Risk taxonomy
Two-axis classification — risk categories and types with cross-cutting themes. Retire, never delete; history stays classified.
How the taxonomy works
Risk categories (Level 1) are the broad families of risk your organisation manages; risk types (Level 2) are the specific risks that sit beneath them.
Cross-cutting themes — AI, Cyber, Third-party and the like — are lenses that cut across categories; approving an assessment tags its risks with the themes chosen there.
The counts are live — a risk count is the register risks classified to that category or type, and a control count is the distinct controls mitigating those risks through their control-risk links on the register; for a theme, the risk count is instead the risks tagged with it when an assessment was approved.
Categories and types are retired, never deleted — retiring keeps history searchable, and any risks still classified there are remapped to a category or type you choose.
Give each category and type a short description — it shows on hover in the tree and in the details panel.
Cross-cutting themes
Select a risk category, type or theme to see its details.