Create a risk initiative
Open the Start Initiative drawer from Risk Management and choose your framework: a risk framework for the overall risk program, or a third-party framework to run the third-party (TPRM) submodule. Set the details and owners, then submit.
Try it in CybervergentOverview
Launch your risk program, the overall risk module, or its third-party (TPRM) submodule, depending on the framework you choose.
Step-by-step
- 1 In the sidebar, open 'Posture Management' then 'Risk Management' (this opens /initiative?t=risk).
- 2 Click 'New Initiative' to open the 'Start Initiative' drawer. The stepper runs Initiative, Details, Mapping, Delegate, Roadmap.
- 3 On the Initiative step, choose your framework. A risk framework gives you the overall risk program, which covers risk types such as operational, IT, cyber, and strategic, with third-party risk as a submodule; a third-party framework focuses on the third-party (TPRM) submodule. You can also click 'Create custom framework'. Click 'Next'.
- 4 On the Details step, enter the name and set the 'From' and 'To' dates. Click 'Next'.
- 5 On the Mapping step, review the control relationship map, then click 'Next'.
- 6 On the Delegate step, set the initiative business unit, add owners, and use 'Link custom frameworks' to attach the frameworks this risk program runs on.
- 7 Review the Roadmap step, then click 'Submit'.
- 8 A risk-program initiative opens with Risk Assessment, Risk Register, and Risk Indicator tabs; a third-party initiative opens the third-party module.
Related articles
Risk Posture Read and manage your risk posture Find your risk posture, read the key risk score and KRI breaches, and drive it down over time. Risk Assessment Run a risk assessment Assess a risk in any domain (operational, financial, IT and cyber, compliance and regulatory, legal, strategic, reputational, ESG, supply chain, and more) against an asset, using vulnerability and threat analysis with inherent risk scoring. Risk Register Work the risk register Track identified risks with their inherent and residual ratings and owners. Risk Register Explore a risk Drill into a single risk to see its profile, assessment, owners, treatment, and activity.