Steps
Treatment is stated as an outcome, not a stage number. The record moves through the same lifecycle as every other register.
- 01Choose the treatmentOpen the risk, click the Assessment tab and set Treatment strategy to reduced, avoided, shared or retained, then give Reasons for the treatment decision. Retaining a risk is a legitimate answer, provided it is authorised and recorded.
- 02Link the measuresClick Link an existing technical or organisational measure to attach a measure that carries the treatment, or click Create a new one instead. Where the measure does not exist yet, click New record and choose Privacy action instead, so the work has an owner and a date.
- 03Rate what remainsOnce the measures operate, set the residual likelihood and both residual consequences on the Assessment tab, with Evidence of effectiveness. A residual rating recorded before the measure operates is a forecast, not a result.
- 04Name the owner and the approverOn the Accountability tab set Owner and Approver. A risk carried without an owner, or retained without an approver, is raised as a gap. Where the residual risk to data subjects remains high, the approver has to be authorised at the level that can carry it.
- 05Take the record through approvalSelect each state in turn on the lifecycle bar and click Record as [state]. Each step becomes available when the answers it depends upon are present, so the order is the order of the work.
- 06Set the reviewOn the Lifecycle tab, set Review date and note the trigger that would bring the risk back earlier: a change to the processing, a new supplier, an incident or a change of measure.
- 07Monitor from the heatmapClick Risk and security in the left menu. The matrix shows where the population of risks sits before and after treatment; click a cell to filter the register below it, which is how a monthly review is run without a separate report.
