Orangescrum Logo

Risk Management

by Orangescrum · Compliance & Governance

Self-HostedVerifiedEnterprise-ready

A first-class risk management workspace built into Orangescrum. Score risks on probability × impact, map them to ISO 31000 / COSO ERM / NIST RMF / SOX / GDPR controls, set Key Risk Indicators with thresholds and alerts, route status changes through configurable workflows and multi-level approvals, and track root cause + loss events end-to-end. No more risk spreadsheets going stale, no more audit fire drills.

Rating
4.7

287 reviews

Installs
8.9K

Active deployments

Support
Vendor Supported

Priority response

Trust
Self-Hosted

Your infra, your data

Screenshots

Risk register with configurable P×I scoring
Portfolio heat map across projects
Compliance framework mapping (ISO 31000 ↔ controls)

Key Features

Risk Register

Project-scoped register with probability × impact scoring on a configurable 1–5 scale. Search, filter, bulk-action, and templated risk creation across every active risk.

Heat Map

Visual portfolio-wide risk landscape with drill-down. See where your exposure concentrates at a glance and trend it over time.

Configurable Workflow Engine

10-status workflow from Draft → Closed plus custom states. Define which roles can move risks where, with mandatory comments, attachments, or approvals on transitions.

Multi-Level Approvals

Status changes route through configurable approver chains — sequential, parallel, or hybrid. Email notifications, SLAs, and full audit trail on every decision.

Compliance Framework Mapping

Map risks to ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR, or custom frameworks. Track control assessments, effectiveness ratings, and gap reports.

Key Risk Indicators (KRIs)

Define quantitative KRIs with green/amber/red thresholds. Automated alerts fire when indicators breach — leadership sees risk movement before incidents do.

Root Cause Analysis

Capture root cause categories, contributing factors, and corrective actions for every materialised risk. Build organisational learning instead of repeating mistakes.

Loss Event Tracking

Log loss events with monetary impact, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio.

Email Notification System

Configurable email alerts for risk creation, status changes, approvals due, KRI breaches, and assessment deadlines. Templates per workflow.

Risk-to-Task Linking

Bidirectional linking between risks and project tasks/milestones. Mitigation work surfaces in the same boards as the rest of the project.

Reusable Risk Templates

Industry- or project-specific risk templates with pre-filled categories, default scoring, and suggested mitigations — accelerate identification and standardise quality.

Granular RBAC

17 permission keys across Risk, Assessment, Reports, Templates, and Administration. Owner / Admin / User / Client / Guest roles supported out of the box.

Version Tracking

Every change to every risk is captured with timestamp, user, before/after diff, and reason — so audit history is always one query away.

File Attachments

Attach supporting documents, evidence, and artefacts to any risk. Versioned alongside the risk record itself.

Reports & Exports

Trend analysis, framework-specific gap reports, KRI dashboards, and exportable PDF / Excel / CSV reports for board packs and auditors.

Bulk Actions

Bulk status change, bulk export, bulk delete with role-gated permission. Manage hundreds of risks without clicking each one.

About this plugin

Why Risk Management for Orangescrum?

Risks live or die on visibility. A spreadsheet nobody opens is a register that never warned you. Orangescrum's Risk Management plugin makes risks first-class objects inside your project — scored, owned, mapped to compliance frameworks, monitored via KRIs, and tracked alongside the work that mitigates them.

Risk register, the way it should work

Identify a risk, score it on probability and impact (1–5, configurable labels and thresholds per company), assign an owner, attach evidence, link it to the tasks and milestones that address it. Status flows through a 10-stage workflow you can extend with custom states. The heat map updates in real-time so leadership always knows where exposure is concentrated.

Compliance framework mapping built in

Map every risk to one or more controls across ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR Article 32, or custom frameworks. Track control assessment effectiveness (Effective / Partially Effective / Ineffective / Not Assessed), generate framework-specific gap reports, and produce auditor-ready evidence on demand.

Key Risk Indicators that actually trigger

Define quantitative KRIs (vulnerability count, MTTR, customer churn, defect leakage — anything you measure) with green / amber / red thresholds. Automated alerts route to risk owners and leadership when indicators breach. Now leadership sees risk movement before incidents do.

Root cause + loss event tracking

When a risk materialises, capture it. Log root cause categories, contributing factors, monetary loss, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio — make next quarter's risk identification smarter than this quarter's.

Built for regulated industries

Banking, healthcare, government, energy, and pharma teams use this plugin to satisfy ISO 31000:2018 and ISO 27005 requirements, generate SOX 404 internal-control evidence, demonstrate GDPR Article 32 risk-of-processing assessments, and pass NIST RMF audits — all from the same register.

What's included

  • Project-scoped risk register with configurable P×I scoring (1–5 scale)
  • Configurable 10-status workflow + custom states with transition rules
  • Multi-level sequential, parallel, and hybrid approval workflows
  • Compliance framework mapping (ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, custom)
  • Hierarchical control register with control assessments and effectiveness ratings
  • Risk-to-control mappings with notes and assessor history
  • Key Risk Indicators (KRIs) with green/amber/red thresholds
  • KRI breach alerts and trend dashboards
  • Root cause analysis with contributing factors and corrective actions
  • Loss event tracking with monetary impact and recovery status
  • Email notification system with configurable templates per workflow
  • Visual portfolio-wide heat map with drill-down
  • Risk-to-task and risk-to-milestone bidirectional linking
  • Reusable risk templates configurable per industry or project
  • File attachments versioned with the risk record
  • Bulk actions: status change, export, delete (role-gated)
  • 17 granular RBAC permissions across Risk, Assessment, Reports, Templates, Admin
  • Owner / Admin / User / Client / Guest role types
  • Trend analysis and framework-specific gap reports
  • Export to PDF, Excel, and CSV for board packs and auditors
  • Full version tracking with timestamp + user + diff on every change
  • Multi-tenant company-scoped data isolation

Compatibility

Compatible with Orangescrum Self-Hosted Core, Business, and Enterprise editions running PHP 8.2+, CakePHP 4.6+, and PostgreSQL 13+. Frontend: Vue 3 (global build) + vanilla JS + CakePHP templates. Multi-tenant aware — every risk, framework, control, KRI, and assessment is company-scoped.

Installation

A self-hosted install takes a few minutes. Buy the add-on, drop the plugin into your plugins/ directory, run the migrations, and you're live.

  1. 1

    Buy the add-on

    Purchase the Risk Management add-on from /self-hosted/pricing — $499/year per company, payable annually.

  2. 2

    Drop the plugin into your install

    Copy the RiskManagement/ folder into plugins/ on your self-hosted Orangescrum server.

  3. 3

    Enable the feature flag

    Add `define('RISK_MANAGEMENT_ENABLED', true);` to config/constants.php and register the plugin in src/Application.php with `routes => true, bootstrap => true`.

  4. 4

    Run the database migrations

    Run `bin/cake migrations migrate --plugin RiskManagement` to create the risk register, workflow, framework, KRI, and audit tables.

  5. 5

    Configure scoring and workflow

    Set custom probability and impact labels for your organisation, configure the 10-status workflow transitions, and enable the email notification system.

  6. 6

    Import compliance frameworks

    Import ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, or custom framework control libraries from CSV/JSON via Settings → Compliance Frameworks.

  7. 7

    Define KRIs and roll out

    Set up your first Key Risk Indicators with green/amber/red thresholds, assign owners and approvers, and start logging risks.

Reviews

4.7
287 reviews
5 star
72%
4 star
18%
3 star
6%
2 star
2%
1 star
2%
AR
Arjun Reddy
April 8, 2026 · Programme Director at IndusBank

We replaced three different risk spreadsheets with this. The heat map alone changed how our steering committee runs.

SL
Sofia Lindgren
March 19, 2026 · Head of PMO at NorthHealth

Mitigation work is finally visible to delivery teams instead of locked in a separate doc. Game-changing for us.

TV
Tomás Vega
February 28, 2026 · ISO Lead at GovTech

Audit-ready out of the box. Took our ISO 27005 evidence collection from a quarter to a sprint.

Frequently Asked Questions

Can I customise the probability and impact scales?

Yes. The 1–5 scale is the default, but you can rename the levels (e.g. Rare/Unlikely/Possible/Likely/Almost Certain), set custom descriptive labels, and define different thresholds per company.

Which compliance frameworks are supported?

Out of the box: ISO 31000:2018, COSO ERM, NIST RMF, SOX 404, GDPR Article 32. Plus a custom framework builder so you can model any internal or industry-specific control library, version it, and import a control register from CSV / JSON.

How do KRIs differ from risks?

Risks describe potential events. KRIs are quantitative measurements that signal risk movement before events materialise — like an early-warning radar. The plugin lets you tie KRIs to specific risks and fires alerts when thresholds breach.

Does it support quantitative as well as qualitative risk?

Both. Qualitative scoring on the 1–5 scale, plus custom fields for monetary impact, schedule impact, exposure value, or any quantitative measure you track. KRIs and loss events provide the quantitative backbone.

How do mitigation tasks get tracked?

Risks link bidirectionally to tasks and milestones. Create a new task from a risk or attach an existing one. Mitigation progress flows back into the risk view, and the heat map shows exposure decreasing as work completes.

Is it suitable for ISO 31000, ISO 27005, SOX 404, and GDPR audits?

Yes. The version-tracked register, framework mapping, control-assessment workflow, and exportable PDF / Excel / CSV reports give you the evidence trail required by all four. Auditors can be granted scoped read-only access via the Client or Guest role.

How granular are the permissions?

17 keys across 5 areas: Risk Management (view, create, edit, delete, change status, bulk actions), Assessment (view, edit, manage scoring), Reports (view, export), Templates (view, manage), Administration (settings, permissions, audit log, workflow). Owner / Admin / User / Client / Guest defaults are included.

Can I import an existing risk register from CSV or another tool?

Yes. CSV import is supported for risks, KRIs, frameworks, and controls. Bulk import scripts are published for common formats including ServiceNow GRC and Archer.

Ready to deploy Risk Management on your own infrastructure?

Talk to our team about Orangescrum Self-Hosted Enterprise — your data, your servers, full control.