breakdown
  • Critical Vendors table
  • Vendor Roster - full roster grouped by category

Covers active vendors only - prospective and terminated are excluded - and criticality is derived from each vendor's IRQ score.

ℹ️
SOA and Overall Compliance Report are framework-specific - they export whichever framework is selected in the sidebar. To export a different standard, switch frameworks first, then click Generate. The other export types (Risks, CA/CI, Assets, BIA, Vendor Portfolio) are organization-wide. The History table's Framework column reflects which framework each SOA/Overall snapshot was for.
⚠️
Export metadata stays in History permanently, but the underlying PDF can be pruned from server storage over time. If Download returns "Export file no longer on disk - re-generate to retain a snapshot", click Generate again. For long-term auditor evidence, download and archive the PDF yourself.

3 Automation - scheduled, emailed exports

Automated exports let you schedule recurring reports instead of generating them by hand. Set up schedules in SettingsAutomation.

1
Open Settings → Automation
Settings is available to Org Admins and Privileged Consultants.
2
Add a schedule
Pick an export type - SOA, Overall Compliance, ISMS Scorecard, Internal Audit, Risk Assessment, CA / CI Register, Asset List, BIA, Vendor Portfolio, Policy Register, Threat Library, Vulnerability Library, Evidence Register, or Maturity Assessment (ISA) - then a framework (shown only for the framework-scoped types: SOA, Overall, Scorecard, and Maturity), a frequency (Weekly, Monthly, or Quarterly), and one or more recipients, with an Also email me (the creator) option. Each saved schedule shows its frequency, recipient count, and next run date, and can be flipped between Active and Paused or deleted at any time.
3
The report arrives on schedule
On each cadence, the platform generates the export automatically and emails every recipient a secure, login-required link to the Exports page - the file itself isn't attached, recipients sign in and download it. It also lands in Exports History like any other export.
💡
Audit tip: Auditors often want to see the evolution of your compliance posture over time, not just the current state - so keep your SOA and Overall Compliance Report exports in History rather than deleting old ones. Set up SettingsAutomation to generate and email these monthly automatically, no manual effort required.
Both Platforms

Audit Trail

Every meaningful action in the platform is recorded. The audit trail is append-only - nothing can be edited or deleted once written.

1 What gets logged

  • Action types - CREATE, UPDATE, DELETE, LOGIN, LOGOUT, EXPORT, UPLOAD, APPROVE, REJECT, VIEW, plus BIA_SECTION_REVIEW, BIA_SECTION_APPROVE and BIA_SECTION_REJECT from BIA section sign-off
  • Who - user name and email
  • When - timestamp to the second
  • Where from - source IP address
  • Result - success or failure with reason

On RiskABC, the top of the page shows four at-a-glance counters - Total Events, Failures, Logins in the last 24 hours, and Changes in the last 24 hours (creates, updates, deletes) - and failed events are highlighted with a red row. Gov's Audit Trail goes straight to the table, with no counters and no row highlighting.

2 The diff modal - what changed and what it was

UPDATE rows go beyond "X edited Y." Click any update row and you see a side-by-side, field-level table of what changed - old value in red on the left, new value in green on the right.

1
Open Audit Trail from the sidebar
You'll see a paginated table of every action. On RiskABC you can filter by action type, resource type, or user; narrow to just Success or Failure results; or type in the search box to match across event description, user, and resource type - and filtering updates the event count at the top of the table. Gov ships the action and result filters only, plus a Clear button.
2
Click an UPDATE row
A modal opens showing the field-by-field diff. Only fields that actually changed are listed.
3
Read the diff
Old value highlighted in red on the left, new value in green on the right. Empty or unset values show as an em dash (-).
🔒
Who can see diffs? The diff modal is restricted to Org Admin and Privileged Consultant - the rest of the audit trail is visible to everyone with audit access. Entries with nothing to show (pre-migration rows, or actions like LOGIN/VIEW/DELETE that don't snapshot field state) display "No diff captured for this entry."
Both Platforms

Objectives & the Scorecard

Objectives are the measurable targets your organization sets against a framework - the numbers the Scorecard tracks over time.

1
Open Performance Evaluation → Monitoring
Objectives live on the ISMS Scorecard - the Monitoring tab of Performance Evaluation. There is no separate Objectives item in the sidebar. Group objectives into your own categories with + Add Category (each category can carry a point of contact), then use + Add Objective. Each objective is scoped either Org-wide (all frameworks) or to one framework, takes an owner, and can be mapped to specific controls in that scope.
2
Set the target
Enter a Target value, a Comparator - At least (≥) or At most (≤) - and a Unit (%, count, days…) so the target reads unambiguously - "at least 95%," "at most 5 days."
3
Describe what it measures and set the review cadence
The What it measures field is what you're actually tracking (e.g. "% of critical patches applied within SLA"). Review cadence (months) is a number - how many months between reviews (defaults to 3). Frequency is free text for how often the measure itself is taken (e.g. Monthly, Quarterly), and there's an optional Due date.
4
Choose Manual or Automatic
In the Metric box, pick Manual - someone enters the current value each period - or Automatic, which adds an Auto metric picker so the value is pulled for you. Save - the objective now appears on the Scorecard.
💡
Not sure whether to pick Automatic or Manual? If you've turned on Decision Engine Suggestions (Beta), a metric advisor recommends which one fits this objective and can walk you through setting it up.
Both Platforms

Performance Evaluation

Monitoring, internal audit, and management (or program) review live on one page with four tabs. Tab names are framework-neutral - they do not carry ISO 9.1 / 9.2 / 9.3 numbers - so the same screens read cleanly on TISAX, SOC 2, CMMC, NIST, and HIPAA. It's always available; it isn't part of the Decision Engine Beta.

ℹ️
Four tabs - Overview (opens by default), Monitoring (the Scorecard), Internal Audit, and Management Review. Gov In RiskABC Gov the same three read Monitoring & Measurement, Internal Audit / Security Assessment, and Program Review, and the page subtitle names the reference that applies to your framework - CMMC's CA & AU domains, NIST 800-171 §3.12 Security Assessment, or HIPAA §164.308(a)(8) Evaluation.

1 Overview

The default tab is a roll-up of the other three - a quick summary pulled from Monitoring, Internal Audit, and Management / Program Review so you can see where you stand without clicking into each sub-tab.

2 Monitoring - the Scorecard

The Scorecard follows the framework selector in the sidebar: it shows the objectives set for the active framework, plus any scoped Org-wide (all frameworks), which appear whichever framework you are on.

  • A Status pill per objective
  • Current / Target side by side
  • The Latest measurement - its value and the date it was recorded
  • A 12-month grid - each month cell shows the recorded numeric value alongside its status color, so you can read both the trend and the number at a glance

3 Internal Audit

1
Click + Add Audit
Open the Internal Audit tab and start a new audit for the active framework.
2
The Scope is pre-populated for you
A new audit's Scope is pre-filled from the framework's Statement of Applicability - Applicable controls are pulled in, and Not Applicable controls are shown greyed out. The scope is editable - check in a Not Applicable control or drop an Applicable one if this audit needs a different boundary.
3
Record findings - CA / CI open themselves
The audit list columns are Title, Scope, Auditor, Planned, Actual, Status (Planned / In Progress / Completed). + Add Finding fields: Type (Major NC, Minor NC, Observation, OFI - default Observation); Status (Open / In Progress / Closed); Description; optional Linked Control; Linked CA/CI defaulting to - Auto-create -. There is no skip: every save without an existing CAPA creates one. Mapping: OFI → Continuous Improvement; every other type → Corrective Action. Title is {type}: {description} (or the audit title); source is audit_finding. This does not auto-create a Task. You can pick an existing CA / CI instead. Clearing CA/CI after unlinking and saving creates a second CAPA. Deleting a finding does not delete the CAPA.

4 Management Review Program Review on Gov

1
Start a review for the framework you're viewing
Management Review (Program Review on Gov) runs per framework. Its sections auto-populate from data already tracked elsewhere in the platform - audit results, objective performance, risk posture - so you're not re-typing what's already on record.
2
Complete the review
Add your narrative, decisions, and action items to the auto-populated sections, then mark the review Complete.
3
Completing it freezes a snapshot
Marking a review Complete freezes it as a point-in-time snapshot - the data it pulled in is locked to that moment, even if the underlying audits, objectives, or risks change afterward.
4
Export and get reminded
Export the completed review as a branded PDF (same Export Branding settings as your other exports). A reminder keeps upcoming reviews from slipping.
💡
Audit results write themselves. When internal audit findings exist, the Audit results notes fill with a grouped summary: listed minors, a count of majors, OFIs, observations, a CA/CI footer, and how many remain open. If there is no audit data yet, the section stays blank for you to type. Either way the text stays yours to edit before you complete the review.
⚠️
Gov platform: this tab is labeled Program Review and adds CMMC/NIST/HIPAA-specific sections, including POA&M status and SSP currency. The SSP section is written by hand - unlike the auto-populated sections, it is there for you to record what changed in the SSP since the last review.
RiskABC Gov Only

System Security Plan (SSP)

A full SSP builder for CMMC 2.0 (Level 1 or 2), NIST SP 800-171, and NIST SP 800-53 Rev. 5. It is not a standing sidebar item on every Gov org: the rail hides it when HIPAA is the selected framework. Open System Security Plan when one of those catalogs is selected. Every field saves as you leave it, so there's no Save button to hunt for.

ℹ️
Eleven tabs - Overview, CUI & Ownership, System Environment, Assets, Network & Interconnectivity, Roles & Privileges, Supply Chain, Compliance, Control Implementation, POA&M, and Authorization. On a CMMC framework an L1 (17) / L2 (110) switch in the header scopes the whole page to that level.
1
Follow the SSP Readiness meter
A bar above the tabs shows overall completion plus a pill per tab - each with its own percentage, turning green with a check once that tab is complete. Jump to next incomplete takes you straight to the first unfinished section, so you never have to guess what's left.
2
Record who prepared it, and the CUI picture
Overview takes the Prepared By block (name, phone, email, organization), a revision-history table, and the general description / purpose. CUI & Ownership takes contracts containing CUI, a CUI overview, an FCI checkbox, CUI categories as chips, and full contact blocks for the Information Owner, System Owner, and System Security Officer (ISSO).
3
Describe the system and its boundary
System Environment holds the system name and ID, type and operational status, the system description and environment narrative, the authorization boundary, operating-model checkboxes, CUI storage locations, and an SDLC section with a phase table.
4
Pull the inventories in rather than retyping them
Assets carries a hardware table (Asset ID, Hostname, Serial Number, Category, Manufacturer, Model, Building / Room, Geo Location, Assigned To, Managed By, Asset Category, Specialized Type) and a software table (IP / Hostname, Function, Version, Patch Level, Virtual). Each table has its own Pull from Assets button: the hardware one appends Asset Inventory records typed Hardware, the software one appends records typed Software, and each skips anything already listed. Assets of other types aren't pulled - add those rows by hand. Nothing you've customized is overwritten or duplicated, and everything stays editable afterward. Supply Chain lists your Vendors register automatically (vendor, service, criticality, status), with a notes field that stays local to the SSP and is never synced back.
5
Upload the network diagram
On Network & Interconnectivity, upload the network / data-flow diagram itself (PNG or JPEG, up to 15 MB). It renders on the tab and is embedded in the exported SSP PDF. Uploading again replaces the current diagram. The tab also holds the interconnectivity and network-boundary narratives, a Ports / Protocols / Services table, and an External System Connections table.
6
Write an implementation statement per practice
Control Implementation (Annex 1) groups every in-scope practice into collapsible domains, each showing an implemented / total count and a progress bar. Each practice takes seven fields - Implementation Status (Implemented (Internal), Implemented (Outsourced), Partially Implemented, Planned, Alternative Implementation, Not Applicable), Process Owner, Process Operator, Occurrence, Location of Additional Documentation, Technology in Use, and Description of Implementation.
7
Let it draft the first pass
Draft this statement on any practice composes a statement from that control's own status, the evidence and policies actually linked to it, and the closest statement you've already written for a similar practice. It fills only the fields you've left blank - it never touches text you've already written, and nothing is saved until you do. Draft all in this domain does the same across a whole domain in one pass. Bulk defaults… sets Process Owner, Process Operator, Occurrence, Technology in Use, and Location of Additional Documentation across a domain or the whole level, filling blanks unless you tick Overwrite existing values.
8
Check the POA&M pull-through
The POA&M tab lists every practice at the selected level that isn't yet Implemented, with its status and owner. Rows click through into the control record, and the View in Controls → and View CAPA Register → links jump to Controls and the CA / CI page, where the remediation is actually tracked. Nothing is authored here - the same count drives the open-POA&M figure in the page header.
9
Authorize, then generate the PDF
Authorization records the SSP version, revision date and revision note, plus the Authorizing Official's name, title, and authorization date - the signature block on the exported plan. Click Generate SSP PDF to mint a timestamped snapshot (scoped to the selected CMMC level) and use View in Exports → to download it from Exports.
ℹ️
Who can author? Editing, drafting, bulk defaults, diagram upload, and PDF generation are open to Org Admin, Compliance Officer, Consultant, and Privileged Consultant. Evidence Owners and Auditors see the whole plan read-only with a banner saying so. Statement saves and diagram uploads are written to the Audit Trail.
Both Platforms Beta

Decision Engine Suggestions - Beta

An opt-in assistant that surfaces suggestions across the platform - never applies anything on its own. Advisory, guarded, logged, reversible, and off any time you want.

1 Turning it on

1
Go to Org Settings
Find the Decision Engine Suggestions card (marked Beta) in Org Settings. Only Org Admins and Privileged Consultants can toggle it.
2
Read and accept the agreement
An agreement modal explains the terms - suggestions are advisory, every apply is guarded and audit-logged, actions are reversible, and you can turn the feature back off at any time. Accepting turns it on org-wide.

2 Where suggestions show up

Once enabled, suggestion cards appear on Controls, Risks, Evidence, Policies, Threats, Vulnerabilities, the Scorecard, Internal Audit, Management Review, Vendors, and Business Continuity (the BCP page titles them BCP suggestions) - plus a central Suggested Actions page in the sidebar that gathers every open suggestion into one inbox, grouped by area and sorted by confidence. There is no suggestion card on the BIA register: Finish-the-BIA items live only in Suggested Actions and as Review deep-links to /bia?process=&section=. CA / CI suggestions are raised too, but they surface only in that central inbox - there's no card on the CA / CI page itself. BIA, vendor-assessment, and BCP cards are advisory (Review, not Apply).

  • Every card is tagged Actionable or Advisory, carries a Rule-based or ML model source tag, names the framework it applies to, and shows an n% confidence figure and a one-line rationale
  • Actionable cards apply in one click with Apply - guarded, logged to the Audit Trail, and reversible
  • Advisory cards have no Apply - Review instead opens the record it's about so you can decide for yourself
  • Work a whole area at once: Accept n applies every actionable item in that group (advisory items are deliberately left for you) and Dismiss all (n) clears it
  • Every apply shows an Undo in the confirmation toast, and the History tab lists every suggestion event - what it was, which record, applied / dismissed / undone, by whom and when - with Undo still available on any applied row

3 The ML metric advisor

In the Add / Edit Objective window on the ISMS Scorecard, the same engine recommends whether the objective should use an Automatic or Manual metric - and when it recommends automatic, Use auto fills in the metric, unit, comparator, and target for you.

ℹ️
Not gated: Performance Evaluation - the Scorecard, Internal Audit, and Management Review - is always available. Only the suggestion cards, the Suggested Actions inbox, and the metric advisor require opting into the beta.
💡
Change your mind? Turn the toggle back off in Settings and new suggestions stop appearing immediately - nothing it applied is retroactively touched, and every past apply remains in the Audit Trail.
Both Platforms

Org Settings

Settings lets Org Admins customize the platform to match your organization's terminology and risk appetite.

ℹ️
Subscription & Billing - Settings opens with a Subscription & Billing card. Click Manage Subscription to jump to the Onboard portal (onboard.risk-abc.com) to add seats, manage users, and handle billing/renewals.
  • Review Reminders - Choose the document-review buffer (15, 30, 45, 60, 75, or 90 days; default 30). Document owners are notified this many days before a policy's review date
  • Risk Severity Tiers - Define 2–6 tiers with custom labels, colors, and contiguous score ranges. The lowest tier starts at 0, the top is open-ended; scores run 0–34
  • Risk Acceptance Threshold - Risks scoring above this value are auto-flagged (a Task in RiskABC, POA&M in Gov). Default 16; set to 100 to disable flagging. Changing it immediately re-scans all risks and adds/removes flags
  • Asset Classification Tiers - Define 2–6 sensitivity tiers (least → most sensitive) with labels and colors; existing assets keep their stored value
  • BIA Criticality Tiers - Define 2–6 tiers with labels and colors. The first band is the most critical: Tier 0 on RiskABC, Tier 1 on Gov
  • Editing tiers - Add or remove tiers with + Add / ; every tier picks a color swatch
  • Vendor Criticality Tiers - Customize the labels, colors, and IRQ score cutoffs for Low / Moderate / High / Critical vendor tiers
  • Asset sharing - Share your asset inventory read-only with your Gov workspace
  • Approval - Separation of Duties - Toggle whether the same person may approve their own submission, covering both policy approvals and SOA approvals (document-level and per-control); off by default (see Policies and SOA Approval & Versioning)
  • Score Not Applicable controls RiskABC only - Toggle whether Not Applicable controls can still be scored and count in dashboard stats. Gov has no equivalent setting because Gov scoring has no Not Applicable option. That is not the same as every Gov catalog being mandatory: only CMMC 2.0 locks Applicability. NIST SP 800-171 and HIPAA still let you mark applicability.
  • Comprehensive BIA flagging - Off (default) checks only core recovery fields - RTO, RPO, MTD, recovery strategy, criticality tier, owner, and impact matrix. On also flags empty dependency, input, output, key-personnel, vendor, and alternative-strategy sections (cross-links to BIA)
  • SOA Approval Mode - Choose Blanket sign-off (one approval for the whole SOA) or Per-control sign-off (each control approved individually); see SOA Approval & Versioning
  • Decision Engine Suggestions Beta - Off by default. Turning it on opens a short Beta agreement you must tick before it saves; turning it off is immediate (see Suggested Actions)
  • NIST SP 800-30 Risk-Based Guidance Gov Beta - Off by default, saves the moment you toggle it. Applies a likelihood × impact risk grade (Very Low → Very High) and a short prioritization line to Decision Engine control and risk suggestions. Advisory only - 800-30 is a risk-assessment methodology, not a control framework
  • Release version & What's new - the card at the bottom of Settings names the current release and opens a plain-language changelog of what shipped
  • Export Branding - cover-page logo - Upload a PNG or SVG (max 2 MB); it renders ~140×60 pt on the export cover, so use a wide-format logo. Remove it any time to revert to the RiskABC logo
  • Export Branding - use the document title as the bold header - Replaces and hides the "RiskABC Export" line
  • Export Branding - hide the tool line - A separate toggle that removes the "Tool: RiskABC ISO 27001+ Platform" line. Branding applies to every PDF export
  • Automation - Set up scheduled, emailed recurring exports (see Reports & Export → Automation)
ℹ️
Who can change settings? Settings can be edited by Org Admins and Privileged Consultants. Other roles see the values read-only ("You do not have permission to change these settings").
Both Platforms

Users & Roles

New user invitations happen centrally in the Onboard portal. Day-to-day role and job-title changes for existing users happen in-app, on the User Management page. Each user is assigned a role that controls what they can see and do within each platform.

1
Open User Management from the sidebar
Visible to Org Admin only. Role cards across the top show a live headcount per role. The table below lists every user with email, job title, role, MFA status (Enabled or Off), and last login time. Use MFA status to see who on your team has not enrolled a passkey yet - you cannot enroll one for them (it has to happen on their device), but you can chase the Off rows. Click a user to open a detail panel showing when they joined, last login, and MFA status, plus role and job-title controls.
2
Click a user to change their role or job title
On RiskABC, pick a new role from the dropdown and click Update Role. You can't move the last remaining Org Admin off that role - promote someone else first, so the org always has an administrator. Job title is edited separately and saves immediately - pick from your org's existing titles or add a new one.

On Gov the detail panel shows the role read-only and lets you set the job title. To change a Gov role, contact support - in-app role management is coming to Gov in a future release.
ℹ️
Inviting a brand-new user still happens on the Onboard portal - there's no in-app "create user" button. Once invited and activated, that user shows up on User Management for role and title changes.

3 Passkeys & Account

Passkeys are the second factor after your password: Face ID, Touch ID, Windows Hello, or a security key. They do not replace the password on the sign-in form. Once enrollment is live, each person sets up their own keys - Org Admins cannot enroll a passkey for someone else. Track the team's progress from User Management (MFA status). After a passkey is enrolled, authenticator-app codes are no longer accepted on that account.

Deadlines are counted from the day enrollment opens, not from a shared calendar date. The in-app banner and reminder emails show your due date. After that date, sign-in requires a passkey. Authenticator-app codes are not a fallback. If you cannot use a passkey (lost device, no platform authenticator), reach out to RiskABC Support at support@risk-abc.com to enroll again. Use Chrome, Edge, or Safari for enrollment and sign-in.

Who Time to enroll
RiskABC staff (system and limited admins) and consultants on the Consultants portal 7 days
Anyone with access to a RiskABC Gov organization 14 days
Everyone else on RiskABC 30 days

If you have Gov access, you are on the 14-day clock even if you also use RiskABC. Consultants and RiskABC staff stay on 7 days. Vendor questionnaire links do not use passkeys.

  • Banners - RiskABC, RiskABC Gov, and SSO show an amber banner while you still have time (dismissible until 72 hours remain), then a red banner that you cannot dismiss. Follow the banner to Account to enroll.
  • Reminder emails fire at launch, 7 days before your deadline, 3 days, tomorrow, and on the due date.
1
Open Account from the SSO chooser
RiskABC and RiskABC Gov do not have a passkey page. After you sign in, the chooser has Account. That page is at sso.risk-abc.com/account - deadline banners send you there too.
2
Enroll, nickname, or add another device
Add a passkey on this device, give it a nickname, or remove one you no longer use. To enroll from a phone, use the QR path. Empty state explains that nothing is enrolled yet.
3
Change password if you need to
Account also has Change Password (minimum eight characters). After a successful change you are signed out and sign in again with the new password, then confirm with your passkey.
💡
Getting the rest of the team on passkeys - it is self-serve once enrollment is open. Open User Management, sort the Off rows, and point those people at Account. You cannot click enroll for them.
Role View Edit Controls Edit Risks Upload Evidence Manage Users Change Settings
Org Admin
Compliance Officer
Risk Manager (ISO only)
Consultant
Evidence Owner (Gov only)
Privileged Consultant
Auditor
ℹ️
Consultant vs Privileged Consultant - both can view and edit controls, risks, and evidence. A Consultant can Submit for Review on a blanket SOA, but cannot Approve or Reject, and cannot Mark Reviewed in per-control mode. A Privileged Consultant can change Org Settings, Approve or Reject the SOA, and bulk-delete records. A Compliance Officer can submit and Mark Reviewed, but cannot Approve.
ℹ️
Changing roles - Only your Org Admin can set account types and role assignments, from the in-app User Management page on RiskABC. Gov shows roles there read-only for now; contact support to change one.
Both Platforms

Preferences

A per-user page for how the platform looks and talks to you. Unlike Org Settings, which only admins can change, Preferences is available to every signed-in user and affects nobody but you. Your choices are stored on your account, so they follow you across every RiskABC product you use.

1 Timezone & reminder time

  • Timezone - shown as friendly names (e.g. "Eastern Standard Time") rather than raw IANA ids. If your device is in a different zone than the one saved, a Detect button appears next to the dropdown to switch to it in one click
  • Reminder time - pick the hour you want your daily task-reminder email, in your own timezone. A line underneath confirms it in plain English: "Your daily task-reminder email will arrive around 7:00 AM Eastern Standard Time"

2 Appearance

Choose Light, Dark, or System (follows your OS setting).

ℹ️
Not here: dashboard widgets and sidebar order are edited from Dashboard → Customize. Preferences does not rearrange the app.
Both Platforms

Support & Feedback

Report a bug, share feedback, or request a feature - it goes straight to the RiskABC team.

1
Open Support
The rail label is Support; the page heading is Support and Feedback. Every role sees it, after Audit Trail.
2
Pick a type
Choose Bug report, Feedback, or Feature request from the segmented toggle.
3
Write it up
Enter a Subject (required, up to 200 chars) and a Message (required, up to 5000 chars - a live character counter is shown).
4
Send
Click Send. On success you see a confirmation and a Send another button.
ℹ️
Submissions are tied to your account and org automatically - you don't need to identify yourself. When you file a bug report, you pick which page you were on when you saw it, so the team can reproduce it.