Risk register (Assess)

Identify, assess, and track privacy risks — from a pre-defined risk catalog to a register instantiated on your processing activities.

2 min read

What is the Risks module for?

The Risks module (Assess > Risks) centralizes the identification and treatment of privacy risks. It feeds directly into PIAs, conditions ROPA approval, and serves as proof of due diligence in the event of a CAI investigation. Each risk is documented with its source (actor, asset, processing activity), probability, severity, and mitigation measures applied. Initial and residual scores are recalculated automatically when you add or change a measure.

Catalog vs. register

The module is organized in two tabs. The "Catalog" groups a library of pre-defined risks (unauthorized access, data loss, unframed cross-border transfer, opaque profiling, etc.) that you can instantiate on your processing activities in one click. The "Register" lists the risks you have instantiated for your organization, with their status, owner, and residual score. This separation avoids starting from a blank page while keeping a register specific to your context.

Catalog vs. register

Catalog vs. register

Instantiating a risk on a processing activity

From the catalog, select a risk template and click "Instantiate". Conformaze asks which processing activity, actor, or asset the risk applies to, then pre-fills the suggested probability and severity. You adjust the values to your context, designate an owner, and select existing or to-be-created mitigation measures. The risk then appears in the register, linked to its source element, and becomes visible on the processing activity record.

Instantiating a risk on a processing activity

Instantiating a risk on a processing activity

Residual score and impact on approval

For each risk, Conformaze calculates two scores: initial risk (probability x severity, before measures) and residual risk (after mitigation). High residual risks (score >= 12) are flagged red in the register and block approval of the associated ROPA until an additional measure is added or a formal risk acceptance is documented by management.

Important

A high unmitigated residual risk prevents final ROPA approval. Either document an additional mitigation measure or a formal risk acceptance by the DPO or executive.

Link to PIAs and audit trail

When you launch a PIA on a processing activity, risks already instantiated on that activity are automatically pulled into the questionnaire — no need to re-enter them. Conversely, risks identified during a PIA are saved into the risk register. Every change (score update, measure added, closure) is recorded in the audit trail with author and timestamp.

    Risk register (Assess) — Conformaze Help Center | Conformaze