100% client-side — your risk data never leaves your browser

Risk Register + Matrix Generator

Build an information-security risk register aligned to ISO 27005 and NIST SP 800-30. Score risks qualitatively (likelihood × impact), quantitatively (SLE / ALE), track treatment and residual risk, and export the register as XLSX, PDF or JSON.

Risk Register
ID Risk Category Owner Inherent Residual Effective Frameworks ALE Status Actions

No risks yet. Click + Add Risk to create your first entry, or Load Templates to seed the register with common infosec risks.

Risk Heatmap
Top Risks
Rollups
Framework Coverage ISO 27002:2022 → NIST CSF 2.0 → SOC 2
Risks Above Appetite

Need help treating these risks?

Get hands-on help with risk treatment, control selection and audit-ready documentation.

Book a consultation →

Frequently asked questions

What standards is this risk register aligned to?

The register follows ISO/IEC 27005 and NIST SP 800-30 methodology — qualitative likelihood × impact scoring on a configurable matrix, with optional quantitative SLE/ALE analysis for monetised risk.

Can I track risk treatment and residual risk?

Yes. Each risk records an inherent score, a treatment plan (accept, mitigate, transfer, avoid) and a residual score after controls, so you can show the before/after on an interactive heatmap and flag anything above your risk appetite.

Is my risk data uploaded anywhere?

No — the tool is 100% client-side. Your risks never leave your browser. Export the register to XLSX, PDF or JSON to save or share it. To map the controls you choose as treatment, use the Control Mapper.

What is the difference between inherent and residual risk?

Inherent risk is the exposure before any controls; residual risk is what remains after your treatment is applied. This register captures both — and only counts residual as the effective score once treatment is marked complete, so current exposure is never understated.

Can one risk register serve ISO 27001, NIST CSF and SOC 2?

Yes. Link the ISO 27002:2022 controls you rely on to each risk and the register automatically derives the matching NIST CSF 2.0 subcategories and SOC 2 Trust Services Criteria using the same crosswalk as the Control Mapper. The framework coverage panel shows how much of each framework your register touches — useful evidence for a Statement of Applicability — and every mapping is carried into the CSV, XLSX and PDF exports. Derived mappings are marked exact, partial or related; verify them against the source standards before submitting them to an auditor.

Does it support ISO 27001 risk acceptance sign-off?

Yes. Risks set to Accepted require a recorded sign-off — who accepted, their role, date, justification and an acceptance review date — satisfying ISO 27001 clause 6.1.3(f) and SOC 2 expectations. The PDF report includes a dedicated acceptance register, plus overdue-review tracking for clause 8.2.