Workflow States
Every risk assessment moves through specific states. Here’s what each state means:
Work in progress. You can save incomplete information and return later.
Submitted and waiting for review. The checker will verify or decline it.
Approved by checker. Asset owners can now add their action plans.
Rejected by checker. Review the feedback and make corrections before resubmitting.
All asset owners have submitted their action plans. Waiting for maker approval.
Action plans approved. Asset owners can begin remediation work.
Action plans need improvement. Asset owners must revise and resubmit.
Work is complete. Asset owner has requested closure.
Risk is fully resolved and closed.
Step 1: Create Risk Assessment
Option A: Save as Draft
Use this when you don’t have all the information yet.
Click Save as Draft
Fill in whatever information you have. Missing fields are okay.
Return Later
Come back anytime to complete and submit.
Option B: Submit Directly
Use this when you have all the required information ready.
Fill All Required Fields
Complete risk name, description, assets, impacts, and findings.
Click Submit
Risk goes directly to Initiated status for review.
Required fields: Risk name, description, at least one asset, impact ratings, control effectiveness, and at least one finding.
Step 2: Submit Draft (If Saved as Draft)
When your draft is complete and ready for review:
Open Your Draft
Navigate to the draft you want to submit.
Click Submit Draft
System validates all required fields are complete.
Risk Moves to Initiated
The checker is notified to review your submission.
Step 3: Checker Review
This step only happens if your organization has checker approval enabled. If disabled, skip to Step 4.
Option A: Checker Approves
Checker Reviews
Checker examines the risk assessment for accuracy and completeness.
Click Verify
Risk moves to Verified status. Asset owners are notified to add action plans.
Option B: Checker Declines
Checker Identifies Issues
Checker finds problems with the risk assessment.
Provides Feedback
Checker enters a decline reason explaining what needs to be fixed.
Risk Moves to Declined
You receive a notification with the feedback.
Step 4: Update Declined Risk
If your risk was declined, here’s how to fix it:
Review Feedback
Read the checker’s decline reason carefully.
Make Corrections
Update the risk assessment based on the feedback.
Click Update and Resubmit
Risk returns to Initiated status. The checker reviews it again.
Step 5: Asset Owners Add Action Plans
Once the risk is verified (or initiated if no checker approval), asset owners create their plans.
Asset Owner Opens Finding
Each person assigned to a finding receives a notification.
Create Action Plan
Describe specific steps to address the risk. Example: Install security patches, enable MFA, update policies.
Set Target Date
Choose a realistic completion date.
Click Submit
Your plan is saved. When ALL asset owners submit their plans, the risk automatically moves to Plan Proposed.
Both action plan and target date are required. You cannot submit without both.
Step 6: Maker Reviews Plans
Option A: Accept Plans
Maker Reviews All Plans
Check that action plans are specific, realistic, and adequate.
Click Accept Plans
Risk moves to Plan Accepted. Asset owners can begin remediation work.
Option B: Reject Plans
Maker Identifies Issues
Plans are too vague, unrealistic, or inadequate.
Provides Feedback
Enter a rejection reason explaining what needs improvement.
Risk Moves to Plan Rejected
Asset owners receive notification to revise their plans.
Step 7: Asset Owners Revise Plans (If Rejected)
Review Rejection Reason
Read the maker’s feedback.
Update Action Plan
Make the requested improvements.
Click Submit
Updated plan is saved. When all owners resubmit, risk returns to Plan Proposed.
Asset Owners Execute Plans
Complete the actions described in your action plan.
Document Progress
Add notes and attach evidence of completion (screenshots, reports, etc).
Verify Completion
Ensure all tasks are finished and documented.
Step 9: Propose Closure
When remediation work is complete:
Asset Owner or Risk Owner Reviews
Confirm all action items are complete.
Click Propose Closure
Risk moves to Closure Proposed. The maker is notified.
Step 10: Close Risk
Maker Reviews Completion
Verify all action plans were executed and documented.
Add Closure Notes (Optional)
Document final outcome, lessons learned, or follow-up actions.
Click Close Risk
Risk moves to Closed status. The workflow is complete.
Closed risks remain in the system for audit and compliance purposes.
Quick Reference
Who Does What
Risk Maker:
- Creates and submits risks
- Updates declined risks
- Accepts or rejects action plans
- Closes risks
Risk Checker:
- Reviews submitted risks
- Verifies or declines with feedback
Asset Owner:
- Creates action plans for assigned findings
- Implements remediation
- Proposes closure when work is complete
Common Scenarios
With Checker Approval
Without Checker Approval
Quick Submit
Flow: Draft → Initiated → Verified → Plan Proposed → Plan Accepted → Closure Proposed → ClosedTotal steps: 7-10 depending on revisions
Flow: Draft → Initiated → Plan Proposed → Plan Accepted → Closure Proposed → ClosedTotal steps: 6-8 depending on revisions
Flow: Submit directly → Initiated → Continue workflowSkip draft when all information is ready
Notifications
You’ll receive email and in-app notifications at key steps:
Risk Makers get notified when:
- Risk is verified or declined
- All action plans are proposed
- Closure is proposed
Risk Checkers get notified when:
- New risk awaits review
- Declined risk is resubmitted
Asset Owners get notified when:
- New finding is assigned
- Action plan is rejected
Tips for Success
For Risk Makers
Use drafts for complex assessments. Address all feedback before resubmitting. Review plans carefully before accepting.
For Risk Checkers
Review within 24-48 hours. Provide specific feedback. Be consistent in your criteria.
For Asset Owners
Create specific, measurable plans. Set realistic dates. Document your work thoroughly.
For Everyone
Use comments to collaborate. Attach evidence. Keep information current.
Troubleshooting
Problem: Submit button is disabledSolution: Complete all required fields. Look for red validation errors on the form.
Problem: Waiting too long for checkerSolution: Contact the checker directly or escalate to admin if urgent.
Problem: Update button not availableSolution: Only Draft and Declined risks can be edited. Other states are locked.
Action plan will not submit
Problem: Submit button disabledSolution: Both action plan text and target date are required.
Configuration
Admins can enable or disable checker approval in Entity Configuration. This setting only affects new risks, not existing ones.
Related Pages
Risk Assessment Basics
Learn fundamentals of risk assessment
User Management
Set up roles and permissions
Asset Management
Manage assets linked to risks
Reports
Generate workflow reports