Skip to Main Content
Created by Guest
Created on Nov 7, 2019

Allow qualitative only risk ratings

Currently you have to enter quantitative values to provide a risk rating number and level. Could there be an option to just have a level, even if in the background you had to use quantitative values the display would just be high, medium, low etc. The other rating criteria can then be the indicator for flagging the risk for follow up. For example if you have a high risk, with deficient control effectiveness but you had agreed it can be managed outside of the target level this would not flag for additional follow up that can be set up in the configuration. See image for examples. It would be ideal if target levels could be entered based on classifications assigned
  • ADMIN RESPONSE
    Feb 23, 2024

    Thank you all very much for posting your feedback. After review we have determined that we will not be moving forward with this request.

  • Attach files
  • Guest
    Reply
    |
    Sep 7, 2022
    Thanks for the suggestion. I can see how this would be beneficial when some controls are deficient but still managed outside of the target level. We'll open this up for voting and monitor interest from other customers.