---
title: "Risk Management Software for Projects | Orangescrum"
description: "Track and control project risk with a full risk register, probability and impact scoring, a five by five heat map, ten statuses, and a complete audit trail."
canonical: https://www.orangescrum.com/risk-management
---

# Risk Management Software for Projects | Orangescrum

> For the complete documentation index, see [llms.txt](https://www.orangescrum.com/llms.txt).

[Home](/) / [Features](/features) / Risk Management

Risk Management

# Risk Management Software to _Spot Problems Early_

Keep every project risk in one register. Score it, rank it, assign an owner, and track it through its lifecycle, so nothing surprises you at the deadline.

Available inCloud[Self-Hosted](/self-hosted "Self-Hosted - included")Open Source

[Explore Self-Hosted →](/self-hosted)[Book a Demo](https://calendly.com/orangescrum)

Available in the Self-Hosted edition - runs on your own servers

This capability is available in the **Self-Hosted (on-premise)** edition. It is not part of the Cloud edition today.

## What is project risk management?

Project risk management is the practice of finding things that could go wrong on a project, judging how likely and how damaging each one is, and deciding what to do about it before it happens. Orangescrum gives you a shared risk register where every risk gets a score, an owner, a mitigation plan, and a clear status, so your team acts on risk instead of reacting to it.

The problem

## Why risk gets missed _on most projects_

Risks live in spreadsheets

Someone keeps a risk list in a file nobody opens after week two.

✓ One shared register inside the project your team already works in.

No agreed way to rank risk

Everything feels urgent, so nothing gets prioritised properly.

✓ Probability and impact scoring puts real numbers behind the ranking.

Nobody owns the follow up

A risk is raised, discussed once, and then quietly forgotten.

✓ Every risk has an owner, a status, and a full audit trail.

What you get

## A complete _risk register_, built in

Grouped the way a register is worked: what a risk record holds, how it is scored, how it moves, how you work the list, what you do about it, and what you can prove afterwards.

01Risk record

-   ### A readable risk reference
    
    Every risk gets its own numbered reference, using a prefix you can change to suit your organisation.
    
-   ### Category, type, and source
    
    Three separate fields say what kind of risk it is, what class it falls in, and where it came from.
    
-   ### Two owners and who raised it
    
    A primary owner, a secondary owner, and the person who identified it are all held on the record.
    
-   ### Four dates that matter
    
    When it was identified, when it is next reviewed, when it must be resolved, and how close it is.
    
-   ### Budget and schedule impact
    
    Record what the risk would cost in money and in time, separately from the general description.
    
-   ### Escalation level and tags
    
    Mark how far a risk has been escalated and tag it so it can be found alongside similar ones.
    
-   ### A description of the impact itself
    
    Write what would actually happen if the risk occurred, kept separate from what the risk is.
    

02Scoring

-   ### Probability multiplied by impact
    
    The score is calculated from the two values you set, so it is consistent across every project.
    
-   ### Four rating bands
    
    Critical, high, medium, and low, worked out from the score rather than chosen by whoever raised it.
    
-   ### Set your own thresholds
    
    Decide where each band begins and ends, so the register matches your organisation's appetite.
    
-   ### A residual score after mitigation
    
    Record the probability, impact, and score that remain once your mitigation is in place.
    
-   ### A five by five heat map
    
    Twenty five cells with probability down one axis and impact across the other, and a click drills into any cell.
    
-   ### Change the scale
    
    The probability and impact scales can run from three points up to ten if five does not suit you.
    

03Lifecycle

-   ### Ten statuses
    
    Draft, identified, under assessment, mitigation in progress, escalated, monitoring, materialised, and three ways of being closed.
    
-   ### Only valid moves are allowed
    
    The register refuses a move that is not permitted, and asks for a comment when you make one that is.
    
-   ### Mark a risk as materialised
    
    When a risk actually happens it is recorded as materialised rather than quietly closed.
    
-   ### Three ways to close
    
    Closed as resolved, closed as accepted, or closed because it expired, so the reason survives.
    
-   ### Seven response strategies
    
    Avoid, mitigate, transfer, accept, exploit, share, or enhance, recorded on the risk itself.
    

04Register

-   ### List, board, or cards
    
    Three ways of looking at the same register, so it suits both a working session and a review.
    
-   ### Six filters
    
    Narrow by search text, status, rating, category, type, or owner, with the active filters shown as chips.
    
-   ### Nine columns you can toggle
    
    Choose which columns the register shows so the view carries what your team actually reads.
    
-   ### Drag a risk across the board
    
    Move a risk between statuses by dragging it, with the same rules and the same comment prompt.
    
-   ### Change or delete several at once
    
    Select several risks and change their status, export them, or delete them together.
    
-   ### Duplicate a risk
    
    Copy an existing risk when a similar one turns up on another project.
    
-   ### Export the register
    
    Send the whole register, or just the risks you selected, out as a spreadsheet file.
    

05Mitigation

-   ### A plan and a contingency plan
    
    Write what you will do to reduce the risk, and separately what you will do if it happens anyway.
    
-   ### Its own owner and due date
    
    The mitigation can belong to somebody other than the risk owner, with its own date and status.
    
-   ### Link a risk to a task
    
    Connect the risk to the tasks that address it, so mitigation work shows up in normal delivery.
    
-   ### A risks tab on epics and features
    
    Open an epic or feature and see the risks attached to it, and link a new one without leaving the task.
    
-   ### Relate one risk to another
    
    Record that a risk is a parent of, dependent on, a duplicate of, or derived from another.
    
-   ### Watchers
    
    Add anybody who needs to know about a risk, so they are told when its status changes.
    
-   ### Comments
    
    Discuss a risk on the risk, with editing and deleting restricted to the author or an admin.
    
-   ### Attachments
    
    Drag supporting evidence onto the risk so the reasoning behind a score is not lost.
    

06Reporting

-   ### A risk dashboard
    
    Counts by rating, a status breakdown, a category breakdown, a small heat map, and the risks overdue for review.
    
-   ### Four governance measures
    
    Total risks, closure rate, the proportion escalated, and average time to resolution.
    
-   ### Six reports
    
    Register, summary, overdue, trend, escalated, and closure dependencies, each on its own card.
    
-   ### Mitigation progress and blocking tasks
    
    See how far each mitigation has got and which tasks are blocking a risk from closing.
    

07Setup

-   ### Your own risk categories
    
    Add, rename, deactivate, and remove the categories your organisation actually uses.
    
-   ### Risk templates
    
    Save a risk you raise repeatedly as a template and use it to prefill the next one.
    
-   ### Bulk import from a spreadsheet
    
    Download a template with dropdowns built in, upload your file, preview every row, then commit it.
    
-   ### Nineteen permissions
    
    Separate rights to view, create, edit, delete, assess, change status, escalate, close, accept, export, import, and administer.
    
-   ### Restrict a role to its own risks
    
    A role can be limited to the risks it owns, so a contractor sees theirs and nobody else's.
    

08Audit

-   ### An activity log on every risk
    
    Created, edited, status changed, commented, and watcher added are all recorded with the user and time.
    
-   ### A full snapshot on every change
    
    Each change stores a complete copy of the risk plus the list of fields that moved, so you can see any earlier state.
    
-   ### In app notifications
    
    The project manager, the owner, and the watchers are told when a risk is raised, moved, commented on, or reassigned.
    

How it works

## How teams _use it_

1

Raise the risk

Anyone with permission logs a risk against a project, with a description and category.

2

Score it

Set probability and impact. The register calculates the rating and places it on the heat map.

3

Assign and plan

Give the risk an owner and a mitigation plan, and link the tasks that will reduce it.

4

Review and close

Move it through its statuses with a comment on every change, until it is closed as resolved, accepted, or expired.

Who it's for

## Built for teams that _have to prove control_

Regulated industries

Banking, government, and healthcare teams that need a defensible record of how risk was identified and handled.

[Learn more →](/solutions/project-management-software-for-banking-and-finance)

Large programs

Program and portfolio managers tracking risk across many projects at once.

[Learn more →](/program-management-software)

Engineering and IT

Delivery teams managing technical, dependency, and release risk alongside their sprints.

[Learn more →](/solutions/it-project-management-software)

Availability

## Which edition includes _what_

Orangescrum runs as managed cloud, self-hosted on your own servers, or as the open-source Community Edition. Here is exactly what each one includes.

Risk Management is part of the Self-Hosted edition.

| Capability | CloudManaged SaaS | Self-HostedOn-premise / private cloud | Open SourceCommunity Edition |

| Risk register with owners, dates, and impact | ✗ | ✓ | ✗ |
| Probability and impact scoring | ✗ | ✓ | ✗ |
| Configurable rating thresholds and scales | ✗ | ✓ | ✗ |
| Residual score after mitigation | ✗ | ✓ | ✗ |
| Five by five heat map with drill down | ✗ | ✓ | ✗ |
| Ten statuses with enforced transitions | ✗ | ✓ | ✗ |
| Seven response strategies | ✗ | ✓ | ✗ |
| List, board, and card views | ✗ | ✓ | ✗ |
| Six filters and a nine column picker | ✗ | ✓ | ✗ |
| Bulk status change, export, and delete | ✗ | ✓ | ✗ |
| Mitigation and contingency plans | ✗ | ✓ | ✗ |
| Link risks to tasks, and a risks tab on epics | ✗ | ✓ | ✗ |
| Risk to risk relationships | ✗ | ✓ | ✗ |
| Watchers, comments, and attachments | ✗ | ✓ | ✗ |
| Risk dashboard and six reports | ✗ | ✓ | ✗ |
| Risk categories and reusable templates | ✗ | ✓ | ✗ |
| Bulk import with a preview step | ✗ | ✓ | ✗ |
| Nineteen risk permissions | ✗ | ✓ | ✗ |
| Activity log and full version snapshots | ✗ | ✓ | ✗ |

Frequently asked questions

## Risk Management _FAQ_

### What is risk management in Orangescrum?

Risk Management in Orangescrum is a built in risk register for your projects. You record each risk, score it by probability and impact, give it an owner and a mitigation plan, and move it through ten statuses until it is closed. Every change is kept in an audit trail.

### Which edition includes Risk Management?

Risk Management is available in the Orangescrum Self-Hosted edition, which you run on your own servers. It is not part of the Cloud edition today.

### How does risk scoring work?

Probability is multiplied by impact to give a score, and the score falls into one of four bands: critical, high, medium, or low. You decide where each band begins, and you can widen the scales beyond five points. The result is plotted on a five by five heat map.

### Can I link risks to actual project work?

Yes. A risk can be linked to the tasks that reduce or resolve it, and epics and features carry a risks tab so the connection works in both directions.

### Can one risk relate to another?

Yes. A risk can be recorded as the parent of, dependent on, a duplicate of, or derived from another risk, which matters when several risks share one cause.

### Is there an audit trail?

Yes. Every action is logged with the user and timestamp, and every change also stores a complete snapshot of the risk with the list of fields that moved, so you can see any earlier state.

### Who can see and edit risks?

Access is controlled by nineteen separate permissions covering view, create, edit, delete, assess, change status, escalate, close, accept, export, import, and administration. A role can also be restricted to only the risks it owns.

### Can we load an existing risk register?

Yes. Download the import template, which comes with the valid values built in as dropdowns, upload your file, check every row in the preview, and then commit it.

## Bring project risk under control

Risk Management is included in the Orangescrum Self-Hosted edition, running entirely on your own infrastructure.

[Explore Self-Hosted →](/self-hosted)[Book a Demo](https://calendly.com/orangescrum)

## Related capabilities

[Self-Hosted editionRun Orangescrum on your own servers](/self-hosted)[Test Case ManagementTrack quality alongside delivery](/test-case-management)[Advanced ReportingReport across projects and risk](/advanced-reporting)[Program ManagementManage risk across many projects](/program-management-software)
