Risks
Open control gaps from the assessment plus vendor risks from Third-Party Risk Management.
Where it lives
Sidebar → Risks (/risks)
Two risk streams
Derived from assessment gaps (No / Partial). Each item shows severity, impact, recommended fix, and related CIS controls. Status is OPEN until you close the gap in Assessment and re-submit.
Risks logged against vendors in Third-Party Risk. Admins can Resolve or Reopen. Open items also appear here so security and procurement share one queue.
How to use it
Triage High first
High severity control risks map to Roadmap Do now.
Jump to the control
Related control IDs send you back to Assessment or the matching framework control.
Close vendor items
Resolve a vendor risk when the questionnaire or contract issue is done. That does not archive the vendor.
Add or edit vendors on Third-Party Risk. This page is the combined risk queue.