A risk register that connects to the work. Score it, treat it, close it.
Every risk links to the controls that reduce it and the Planner task that fixes it. When a control improves, the risk re-scores. When the task closes with evidence, the risk closes with it — and the auditor sees the whole chain.
Start Free Book a Demo

4.8/5 across 223 reviews on SourceForge · #1 vCISO platform on G2, Summer 2026
Risk registers become graveyards
Risk registers live in spreadsheets, disconnected from the actual remediation. You identify a risk, log it, and the work happens somewhere else. Six months later an auditor asks "has this been addressed?" and you cross-reference two systems by hand. Risk management becomes theater: risks get logged, nobody closes them, and the register fills with year-old items. What you need is a register linked to your controls and your remediation workflow, so risks, tasks and evidence are one connected record.
Six steps from identified to closed
Identify
A control gap, security issue or compliance risk — from the assessment, an automated test, or by hand. Name it, describe it, link it to a control.
Score
Impact (1–5) × likelihood (1–5). Low 1–5, Medium 6–15, High 16–25. Sort the register by score and the top of the list is what matters.
Treat
Accept, Avoid, Mitigate or Transfer — and record why. Cleo can help you choose.
Close with evidence
Link a Planner card, do the work, attach the proof. Status advances Open → Mitigating → Mitigated → Closed, and the dashboard shows the auditor treatment, status, evidence and closure date.
What the register does that a spreadsheet can't
Bidirectional control ↔ risk mapping
Risks tied to the controls that mitigate them. "Implement this control" shows the impact on every linked risk; a control degrading re-scores the risks it addresses. Five risks on access control? Fixing access control moves all five.
Risk-to-task traceability
Click a risk, see the task. Click the task, see the risk. Complete the task and the risk status updates — no manual cross-referencing.
Status lifecycle
Open → Mitigating → Mitigated → Closed. Clear progression, tied to the Planner. Not "open forever".
Treatment options
Accept, Avoid, Mitigate, Transfer — with the approval and rationale recorded. Competitors assume every risk needs fixing.
Register dashboard & export
Name, score, status, treatment, due date, owner, linked control. Filter by status, sort by score, export for auditors. Top risks appear in Briefs and rollup dashboards.
Trend reporting
"Month 1: 15 open. Month 3: 8 open, 7 mitigated." Show leadership that risk posture is improving, quarter over quarter.
Four risks, four treatments
Access control gap — Mitigate
User access not reviewed quarterly; stale accounts keep permissions. Impact 4 × Likelihood 5 = 20 (High). Task: implement quarterly access review with an Okta export. Evidence: review policy + Q1 log. ✓ Mitigated.
Encryption weakness — Accept
Backups encrypted with AES-128 rather than AES-256. Impact 3 × Likelihood 2 = 6 (Medium). Business decision: cost of upgrade exceeds the risk; CTO and CISO sign off. Evidence: risk-acceptance form. ✓ Accepted.
Vendor risk — Transfer + Mitigate
Payment processor hasn't provided a SOC 2 report in 18 months. Impact 4 × Likelihood 2 = 8 (Medium). Transfer (vendor's cyber insurance) + Mitigate (request the report by Q2 via TPRM). ✓ Mitigating.
Missing API rate limiting — Avoid
Public endpoints lack rate limiting. Impact 4 × Likelihood 4 = 16 (High). Add rate limiting and change the process: every public API requires it. Evidence: code review, deployment log, load test. ✓ Avoided.
This is the differentiator
You assess a control — "do we have an access review process?" — and answer no. That creates a gap. You raise the risk: "lack of access review allows stale accounts to retain permissions." You mitigate it by implementing the control. When the control is satisfied, the risk can move to Mitigated. Risks aren't separate from compliance; they are tied to the controls that address them — and to the vendors and evidence in the same graph.
Risk Management FAQ
How are risks scored?
Impact on a five-point scale (negligible to catastrophic) times likelihood on a five-point scale (rare to almost certain) gives a score from 1 to 25. RealCISO groups it as Low (1–5), Medium (6–15) and High (16–25). Two separate scales force you to think about impact and likelihood independently — a high-impact, low-likelihood risk needs a different treatment from a low-impact, high-likelihood one.
What treatment options are there?
Accept (documented and approved), Avoid (change the process), Mitigate (reduce impact or likelihood through controls and work), or Transfer (to a vendor or insurer). Not every risk needs fixing; the register records the decision either way.
How is the risk register connected to my controls?
Bidirectionally. Each risk links to the controls that mitigate it, so implementing a control shows its effect on every linked risk — and when a control's maturity changes, the risks it addresses re-score. Unmet controls surface as risks in the first place.
How does a risk get closed?
Link it to a Planner card, work the task, and attach the evidence — policy, certificate, log, screenshot. The risk moves Open → Mitigating → Mitigated → Closed with a closure date and the evidence behind it, which is what an auditor wants to see.
Can I report on risk over time?
Yes. The register trends open, mitigating and closed risks across periods ("15 open in month 1, 8 in month 3, 7 mitigated"), Briefs include top risks with the organization each belongs to, and the export is auditor-ready.
Go deeper on any capability
Where risks come from and where their evidence lives.
Turn your risk register into a working system
Score it, treat it, track it to closed — with evidence auditors actually want to see.
Start Free Book a Demo