> ## Documentation Index
> Fetch the complete documentation index at: https://docs.figorisk.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Risk Assessment

> Step-by-step guide to managing risks from creation to closure

## Workflow States

Every risk assessment moves through specific states. Here's what each state means:

<AccordionGroup>
  <Accordion title="Draft" icon="file-pen">
    Work in progress. You can save incomplete information and return later.
  </Accordion>

  <Accordion title="Initiated" icon="paper-plane">
    Submitted and waiting for review. The checker will verify or decline it.
  </Accordion>

  <Accordion title="Verified" icon="circle-check">
    Approved by checker. Asset owners can now add their action plans.
  </Accordion>

  <Accordion title="Declined" icon="circle-xmark">
    Rejected by checker. Review the feedback and make corrections before resubmitting.
  </Accordion>

  <Accordion title="Plan Proposed" icon="list-check">
    All asset owners have submitted their action plans. Waiting for maker approval.
  </Accordion>

  <Accordion title="Plan Accepted" icon="thumbs-up">
    Action plans approved. Asset owners can begin remediation work.
  </Accordion>

  <Accordion title="Plan Rejected" icon="thumbs-down">
    Action plans need improvement. Asset owners must revise and resubmit.
  </Accordion>

  <Accordion title="Closure Proposed" icon="flag-checkered">
    Work is complete. Asset owner has requested closure.
  </Accordion>

  <Accordion title="Closed" icon="check-double">
    Risk is fully resolved and closed.
  </Accordion>
</AccordionGroup>

***

## Step 1: Create Risk Assessment

### Option A: Save as Draft

Use this when you don't have all the information yet.

<Steps>
  <Step title="Click Save as Draft">
    Fill in whatever information you have. Missing fields are okay.
  </Step>

  <Step title="Return Later">
    Come back anytime to complete and submit.
  </Step>
</Steps>

### Option B: Submit Directly

Use this when you have all the required information ready.

<Steps>
  <Step title="Fill All Required Fields">
    Complete risk name, description, assets, impacts, and findings.
  </Step>

  <Step title="Click Submit">
    Risk goes directly to Initiated status for review.
  </Step>
</Steps>

<Note>
  Required fields: Risk name, description, at least one asset, impact ratings, control effectiveness, and at least one finding.
</Note>

***

## Step 2: Submit Draft (If Saved as Draft)

When your draft is complete and ready for review:

<Steps>
  <Step title="Open Your Draft">
    Navigate to the draft you want to submit.
  </Step>

  <Step title="Click Submit Draft">
    System validates all required fields are complete.
  </Step>

  <Step title="Risk Moves to Initiated">
    The checker is notified to review your submission.
  </Step>
</Steps>

***

## Step 3: Checker Review

<Info>
  This step only happens if your organization has checker approval enabled. If disabled, skip to Step 4.
</Info>

### Option A: Checker Approves

<Steps>
  <Step title="Checker Reviews">
    Checker examines the risk assessment for accuracy and completeness.
  </Step>

  <Step title="Click Verify">
    Risk moves to Verified status. Asset owners are notified to add action plans.
  </Step>
</Steps>

### Option B: Checker Declines

<Steps>
  <Step title="Checker Identifies Issues">
    Checker finds problems with the risk assessment.
  </Step>

  <Step title="Provides Feedback">
    Checker enters a decline reason explaining what needs to be fixed.
  </Step>

  <Step title="Risk Moves to Declined">
    You receive a notification with the feedback.
  </Step>
</Steps>

***

## Step 4: Update Declined Risk

If your risk was declined, here's how to fix it:

<Steps>
  <Step title="Review Feedback">
    Read the checker's decline reason carefully.
  </Step>

  <Step title="Make Corrections">
    Update the risk assessment based on the feedback.
  </Step>

  <Step title="Click Update and Resubmit">
    Risk returns to Initiated status. The checker reviews it again.
  </Step>
</Steps>

***

## Step 5: Asset Owners Add Action Plans

Once the risk is verified (or initiated if no checker approval), asset owners create their plans.

<Steps>
  <Step title="Asset Owner Opens Finding">
    Each person assigned to a finding receives a notification.
  </Step>

  <Step title="Create Action Plan">
    Describe specific steps to address the risk. Example: Install security patches, enable MFA, update policies.
  </Step>

  <Step title="Set Target Date">
    Choose a realistic completion date.
  </Step>

  <Step title="Click Submit">
    Your plan is saved. When ALL asset owners submit their plans, the risk automatically moves to Plan Proposed.
  </Step>
</Steps>

<Warning>
  Both action plan and target date are required. You cannot submit without both.
</Warning>

***

## Step 6: Maker Reviews Plans

### Option A: Accept Plans

<Steps>
  <Step title="Maker Reviews All Plans">
    Check that action plans are specific, realistic, and adequate.
  </Step>

  <Step title="Click Accept Plans">
    Risk moves to Plan Accepted. Asset owners can begin remediation work.
  </Step>
</Steps>

### Option B: Reject Plans

<Steps>
  <Step title="Maker Identifies Issues">
    Plans are too vague, unrealistic, or inadequate.
  </Step>

  <Step title="Provides Feedback">
    Enter a rejection reason explaining what needs improvement.
  </Step>

  <Step title="Risk Moves to Plan Rejected">
    Asset owners receive notification to revise their plans.
  </Step>
</Steps>

***

## Step 7: Asset Owners Revise Plans (If Rejected)

<Steps>
  <Step title="Review Rejection Reason">
    Read the maker's feedback.
  </Step>

  <Step title="Update Action Plan">
    Make the requested improvements.
  </Step>

  <Step title="Click Submit">
    Updated plan is saved. When all owners resubmit, risk returns to Plan Proposed.
  </Step>
</Steps>

***

## Step 8: Implement Remediation

<Steps>
  <Step title="Asset Owners Execute Plans">
    Complete the actions described in your action plan.
  </Step>

  <Step title="Document Progress">
    Add notes and attach evidence of completion (screenshots, reports, etc).
  </Step>

  <Step title="Verify Completion">
    Ensure all tasks are finished and documented.
  </Step>
</Steps>

***

## Step 9: Propose Closure

When remediation work is complete:

<Steps>
  <Step title="Asset Owner or Risk Owner Reviews">
    Confirm all action items are complete.
  </Step>

  <Step title="Click Propose Closure">
    Risk moves to Closure Proposed. The maker is notified.
  </Step>
</Steps>

***

## Step 10: Close Risk

<Steps>
  <Step title="Maker Reviews Completion">
    Verify all action plans were executed and documented.
  </Step>

  <Step title="Add Closure Notes (Optional)">
    Document final outcome, lessons learned, or follow-up actions.
  </Step>

  <Step title="Click Close Risk">
    Risk moves to Closed status. The workflow is complete.
  </Step>
</Steps>

<Check>
  Closed risks remain in the system for audit and compliance purposes.
</Check>

***

## Quick Reference

### Who Does What

**Risk Maker:**

* Creates and submits risks
* Updates declined risks
* Accepts or rejects action plans
* Closes risks

**Risk Checker:**

* Reviews submitted risks
* Verifies or declines with feedback

**Asset Owner:**

* Creates action plans for assigned findings
* Implements remediation
* Proposes closure when work is complete

***

## Common Scenarios

<Tabs>
  <Tab title="With Checker Approval">
    **Flow:** Draft → Initiated → Verified → Plan Proposed → Plan Accepted → Closure Proposed → Closed

    Total steps: 7-10 depending on revisions
  </Tab>

  <Tab title="Without Checker Approval">
    **Flow:** Draft → Initiated → Plan Proposed → Plan Accepted → Closure Proposed → Closed

    Total steps: 6-8 depending on revisions
  </Tab>

  <Tab title="Quick Submit">
    **Flow:** Submit directly → Initiated → Continue workflow

    Skip draft when all information is ready
  </Tab>
</Tabs>

***

## Notifications

You'll receive email and in-app notifications at key steps:

**Risk Makers get notified when:**

* Risk is verified or declined
* All action plans are proposed
* Closure is proposed

**Risk Checkers get notified when:**

* New risk awaits review
* Declined risk is resubmitted

**Asset Owners get notified when:**

* New finding is assigned
* Action plan is rejected

***

## Tips for Success

<CardGroup cols={2}>
  <Card title="For Risk Makers" icon="lightbulb">
    Use drafts for complex assessments. Address all feedback before resubmitting. Review plans carefully before accepting.
  </Card>

  <Card title="For Risk Checkers" icon="lightbulb">
    Review within 24-48 hours. Provide specific feedback. Be consistent in your criteria.
  </Card>

  <Card title="For Asset Owners" icon="lightbulb">
    Create specific, measurable plans. Set realistic dates. Document your work thoroughly.
  </Card>

  <Card title="For Everyone" icon="lightbulb">
    Use comments to collaborate. Attach evidence. Keep information current.
  </Card>
</CardGroup>

***

## Troubleshooting

<AccordionGroup>
  <Accordion title="Cannot submit draft" icon="circle-question">
    **Problem:** Submit button is disabled

    **Solution:** Complete all required fields. Look for red validation errors on the form.
  </Accordion>

  <Accordion title="Risk stuck in Initiated" icon="circle-question">
    **Problem:** Waiting too long for checker

    **Solution:** Contact the checker directly or escalate to admin if urgent.
  </Accordion>

  <Accordion title="Cannot edit risk" icon="circle-question">
    **Problem:** Update button not available

    **Solution:** Only Draft and Declined risks can be edited. Other states are locked.
  </Accordion>

  <Accordion title="Action plan will not submit" icon="circle-question">
    **Problem:** Submit button disabled

    **Solution:** Both action plan text and target date are required.
  </Accordion>
</AccordionGroup>

***

## Configuration

<Note>
  Admins can enable or disable checker approval in Entity Configuration. This setting only affects new risks, not existing ones.
</Note>

***

## Related Pages

<CardGroup cols={2}>
  <Card title="Risk Assessment Basics" icon="book" href="/guides/risk-assessment">
    Learn fundamentals of risk assessment
  </Card>

  <Card title="User Management" icon="users" href="/guides/user-management">
    Set up roles and permissions
  </Card>

  <Card title="Asset Management" icon="server" href="/guides/asset-management">
    Manage assets linked to risks
  </Card>

  <Card title="Reports" icon="chart-bar" href="/guides/reporting">
    Generate workflow reports
  </Card>
</CardGroup>
