Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Add a Risk

Prev Next

Who can use this feature

  • Supported on Foundation, Growth, and Scale plans

In Scrut, you can add risks to your Risk Register in four ways:

  1. Add Risks from the Risk Discovery tab

  2. Add a Risk Manually

  3. Import Risks in Bulk

  4. Create Risks from Scrut Modules

This article explains how to use each of the four methods.

#1: Add Risks from the Risk Discovery Tab

Pro Tip!

Use the Risk Discovery tab to quickly add common risks to your Risk Register. You can then add more complex and specific risks, unique to your organization either manually or import them in bulk.

The Risk Discovery tab provides an excellent starting point for populating your Risk Register. It contains a curated list of potential threats and risks, providing a comprehensive overview of the typical challenges organizations face. This tab categorizes risks into groups such as governance, operations, people, regulatory, resilience, technology, and others.

Follow these steps to add a risk from the Risk Discovery tab:

  1. Sign in to Scrut and navigate to Risk → Risk Management via the left navigation panel.

  2. Go to the Risk Discovery tab and review the available risks.

  3. Use the In Risk Register filter to show risks that are either added or not added to the Risk Register.

  4. Apply the Category filter to focus on specific categories.

  5. Use the search bar at the top to find risks by specific terms or keywords.

  6. Select one or more relevant risks and click the Add to Risk Register button.

    Heads up! You can add multiple risks to the Risk Register at once.  

  7. Choose the organizational entity or entities to which this risk applies. By default, all risks are organization-wide. However, you can change this setting and limit it to one or more entities.

  8. Click Save.

#2: Add a Risk Manually

Note:

The fields shown on this form and whether each is required depends on your organization's configuration. You can show, hide, reorder, and mark fields as Optional or Mandatory in Form Setup. The list below reflects Scrut's default configuration.

Use this method to add a single risk to your Risk Register:

  1. Sign in to Scrut and navigate to Risk → Risk Management via the left navigation panel.

  2. Click the Add Risk button and select Add Manually.

  3. Enter the risk details.

  4. Risk Name (Mandatory by default): Enter the risk name. Risk Name is always required and can't be made optional.

  5. Description [Optional]: Enter a detailed risk description to clarify what it is.

  6. Assignees [Optional]: Use the Assignee dropdown to select one or more users to work on the risk.

  7. Category [Optional]: Assign a risk category, such as Customer, Governance, Infra, ITMSNIRU, Network, New, Operations, People, Regulatory, Reporting, Resilience, Technology, or Vendor Management. If a risk doesn’t fit into any of the categories mentioned above, you can group it under ‘Others’.

  8. Departments [Optional]: Select the departments in your organization to which the risk applies.

  9. Entities (Mandatory by default): Select the organizational entity or entities to which this risk applies. By default, all risks are organization-wide. However, you can change this setting and limit it to one or more entities.

  10. Application Name [Optional]: Enter the application associated with the risk.

  11. Linked Assets [Optional]: Select the assets impacted by this risk. You can leave it blank if you’re unsure.

  12. Click Save.

#3: Import Risks in Bulk

Use this method when you have several risks to input into Scrut. This method is especially useful when you already manage risks in an external spreadsheet or data source.

Before You Begin

Make sure the following are in place before starting the import:

  • The Risk Name field must be present in your file; it is mandatory. Similarly, if entities are enabled for your Scrut organization, the Entity field must be present in your file.

  • Any custom fields you want to import must already exist in Risk Settings. You cannot create new custom fields during the import process.

  • Your file must be in CSV or XLSX format and must not exceed 100 MB.

Note:

The following cannot be imported: Risk Status, Risk Scores, Controls, Risk ID, and the Source field.

Steps to Import Risks

  1. Sign in to Scrut and navigate to Risk → Risk Management using the left navigation panel.

  2. Click Add Risk and select Import (CSV/XLSX).

  3. Drag and drop your file, or click to upload it manually. Then click Upload.

  4. On the Map Columns screen, map each column in your file to the corresponding field in Scrut's Risk Register.

    • Risk Name and Entity are mandatory — you must map these before you can proceed.

    • All other default fields (such as Assignee and Department) and custom fields are optional.

    • If a column in your file doesn't correspond to any Scrut field, you can leave it unmapped or choose Field Not Available from the dropdown. Unmapped columns are ignored during import.

    • The Confirm Mapping button activates only after all mandatory fields are mapped.

  5. Review the mapped columns and click Save.

Scrut processes the file and imports your risks. If any rows fail to import, you'll be prompted to download a CSV file containing error details. Fix the flagged entries and re-import. If issues persist, contact support@scrut.io.

Tips for Preparing Your Bulk Risk Import File

  • You don't need to follow a specific column order — Scrut lets you map columns during import.

  • Include each risk in a separate row.

  • For fields that accept multiple values (such as Assignee or Entity), separate values with commas. Example: Entity A, Entity B.

  • For Assignee, use email addresses that match existing users in Scrut.

#4: Create Risks from Scrut Modules

Scrut enables you to create risks directly from different modules, ensuring that the new risk inherits relevant context from the source module. This establishes clear connections between risks and their origins, making risk management more accurate and actionable.

You can create risks from the following Scrut modules:

  • Tests → Automated Tests

  • Cloud

  • Asset Management

  • Vendor

  • Vulnerabilities

  • Audit Center

How To Create Risks From Scrut Modules

  1. Sign in to Scrut and navigate to the desired module (Tests, Cloud, Asset Management, Vendor, Vulnerabilities, or Audit Center).

  2. Select the specific item (test, asset, vendor, vulnerability, or audit finding) for which you want to create a risk.

  3. Click the three-dot icon at the top right and click Create Risk.

  4. Scrut automatically fills in the risk name and description, thereby providing context for the risk. You can edit these fields if required.

  5. Choose the risk assignees, category, departments, and entities.

  6. Optionally, enter the name of the application associated with the risk.

  7. Select the assets impacted by this risk. If you’re unsure, you can leave this field blank.

  8. Click Save.

Scrut adds the risk to the Risk Register.

You can view all risks for a specific item in the Risk tab on its page. The table displays details such as Risk ID, Name, Status, Assignee, Approver, creation date, and more. Clicking on the risk opens its page in the Risk Management module, where you can create a mitigation task, monitor it, and perform additional actions as needed.