Set up your workspace
Create an account and follow the organization setup flow. If you have an invitation or a pending join request, continue through the welcome page. Agree responsibilities and scoring criteria before your team starts adding risks.
Build and review the risk register
Record each risk with its owner and context. Review inherent, residual, and target scores together. Use filters to focus on the risks that need discussion, then open the detail view to inspect treatments, controls, and evidence.
Turn assessments into decisions
Propose a treatment for a risk, add the rationale, and route the decision for approval. Follow linked findings and controls as work progresses. Reassess the risk when the treatment or supporting evidence changes.
Coordinate supplier assessments
Maintain supplier records and assign assessments. Share an assessment portal link with the supplier, review submitted answers, and follow up on evidence. Use the supplier's risk and dependency context when deciding the next action.
Maintain the evidence record
Upload documents to the evidence workspace, keep versions together, and link them to the relevant records. Review the document's scope and currency before relying on it for a control review or an assessment.
Review framework assessment results
Select a supported assessment framework and submit the documents in scope. Review gaps and evidence references before using the report. A framework assessment supports preparation; it does not replace an independent audit or grant certification.
Assign access deliberately
Client roles are viewer, contributor, approver, and admin. Provider roles support managed-service operations. Assign roles to match each person's responsibilities and review membership when those responsibilities change.
Prepare management reviews
Review current scores, treatment status, open findings, and supporting evidence before exporting reports. State the period and scope of the review so readers can distinguish a current assessment from a previous reporting snapshot.