---
title: "Risk Management Plugin for Orangescrum Self-Hosted"
description: "Run a live risk register inside Orangescrum, probability × impact scoring, heat maps, workflow approvals, and ISO 31000-ready audit trails."
canonical: https://www.orangescrum.com/self-hosted/plugins/risk-management
---

# Risk Management Plugin for Orangescrum Self-Hosted

> For the complete documentation index, see [llms.txt](https://www.orangescrum.com/llms.txt).

1.  [Home](/)
2.  ›
3.  [Self-Hosted](/self-hosted)
4.  ›
5.  [Plugins](/self-hosted/plugins)
6.  ›
7.  Risk Management

# Risk Management

by [Orangescrum](/) · Compliance & Governance

Self-HostedVerifiedEnterprise-ready

A first-class risk management workspace built into Orangescrum. Score risks on probability × impact, map them to ISO 31000 / COSO ERM / NIST RMF / SOX / GDPR controls, set Key Risk Indicators with thresholds and alerts, route status changes through configurable workflows and multi-level approvals, and track root cause + loss events end-to-end. No more risk spreadsheets going stale, no more audit fire drills.

Installs

Available

Active deployments

Support

Vendor Supported

Priority response

Trust

Self-Hosted

Your infra, your data

$499/year

Per company • Add-on to any Self-Hosted plan

[Buy & See All Plans](/self-hosted/pricing#addons)[Talk to Sales](/contact-sales)

-   Probability × Impact scoring (configurable 1–5 scale)
-   Compliance framework mapping (ISO 31000, COSO, NIST, SOX, GDPR)
-   Key Risk Indicators with thresholds & alerts
-   10-status configurable workflow + custom transitions
-   Multi-level sequential or parallel approvals
-   Root cause analysis & loss event tracking
-   Visual portfolio heat map
-   17 granular RBAC permission keys

Pairs with [Self-Hosted Core ($1,500/yr) or Business ($2,250/yr)](/self-hosted/pricing)

[Overview](#overview)[Features](#features)[About](#about)[Install](#install)[FAQ](#faq)

## Screenshots

Risk register with configurable P×I scoring

Portfolio heat map across projects

Compliance framework mapping (ISO 31000 ↔ controls)

## Key Features

### Risk Register

Project-scoped register with probability × impact scoring on a configurable 1–5 scale. Search, filter, bulk-action, and templated risk creation across every active risk.

### Heat Map

Visual portfolio-wide risk landscape with drill-down. See where your exposure concentrates at a glance and trend it over time.

### Configurable Workflow Engine

10-status workflow from Draft → Closed plus custom states. Define which roles can move risks where, with mandatory comments, attachments, or approvals on transitions.

### Multi-Level Approvals

Status changes route through configurable approver chains, sequential, parallel, or hybrid. Email notifications, SLAs, and full audit trail on every decision.

### Compliance Framework Mapping

Map risks to ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR, or custom frameworks. Track control assessments, effectiveness ratings, and gap reports.

### Key Risk Indicators (KRIs)

Define quantitative KRIs with green/amber/red thresholds. Automated alerts fire when indicators breach, leadership sees risk movement before incidents do.

### Root Cause Analysis

Capture root cause categories, contributing factors, and corrective actions for every materialised risk. Build organisational learning instead of repeating mistakes.

### Loss Event Tracking

Log loss events with monetary impact, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio.

### Email Notification System

Configurable email alerts for risk creation, status changes, approvals due, KRI breaches, and assessment deadlines. Templates per workflow.

### Risk-to-Task Linking

Bidirectional linking between risks and project tasks/milestones. Mitigation work surfaces in the same boards as the rest of the project.

### Reusable Risk Templates

Industry- or project-specific risk templates with pre-filled categories, default scoring, and suggested mitigations, accelerate identification and standardise quality.

### Granular RBAC

17 permission keys across Risk, Assessment, Reports, Templates, and Administration. Owner / Admin / User / Client / Guest roles supported out of the box.

### Version Tracking

Every change to every risk is captured with timestamp, user, before/after diff, and reason, so audit history is always one query away.

### File Attachments

Attach supporting documents, evidence, and artefacts to any risk. Versioned alongside the risk record itself.

### Reports & Exports

Trend analysis, framework-specific gap reports, KRI dashboards, and exportable PDF / Excel / CSV reports for board packs and auditors.

### Bulk Actions

Bulk status change, bulk export, bulk delete with role-gated permission. Manage hundreds of risks without clicking each one.

## About this plugin

### Why Risk Management for Orangescrum?

Risks live or die on visibility. A spreadsheet nobody opens is a register that never warned you. Orangescrum's Risk Management plugin makes risks first-class objects inside your project, scored, owned, mapped to compliance frameworks, monitored via KRIs, and tracked alongside the work that mitigates them.

### Risk register, the way it should work

Identify a risk, score it on probability and impact (1–5, configurable labels and thresholds per company), assign an owner, attach evidence, link it to the tasks and milestones that address it. Status flows through a 10-stage workflow you can extend with custom states. The heat map updates in real-time so leadership always knows where exposure is concentrated.

### Compliance framework mapping built in

Map every risk to one or more controls across ISO 31000, COSO ERM, NIST RMF, SOX 404, GDPR Article 32, or custom frameworks. Track control assessment effectiveness (Effective / Partially Effective / Ineffective / Not Assessed), generate framework-specific gap reports, and produce auditor-ready evidence on demand.

### Key Risk Indicators that actually trigger

Define quantitative KRIs (vulnerability count, MTTR, customer churn, defect leakage, anything you measure) with green / amber / red thresholds. Automated alerts route to risk owners and leadership when indicators breach. Now leadership sees risk movement before incidents do.

### Root cause + loss event tracking

When a risk materialises, capture it. Log root cause categories, contributing factors, monetary loss, recovery actions, and post-incident review status. Roll up actual vs forecast loss across the portfolio, make next quarter's risk identification smarter than this quarter's.

### Built for regulated industries

Banking, healthcare, government, energy, and pharma teams use this plugin to satisfy ISO 31000:2018 and ISO 27005 requirements, generate SOX 404 internal-control evidence, demonstrate GDPR Article 32 risk-of-processing assessments, and pass NIST RMF audits, all from the same register.

### What's included

-   Project-scoped risk register with configurable P×I scoring (1–5 scale)
-   Configurable 10-status workflow + custom states with transition rules
-   Multi-level sequential, parallel, and hybrid approval workflows
-   Compliance framework mapping (ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, custom)
-   Hierarchical control register with control assessments and effectiveness ratings
-   Risk-to-control mappings with notes and assessor history
-   Key Risk Indicators (KRIs) with green/amber/red thresholds
-   KRI breach alerts and trend dashboards
-   Root cause analysis with contributing factors and corrective actions
-   Loss event tracking with monetary impact and recovery status
-   Email notification system with configurable templates per workflow
-   Visual portfolio-wide heat map with drill-down
-   Risk-to-task and risk-to-milestone bidirectional linking
-   Reusable risk templates configurable per industry or project
-   File attachments versioned with the risk record
-   Bulk actions: status change, export, delete (role-gated)
-   17 granular RBAC permissions across Risk, Assessment, Reports, Templates, Admin
-   Owner / Admin / User / Client / Guest role types
-   Trend analysis and framework-specific gap reports
-   Export to PDF, Excel, and CSV for board packs and auditors
-   Full version tracking with timestamp + user + diff on every change
-   Multi-tenant company-scoped data isolation

### Compatibility

Compatible with Orangescrum Self-Hosted Core, Business, and Enterprise editions running PHP 8.2+, CakePHP 4.6+, and PostgreSQL 13+. Frontend: Vue 3 (global build) + vanilla JS + CakePHP templates. Multi-tenant aware, every risk, framework, control, KRI, and assessment is company-scoped.

## Installation

A self-hosted install takes a few minutes. Buy the add-on, drop the plugin into your `plugins/` directory, run the migrations, and you're live.

1.  1
    
    ### Buy the add-on
    
    Purchase the Risk Management add-on from /self-hosted/pricing, $499/year per company, payable annually.
    
2.  2
    
    ### Drop the plugin into your install
    
    Copy the RiskManagement/ folder into plugins/ on your self-hosted Orangescrum server.
    
3.  3
    
    ### Enable the feature flag
    
    Add \`define('RISK\_MANAGEMENT\_ENABLED', true);\` to config/constants.php and register the plugin in src/Application.php with \`routes => true, bootstrap => true\`.
    
4.  4
    
    ### Run the database migrations
    
    Run \`bin/cake migrations migrate --plugin RiskManagement\` to create the risk register, workflow, framework, KRI, and audit tables.
    
5.  5
    
    ### Configure scoring and workflow
    
    Set custom probability and impact labels for your organisation, configure the 10-status workflow transitions, and enable the email notification system.
    
6.  6
    
    ### Import compliance frameworks
    
    Import ISO 31000, COSO ERM, NIST RMF, SOX, GDPR, or custom framework control libraries from CSV/JSON via Settings → Compliance Frameworks.
    
7.  7
    
    ### Define KRIs and roll out
    
    Set up your first Key Risk Indicators with green/amber/red thresholds, assign owners and approvers, and start logging risks.
    

## Frequently Asked Questions

### Can I customise the probability and impact scales?

▾

Yes. The 1–5 scale is the default, but you can rename the levels (e.g. Rare/Unlikely/Possible/Likely/Almost Certain), set custom descriptive labels, and define different thresholds per company.

### Which compliance frameworks are supported?

▾

Out of the box: ISO 31000:2018, COSO ERM, NIST RMF, SOX 404, GDPR Article 32. Plus a custom framework builder so you can model any internal or industry-specific control library, version it, and import a control register from CSV / JSON.

### How do KRIs differ from risks?

▾

Risks describe potential events. KRIs are quantitative measurements that signal risk movement before events materialise, like an early-warning radar. The plugin lets you tie KRIs to specific risks and fires alerts when thresholds breach.

### Does it support quantitative as well as qualitative risk?

▾

Both. Qualitative scoring on the 1–5 scale, plus custom fields for monetary impact, schedule impact, exposure value, or any quantitative measure you track. KRIs and loss events provide the quantitative backbone.

### How do mitigation tasks get tracked?

▾

Risks link bidirectionally to tasks and milestones. Create a new task from a risk or attach an existing one. Mitigation progress flows back into the risk view, and the heat map shows exposure decreasing as work completes.

### Is it suitable for ISO 31000, ISO 27005, SOX 404, and GDPR audits?

▾

Yes. The version-tracked register, framework mapping, control-assessment workflow, and exportable PDF / Excel / CSV reports give you the evidence trail required by all four. Auditors can be granted scoped read-only access via the Client or Guest role.

### How granular are the permissions?

▾

17 keys across 5 areas: Risk Management (view, create, edit, delete, change status, bulk actions), Assessment (view, edit, manage scoring), Reports (view, export), Templates (view, manage), Administration (settings, permissions, audit log, workflow). Owner / Admin / User / Client / Guest defaults are included.

### Can I import an existing risk register from CSV or another tool?

▾

Yes. CSV import is supported for risks, KRIs, frameworks, and controls. Bulk import scripts are published for common formats including ServiceNow GRC and Archer.
