Skip to main content

Risk Register

Use the Nexxis Risk Register to document, assess, and track remediation of compliance risks.

4 min readUpdated 2026-02-01
riskregisterassessmentremediation

Overview

The Risk Register is a centralised list of compliance risks for your organisation. Nexxis auto-populates it from workflow findings and lets you add manual entries.


Risk Properties

Each risk entry includes:

FieldDescription
TitleShort description of the risk
CategoryFramework control family (e.g., Access Control, Logging)
Likelihood1–5 scale (1 = rare, 5 = almost certain)
Impact1–5 scale (1 = negligible, 5 = critical)
Risk ScoreLikelihood × Impact (1–25)
OwnerTeam member responsible for remediation
Due DateTarget remediation date
StatusOpen / In Progress / Accepted / Closed
TreatmentMitigate / Accept / Transfer / Avoid

Auto-Generated Risks

When a workflow identifies a finding, it automatically creates a Risk Register entry:

  • Severity is mapped to Likelihood + Impact
  • Framework control is linked
  • Owner defaults to the project owner (reassign as needed)

Accepting Risks

For risks that can't be remediated (e.g., a legacy system that can't be upgraded), you can Accept the risk:

  1. Open the risk
  2. Click Accept Risk
  3. Provide a justification and get sign-off from an owner
  4. Accepted risks appear in the audit export with full documentation

Risk Dashboard

The Risk Dashboard (Projects → Risk Register → Dashboard) shows:

  • Current risk score distribution
  • Risks by category
  • Trend over time
  • Overdue remediations