Complies
RR-06 RISK

Risk register software your auditor will actually respect

Risks scored by likelihood and impact, each tied to the controls that mitigate it, reviewed on a cadence the calendar enforces. Not a spreadsheet from 2023.

See pricing

Risk register software maintains a living list of your security and compliance risks, each scored by likelihood and impact, assigned an owner, and linked to the controls that mitigate it, so risk management is demonstrable rather than performed once a year. Complies builds the register into the same system as your controls and evidence: score a risk on the likelihood-times-impact matrix, link it to mitigating controls, and its residual picture updates as those controls are implemented and their evidence stays fresh. Review cadences are enforced by the compliance calendar, so quarterly or annual risk reviews actually happen and are recorded, which matters because ISO 27001 requires a documented risk methodology and SOC 2 auditors ask how risks informed control selection. Accepted risks are recorded with a named owner and a rationale, which auditors read as maturity, not weakness. The risk register is included in the Growth plan at $199 per month billed yearly, alongside cross-mapped controls and evidence collection, rather than sold as an enterprise GRC add-on the way $30,000-plus platforms like OneTrust or Hyperproof package risk. One honest limitation: a register does not reduce risk by existing, and scoring is judgment, not measurement. What it does is make your judgments explicit, owned, reviewed on schedule, and defensible in front of an auditor.

It works alongside control mapping software and audit readiness, and plugs straight into iso 27001 compliance software, soc 2 compliance software on every plan from Growth up.

RR-06 RISK

What changes when it is in place

Likelihood times impact, visibly

Every risk is scored on a consistent matrix with the rationale recorded, so two people scoring the same risk argue about substance instead of formatting.

Risks tied to real controls

Each risk links to the controls that mitigate it. When a control is implemented and evidenced, the residual risk picture updates, connecting risk paperwork to actual work.

Reviews that actually happen

Risk review cadences live on the compliance calendar with owners and reminders, so the register is demonstrably alive, which is precisely what ISO 27001 auditors check.

Accepted risks, documented honestly

Not every risk gets mitigated, and pretending otherwise fools nobody. Accepted risks are recorded with an owner and a rationale, which auditors read as maturity.

QUESTIONS

Common questions

Yes. SOC 2 includes risk assessment criteria, and auditors ask how identified risks informed your control choices. ISO 27001 goes further and requires a documented risk methodology with recorded reviews. A register that is scored, owned, linked to controls, and demonstrably reviewed answers both, and Complies produces exactly that record as a byproduct of using it.

The spreadsheet rots. Nobody is reminded to review it, scores drift out of date, and it has no connection to whether mitigating controls actually exist. In Complies the register shares a system with your controls and evidence, so residual risk reflects real implementation status, and review cadences are enforced by the same calendar that runs the rest of your compliance work.

You record the acceptance with a named owner, a rationale, and a review date, and Complies keeps it visible instead of buried. Auditors do not expect zero risk; they expect deliberate decisions. A documented acceptance reviewed on schedule reads as maturity. An unmitigated risk with no decision attached is what reads as a finding.

Put risk register on autopilot

All plans include it. Prices are public. Start today.