Total Logged Risks
0
Active Organization Structure
0
System Users
0
Risk Matrix
|
|
|||
Risk Summary
| Date Recorded | Risk ID | Risk Description | Owner | Status | KRI | Mitigations | Overdue | Completion | Export | |
|---|---|---|---|---|---|---|---|---|---|---|
| No risks recorded. | ||||||||||
|
|
|
|||||||||
Branch / Department Risk Profile
| Risk Description | |
|---|---|
| – |
Risk Rating Timeline
Each risk's recorded rating over time, for all three ratings at once. Reading down the rows from Very High (top) to Very Low (bottom), each marker in a time column sits at that rating's band at that moment. A new column is added whenever any of the three moves.
No rating history yet — add or update risks to build the timeline.
| Risk | Rating | |
|---|---|---|
| (removed) |
|
|
| Timeline |
Risk Information Summary
0
Total KRIs
0
Mitigations
0
KRIs Summary
Critical (Breached)
0
Warning
0
Within Limit
0
Unrated
0
Mitigations Summary
Not Started
0
In Progress
0
Delayed / Overdue
0
Completed
0
Total Actions
0
Completion
Mitigation Monitoring — Due Date Target vs Current Date
| Risk ID | Mitigation ID | Mitigation Name | Action Owner | Due Date Target | Current Date | Status Tracking | No. of Days |
|---|---|---|---|---|---|---|---|
| No mitigations under tracking (all completed or none defined). | |||||||
| — | |||||||
Data Movement Summary
Tracked from the record history — how risks, mitigations and KRIs have moved over time.
Risk Rating Movement
Mitigation Movement
KRI Movement
Detailed Movement Log
Every recorded change in chronological order (oldest first) — with before → after values.
Risk Rating Movement
No movement recorded yet.
No movement matches your search.
| Item | Movement | Rating Change | Reason | Evidence | When | |||
|---|---|---|---|---|---|---|---|---|
| — |
Mitigation Movement
No movement recorded yet.
No movement matches your search.
| Risk | Item | Movement | Change | Reason | Evidence | When |
|---|---|---|---|---|---|---|
| — |
KRI Movement
No movement recorded yet.
No movement matches your search.
| Risk | Item | Movement | Change | Reason | Evidence | When |
|---|---|---|---|---|---|---|
| — |
Dropped / Closed Records
Risks, mitigations and KRIs that were dropped/closed — full last-known detail with the drop reason and supporting evidence. Click 📎 View to open an evidence file.
Dropped Risks
| Risk ID | Risk Description | Owner | Department | Category | Status | Created | Approval | Root Cause | Consequences | Risk Evidence | Drop Reason | Drop Evidence | Dropped At | Action | |||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
×
|
— | — | |||||||||||||||
Dropped Mitigations
| Risk ID | Mitigation ID | Mitigation Name | Action Owner | Due Date | Status | Effectiveness | Mitigation Evidence | Source | Drop Reason | Drop Evidence | Dropped At | Action |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| — | via Risk drop Direct | — | ||||||||||
Dropped Key Risk Indicators
| Risk ID | KRI ID | KRI Name | Base | Warning | Critical | Current | Source | Drop Reason | Drop Evidence | Dropped At | Action |
|---|---|---|---|---|---|---|---|---|---|---|---|
| via Risk drop Direct | — | ||||||||||
Risks by Category
Action Completion Status
High & Very High Risk Summary Index
| Risk Detail | Owner | Rating | KRI Count |
|---|---|---|---|
| No high or very high risks recorded. | |||
|
|
|||
Mitigation Monitoring — Due Date Target vs Current Date
| Risk ID | Mitigation ID | Mitigation Name | Action Owner | Due Date Target | Current Date | Status Tracking | No. of Days |
|---|---|---|---|---|---|---|---|
| No mitigations under tracking (all completed or none defined). | |||||||
| — | |||||||
Detailed Risk Register
No risks recorded yet.
No risks match your search.
| Indicator | Base | Warning | Critical | Current |
|---|---|---|---|---|
No KRIs defined.
| Action Plan | Owner | Due Date | Status | Effectiveness | Evidence |
|---|---|---|---|---|---|
No mitigation actions mapped.
Risk Rating Timeline
No rating history yet.
|
|
|
Risk Rating Movement
No movement recorded yet.
| Movement | Likelihood | Impact | Rating Change | Reason | Evidence | When |
|---|---|---|---|---|---|---|
| — |
Mitigation Movement
No movement recorded yet.
| Item | Movement | Change | Reason | Evidence | When |
|---|---|---|---|---|---|
| — |
KRI Movement
No movement recorded yet.
| Item | Movement | Change | Reason | Evidence | When |
|---|---|---|---|---|---|
| — |
Operational Integrity Maintained
No overdue tasks or critical alerts currently active.
Log Risk Assessment Framework
Active Risk Matrix Index Logs
| Actions | ID | Risk Owner | Department | Category | Created Date | Status | Approval Date | Evidence Reference | Risk Description | Root Cause | Consequences | L × I → Rating | Mapped Key Risk Indicators (KRI Framework) | Relational Safeguards & Action Evidence (1:N) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|
No evidence
|
×
×
|
Base
Warning
Critical
Metric Value:
|
Owner:
Due:
No Evidence Uploaded
|
Security Alerts
No active alerts.
Live Log Stream
CPU history
Memory history
API latency (p95)
Requests / sec
Module usage frequency
User activity
| User | Role | Events | Last |
|---|---|---|---|
| Time | Sev | User | Module | Action | Record | Remark |
|---|---|---|---|---|---|---|
| No log entries match the filters. | ||||||
| # | ||||||
Log Detail
Security & audit events
| Time | User | Module | Action | Record | Type |
|---|---|---|---|---|---|
| No security-relevant events captured yet. | |||||
| # | |||||
Failed logins, brute-force and suspicious-IP detection require server-side auth logging; this view surfaces the security-relevant events available in the audit stream (access changes, methodology changes, deletions).
Generate Report
Reports honour the filters set on the Logs tab. Each export embeds a report version, UTC timestamp, the filters used, and a SHA-256 signature.
Report catalogue
Alert Thresholds
Alert channels (Email / In-app / Teams / Slack / SMS) route through the existing Notification engine; these thresholds drive the in-app alerts below.
Active alerts
No active alerts.
Alert history
No alerts fired this session.
Live data: system metrics from /api/metrics; application, audit & security events from the real-time event stream; API latency/error/throughput measured in-client. Infrastructure-scoped items in the spec (Kafka/OpenSearch pipeline, WORM storage, MFA, AES-256 log encryption, anomaly-detection AI) are architectural and layer beneath this dashboard.
Risk Assessment Methodology
Define the entire heat map, scales, thresholds, colours and risk categories here. Every risk form, rating and heat map across the application updates from this configuration — no code changes required.
Likelihood Scale
Impact Scale
| Impact |
|
|---|---|
|
|
|
| No impact dimensions yet — click “+ Add dimension” to add rows like People, Environment, Reputation, or Financial. |
Columns are severity levels (add/remove with “+ Add level” / ×). Rows are impact dimensions (add/remove with “+ Add dimension” / ×). Level names flow through the whole app; the cell descriptors document what each level means for each dimension.
Rating Bands & Quadrant Assignment
First define your bands (name + colours), ordered lowest → highest severity (this order drives the rating-timeline axis). Then assign a band to every quadrant in the grid below — no score multiplication, you decide each cell (e.g. Catastrophe + Rare can be High).
| Band Name | Fill Colour | Text Colour | Preview | |
|---|---|---|---|---|
|
|
|
Quadrant Assignment
Tip: pick a band and (optionally) type any quadrant number shown top-right. Numbers may repeat — the same number can be used on more than one cell. The heat map preview below and every rating/heat map across the app and exports follow these assignments.
Axis orientation is presentation only — it transposes every heat map (this grid, the preview, the dashboard Risk Matrix, and the Word/PDF report) on save. Band assignments and quadrant numbers stay bound to the same Likelihood × Impact pair, so no rating changes when you flip it.
Heat Map Preview
Risk Categories
Categories available in the Core Risk Profiles & Internal Index (the Category field when logging a risk).
Note: renaming a category will not relabel risks already saved under the old name.
| ID | Department | State | Zone | Region | Actions |
|---|---|---|---|---|---|
|
|
|||||
| ID | Identity / Risk Assessor Name | Email Context | Position | Department | Organization Structure | User ID | Password | Access Group | Actions |
|---|---|---|---|---|---|---|---|---|---|
|
|
|||||||||
User Access Matrix
Configure permissions for every system process, per role — aligned to enterprise governance, ISO 31000, ISO 27001 (A.5.15 Access Control / A.5.3 Segregation of Duties) and COBIT. One row per process, one column per permission. Conflicts of duty are flagged automatically.
Controls how much of the organization hierarchy a can view risks from. Region > Zone > State > Department — a higher level sees every level beneath it.
| Process / Module | Row | |
|---|---|---|
| Admin only | / |
- : holds both and
A single role should not perform both a maker (create / submit / configure) and a checker (review / approve) duty on the same process. Split these across roles to preserve SoD.
Checking Full Control grants every permission for that process and clears automatically if any permission is removed. This matrix is the authoritative permission configuration for MyRisiko governance and serves as access-control audit evidence (ISO 27001 A.5.15).
SMTP_* values to send real email.
| Name | Applies to | Status | Action |
|---|---|---|---|
| No notifications. Click “+ New”. | |||
{Action} and {Event} are available.Fire when a date field is exactly this many days before/after today. Enter several to get a reminder ladder (e.g. 30, 14, 7, 3, 1).
Only records matching these rules are considered. Choose any field from the database.
| # | Field | Operator | Value | |
|---|---|---|---|---|
| No filter rules — all records of this type match. | ||||
e.g. “Due Date within 10 days After Today” (upcoming) or “…within 2 days Before Today” (overdue). All date rules must pass.
| Date field | Within (days) | Target | |
|---|---|---|---|
| No date rule — fires regardless of dates. | |||
Local time is UTC+8 (Malaysia). Sends once per day at or after this time.
{Items} expands to the matching records. Toggle </> to edit raw HTML.{Items} expands to one per-item line for each matching record.)Every record type and its fields. Use each as {Field:name} in the per-item line — but only the fields of the notification's selected record type will have data. Fields with › are joined from a related table.
| Label | Variable | Type |
|---|---|---|
{Items} {Count} {CurrentDate}, and for Event triggers: {Action} {Event} {Remark} {Reason} {Movement} {RatingChange} {Changes} {MovementDetail}. {ID} gives the record's ID in the per-item line.
| Time | Notification | Recipient | Status | Detail |
|---|---|---|---|---|
| No notifications logged yet. | ||||
Uploaded Documents
| # | Document Name | File Name | Uploaded Date | Size | Actions |
|---|---|---|---|---|---|
|
|
|
Record Risk Management Activity
Activity Details
BCM Emergency Call Tree
Activate incident response call trees and notify personnel via WhatsApp, SMS and email with automatic escalation.
Response Status — Active Incidents
Live Response Board
LIVENo incident selected. Activate an incident or open one from the Incidents tab.
| Name | Role | Level | Notified | Status | Set Status |
|---|---|---|---|---|---|
Activity & Audit Trail
| # | Type | Severity | Location | Call Tree | Status | Activated | Actions |
|---|---|---|---|---|---|---|---|
|
|
|||||||
BCM Incident Report
Full log of every activated event. Open a report for details, evidence and export.
| # | Type | Severity | Location | Call Tree | Status | Activated | Evidence | Remark | Actions |
|---|---|---|---|---|---|---|---|---|---|
| — |
|
||||||||
Edit Incident Report
Call Trees
No call trees yet. Create one to begin.
Tree Members (sorted by escalation level)
Select a call tree on the left.
| Level | Name | Role | Department | SMS | Actions | ||
|---|---|---|---|---|---|---|---|
| — | — | — |
|
Escalation Timetable
Minutes after activation at which each level is notified. Applies to all trees unless a tree-specific rule set exists.
Members to Notify
No members yet. Add the people this tree should notify.
Activate BCM Incident
This will trigger the call tree and notify all Level-1 personnel immediately.
AI Risk Analysis
Ask questions in plain language. The model writes a read-only query, MyRisiko runs it on your data, and answers are grounded in the real figures.
Ask about your risks, mitigations, KRIs, departments or exposure trends.
View SQL
AI Settings
Higher = longer answers & reports. 1500 is a good default.
Lower = precise & consistent (best for data queries). Higher = more creative.
Report Builder
Build your own dashboard, then export to Word, PDF or Excel.
Add a widget
Drag any widget to reorder — or use the ↑ ↓ handles on each widget.
This dashboard is empty.
Turn on Edit Layout, then add KPI cards, charts, or tables.
0
| No records. |
| No rows. |
| No records. |
Tables: risks, mitigations, key_risk_indicators — append-only history (each edit is a row). For the latest version of each record, join on MAX(_seq) per record_id. Only SELECT/WITH is allowed.
Tokens: {{records}} inserts the data as a table · {{count}} row count · {{scope}} scope · {{dashboard}} name · {{date}}. <script> runs when the widget renders \u2014 the data rows are available as window.rbRecords. A full HTML document (starting with <!DOCTYPE> or <html>, incl. its own CDN libraries) renders in an isolated frame; an HTML fragment renders inline.
Feeds {{records}}, {{count}} and window.rbRecords. Tables: risks, mitigations, key_risk_indicators (append-only history). Only SELECT/WITH.
Bands, colours, quadrant numbers and axis orientation follow the Risk Management configuration automatically — change them there and this widget updates everywhere, including exports.
This reason is saved to the movement history and appears in reports.
Select a Risk Evidence folder in Settings to attach the required document.