Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It covers the Risk entry in the left navigation: the register, the chain, scenarios, exposure and the board report. The Geography tab has its own guide, Risk geography map. Vendor-level risk scores and how services roll up into them are in the Admin and setup guide.
Risk is an optional module. If you do not see Risk in the left navigation, ask your Coverbase representative to turn it on.
The register is a list of statements about what could hurt your organization, each scored on a 5x5 of likelihood and impact. It does not hold evidence of its own. A risk points at records in the other modules (an open finding, a contract without a DPA, a Radar alert, a sanctions match) through signals, and those signals open and close as the source record changes. An agent reads the same modules, proposes risks and re-scores, and files stale ones for review. It never closes or deletes a risk on its own. Everything it wants changed waits in an inbox for a person. The mistake to avoid: leaving the residual score empty. An unscored residual falls back to the inherent score, so a risk you have treated keeps reading Outside appetite until you score the residual likelihood and impact.

Where it lives

Click Risk in the left navigation. Six tabs run across the top, in the order a risk officer reads them: Two buttons sit to the right of the tabs. Ask the register opens a question box that answers from the register, the chain and the signals, and cites the records it used. Configuration opens Configuration → Risk, covered below.

Reading the register

Risk register with summary tiles, a filterable table of risks and a side panel

The Register tab. Summary tiles across the top, the table with its filters, and the side panel with domains, sources and the last agent run.

The five tiles at the top are filters. Click Outside appetite, Unowned or Reviews overdue to narrow the table to those risks; click again to clear. Proposed by agent opens the agent inbox. Open signals shows the count and the change since the last run. The line under the filters reads, for example, “12 risks · 3 proposed hidden · sorted by residual, highest first”. Proposed risks never appear in the table; they wait in the inbox. Appetite is read from the domain’s Max Residual (default 12). A residual above it is Outside, a residual within two points of it is Near, and anything lower is Inside. A risk without a domain uses the default and rolls up as “No domain”. The filter bar narrows by domain, owner, institution, signal source, status scope (Active risks, Closed risks, All risks) and free text, and sorts by residual, inherent, review date or last updated. Matrix switches the table to the 5x5 heat map, with inherent and residual dots and the tolerance line drawn on it. Every filter is in the URL, so a filtered view is a link you can send. The side panel lists By Risk Domain (count and how many are outside appetite) and Where Risks Come From (signals per source module). Clicking a row filters the table. Underneath, the panel shows when the agent last ran and what it did, with a Run agent now button.

Statuses

Archiving is separate from closing. Archive removes the risk from the register and its scores. Its signals stay on their source records.

Creating a risk

1

Open the form

Click New risk in the filter bar. From a vendor, service, contract or finding page, the Risks card has Add risk, which opens the same form with that record already in scope.
2

Write the statement

Statement is what a board reader sees. The placeholder asks the right question: what could hurt the organization, and how?
3

Classify and assign

Pick a Risk Domain (its appetite decides the tolerance), a Category, an Owner (a person or a department) and, if your org has institutions, an Institution or Group.
4

Score it

Pick Likelihood and Impact from your org’s five levels; the inherent score updates as you choose. Then pick Residual Likelihood and Residual Impact for the position after treatment. Leave them at Unscored only if you have not treated the risk yet.
5

Treatment and scope

Choose a Treatment (No treatment, Mitigate, Accept, Transfer, Avoid), a Review Date, and write the Treatment Plan: what is being done, by whom, and the residual target. Add the vendors in scope. Click Create risk.
When you edit a risk later, the same form adds a Note field. Whatever you write there is recorded in the risk’s history alongside the change.

Working a risk record

Click a row to open the record. The URL becomes /risk/register/<id>, so it is a link too.
Risk detail drawer showing scoring, treatment, chain, signals and history

A risk record. Scoring against the domain tolerance, the owner and treatment actions, the chain position, the agent's rationale, the signals and the history.

The header carries Simulate (opens the Simulate tab with this statement as the question and runs it), History, Edit, and Archive. Below it, the appetite pill, the status pill and where the risk came from: “Agent-created · accepted by name, date” or “Created by name, date”. Scoring shows the inherent and residual lines as likelihood x impact and the domain tolerance they are read against. Treatment shows the chosen treatment, the plan and the residual target. Owner carries the actions that move a risk: In the Chain shows how many business units and customer channels sit behind the risk’s vendor, with Open in Chain. A risk not tied to a chain node says so. Agent rationale appears on agent-created risks and on any risk the agent re-scored. Explain more expands it. If the agent applied a re-score, Undo restores the previous levels and journals the reversal.

Signals on a risk

Signals lists every attached record with its source icon, its severity, and its status. A status that changed since attachment reads “from → to”. A signal that closed says Closed, a dismissed one Dismissed, and one whose source was archived Source removed. Nothing is ever deleted from this list, so a finding that was open when the risk was raised still shows on the timeline after it resolves.
  • Attach signal opens evidence the agent found in other modules but did not attach. Attaching keeps a reference, never a copy. Suggest more asks the agent to look again.
  • The x on a signal dismisses it. The source record is untouched.
History is the append-only journal: created, proposed, accepted, re-scored, owner changed, status changed, signal attached or closed, merged, edited, scale remapped, closed, reopened. Each row names the person or the agent and shows the scores after the change.

Signal sources and thresholds

A signal is attached only when its source is enabled under Configuration → Risk → Signal Sources and the record clears the threshold set there. Every source is on by default except Assessments. Turning a source off stops new attachments. It never removes signals already on a risk. Signal statuses refresh when the source module changes and again in a nightly pass.

The agent

The agent runs every night, about five minutes after a qualifying change in another module, and whenever someone clicks Run agent now (on the register side panel or under Configuration → Risk → Agent). One pass refreshes signal statuses, scans the sources, attaches new evidence to the open risk on the same vendor and category (or proposes a new risk), suggests re-scores, and flags stale risks. Two settings under Agent decide how much it does on its own:
  • New risks: Propose for review (default) files each new risk as Proposed for a person to accept. Create directly opens them as Open risks.
  • Re-scoring: Suggest files a re-score suggestion. Apply and notify writes the new levels and journals the change; you can still Undo on the record.
Stale after (default 120 days without a signal change) and free-text Instructions (for example, “treat any vendor with access to the core ledger as Tier 1”) complete the settings.
The agent never closes, archives or deletes a risk. When every vendor in scope is retired, or every signal has closed, it files a stale proposal with a suggested close. A person applies it or keeps the risk open. A risk you edited or dismissed is never re-proposed by a later scan.

Deciding on what the agent proposes

Click the Proposed by agent tile. The inbox has four tabs.
Agent inbox listing proposed risks with Accept, Edit and accept, Merge into and Dismiss buttons

The agent inbox. Each card carries the reasoning, the suggested scoring and owner, and the evidence, with the decision buttons underneath.

Dismiss asks why: Not a risk for us, Duplicate, Wrong scoring, Already treated or Other. The reason is fed back to the agent and recorded in history. Each card shows the agent’s confidence, its rationale under Why, and the signals under Evidence. A proposal the agent files with no signals of its own still cites the records it read.

Chain

Dependency chain graph with columns for business units, services, vendors, fourth parties and regions

The Chain tab following Operations. Business units on the left, services, vendors, fourth parties and regions to the right. Red nodes are single points of failure.

The chain is rebuilt nightly from business unit dependencies, services, active contracts, each vendor’s fourth parties (subprocessor lists where there is no entity), supplier sites and vendor risk profiles. The header names the snapshot and its date, so a scenario always says which chain it ran on. Follow picks which chain the graph traces: Narrow with Data scope, Business unit, Depth and Show only critical paths. A column with too many nodes collapses the rest behind +N more; Show all expands it. In the legend, a red edge has no contractual protection, a ring marks a node with an open register risk, and a red node is a single point of failure. Click a node to see what it depends on, what it serves, its contract (liability cap, SLA, DPA in place or not), and what is open against it (findings, obligations). Simulate outage runs an event scenario on it. Single points lists every single point of failure by reach, with how many alternatives are on record.

Simulate

Simulate tab with the scenario builder showing Event, Subject, Duration and Starts fields and the Or ask box

The Simulate tab. Build an event, change or offboarding scenario on the left, or type the question under Or ask. The result fills the panel on the right.

Pick a Scenario kind:
  • Event: an Outage, Breach, Insolvency, Sanction or Market exit on a Subject from the chain, for a Duration, starting in Business hours, weekday, Overnight or Weekend.
  • Change: Describe the change in a sentence and name the Vendors involved and Business units involved. The result lists what it touches: control sets, register risks, obligations and open questions for stakeholders.
  • Offboard: a Vendor to offboard. The result is a brief: termination terms on file, dependencies, open findings and obligations, and alternatives.
Or type the question under Or ask (“What if Cloudflare is down for a working day?”) and click Ask. The form adopts the inputs the model understood, so you can adjust and re-run.
The engine never fills in a number you have not recorded. If an estimate needs an input the org does not hold (a liability cap, a business unit’s revenue), the loss reads Estimate withheld with the reason, and Improve it lists what to record. Confidence is derived from how many inputs are present, never asserted.
A result shows services down, items touched, business units and customer channels, obligations triggered (regulatory and contractual), open findings on the path, the estimated loss, contractual protection per contract, and the Blast radius table: each business unit, the services affected, whether the channel is customer-facing, whether a workaround is on file, and the owner. Under the result: Save scenario, Attach to risk (the scenario is recorded against that risk and listed as attached to it under Saved scenarios), Create risks from gaps (each selected draft becomes a proposed risk with the scenario as its first signal) and Export brief (a Markdown file). Saved scenarios reopens any earlier run with its result.

Exposure

Exposure tab with appetite gauges per domain, a loss exceedance curve, a cushion table and concentration bars

The Exposure tab. One gauge per domain, the loss curve with its inputs coverage, the cushion table and the concentration bars.

  • Appetite by domain: one gauge per domain plus “No domain”, with the count outside appetite, the appetite statement, the average residual and a 90-day trend (rising, flat, falling). Click N outside to open those risks in the register.
  • Probable annual loss: the loss curve with the appetite line, the Method chip (change it under Configuration → Risk → Quantification), Inputs present per input type, the confidence, and Vendors without inputs. Only vendors with a residual score and a sized exposure are modeled; the rest are named, not defaulted.
  • Cushion analysis: per contract, the ACV, liability cap, insurance (none on file or not extracted) and the unprotected amount. Extract from contract runs clause extraction on rows missing a cap. Unknown stays unknown.
  • Concentration: shared fourth parties, business units on one vendor, and geography, each linking into the chain.
The line at the bottom names how fresh the assessments, contracts and Radar data are. Institution switches between Group and one institution.

Report

Report tab showing KRI tiles, movers this period, appetite breaches and a domain table

The Report tab for a quarter. The four indicator tiles, movers and appetite breaches, the KRI table by domain, and the narrative.

Choose a Period (the last six quarters). Four tiles carry a six-quarter sparkline: Risks outside appetite, Avg residual · Tier 1 vendors, Commitments on time and Framework coverage (against the frameworks chosen in configuration). Movers this period lists re-scored, new and closed risks; Appetite breaches lists the domains over their Max Outside; KRIs by domain gives each domain its owner, risk count, outside count, residual trend, open signals and top risk. All of it is read from the journal, so a re-score that later reversed still shows as a move in its period. Narrative drafts the board text from the register, the chain and the period’s signals. It is marked “drafted · edit before export”; click Edit, change it, Save. Every number in it traces to a risk or signal. Pinned Chart shows one chart from an org dashboard (see the Dashboard library); the PDF names it but cannot embed the live view. Export board pack builds the PDF in your browser. Schedule emails the report monthly or quarterly on a chosen day to the recipients you list, for one institution or the whole group. The same schedule is editable under Configuration → Risk → Board Pack Schedule.

Configuring the module

Open Configuration → Risk, or click Configuration on the Risk page. Each section saves on its own.
Editing a scale re-maps existing risks by level name; it never re-scores them. A label you move from level 2 to level 3 takes its risks with it, and a name you remove leaves its risks at their number. Each moved risk gets a Scale remapped row in its history.
Risk configuration Signal Sources section with a toggle and threshold per source

Signal Sources in configuration. One switch and threshold per source module.

The 5x5 here is not the vendor risk scale. Vendor and service scores (0 to 100, with bands and service roll-up) are configured under Configuration → Scales and described in the Admin and setup guide. A vendor score that rises reaches the register as a Vendor risk change signal.

How the other modules connect

Vendor, service, contract and finding pages each carry a Risks card listing the register entries scoped to that record, with their residual score and appetite state, Add risk, and View in register, which opens the register filtered to that record (“Scoped to this vendor”). Proposed risks show as Proposed by agent on the card. The reverse direction is the signal table above: findings and their commitments, Radar signals and alerts, contract components and clause reviews, obligations, sanctions screening, the financial health score, supplier sites, Inspect evaluations and assessments all reach the register as signals on the risks that cover them. Charts on your dashboards can slice the register by domain, status, appetite, owner and institution. Workflow automations have Create risk and Update risk actions (see Workflow templates). A risk that needs a person (a proposal, an overdue review, or an unowned risk outside appetite) also appears once in the work queue, assigned to its owner, or failing that the owning department’s lead or a domain reviewer.

Who can do what

Risk has its own permission resource, Risk register, with these grants. Members hold them by default; a missing button means the grant is missing from your role. Saving anything under Configuration → Risk needs the organization settings permission, which Admins hold. Roles are managed as described in Permissions and roles.

Notifications

Two notification types live under the Risk category in your personal notification settings. Both group one agent run’s output into a single email. Each email carries a button that opens the risk. Delivery settings are covered in Email and notifications.

Troubleshooting

Risk geography map

The Geography tab: supplier density, country marks and the vendor filters.

Admin and setup guide

Vendor risk scales, service roll-up and the rest of the organization setup.

Contract components

The DPA, SLA and liability cap slots that feed component-gap signals and the cushion table.

Email and notifications

Where to turn the two risk notifications on or off.