Creating and editing risks (Data Center)

Creating and editing risks (Data Center)

At a glance: Create risks as Jira issues, assess inherent and residual risk, and manage treatment through Jira workflows.

Before you begin

Make sure that:

  • Risk management is enabled for the project.

  • The nominated risk issue type is available in the project.

  • You have permission to create and edit issues in the project.

  • The project’s screens and custom field contexts include the required Risk Register fields.

Your Jira administrator controls the fields, terminology, workflow, risk model, and assessment controls available in each project.

Create a risk

You can create a risk from the project risk register or by using Jira’s standard issue creation process.

Create a risk from the risk register

To create a risk:

  1. Open the Jira project.

  2. Select Risk register from the project navigation.

  3. Select Add a risk.

  4. Enter the risk details.

  5. Select Create.

The project and nominated risk issue type are selected automatically when you create the risk from the risk register.

The fields shown in the create dialog depend on the project’s Jira screen configuration.

Create a risk using Jira

You can also use Jira’s standard Create button:

  1. Select Create in the Jira navigation.

  2. Select the project.

  3. Select the issue type nominated for risks.

  4. Enter the risk details.

  5. Select Create.

Any issue created with the nominated risk issue type is treated as a risk in a project that has Risk Register enabled.

Enter the risk details

Complete the standard Jira fields required by your organisation. These may include:

  • Summary

  • Description

  • Assignee

  • Reporter

  • Priority

  • Labels

  • Components

  • Due date

Use the Summary to state the risk clearly and concisely.

For example:

A key supplier may not deliver the equipment before installation begins.

Use the Description to record additional information such as:

  • The cause of the risk

  • The uncertain event

  • The possible consequences

  • Existing controls

  • Assumptions or dependencies

Your Jira administrator may have added other fields to the risk create or edit screen.

Assess a risk

Open the risk issue to record its probability, impact, and calculated level of risk.

When slider-based assessment is enabled, the issue displays a Risk assessment panel. The panel initially shows the inherent risk assessment.

To assess the risk:

  1. Open the risk issue.

  2. Find the Risk assessment panel.

  3. Select Modify.

  4. Select an inherent probability.

  5. Select an inherent impact.

  6. Select Save.

The app calculates the inherent level of risk from the selected probability and impact using the risk model assigned to the project.

The names of these fields may differ if your Jira administrator has customised the Risk Register terminology.

Understand the inherent risk assessment

The inherent risk assessment represents the level of risk before additional treatments or controls are applied.

The assessment contains:

  • Inherent probability — how likely the risk is to occur.

  • Inherent impact — the expected consequence if the risk occurs.

  • Inherent risk — the calculated level of risk.

The available probability and impact values come from the project’s risk model.

Select a probability or impact value to see its configured name and description. The calculated level of risk is displayed with the label and colour defined in the risk model.

If either probability or impact is not selected, the level of risk remains unspecified.

Specify residual risk

Residual risk represents the expected level of risk after the planned treatments or controls have been applied.

To add a residual risk assessment:

  1. Open the risk issue.

  2. Find the Risk assessment panel.

  3. Select Modify.

  4. Turn on Specify residual risk.

  5. Select a residual probability.

  6. Select a residual impact.

  7. Select Save.

When residual risk is first enabled during the project’s Treat workflow transition, the app may initialise the residual probability and impact using the current inherent values. You can then change them to reflect the expected effect of the treatment.

To remove the residual assessment:

  1. Select Modify.

  2. Turn off Specify residual risk.

  3. Select Save.

This removes the residual estimate but retains the inherent assessment.

Edit an assessment

To change an existing risk assessment:

  1. Open the risk.

  2. Find the Risk assessment panel.

  3. Select Modify.

  4. Change the probability or impact values.

  5. Select Save.

The calculated level of risk updates when the probability or impact changes.

Select Cancel to discard your unsaved changes.

While the assessment is being saved, the panel displays Saving.... The issue page refreshes after the update has completed.

Edit other risk information

Risk Register risks remain standard Jira issues. Use Jira’s normal issue editing controls to change fields outside the assessment panel.

To edit a risk:

  1. Open the risk issue.

  2. Select Edit, or edit an individual field inline.

  3. Update the required fields.

  4. Select Update.

Depending on your configuration, risk-related fields may also appear on Jira’s create, edit, or workflow transition screens.

These fields can include:

  • Inherent probability

  • Inherent impact

  • Residual probability

  • Residual impact

  • Treatment

  • Treatment plan

  • Contingency plan

  • Realisation information

The calculated inherent and residual risk fields are maintained by Risk Register from the selected probability and impact.

Record a treatment

A treatment describes how you intend to modify or manage the risk.

When the project uses the workflow supplied with Risk Register, select Treat after the risk has been analysed.

To treat a risk:

  1. Open the risk issue.

  2. Select the Treat workflow action.

  3. Enter the required treatment information.

  4. Review or update the residual probability and impact.

  5. Complete the transition.

The Treat transition requires an inherent probability, an inherent impact, and a treatment.

The exact fields displayed during the transition depend on the treatment screen configured by your Jira administrator.

Risk Register can also be configured to show Jira issues linked to the risk as treatments. Linked treatments remain separate Jira issues with their own assignees, statuses, priorities, and workflows.

Use the Risk Register workflow

Projects may use the workflow supplied with Risk Register. Its principal stages are:

Status

Description

Status

Description

Open

The risk has been created but may not yet be assessed.

Analyzed

The inherent probability and impact have been specified.

Treated

Treatment information has been recorded.

Closed

The risk has been closed.

The workflow includes the following user transitions:

  • Analyze — specify the inherent probability and impact.

  • Treat — specify the treatment and, where appropriate, residual risk.

  • Close Issue — close the risk.

  • Reopen Issue — reopen a closed risk.

Workflow transitions may fail if required risk assessment or treatment information is missing.

The workflow can also move a risk automatically:

  • From Open to Analyzed when probability and impact are added.

  • From Analyzed to Treated when treatment information is added.

  • Back to an earlier status when required assessment or treatment information is removed.

Your project may use a different Jira workflow, so the available statuses and transitions can vary.

Add an assessment to another Jira issue

When slider-based assessment is enabled, you may be able to assess an issue that does not use the nominated risk issue type.

To add a risk assessment:

  1. Open the Jira issue.

  2. Open the issue actions menu.

  3. Select Assess risk.

Risk Register attaches an empty risk assessment to the issue and reloads the issue page. You can then use the Risk assessment panel to enter the inherent and residual estimates.

The Assess risk action is available only when:

  • The issue belongs to a project with Risk Register enabled.

  • Slider-based assessment is enabled.

  • The issue is not already assessed.

  • The issue does not use the nominated risk issue type.

An assessed issue can appear in the project risk register even though it uses another issue type.

Remove a risk assessment

For an assessed issue that does not use the nominated risk issue type, you can remove the attached assessment.

To remove it:

  1. Open the assessed issue.

  2. Find the Risk assessment panel.

  3. Select Remove.

  4. Review the confirmation message.

  5. Select Delete.

This removes the risk assessment from the issue. It does not delete the Jira issue.

The Remove option is not available for issues that use the nominated risk issue type. Those issues remain risks by virtue of their issue type.

Open the project risk register

From the issue’s Risk assessment panel, select View risk register to return to the project risk register.

The risk appears in the register or matrix according to its current assessment values and the register’s configured criteria.

Troubleshoot risk creation and editing

The Add a risk button is unavailable

The app may not have a valid licence. Contact your Jira administrator.

The risk does not appear in the register

Check that:

  • The issue belongs to the correct project.

  • The issue uses the nominated risk issue type, or has a risk assessment attached.

  • The issue matches any additional criteria configured for the register.

  • Risk management is enabled for the project.

The Risk assessment panel is missing

The panel appears only when:

  • Risk Register is enabled for the project.

  • Slider-based assessment is enabled.

  • The issue uses the nominated risk issue type or has an assessment attached.

When slider-based assessment is disabled, use the risk custom fields on Jira’s create, edit, or transition screens instead.

I cannot save an assessment

Make sure that you have permission to edit the issue and that the Risk Register custom fields have valid contexts for the project and issue type.

A Jira administrator may need to correct the project’s field, screen, or custom field context configuration.

A workflow transition will not complete

The transition may require additional risk information.

For the standard Risk Register workflow:

  • Analyze requires inherent probability and impact.

  • Treat requires inherent probability, impact, and treatment information.

Complete the missing fields and try the transition again.