Perform advanced risk assessment in the Risk Workspace
- UpdatedJul 31, 2025
- 6 minutes to read
- Zurich
- Risk Management
Conduct risk assessments to assess inherent risks, effectiveness of controls, residual risks, and target risks in the Risk Workspace application. You can define risk responses that enable you to manage and mitigate the risks identified during the risk assessment process.
Before you begin
About this task
- Inherent risks
- Effectiveness of controls
- Residual risks
- Target risks
The risk assessments yield risk scores that are automatically calculated based on the configurations made in the risk assessment methodology (RAM). If you want to change the automatically calculated scores, you can overwrite the calculated scores and provide a justification. If you have no controls to assess, then the residual risk score is the same as the inherent risk score.
After performing the assessment, you can define the risk response. Risk response refers to the process of managing identified risks. It’s a planning and decision-making process where the risk managers decide how to deal with each risk. While performing the assessment, you can view detailed reference information on the Contextual side panel. This panel provides information for the risk events, open issues, key indicator breaches, control test results, and control indicator failures.
If the risk assessment in being performed by an assessor's delegate, the Assessor's delegates field shows the delegate's name.
- New: The risk assessment is created but not yet initiated or is in a ready-to-assess state.
- In progress: The risk assessment is currently being evaluated. This status applies when the assessment is in any of the following states: Inherent Assessment, Control Assessment, Residual Assessment, Target Assessment, or Respond.
- Awaiting approval: The risk assessment is complete and awaiting review or approval from the designated approvers.
- Completed: The risk assessment has been fully approved, finalized, and requires no further actions.
- Archived: The risk assessment is no longer active. When an assessment is in the Completed status and a reassessment begins for the same risk, the old assessment is moved to the Archived status.
- Cancelled: The risk assessment has been terminated or withdrawn.
Procedure
Result
Example
.
.