Risk register
A risk register is the running list of what could go wrong, how bad it would be, and what you are doing about it. In Keel the register is not a standalone spreadsheet: each risk connects to the controls that reduce it, so your risk picture and your control work stay in step.
Add a risk
Section titled “Add a risk”In Risks, create a risk with a short title, a description, and a category (for example third party, operations, people, or availability). Give it an owner so there is always someone accountable for the decision, not just the entry.
Rate inherent and residual risk
Section titled “Rate inherent and residual risk”Keel captures two scores for every risk:
- Inherent risk: how severe the risk is before your controls, based on likelihood and impact.
- Residual risk: how severe it remains after the controls you have in place.
The gap between the two is the value your controls are actually adding. When you strengthen or add a control that a risk depends on, Keel recalculates the residual score so the register reflects reality instead of a number someone set months ago.
Connect risks to controls
Section titled “Connect risks to controls”Link each risk to the controls that treat it. Because controls are crosswalked across frameworks, the same control work that lowers a risk also moves your framework coverage forward. This is the practical benefit of one connected graph: reduce a risk once and the effect shows up everywhere that control applies.
Treat and track
Section titled “Treat and track”Decide how to handle each risk, treat it (implement or improve controls), accept it (record the decision and who made it), transfer it, or avoid it. Turn treatment work into tasks so it has an owner and a due date, and review the register on a cadence so nothing quietly drifts.
Next steps
Section titled “Next steps”- Evidence: prove the controls that treat your risks are operating.
- Tasks: turn risk treatment into owned, dated work.
- Frameworks & crosswalks: how one control reduces risk across many standards.