Risk Management Software to Spot Problems Early
Keep every project risk in one register. Score it, rank it, assign an owner, and track it through its lifecycle, so nothing surprises you at the deadline.
Available in the Self-Hosted edition - runs on your own servers
This capability is available in the Self-Hosted (on-premise) edition. It is not part of the Cloud edition today.
What is project risk management?
Project risk management is the practice of finding things that could go wrong on a project, judging how likely and how damaging each one is, and deciding what to do about it before it happens. Orangescrum gives you a shared risk register where every risk gets a score, an owner, a mitigation plan, and a clear status, so your team acts on risk instead of reacting to it.
Why risk gets missed on most projects
A complete risk register, built in
01Risk record
A readable risk reference
Every risk gets its own numbered reference, using a prefix you can change to suit your organisation.
Category, type, and source
Three separate fields say what kind of risk it is, what class it falls in, and where it came from.
Two owners and who raised it
A primary owner, a secondary owner, and the person who identified it are all held on the record.
Four dates that matter
When it was identified, when it is next reviewed, when it must be resolved, and how close it is.
Budget and schedule impact
Record what the risk would cost in money and in time, separately from the general description.
Escalation level and tags
Mark how far a risk has been escalated and tag it so it can be found alongside similar ones.
A description of the impact itself
Write what would actually happen if the risk occurred, kept separate from what the risk is.
02Scoring
Probability multiplied by impact
The score is calculated from the two values you set, so it is consistent across every project.
Four rating bands
Critical, high, medium, and low, worked out from the score rather than chosen by whoever raised it.
Set your own thresholds
Decide where each band begins and ends, so the register matches your organisation's appetite.
A residual score after mitigation
Record the probability, impact, and score that remain once your mitigation is in place.
A five by five heat map
Twenty five cells with probability down one axis and impact across the other, and a click drills into any cell.
Change the scale
The probability and impact scales can run from three points up to ten if five does not suit you.
03Lifecycle
Ten statuses
Draft, identified, under assessment, mitigation in progress, escalated, monitoring, materialised, and three ways of being closed.
Only valid moves are allowed
The register refuses a move that is not permitted, and asks for a comment when you make one that is.
Mark a risk as materialised
When a risk actually happens it is recorded as materialised rather than quietly closed.
Three ways to close
Closed as resolved, closed as accepted, or closed because it expired, so the reason survives.
Seven response strategies
Avoid, mitigate, transfer, accept, exploit, share, or enhance, recorded on the risk itself.
04Register
List, board, or cards
Three ways of looking at the same register, so it suits both a working session and a review.
Six filters
Narrow by search text, status, rating, category, type, or owner, with the active filters shown as chips.
Nine columns you can toggle
Choose which columns the register shows so the view carries what your team actually reads.
Drag a risk across the board
Move a risk between statuses by dragging it, with the same rules and the same comment prompt.
Change or delete several at once
Select several risks and change their status, export them, or delete them together.
Duplicate a risk
Copy an existing risk when a similar one turns up on another project.
Export the register
Send the whole register, or just the risks you selected, out as a spreadsheet file.
05Mitigation
A plan and a contingency plan
Write what you will do to reduce the risk, and separately what you will do if it happens anyway.
Its own owner and due date
The mitigation can belong to somebody other than the risk owner, with its own date and status.
Link a risk to a task
Connect the risk to the tasks that address it, so mitigation work shows up in normal delivery.
A risks tab on epics and features
Open an epic or feature and see the risks attached to it, and link a new one without leaving the task.
Relate one risk to another
Record that a risk is a parent of, dependent on, a duplicate of, or derived from another.
Watchers
Add anybody who needs to know about a risk, so they are told when its status changes.
Comments
Discuss a risk on the risk, with editing and deleting restricted to the author or an admin.
Attachments
Drag supporting evidence onto the risk so the reasoning behind a score is not lost.
06Reporting
A risk dashboard
Counts by rating, a status breakdown, a category breakdown, a small heat map, and the risks overdue for review.
Four governance measures
Total risks, closure rate, the proportion escalated, and average time to resolution.
Six reports
Register, summary, overdue, trend, escalated, and closure dependencies, each on its own card.
Mitigation progress and blocking tasks
See how far each mitigation has got and which tasks are blocking a risk from closing.
07Setup
Your own risk categories
Add, rename, deactivate, and remove the categories your organisation actually uses.
Risk templates
Save a risk you raise repeatedly as a template and use it to prefill the next one.
Bulk import from a spreadsheet
Download a template with dropdowns built in, upload your file, preview every row, then commit it.
Nineteen permissions
Separate rights to view, create, edit, delete, assess, change status, escalate, close, accept, export, import, and administer.
Restrict a role to its own risks
A role can be limited to the risks it owns, so a contractor sees theirs and nobody else's.
08Audit
An activity log on every risk
Created, edited, status changed, commented, and watcher added are all recorded with the user and time.
A full snapshot on every change
Each change stores a complete copy of the risk plus the list of fields that moved, so you can see any earlier state.
In app notifications
The project manager, the owner, and the watchers are told when a risk is raised, moved, commented on, or reassigned.
How teams use it
Built for teams that have to prove control
Which edition includes what
| Capability | CloudManaged SaaS | Self-HostedOn-premise / private cloud | Open SourceCommunity Edition |
|---|---|---|---|
| Risk register with owners, dates, and impact | ✗ | ✓ | ✗ |
| Probability and impact scoring | ✗ | ✓ | ✗ |
| Configurable rating thresholds and scales | ✗ | ✓ | ✗ |
| Residual score after mitigation | ✗ | ✓ | ✗ |
| Five by five heat map with drill down | ✗ | ✓ | ✗ |
| Ten statuses with enforced transitions | ✗ | ✓ | ✗ |
| Seven response strategies | ✗ | ✓ | ✗ |
| List, board, and card views | ✗ | ✓ | ✗ |
| Six filters and a nine column picker | ✗ | ✓ | ✗ |
| Bulk status change, export, and delete | ✗ | ✓ | ✗ |
| Mitigation and contingency plans | ✗ | ✓ | ✗ |
| Link risks to tasks, and a risks tab on epics | ✗ | ✓ | ✗ |
| Risk to risk relationships | ✗ | ✓ | ✗ |
| Watchers, comments, and attachments | ✗ | ✓ | ✗ |
| Risk dashboard and six reports | ✗ | ✓ | ✗ |
| Risk categories and reusable templates | ✗ | ✓ | ✗ |
| Bulk import with a preview step | ✗ | ✓ | ✗ |
| Nineteen risk permissions | ✗ | ✓ | ✗ |
| Activity log and full version snapshots | ✗ | ✓ | ✗ |
Risk Management FAQ
What is risk management in Orangescrum?
Risk Management in Orangescrum is a built in risk register for your projects. You record each risk, score it by probability and impact, give it an owner and a mitigation plan, and move it through ten statuses until it is closed. Every change is kept in an audit trail.
Which edition includes Risk Management?
Risk Management is available in the Orangescrum Self-Hosted edition, which you run on your own servers. It is not part of the Cloud edition today.
How does risk scoring work?
Probability is multiplied by impact to give a score, and the score falls into one of four bands: critical, high, medium, or low. You decide where each band begins, and you can widen the scales beyond five points. The result is plotted on a five by five heat map.
Can I link risks to actual project work?
Yes. A risk can be linked to the tasks that reduce or resolve it, and epics and features carry a risks tab so the connection works in both directions.
Can one risk relate to another?
Yes. A risk can be recorded as the parent of, dependent on, a duplicate of, or derived from another risk, which matters when several risks share one cause.
Is there an audit trail?
Yes. Every action is logged with the user and timestamp, and every change also stores a complete snapshot of the risk with the list of fields that moved, so you can see any earlier state.
Who can see and edit risks?
Access is controlled by nineteen separate permissions covering view, create, edit, delete, assess, change status, escalate, close, accept, export, import, and administration. A role can also be restricted to only the risks it owns.
Can we load an existing risk register?
Yes. Download the import template, which comes with the valid values built in as dropdowns, upload your file, check every row in the preview, and then commit it.
Bring project risk under control
Risk Management is included in the Orangescrum Self-Hosted edition, running entirely on your own infrastructure.