Creating and assessing risks

Creating and assessing risks

Use risk assessments to record, assess, and track risks on Jira work items. A risk assessment captures the likelihood and impact of a risk, then calculates the risk level using the risk model configured for the Jira space.

Risk assessments are stored on Jira work items. This means you can manage risks with standard Jira capabilities such as workflows, assignees, comments, links, automation, and reporting.

You can record both:

  • Inherent risk — the level of risk before treatments or controls are applied.

  • Residual risk — the level of risk that remains after treatments or controls are applied.

Before you begin

Make sure the relevant Jira space has been configured for risk assessments.

  • The work item type must be configured as a primary risk work item type or a supplementary risk work item type.

  • To create or edit risks, you need the relevant Jira permissions, including permission to create or edit the work item.

  • The Risk Register app must be licensed and available for the site.

If Risk assessment is not available on a work item, contact your Jira or Risk Register administrator to confirm that the work item type is enabled for risk assessments.

Create a risk

A risk is a Jira work item that has risk assessment information saved against it.

Create a risk from Jira

  1. Create a Jira work item using a primary or supplementary risk work item type.

  2. Open the work item.

  3. Select Risk assessment, if the assessment panel is not already displayed.

  4. Select Modify.

  5. Enter the risk assessment values.

  6. Select Save.

The work item becomes a risk when the risk assessment is saved.

Create a risk from a risk register

For a risk register scoped to a Jira space, you may be able to create risks directly from the register.

  1. Open the risk register.

  2. Select Actions.

  3. Select Add a risk.

  4. Complete the Jira create work item form.

  5. Select Create.

Risk Register creates the work item using the configured primary risk work item type and adds an empty risk assessment automatically. This ensures that the new risk appears in the risk register before probability and impact have been assessed.

Add a risk is only available when the register is scoped to a Jira space, a primary risk work item type has been configured, and you have permission to create that work item type in the space.

Add a risk assessment to an existing work item

You can add a risk assessment to an existing work item when its work item type is configured as a primary or supplementary risk work item type.

  1. Open the Jira work item.

  2. Select Risk assessment.

  3. Select Modify.

  4. Enter the assessment values.

  5. Select Save.

A work item that already contains a risk assessment continues to display its risk information even if its work item type is later removed from the primary or supplementary risk type configuration.

Assess a risk

Open the Jira work item and locate the Risk assessment panel.

The panel shows:

  • the risk model used for the assessment

  • inherent probability

  • inherent impact

  • inherent risk

  • residual risk information, when specified.

Select Modify to update the assessment.

You need Jira's Edit issues permission for the work item to modify its risk assessment. Risk assessments are read-only if you do not have permission to edit the work item.

Risk model

Each assessment uses the risk model configured for its Jira space. The risk model defines:

  • the available probability values

  • the available impact values

  • how combinations of probability and impact map to risk levels.

The risk model name is displayed at the top of the risk assessment. Risk Register administrators can select the risk model name to open its configuration.

Risk model out of date

A risk assessment keeps a reference to the version of the risk model used when it was assessed.

If the space's risk model has changed, Risk Register displays Risk model out of date.

  1. Select Sync to update the assessment to the current risk model.

  2. Review the resulting probability, impact, and risk level.

  3. Select Modify if you need to update the assessment values.

If the previous risk model has been deleted, the assessment may be marked as invalid. Select Modify to move the assessment to the current risk model and set appropriate values.

Assess inherent risk

Inherent risk represents the level of risk before treatments or controls are applied.

When an assessment is first created, inherent probability and impact are Unspecified.

  1. Select Modify.

  2. Select the inherent probability.

  3. Select the inherent impact.

  4. Review the calculated inherent risk.

  5. Select Save.

Field

Description

Field

Description

Inherent probability

The likelihood of the risk occurring before treatments or controls are applied.

Inherent impact

The consequence or impact if the risk occurs before treatments or controls are applied.

Inherent risk

The risk level calculated from the selected inherent probability and inherent impact.

You do not select the inherent risk level directly. Risk Register calculates it automatically using the matrix in the applicable risk model.

Specify residual risk

Residual risk represents the risk remaining after treatments or controls have been applied.

  1. Select Modify.

  2. Turn on Specify residual risk.

  3. Set the residual probability and residual impact.

  4. Review the calculated residual risk.

  5. Select Save.

When you first turn on Specify residual risk, Risk Register copies the current inherent probability and impact into the residual assessment. You can then change the residual values to reflect the expected or actual effect of treatments.

Field

Description

Field

Description

Residual probability

The likelihood of the risk occurring after treatments or controls are applied.

Residual impact

The consequence or impact if the risk occurs after treatments or controls are applied.

Residual risk

The risk level calculated from residual probability and residual impact using the same risk model as the inherent assessment.

You do not select the residual risk level directly. For example, a risk may have an inherent risk of High and a residual risk of Medium, showing the expected reduction in exposure after treatments are applied.

Remove a residual assessment

To stop recording a separate residual assessment:

  1. Select Modify.

  2. Turn off Specify residual risk.

  3. Select Save.

The saved residual probability, impact, and risk level are removed from the assessment. This does not remove the inherent risk assessment or the Jira work item.

Some risk registers can be configured to display inherent risk as the residual risk when no separate residual assessment exists. This is a display setting for the risk register and does not create a residual assessment on the Jira work item.

Save or cancel changes

Use the edit controls in the risk assessment panel to save or discard changes.

Action

Result

Action

Result

Save

Stores your changes, returns the assessment to read-only mode, and makes the updated values available to Risk Register features such as risk registers and risk matrices.

Cancel

Discards unsaved changes and returns the assessment to read-only mode using the values that were last saved.

Remove a risk assessment

You can remove the risk assessment from work items that use a supplementary risk work item type.

  1. Open the risk.

  2. Select Remove in the Risk assessment panel.

  3. Review the confirmation.

  4. Select Remove.

Removing an assessment deletes the risk assessment information but does not delete the Jira work item.

You cannot remove the risk assessment from a work item that uses the configured primary risk work item type. The primary risk work item type is reserved for risks, so the Remove option is not displayed.

Hide the Risk assessment panel

For supplementary risk work item types, you can hide the Risk assessment panel from the Jira work item view.

  1. Open the Jira work item.

  2. Use Jira's issue content controls to select Hide Risk assessment.

Hiding the panel does not remove the assessment or change any of its values. The risk continues to appear in applicable risk registers and matrices.

Select Risk assessment again to display the panel.

The Risk assessment panel cannot be hidden from work items that use the primary risk work item type.

View risk history

Risk Register records changes made to risk assessments.

  1. Open the Jira work item.

  2. Go to the work item's activity area.

  3. Select Risk history.

Risk history can show:

  • when a risk assessment was created

  • changes to probability, impact, and risk level

  • changes to inherent and residual assessments

  • when a risk assessment was removed

  • who made each change

  • when each change was made.

For assessments created before risk history was introduced, or assessments migrated from Jira Server or Data Center, the earliest changes may not be available.

Troubleshooting

Problem

What to check

Problem

What to check

I can't modify a risk assessment

Check that you have Jira's Edit issues permission for the work item, the Risk Register license is active, and the assessment is synchronized with the current risk model.

Risk assessment isn't available

Check that the work item type is configured as either the primary risk work item type or a supplementary risk work item type. Contact your Jira or Risk Register administrator if the work item type needs to be enabled.

Add a risk isn't available in the risk register

Check that the risk register is scoped to a Jira space, a primary risk work item type has been configured, and you have permission to create that work item type in the space.

The assessment says the risk model is out of date

Select Sync, then review the mapped probability, impact, and risk level before saving further changes.

Related pages