Create or manage risks on a processing activity

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • Add new risks or manage the risks that are automatically added to the processing activity from the assessment responses. Adding risks helps you manage processing activities using the risk-based approach.

    Before you begin

    Role required: sn_privacy.analyst who owns the processing activity or sn_privacy.manager

    About this task

    You can add or manage risks to a processing activity in the following ways:
    • Selecting risk statements: You can add existing risk statements to a processing activity. When you add a risk statements to a processing activity, the risks associated with that particular risk statement are added to the processing activity.
    • Selecting from the recommended risks: This option enables you to choose from a list of recommended risks based on the information object that is mapped to a processing activity. If an information object is mapped to one or more risk statements, and the same information object is mapped to a processing activity, the system recommends the corresponding risk statements.
    • Creating risks: You can create risks and add them to the processing activity.
    • Applying risks from entities: You can apply privacy-related risks on the processing activity from the related entity.

    Procedure

    1. Navigate to All > Privacy Workspace > Processing activities > All processing activities.
    2. Select and open the processing activity to which you want to add controls.
    3. Click the Risks related list.
    4. To add a risk to the processing activity, do one of the following.
      OptionDescription
      To create a risk Click New and fill in the form.

      For details see, Create a risk.

      To add a risk by using the existing risk statement
      1. Click Add risk by risk statement.
      2. Select the risk statements that you want to add.
      3. Click Add.
      To select a risk from the list of recommended risks
      1. From the Add risk by risk statement list, select Recommend risks.
      2. Click Add.
      Note:
      If a risk has already been added to a processing activity, then it does not appear in the list of recommendations.

    Result

    The mitigating controls are added to the processing activity.