Automating risks for Requirement-Based Assessments

Learn how to streamline the process of linking risks to Requirement-Based Assessment (RBA) answers

Table of contents:

  1. Adding risk automation to an assessment template
  2. Adding recommended risks when responding to the RBA

Adding risk automation to an assessment template

Go to Audits & Assessments > Templates.

Create a new template or find the template you would like to automate risks for.

You are able to further edit any automations when creating an actual assessment based on this template.

In the template's Assessment builder tab (1), click on a requirement (2) that you would like to automate risks for, then select the Automations tab (3).

Click + Add automation to create an automation based on the condition of a field.

For example, in this RBA we have a dropdown field called 'Compliance' and it has the options 'Yes' and 'No'. We want risk association to be automated if the respondent selects 'No' for this requirement's 'Compliance' field, so we select the corresponding field and response and click Link risks.

All risks currently in your libraries are displayed here. You can perform the following actions regarding this response, to this field, of this requirement.

  • Select + next to a risk to link it; a green check indicates the risk has been linked (1). 
  • Select Linked to show all risks currently linked (2).
  • Use the available search and filter functions to find your risks (3).

Click on the arrow next to each risk to view its details. Back out of the Linked rules view by clicking on the arrow next to it, and you can see that the answer 'No' now has the above ticked risks linked to it. There is also a cog icon that indicates automation next to the requirement.

Adding recommended risks when responding to the RBA

While responding to the RBA, when a response to a field of a particular requirement is selected that has risk automation, you will see risk recommendations.

Expand the Risks dropdown to see the recommended risks. You can link them from here or click into them to see their details.

A recommended risk from the risk libraries may already exist in the risk register. You can choose to create a new version of this risk on the risk register, or link the response to the risk that already exists in the risk register.

You will be asked to Compare the recommended risk and the risk that exists on the risk register.

Compare the recommended risk with the risk that already exists on the risk register and choose to either create a new version of the recommended risk (1), or link the response to the existing issue on the risk register (2).

Once the choice has been made, the risk will appear under Linked risks.