Who can use this feature
Supported on Foundation, Growth, and Scale plans
Risk Management in Scrut lets you track, assess, treat, and monitor risks across your organization in a structured lifecycle. This guide walks you through the complete process from creating a risk to closing it.
Before You Begin
Risk Management uses a fixed lifecycle with defined statuses and treatment rules. Understanding the lifecycle before you start helps you move risks forward without blockers. The risk lifecycle follows this order:
Open → Assessed → Treatment in Progress → Treated → Monitor / Closed
If your organization has the approval workflow turned on, an additional step is introduced: risks must be sent for approval and approved before they can be marked Treated.
Open → Assessed → Treatment in Progress → Pending Approval → Needs Revision → Treated → Monitor / Closed
Risk Statuses
Open: Risk identified. Assessment pending.
Assessed: Initial risk assessment complete. Inherent risk added and controls linked.
Treatment in Progress: Risk treatment strategy set.
Pending Approval: Submitted for approval. Awaiting approver action. (Approval workflow only)
Needs Revision: Approver has requested a revision. Review the approver's comments and resubmit. (Approval workflow only)
Treated: Treatment complete. Residual risk recorded and mitigation tasks closed.
Monitor: Risk under continuous monitoring until the next recurrence cycle.
Closed: Risk retired. No further action required.
Step 1: Create a Risk
Risks can be added to Scrut in several ways, depending on your source and volume.
Use the Risk Discovery tab: Browse a curated table of common risks across organizations. Select any risks that apply to your organization and add them to your risk register in one go.
Import in bulk: Upload risks from a spreadsheet or export from another tool using an XLSX or CSV file. Use this when migrating an existing risk register or adding multiple risks at once.
Add manually: Create risks one by one by entering details directly in Scrut. Use this for individual, ad hoc risks that fall outside your existing data sources.
Create from other modules: You can also create risks directly from other Scrut modules.
The risk is created in the Open state.
Step 2: Perform the Initial Assessment
Open the risk.
Add the Inherent Risk details, including the likelihood, impact, and risk score.
Link the relevant controls associated with the risk under the Controls section.
Click Save.
Heads Up!
The risk remains in the Open state until you explicitly move it to Assessed. Complete both the inherent risk details and control mapping before changing the state.
Step 3: Move the Risk to Assessed
Open the risk.
Change the risk state from Open to Assessed.
Click Save.
The risk is now in the Assessed state and ready for treatment strategy selection.
Step 4: Select a Treatment Strategy
Open the risk.
Under Treatment Strategy, select one of the following options based on the risk:
Accept: Acknowledge and accept the risk as-is without active mitigation. The risk will be monitored at regular intervals. Residual risk must be added.
Avoid: The root cause of the risk has been removed, and no further action is needed.
Transfer: Shift the risk’s impact to a third party (e.g., a vendor or insurer). Mitigation tasks and residual risk are mandatory.
Mitigate: Reduce the likelihood or impact of the risk through active mitigation tasks. Mitigation tasks and residual risk are mandatory.
Click Save.
The risk moves to the Treatment in Progress state.
Step 5: Complete Treatment Actions
Treatment Strategy Quick Reference
Treatment Strategy | Mitigation Task | Residual Risk |
|---|---|---|
Avoid | Optional | Optional |
Accept | Optional | Mandatory |
Mitigate | Mandatory | Mandatory |
Transfer | Mandatory | Mandatory |
The actions required depend on the treatment strategy you selected.
Avoid
No additional actions are required. The risk can proceed directly to the Treated state.
Accept
Add the Residual Risk details to the risk.
Click Save.
The risk is now eligible to move to the Treated state.
Note: You cannot create any mitigation task after the residual risk is added for the Accept strategy.
Mitigate or Transfer
Create at least one mitigation task under the Mitigation Tasks section.
Complete the work associated with the task.
Mark the mitigation task as Closed.
Important: All mitigation tasks must be closed before you can add residual risk. Adding residual risk is not available until all linked tasks are closed.
Add the Residual Risk details.
Click Save.
The risk is now eligible to move to the Treated state.
Step 6: Mark the Risk as Treated
If the approval workflow is turned off:
Add the Review Date to the risk.
Change the risk state to Treated.
Click Save.
If the approval workflow is turned off:
Click Submit for Approval. The risk moves to the Pending Approval state.
The designated approver reviews the risk treatment.
If the approver requests a revision, the risk moves to Needs Revision. Review the approver's comments, make the required updates, and resubmit for approval.
If approved, the risk moves to the Approved state.
Add the Review Date.
Change the risk state to Treated.
Click Save.
The risk is now in the Treated state.
Step 7: Monitor the Risk
No action is required to initiate monitoring. When the Review Date passes the current date, the risk automatically moves to the Monitor state. During this phase, the risk is under continuous monitoring until the next recurrence cycle. Review and update the risk record as needed during this period.
Step 8: Close the Risk
If a risk is no longer relevant to your organization:
Open the risk.
Change the risk state to Closed.
Click Save.
The risk is retired, and no further action is required.
Reach out to support@scrut.io or contact your CSM for further assistance.