Joopler docs
Run your program

Risk register

Track risks, link them to the controls that mitigate them, and record how each is treated.

Keep a living risk register that ties each risk to the controls that reduce it, so your risk decisions are backed by what you actually have in place, not a static spreadsheet.

Record a risk

For each risk, capture what it is, its category, and an owner. Score it two ways:

  • Inherent - the exposure before any controls.
  • Residual - the exposure that remains after the controls that mitigate it.

The gap between the two is the value your controls are providing.

Map each risk to the controls that mitigate it. Because those controls are graded live from your evidence, your residual risk reflects reality: if a mitigating control starts failing, the risk it was holding down is visibly exposed again.

Treat and review

Record a treatment decision for each risk - mitigate, accept, transfer, or avoid - and a next-review date so risks are revisited on a cadence. A maintained register with owners, scoring, and treatment is what satisfies the risk-assessment control across SOC 2, ISO 27001, HIPAA, and PCI.