Complies
RR-06 RISK

Risk register software: the compliance risk register your auditor will respect, mapped to ISO 27001

Risks scored by likelihood and impact, each tied to the controls that mitigate it, reviewed on a cadence the calendar enforces. Not a spreadsheet from 2023.

See pricing

Risk register software maintains a living list of your security and compliance risks, each scored by likelihood and impact, assigned an owner, and linked to the controls that mitigate it, so risk management is demonstrable rather than performed once a year. Complies builds the register into the same system as your controls and evidence: score a risk on the likelihood-times-impact matrix, link it to mitigating controls, and its residual picture updates as those controls are implemented and their evidence stays fresh. Review cadences are enforced by the compliance calendar, so quarterly or annual risk reviews actually happen and are recorded, which matters because ISO 27001 requires a documented risk methodology and SOC 2 auditors ask how risks informed control selection. Accepted risks are recorded with a named owner and a rationale, which auditors read as maturity, not weakness. The risk register is included in the Growth plan at $199 per month billed yearly, alongside cross-mapped controls and evidence collection, rather than sold as a separately priced enterprise GRC module the way suites like OneTrust and Hyperproof package risk, which are quote-only and sized for larger programs. One honest limitation: a register does not reduce risk by existing, and scoring is judgment, not measurement. What it does is make your judgments explicit, owned, reviewed on schedule, and defensible in front of an auditor.

It works alongside control mapping software and audit readiness, and plugs straight into iso 27001 compliance software, soc 2 compliance software on every plan from Growth up.

RR-06 RISK

What changes when it is in place

Likelihood times impact, visibly

Every risk is scored on a consistent matrix with the rationale recorded, so two people scoring the same risk argue about substance instead of formatting.

Risks tied to real controls

Each risk links to the controls that mitigate it. When a control is implemented and evidenced, the residual risk picture updates, connecting risk paperwork to actual work.

Reviews that actually happen

Risk review cadences live on the compliance calendar with owners and reminders, so the register is demonstrably alive, which is precisely what ISO 27001 auditors check.

Accepted risks, documented honestly

Not every risk gets mitigated, and pretending otherwise fools nobody. Accepted risks are recorded with an owner and a rationale, which auditors read as maturity.

QUESTIONS

Common questions

A risk register is a maintained list of the risks facing your organization, each recorded with a description, an owner, a likelihood and impact score, and a decision about what you are doing about it. It is the document that shows how risk drove your control choices, which is the question both SOC 2 and ISO 27001 auditors ask first.

Risk register software keeps that list current instead of letting it rot in a spreadsheet. It scores each risk on a consistent matrix, assigns an owner, links the risk to the controls that mitigate it, and enforces a review cadence. In Complies the register shares a system with your controls and evidence, so residual risk reflects what is actually implemented.

ISO 27001 does not use the phrase "risk register", but Clause 6.1.2 requires a documented information security risk assessment process and Clause 8.2 requires you to perform and retain results of those assessments. A register is how nearly every certified organization satisfies that, and Clause 6.1.3 then ties each risk to a treatment decision and the Statement of Applicability.

At minimum: a clear risk description, the asset or process affected, a named owner, likelihood and impact scores with the rationale behind them, the treatment decision (mitigate, accept, transfer, or avoid), the controls that mitigate it, a residual score, and a review date. Auditors look hardest at the owner, the rationale, and evidence that reviews actually happened on schedule.

Yes. SOC 2 includes risk assessment criteria, and auditors ask how identified risks informed your control choices. ISO 27001 goes further and requires a documented risk methodology with recorded reviews. A register that is scored, owned, linked to controls, and demonstrably reviewed answers both, and Complies produces exactly that record as a byproduct of using it.

The spreadsheet rots. Nobody is reminded to review it, scores drift out of date, and it has no connection to whether mitigating controls actually exist. In Complies the register shares a system with your controls and evidence, so residual risk reflects real implementation status, and review cadences are enforced by the same calendar that runs the rest of your compliance work.

You record the acceptance with a named owner, a rationale, and a review date, and Complies keeps it visible instead of buried. Auditors do not expect zero risk; they expect deliberate decisions. A documented acceptance reviewed on schedule reads as maturity. An unmitigated risk with no decision attached is what reads as a finding.

Put risk register on autopilot

All plans include it. Prices are public. Start today.