A first-class risk management workspace built into Orangescrum. Score risks on probability × impact, map them to ISO 31000 / COSO ERM / NIST RMF / SOX / GDPR controls, set Key Risk Indicators with thresholds and alerts, route status changes through configurable workflows and multi-level approvals, and track root cause + loss events end-to-end. No more risk spreadsheets going stale, no more audit fire drills.
- Rating
- 4.7
- Installs
- 8.9K
- Support
- Vendor Supported
- Trust
- Self-Hosted
287 reviews
Active deployments
Priority response
Your infra, your data
Screenshots
Key Features
Risk Register
Project-scoped register with probability × impact scoring on a configurable 1–5 scale. Search, filter, bulk-action, and templated risk creation across every active risk.
Heat Map
Visual portfolio-wide risk landscape with drill-down. See where your exposure concentrates at a glance and trend it over time.
Configurable Workflow Engine
10-status workflow from Draft → Closed plus custom states. Define which roles can move risks where, with mandatory comments, attachments, or approvals on transitions.
Multi-Level Approvals
Status changes route through configurable approver chains — sequential, parallel, or hybrid. Email notifications, SLAs, and full audit trail on every decision.
Compliance Framework Mapping
Map risks to ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR, or custom frameworks. Track control assessments, effectiveness ratings, and gap reports.
Key Risk Indicators (KRIs)
Define quantitative KRIs with green/amber/red thresholds. Automated alerts fire when indicators breach — leadership sees risk movement before incidents do.
Root Cause Analysis
Capture root cause categories, contributing factors, and corrective actions for every materialised risk. Build organisational learning instead of repeating mistakes.
Loss Event Tracking
Log loss events with monetary impact, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio.
Email Notification System
Configurable email alerts for risk creation, status changes, approvals due, KRI breaches, and assessment deadlines. Templates per workflow.
Risk-to-Task Linking
Bidirectional linking between risks and project tasks/milestones. Mitigation work surfaces in the same boards as the rest of the project.
Reusable Risk Templates
Industry- or project-specific risk templates with pre-filled categories, default scoring, and suggested mitigations — accelerate identification and standardise quality.
Granular RBAC
17 permission keys across Risk, Assessment, Reports, Templates, and Administration. Owner / Admin / User / Client / Guest roles supported out of the box.
Version Tracking
Every change to every risk is captured with timestamp, user, before/after diff, and reason — so audit history is always one query away.
File Attachments
Attach supporting documents, evidence, and artefacts to any risk. Versioned alongside the risk record itself.
Reports & Exports
Trend analysis, framework-specific gap reports, KRI dashboards, and exportable PDF / Excel / CSV reports for board packs and auditors.
Bulk Actions
Bulk status change, bulk export, bulk delete with role-gated permission. Manage hundreds of risks without clicking each one.
About this plugin
Why Risk Management for Orangescrum?
Risks live or die on visibility. A spreadsheet nobody opens is a register that never warned you. Orangescrum's Risk Management plugin makes risks first-class objects inside your project — scored, owned, mapped to compliance frameworks, monitored via KRIs, and tracked alongside the work that mitigates them.
Risk register, the way it should work
Identify a risk, score it on probability and impact (1–5, configurable labels and thresholds per company), assign an owner, attach evidence, link it to the tasks and milestones that address it. Status flows through a 10-stage workflow you can extend with custom states. The heat map updates in real-time so leadership always knows where exposure is concentrated.
Compliance framework mapping built in
Map every risk to one or more controls across ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR Article 32, or custom frameworks. Track control assessment effectiveness (Effective / Partially Effective / Ineffective / Not Assessed), generate framework-specific gap reports, and produce auditor-ready evidence on demand.
Key Risk Indicators that actually trigger
Define quantitative KRIs (vulnerability count, MTTR, customer churn, defect leakage — anything you measure) with green / amber / red thresholds. Automated alerts route to risk owners and leadership when indicators breach. Now leadership sees risk movement before incidents do.
Root cause + loss event tracking
When a risk materialises, capture it. Log root cause categories, contributing factors, monetary loss, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio — make next quarter's risk identification smarter than this quarter's.
Built for regulated industries
Banking, healthcare, government, energy, and pharma teams use this plugin to satisfy ISO 31000:2018 and ISO 27005 requirements, generate SOX 404 internal-control evidence, demonstrate GDPR Article 32 risk-of-processing assessments, and pass NIST RMF audits — all from the same register.
What's included
- Project-scoped risk register with configurable P×I scoring (1–5 scale)
- Configurable 10-status workflow + custom states with transition rules
- Multi-level sequential, parallel, and hybrid approval workflows
- Compliance framework mapping (ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, custom)
- Hierarchical control register with control assessments and effectiveness ratings
- Risk-to-control mappings with notes and assessor history
- Key Risk Indicators (KRIs) with green/amber/red thresholds
- KRI breach alerts and trend dashboards
- Root cause analysis with contributing factors and corrective actions
- Loss event tracking with monetary impact and recovery status
- Email notification system with configurable templates per workflow
- Visual portfolio-wide heat map with drill-down
- Risk-to-task and risk-to-milestone bidirectional linking
- Reusable risk templates configurable per industry or project
- File attachments versioned with the risk record
- Bulk actions: status change, export, delete (role-gated)
- 17 granular RBAC permissions across Risk, Assessment, Reports, Templates, Admin
- Owner / Admin / User / Client / Guest role types
- Trend analysis and framework-specific gap reports
- Export to PDF, Excel, and CSV for board packs and auditors
- Full version tracking with timestamp + user + diff on every change
- Multi-tenant company-scoped data isolation
Compatibility
Compatible with Orangescrum Self-Hosted Core, Business, and Enterprise editions running PHP 8.2+, CakePHP 4.6+, and PostgreSQL 13+. Frontend: Vue 3 (global build) + vanilla JS + CakePHP templates. Multi-tenant aware — every risk, framework, control, KRI, and assessment is company-scoped.
Installation
A self-hosted install takes a few minutes. Buy the add-on, drop the plugin into your plugins/ directory, run the migrations, and you're live.
- 1
Buy the add-on
Purchase the Risk Management add-on from /self-hosted/pricing — $499/year per company, payable annually.
- 2
Drop the plugin into your install
Copy the RiskManagement/ folder into plugins/ on your self-hosted Orangescrum server.
- 3
Enable the feature flag
Add `define('RISK_MANAGEMENT_ENABLED', true);` to config/constants.php and register the plugin in src/Application.php with `routes => true, bootstrap => true`.
- 4
Run the database migrations
Run `bin/cake migrations migrate --plugin RiskManagement` to create the risk register, workflow, framework, KRI, and audit tables.
- 5
Configure scoring and workflow
Set custom probability and impact labels for your organisation, configure the 10-status workflow transitions, and enable the email notification system.
- 6
Import compliance frameworks
Import ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, or custom framework control libraries from CSV/JSON via Settings → Compliance Frameworks.
- 7
Define KRIs and roll out
Set up your first Key Risk Indicators with green/amber/red thresholds, assign owners and approvers, and start logging risks.
Reviews
We replaced three different risk spreadsheets with this. The heat map alone changed how our steering committee runs.
Mitigation work is finally visible to delivery teams instead of locked in a separate doc. Game-changing for us.
Audit-ready out of the box. Took our ISO 27005 evidence collection from a quarter to a sprint.
Frequently Asked Questions
Can I customise the probability and impact scales?
▾
Yes. The 1–5 scale is the default, but you can rename the levels (e.g. Rare/Unlikely/Possible/Likely/Almost Certain), set custom descriptive labels, and define different thresholds per company.
Which compliance frameworks are supported?
▾
Out of the box: ISO 31000:2018, COSO ERM, NIST RMF, SOX 404, GDPR Article 32. Plus a custom framework builder so you can model any internal or industry-specific control library, version it, and import a control register from CSV / JSON.
How do KRIs differ from risks?
▾
Risks describe potential events. KRIs are quantitative measurements that signal risk movement before events materialise — like an early-warning radar. The plugin lets you tie KRIs to specific risks and fires alerts when thresholds breach.
Does it support quantitative as well as qualitative risk?
▾
Both. Qualitative scoring on the 1–5 scale, plus custom fields for monetary impact, schedule impact, exposure value, or any quantitative measure you track. KRIs and loss events provide the quantitative backbone.
How do mitigation tasks get tracked?
▾
Risks link bidirectionally to tasks and milestones. Create a new task from a risk or attach an existing one. Mitigation progress flows back into the risk view, and the heat map shows exposure decreasing as work completes.
Is it suitable for ISO 31000, ISO 27005, SOX 404, and GDPR audits?
▾
Yes. The version-tracked register, framework mapping, control-assessment workflow, and exportable PDF / Excel / CSV reports give you the evidence trail required by all four. Auditors can be granted scoped read-only access via the Client or Guest role.
How granular are the permissions?
▾
17 keys across 5 areas: Risk Management (view, create, edit, delete, change status, bulk actions), Assessment (view, edit, manage scoring), Reports (view, export), Templates (view, manage), Administration (settings, permissions, audit log, workflow). Owner / Admin / User / Client / Guest defaults are included.
Can I import an existing risk register from CSV or another tool?
▾
Yes. CSV import is supported for risks, KRIs, frameworks, and controls. Bulk import scripts are published for common formats including ServiceNow GRC and Archer.
Ready to deploy Risk Management on your own infrastructure?
Talk to our team about Orangescrum Self-Hosted Enterprise — your data, your servers, full control.