Risk Register
Use the Nexxis Risk Register to document, assess, and track remediation of compliance risks.
4 min readUpdated 2026-02-01
riskregisterassessmentremediation
Overview
The Risk Register is a centralised list of compliance risks for your organisation. Nexxis auto-populates it from workflow findings and lets you add manual entries.
Risk Properties
Each risk entry includes:
| Field | Description |
|---|---|
| Title | Short description of the risk |
| Category | Framework control family (e.g., Access Control, Logging) |
| Likelihood | 1–5 scale (1 = rare, 5 = almost certain) |
| Impact | 1–5 scale (1 = negligible, 5 = critical) |
| Risk Score | Likelihood × Impact (1–25) |
| Owner | Team member responsible for remediation |
| Due Date | Target remediation date |
| Status | Open / In Progress / Accepted / Closed |
| Treatment | Mitigate / Accept / Transfer / Avoid |
Auto-Generated Risks
When a workflow identifies a finding, it automatically creates a Risk Register entry:
- Severity is mapped to Likelihood + Impact
- Framework control is linked
- Owner defaults to the project owner (reassign as needed)
Accepting Risks
For risks that can't be remediated (e.g., a legacy system that can't be upgraded), you can Accept the risk:
- Open the risk
- Click Accept Risk
- Provide a justification and get sign-off from an owner
- Accepted risks appear in the audit export with full documentation
Risk Dashboard
The Risk Dashboard (Projects → Risk Register → Dashboard) shows:
- Current risk score distribution
- Risks by category
- Trend over time
- Overdue remediations