Require Lower Risk Rating After Mitigation Is Applied

When a user selects the "mitigate" option for a risk, the system should enforce that the post-mitigation risk rating is lower than the initial rating. Right now, it's possible to apply a mitigation and keep the same risk score, which doesn't make logical sense and can lead to confusion during audits or internal reviews.

Ideally, there should be a validation or warning to guide the user to adjust the rating appropriately—or at least justify why it remains unchanged (e.g., if it's already at the lowest possible level). This would help ensure that the mitigation steps are meaningfully reflected in the risk scoring and support better risk management practices.

This improvement would prevent user errors, make the risk register more reliable, and align with auditor expectations.

Please authenticate to join the conversation.

Upvoters
Status

Open

Board
💡

Feature Request

Tags

Risk register

Date

9 months ago

Author

Olivia Kiniger

Subscribe to post

Get notified by email when there are changes.