Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a risk statement in the Risk Workspace

Create risk statements to group risks into manageable categories.

Before you begin

Role required: sn_risk.admin

About this task

When you create a risk statement, you can associate entity types or add additional entities to generate risks.

Note: When any of the following risk statement fields changes: Name, Description, Reference, Category, Type, Classification, and Attestation, all the associated controls and risks are updated, and their state is set back to Draft. All the associated risk assessments also get canceled.

Procedure

  1. Navigate to All > Risk Workspace > Library > Risk statements.

  2. Click New.

  3. On the form, fill in the fields.

FieldDescription
NameName of the risk statement.
DescriptionDescription of the risk statement.
ParentParent risk statement. You can define the hierarchy using this field.
FrameworkFramework this risk statement is associated with.Note: This field only appears if the Migrate to Advanced Risk Assessment property is enabled. For more information, see Risk score rollup in Advanced Risk Assessment
CategoryCategory of the risk statement. The choices are as follows:- Legal - Financial - Operational - Reputational - Legal/Regulatory - Credit - Market - IT - Project
LevelLevel at which the risk statement is created. For example, if the risk statement has a parent and a grandparent, then the level of this new risk statement will be 3.
AssessmentRisk assessment template to be assigned to this risk statement. An assessment template is a questionnaire that is used for assessing a risk.Note: This field appears when you use classic risk with enabling the advanced risk property.
Issue group ruleIssue group rule assigned to this risk statement for reporting. The purpose of the issue group rule is to group similar issues together into a parent issue based on conditions defined in the rule. This feature enables you to work on the similar issues at once and close out the parent issue once resolved, which will close out all the child issues.
Additional informationAdditional information for this risk statement.
  1. To fill in the fields for the risk appetite section, see Define the risk appetite for a risk statement.

  2. If you're using classic risk, in the Default Scores section, fill in the fields.

    FieldDescription
    Inherent SLESingle-loss expectancy (SLE) is the monetary value expected from the occurrence of a risk on an asset if there are no controls to check the event.
    Residual SLEMonetary value expected from the occurrence of a risk on an asset if there are controls to check the event.
    Inherent AROAnnualized rate of occurrence (ARO) is an estimated frequency of the threat occurring in one year. ARO is used to calculate annualized loss expectancy (ALE). The value in this field indicates the likelihood of the event occurring if there are no controls to check the event.
    Residual AROThe value in this field indicates the likelihood of the event occurring if there are controls to check the event.
  3. If you're using classic risk with the advanced risk plugin activated, in the Risk Rollup and Tolerance section, fill in the fields.

FieldDescription
Expected ALEALE refers to the product of the ARO and the SLE. Expected ALE is the expected value of the ALE for the risk statement. Enter currency and amount for the expected ALE.Note: This value must be less than or equal to the Maximum acceptable ALE.
Sum of calculated ALEThis calculation is based on the sum of calculated ALE of all the underlying risks of the risk statement and its children risk statements.
Maximum calculated ALEThis calculation is based on the maximum of calculated ALE of all the underlying risks of the risk statement and its children risk statements.
Maximum acceptable ALEThreshold value for the ALE for the risk statement.Note: This value must be greater than or equal to the Expected ALE. This value has an impact on the Tolerance status field.
Average calculated ALEThis calculation is based on the average of calculated ALE of all the underlying risks of the risk statement and its children risk statements.
Minimum calculated ALEThis calculation is based on the minimum of calculated ALE of all the underlying risks of the risk statement and its children risk statements.
Tolerance StatusOverall risk status. This field appears when the other ALE fields are populated.
Calculated ScoreThe corresponding score for the calculated ALE:- Low - Med - High
  1. In the Basel Categorization section, select the Basel Categories Hierarchy.

    The Basel categories are as follows:

    • Internal Fraud: misappropriation of assets, tax evasion, intentional mismarking of positions, bribery.
    • External Fraud: theft of information, hacking damage, third-party theft, and forgery.
    • Employment Practices and Workplace Safety: discrimination, workers' compensation, employee health, and safety.
    • Clients, Products, and Business Practice: market manipulation, antitrust, improper trade, product defects, breaches, account churning.
    • Damage to Physical Assets: natural disasters, terrorism, vandalism.
    • Business Disruption and Systems Failures: utility disruptions, software failures, hardware failures.
    • Execution, Delivery, and Process Management: data entry errors, accounting errors, failed required reporting, negligent loss of client assets.
    • Click Save.
  2. To add entity types, click the Entity types related list.

    1. Click Add.

    2. Select the entity types to add.

    3. Click Add.

  3. To add additional entities, click the Additional entities related list.

    1. Click Add.

    2. Select the entities to add.

    3. Click Add.

  4. Click Save.

Result

The risk statement is created.

What to do next

You can continue to add control objectives, indicator templates, and information objects to the risk statement. You can also now assess the risks that are generated in the Risks tab. You can also view the hierarchy of the risks statement on the risk statement side bar. To view the complete risk profile at a glance, click the Overview tab.

Parent Topic:Create a risk framework in the Risk Workspace