TL;DR

  • What it is: a risk register inside every Orangescrum project. Each risk has an owner, a score, a treatment plan, a review date and a full history.
  • Scoring: five methods (ISO 31000 5×5, ISO/IEC 27005, ISMS 4-factor, NIST SP 800-30 and CIS RAM) or your own formula, with inherent and residual risk side by side.
  • ISO 27001: threat and vulnerability catalogues, links to the 93 Annex A controls, and four ISMS reports for your auditor.
  • Control: a heat map, a dashboard, a workflow you design, treatment as linked tasks, 19 permissions and an audit trail.
  • Where: Orangescrum Cloud (Enterprise plan) and the Self-Hosted plugin (Core, Business and Enterprise). Some features are on Self-Hosted first.

Orangescrum Risk Management is risk management software that lives inside your projects. Every risk gets an owner, a score, a treatment plan and a full history, and the work that reduces it runs as ordinary tasks. You can score risks with ISO 31000, ISO/IEC 27005, NIST SP 800-30, CIS RAM or your own formula. You can also keep an ISO 27001 risk register and route each risk through a workflow you design. It is available on Orangescrum Cloud (Enterprise plan) and as a plugin for Orangescrum Self-Hosted (Core, Business and Enterprise editions).

Most risk registers start as a spreadsheet. At first, the spreadsheet is fine. A month later, nobody has updated it, the mitigation actions live in someone’s inbox, and the next audit turns into a hunt for evidence. Risk Management keeps each risk next to the project it threatens, and keeps a record of every score, every decision and every change.

What is new, at a glance

Identify, score and treat

Feature What it does
Risk register in every project List, Kanban and Cards views, with search, filters, a column picker and bulk actions. Each risk gets an ID such as RISK-0042.
Five scoring methodologies ISO 31000 5×5, ISO/IEC 27005 asset-based, an ISMS 4-factor register, NIST SP 800-30 and CIS RAM. Pick one, or copy one and change it.
Custom risk formulas Write your own risk value formula from the rating factors. Orangescrum checks it before you save it.
Inherent and residual risk Score each risk before and after treatment, and compare the result with your acceptance threshold.
Heat map A likelihood × impact grid that follows your methodology. Click a cell to see its risks.
Treatment as tasks Choose a response, write the plan, and link the tasks that carry it out. Risks also show on the task itself.

Control, workflow and evidence

Feature What it does
ISO 27001 risk register Threat and vulnerability catalogues, confidentiality, integrity and availability ratings, and links to the 93 Annex A controls of ISO/IEC 27001:2022.
Workflow you design Your own statuses, transitions, required fields, required comments and the roles allowed to make each move.
Risk dashboard Risks by level, status and category, overdue reviews, mitigation progress, risks that block tasks, and a six-month trend.
Owners, watchers and reminders An owner and a second owner on every risk, watchers, @mentions, and email reminders before a review falls due.
Import and export Bring in your spreadsheet as XLSX, CSV or TXT, preview it, then commit. Export the register to Excel or CSV and import it again.
Reports for auditors ISMS Risk Register, Risk Treatment Plan, Residual Risk and Acceptance, SoA Control Coverage, plus six operational reports.
Permissions and history 19 permissions across five roles, an “assigned only” view, an activity log and a version snapshot of every change.

Some of these features are on Self-Hosted first. The availability table shows which.

Why risk registers in spreadsheets fail

A risk register only protects you if people use it. However, a spreadsheet makes that hard. The risk sits in one file, the work that reduces it sits in the project tool, and nothing connects them. As a result, the score never changes, the owner forgets the review, and the register shows last quarter’s picture.

The research points the same way. In PMI’s Pulse of the Profession 2026, 31% of complex projects failed to deliver the full benefits they set out to deliver. Also, in the 2026 State of Risk Oversight study by AICPA and CIMA with NC State, 74% of organizations reported a significant operational surprise. Only 29% had formally stated their risk appetite.

Good risk management software closes the gap between the register and the work. In Orangescrum, each risk belongs to a project. Its mitigation actions are tasks with an assignee and a due date. Then, every status change follows your workflow and lands in the risk’s history. So the register stays current, because updating it is part of doing the work.

A risk register inside every project

First, open Risk Management from the sidebar to see the register. Every risk shows its ID, title, category, score, rating, residual score, owner and status. Switch between three views:

  • List for review meetings and bulk updates.
  • Kanban, with one column for each status in your workflow. Drag a card to move a risk. Orangescrum only allows the moves your workflow permits.
  • Cards for a quick visual scan of the top risks.

Search by risk ID, title, description or tag. Filter by status, rating, category, type and owner, and remove a filter with one click on its chip. Next, choose the columns you need, including threat, vulnerability, asset value and SoA controls for ISO 27001 work. Select several risks to change their status, export them or delete them in one go. A bulk status change still follows your workflow rules, so a required comment is still required.

The Orangescrum risk register in List view: risk IDs, titles, categories, scores, colour-coded ratings, owners and statuses, with search and filters above.
The risk register: search, filter, choose columns and act on many risks at once.
The risk register in Kanban view, with one column per workflow status: Draft, Identified, Under Assessment and Mitigation In Progress.
Kanban view: each column is a status in your workflow.

Log a risk in one form

The risk form follows the order of a real assessment. First you identify the risk: title, description, category, type (threat or opportunity), source and date. Then you rate it and watch the score and the rating update as you type. After that come the owner and the review date, the mitigation strategy, the residual rating, the estimated budget and schedule impact, the tasks to link and any attachments.

To go faster, start from a template. A risk template carries a category, default ratings, a response strategy and a mitigation plan. Build one for each risk your teams meet again and again, such as “key person leaves the project” or “client delays sign-off”.

Risk Templates: cards such as Budget overrun, Data breach via compromised credentials and Key person dependency, each with a rating, category, default scores, a response and a Use button.
Reusable risk templates, ready to use in one click.
The Create New Risk form: title, description, category, type, source, date identified, ISMS SoA control mapping, threat, vulnerability and the assessment section.
Identification, SoA controls, threat and vulnerability on one form, with the methodology shown above the ratings.

Risk scoring with the methodology your auditor knows

However, teams score risk in different ways. A delivery team often uses a 5×5 likelihood and impact matrix. An information security team, on the other hand, often uses an asset-based method. A bank’s supplier may have to follow the method in its client’s contract. For this reason, Risk Management ships five methodologies. Each company can adopt one, copy it and change it.

Methodology How it scores Risk levels
Likelihood × Impact (ISO 31000 5×5) Likelihood × impact, each rated 1 to 5. This is the default. Low, Medium, High, Critical
Asset × Threat × Vulnerability (ISO/IEC 27005) Asset value × threat likelihood × vulnerability Low, Medium, High, Critical
ISMS 4-factor register (Vulnerability × threat likelihood × impact) + asset value, where asset value is the highest of the C, I and A ratings Insignificant, Low, Medium, High
NIST SP 800-30 Rev. 1 A qualitative lookup matrix of likelihood and impact Very Low, Low, Moderate, High, Very High
CIS RAM v2.1 (IG1, 3×3) Likelihood × impact on a 1 to 3 scale Acceptable, Unacceptable, High

Each methodology becomes your company’s own copy, with a version history. You can change the rating scale (from 2 to 10 points), the bands and their names, and the acceptance threshold. Asset value can come from the C, I and A ratings in three ways: the highest, the sum or the average. You can also rename fields to match your existing register. For example, the ISMS 4-factor method calls the score “Risk Value” and the plan “Risk Treatment Plan”.

When you change a methodology, you choose what happens next. Rescore only the open risks, or rescore every risk. Every methodology maps its bands to four common levels, so the dashboard and the filters keep working, whatever you choose.

Settings, Scoring Methodology: the active Asset × Threat × Vulnerability (ISO/IEC 27005) method with its bands, and the CIS RAM, ISMS 4-factor and ISO 31000 5×5 templates with Use, Customise and Duplicate.
Five scoring methodologies, each with its own version history.

Write your own risk value formula

If none of the five fits, write your own formula. Use the rating factors (likelihood, impact, vulnerability, asset value, and the confidentiality, integrity and availability ratings), numbers, the four basic operators, brackets, max() and min(). For example:

(vulnerability_rating * probability * impact) + asset_value

Orangescrum checks the formula before you save it. It must only use the factors you allow, it must give a score above zero at the lowest and the highest ratings, and it must never divide by zero. Meanwhile, a live preview shows the result for sample ratings. The formula is read as arithmetic and never run as code, so a typo cannot break anything.

Inherent and residual risk, side by side

Inherent risk is the risk before you act. Residual risk is what is left after your controls and actions work. So Risk Management scores both, each with its own formula and bands. As a result, you can show how much each treatment reduced the risk, and whether what is left is inside your acceptance threshold.

The Assessment tab of a risk: the original assessment with confidentiality, integrity, availability, asset value, threat likelihood, vulnerability and a score of 80, and the residual assessment with a score of 20. A Score Summary card shows 5 × 4 × 4 = 80 and 5 × 2 × 2 = 20.
The original and the residual assessment, side by side.

The Residual Risk and Acceptance report lists every risk with its inherent score, its residual score, the reduction in percent and whether it is within the threshold. Accepting a risk is a status of its own, which needs its own permission and a comment. So the record shows who accepted each risk, and why.

A risk heat map that follows your methodology

The heat map plots each risk by likelihood and impact. The grid takes its size and its colours from your methodology, so a 3×3 CIS RAM grid and a 5×5 ISO 31000 grid both read correctly. Each cell shows how many risks it holds. Click a cell to list them, or filter the map by category to see where, for example, your security risks gather.

Risks that are not rated yet do not vanish. The map counts them as “not plotted”, so nobody mistakes an unrated risk for a low one. Finally, export the map to CSV for a board pack.

The risk heat map: a 5×5 threat likelihood by impact grid with the number of risks in each cell, coloured Low, Medium, High and Critical, with a legend.
Click any cell to see the risks behind the number.

An ISO 27001 risk register, built in

ISO/IEC 27001:2022 asks you to identify information security risks, name their owners, analyse and evaluate them, and keep a record (clauses 6.1.2 and 8.2). It also asks for a risk treatment plan and a Statement of Applicability (clause 6.1.3). Risk Management gives an information security team the pieces for that record in the same place as the rest of the work:

  • Threat and vulnerability catalogues. Keep your own lists, or import starter packs: the typical threats in ISO/IEC 27005 Annex C, the elementary threats G 0.1 to G 0.47 of BSI IT-Grundschutz, and the typical vulnerabilities in ISO/IEC 27005 Annex D. Pick a threat on a risk and its default likelihood fills in.
  • Confidentiality, integrity and availability. Rate each one, and let the methodology turn them into an asset value.
  • Annex A controls. Link each risk to the controls that treat it, from the 93 controls of ISO/IEC 27001:2022 Annex A, grouped as Organizational, People, Physical and Technological.
  • Four ISMS reports. ISMS Risk Register, Risk Treatment Plan, Residual Risk and Acceptance, and SoA Control Coverage, each ready to export to Excel or CSV.

These reports help you prepare the evidence an auditor asks for. However, they do not certify your company on their own, and the Statement of Applicability stays your document. Still, the risks, the controls they map to and the treatment status all come from one place, and you do not have to copy them between files. Keep the policies and evidence documents themselves in Orangescrum Document Management.

Settings, Threats and Vulnerabilities: a catalogue of threats such as fire, water damage and pollution, with category, origin and likelihood, and an Import starter pack button.
Threat and vulnerability catalogues, with starter packs to import.
Risk Reports: the ISMS / ISO 27001 group with ISMS Risk Register, Risk Treatment Plan, Residual Risk and Acceptance and SoA Control Coverage, each with Excel and CSV buttons.
Four ISMS reports, each ready to export to Excel or CSV.

A risk workflow you design

Every risk moves through a workflow. Orangescrum starts you with a standard lifecycle:

Draft → Identified → Under Assessment → Mitigation In Progress → Monitoring → Closed (Resolved), Closed (Accepted) or Closed (Expired), with Escalated and Materialised for risks that grow or happen.

Then change it to fit your process. For each workflow, you decide:

  • Statuses, with their names, colours and descriptions, which one is the start, and which ones close a risk.
  • Allowed moves from each status.
  • Required fields for each status. For example, a risk cannot enter Under Assessment without a likelihood and an impact.
  • Required comments, for moves such as escalating, accepting or closing a risk.
  • Roles allowed to make each move.

Importantly, Orangescrum checks these rules on the server, not only in the browser. So a bulk update, a Kanban drag and an import all follow the same rules. Keep several workflows if different kinds of risk need different routes, and set one as the default.

The Workflow Configuration page: the Default Risk Workflow template, its ten statuses as coloured chips, and the Draft status open with label, colour, initial and terminal settings.
Statuses, transitions, required fields and roles, all in one editor.
A risk's detail page with the status menu open, listing only the statuses the workflow allows next.
The status menu on a risk follows your workflow.

Risk treatment that becomes real work

For each risk, choose a response: avoid, mitigate, transfer, accept, or, for opportunities, exploit, share or enhance. Write the mitigation plan and a contingency plan, and track the mitigation status: not started, in progress, completed or on hold.

Then link the tasks that carry out the plan. Link them from the risk, or open any task and use its Risks tab to link a risk from there. The tasks keep their own assignees, due dates and boards, so the mitigation work shows up where your team already works. Linked risks can also point at each other, as parent, dependent, duplicate or derived risks.

The Risk Treatment Plan report then shows every planned action against its target date, its actual closure date and how many days late it is. In short, that is the record ISO 27001 clause 8.3 asks you to keep.

The Mitigation tab of a risk: mitigation plan, contingency plan, mitigation status, planned closure date, budget impact of 85,000 US dollars, 10 days of schedule impact and the residual score.
The treatment plan on the risk, with its status, budget and schedule impact.

A dashboard for the weekly risk review

The dashboard answers the questions a risk review starts with:

  • How many risks are critical, high, medium and low, and how many are not assessed yet?
  • Where are risks in the workflow, and which categories hold the most?
  • Which risks are overdue for review?
  • How far along is the mitigation work?
  • Which risks block tasks right now?
  • What came in during the last 30 days, and how has the number of open risks moved over six months?

Governance figures sit at the top: total risks, closure rate, the share of escalated risks and the average time to resolve a risk. A small heat map links to the full one.

The Risk Dashboard: total, critical, high, medium and low risk counts, a donut of risks by status, bars of risks by category and a small heat map.
The risk dashboard, ready for the weekly review.

Owners, watchers and review reminders

Every risk has an owner, and it can have a second owner and watchers. The right people get a notification in Orangescrum and by email when a risk is created, assigned to them, changes status or is escalated. They also hear when someone comments, mentions them or adds them as a watcher.

Each risk also has a review date. Orangescrum reminds the owner before the date and again when the review is overdue. The dashboard and the Overdue Risks report show what has slipped. In addition, admins choose which events send email, and can edit the wording in the email templates.

Settings, Notification Rules: events such as new risk created, risk status changed, risk assigned to you, review date approaching and risk escalated, each with Email and In-App switches.
Choose which events send an email and which stay in the app.

Bring your spreadsheet in, take your register out

You probably have a register already. Download the import template, which has drop-down lists, help notes and an instruction sheet, and whose column names follow your methodology. Then upload your file as XLSX, CSV or TXT. Orangescrum shows a preview first: which rows are new, which update an existing risk, which have not changed, and which have errors or warnings. Nothing is saved until you commit.

Better still, the round trip works both ways. Export the register to Excel or CSV, edit it offline, and import it again. Rows with an existing risk ID update that risk, and only the changed cells apply. A “Last Updated” column stops an old file from overwriting a newer edit. Status changes stay in the workflow, so an import cannot skip it.

The Import Risks page: rules for new and updated risks, buttons to download the XLSX and CSV samples, and the file picker with Preview and Import.
Download a sample, fill it in, then preview before you import.

Permissions and an audit trail you can trust

Risk data is sensitive, so access is precise. 19 permissions, in five groups, decide who can view, create, edit, delete, escalate, accept or close risks. They also decide who sees financial impact, exports reports, manages templates, imports and changes settings. Owner, Admin, User, Client and Guest roles come with sensible defaults, and you can change them in a permission matrix.

Two settings help most in practice. With “assigned only”, users see just the risks they own or watch. Without the financial permission, the budget impact is hidden everywhere, including in the history.

Above all, every change is recorded. The Activity tab on each risk shows each field change with the old value, the new value, the person and their role. The Versions tab keeps a full snapshot of the risk at each change. Comments with @mentions and attachments sit on the same record.

The Activity tab of a risk: a timeline of comments, status changes and owner assignments, each with the person and the time.
Every change to a risk, with who made it and when.

Availability

Orangescrum Cloud Orangescrum Self-Hosted
Where it is available Enterprise plan Plugin for the Core, Business and Enterprise editions
How it is turned on Our team turns it on for your company You install the plugin, then run its setup command
Register, Kanban, heat map, dashboard, templates, task links Yes Yes
Editable score bands, 19 permissions, activity and versions Yes Yes
Six operational reports, import of new risks Yes Yes
Five methodologies and custom formulas Coming soon Yes
ISO 27001 register, catalogues, Annex A and the four ISMS reports Coming soon Yes
Workflow editor Coming soon Yes
Email notifications, @mentions and review reminders Coming soon Yes
Import that updates existing risks, Excel export Coming soon Yes

Risk Management is not part of the free, open source Community Edition. On Self-Hosted, the plugin needs PHP 8.2 or later, CakePHP 4.6 or later and PostgreSQL 13 or later. Review reminders come from a command that you schedule on your server, for example once a day.

How to get started

On Orangescrum Cloud

  1. Talk to our sales team about the Enterprise plan.
  2. We turn on Risk Management for your company.
  3. Open Risk Management from the left sidebar, then set your score bands, categories and permissions in Settings.

On Orangescrum Self-Hosted

  1. Talk to our sales team to buy the Risk Management plugin for your Self-Hosted edition.
  2. Install the plugin and run its setup. It creates the tables, the permissions and the default workflow.
  3. In Settings, choose your scoring methodology, import a threat and vulnerability starter pack if you work to ISO 27001, and set your permissions and notification rules. Then import your existing register.

What is risk management?

ISO defines risk as the “effect of uncertainty on objectives”, and risk management as the “coordinated activities to direct and control an organization with regard to risk” (ISO Guide 73, quoted by NIST). In plain words, risk management means finding what could go wrong, or right, before it happens, deciding how much it matters, and acting on the risks that matter most.

So risk management software is the tool that holds this work. At minimum, it keeps a risk register: a central record of current risks and related information for a given scope or organization, as NIST puts it. Better tools also score risks, assign owners, track treatment, remind people to review, and keep an audit trail.

Key terms in one place

Term Meaning
Risk register The central list of risks, with their scores, owners, treatments and status.
Likelihood × impact The most common way to score a risk: how likely it is, times how bad it would be.
Risk heat map The likelihood × impact grid, coloured by level, with the risks placed in its cells.
Inherent risk The risk before any action to change it.
Residual risk The risk that remains after controls and treatment are in place.
Risk appetite How much risk, and what kind, an organization is willing to accept to reach its goals.
Risk owner The person accountable for managing a risk, who also accepts what remains of it.
Risk treatment plan The actions chosen for each risk, with owners and dates.

For the project side of the topic, read our practical guide to project risk management and how to build a risk register and risk matrix in Orangescrum.

What are the steps of the risk management process?

ISO 31000:2018 describes the process as communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting. The steps repeat, rather than run once. Here is how a delivery team can run them, and where each step lives in Orangescrum.

Step What you do In Orangescrum
1. Set criteria Agree the rating scales, the levels and the acceptance threshold. Scoring methodology and its bands
2. Identify Record the risk, its cause, its category, its project and its owner. The risk form and risk templates
3. Analyse Rate likelihood and impact to get the inherent score. The live score in the Assessment section
4. Evaluate Compare the score with your criteria and rank the risks. Rating, heat map and register filters
5. Choose a treatment Avoid, mitigate, transfer, accept or escalate, and say why. Response strategy and the required comment
6. Plan the actions Turn the plan into actions with owners and dates. Linked tasks
7. Track to done Do the work and keep the evidence. Task boards, attachments, Risk Treatment Plan report
8. Re-score Rate the residual risk, and have the owner accept it. Residual Risk section, Closed (Accepted) status
9. Review Review on a schedule and when something important changes. Review dates, reminders, dashboard
10. Record and report Keep the history and report it to management. Activity, versions, reports and exports

What is risk management in IT services?

Risk management in IT services is the practice of finding, scoring and treating the risks that threaten delivery and the client’s systems and data. IT services firms, IT-enabled services (ITES) and BPO providers carry two kinds of risk at once. The first is delivery risk: the project slips, the scope grows, or a key engineer leaves. The second is the client’s risk, which the firm takes on when it handles the client’s systems and data. Clients, contracts and regulators now ask the provider to prove it manages both.

Typical risks in IT services

  • Delivery: schedule slip, scope creep, unclear requirements, estimates that do not hold.
  • People: attrition, key-person dependency, skill gaps on a new technology.
  • Third parties: a cloud provider outage, a subcontractor that fails, a licence that changes.
  • Security and privacy: a client data leak, too much access for too long, a breach at a vendor.
  • Commercial: SLA penalties, one client that brings most of the revenue, unpaid change requests.
  • Compliance: an audit finding, a missed certification renewal, a contract clause nobody tracked.

Meanwhile, the cost of getting security risk wrong keeps rising. The IBM Cost of a Data Breach 2026 report puts the global average cost of a breach at 4.99 million US dollars, a record high.

What a good IT risk register needs

For an IT services firm, risk management software works best when it lives where the delivery work lives. Group risks by client project. Use one methodology for delivery risk and an asset-based one for security risk. Link every mitigation to a task, so the delivery manager sees it on the board. Give the client a Client role with view-only access to the risks on their project. Then export the ISMS reports when the client’s security team or your ISO 27001 auditor asks for them.

Which standards ask for risk management?

Many of the standards that IT and IT-enabled services firms work to ask for a risk assessment, and most auditors expect a register as the evidence. Here is what each one asks for, in short.

Standard or law What it asks for Who it reaches
ISO/IEC 27001:2022 A documented risk assessment with owners (6.1.2), a treatment plan and a Statement of Applicability (6.1.3), assessments at planned intervals (8.2), and treatment results (8.3). Any firm certified, or asked by clients to be
SOC 2 Trust Services Criteria CC3.1 to CC3.4 (identify and analyse risks, including fraud and change) and CC9.2 (vendor and business partner risk). Service providers whose clients ask for a SOC 2 report
GDPR Article 32: security appropriate to the risk, for controllers and processors. Article 35: a data protection impact assessment for high-risk processing. Anyone processing EU personal data, including processors
India’s DPDP Act 2023 Section 8(5): reasonable security safeguards to prevent a personal data breach. Under the DPDP Rules 2025, a Significant Data Fiduciary also runs a yearly impact assessment and audit. Data fiduciaries and the processors that work for them
EU DORA An ICT risk management framework (Article 6), documented ICT assets (Article 8), and a register of ICT third-party contracts with a risk assessment before signing (Article 28). Contract terms flow down to ICT suppliers. EU financial firms and their ICT suppliers
EU NIS2 Article 21: risk management measures, including policies on risk analysis and supply chain security, approved by management. Essential and important entities, including managed service providers
RBI IT Governance Directions 2023 A risk policy that covers IT and cyber risk, an IT and information security risk framework, and a risk assessment for each information asset. Indian banks and NBFCs, and through outsourcing rules, their IT vendors
ISO 9001:2015 Clause 6.1: determine and address risks and opportunities. It does not require a formal register. Firms with a certified quality system
CMMI The Risk and Opportunity Management practice area: identify, record, analyse, monitor and plan for risks. Firms appraised against CMMI

Of course, a register does not make you compliant on its own. It is the record that shows you did the work. That record is easier to keep, and to show, when it lives in the same tool as the work. If the data must stay in your own data centre, see our guide to on-premises project management software for GDPR.

Risk management software vs a spreadsheet: which do you need?

A spreadsheet works for one team and a short list of risks. Risk management software is the better choice once several teams own risks, actions need owners and dates, or an auditor needs the history.

Spreadsheet register Risk management software
Scoring Formulas that anyone can overwrite One methodology, checked and versioned
Ownership A name in a cell An owner who gets notifications and reminders
Treatment A text column Linked tasks with assignees and due dates
Workflow None Statuses, required fields, comments and roles
History Version files, if someone saves them Every change, with who, when and the old value
Access Everyone with the file sees everything Role-based, with “assigned only” and hidden financials
Audit evidence Assembled by hand before each audit Reports on demand

In short, a spreadsheet is a good place to start. Once more than one team owns risks, or an auditor needs to see the history, the spreadsheet starts to cost more than it saves.

Top 6 risk management software in 2026

If you are comparing risk management software, these six cover the main kinds of buyer, from project tools with a register to dedicated GRC platforms. They are not ranked, because each one suits a different team. Orangescrum publishes this blog and is on the list, so we describe it with the same kind of facts as the others. We checked every fact on the vendor’s own website on 1 October 2026.

Software Best for Deployment
Orangescrum Delivery and IT teams that want the risk register, ISO 27001 scoring and the mitigation tasks in one project tool Cloud or self-hosted
Jira with a risk app Teams already on Jira. A risk register comes from Marketplace apps, not from Jira itself Cloud. Data Center is no longer sold to new customers since 30 March 2026
monday.com Small teams that want a quick register built from a template Cloud only
Wrike Project teams that want an automatic forecast of which projects may miss their deadline Cloud only
LogicManager Mid-sized organizations that want enterprise risk management across departments Cloud
Vanta Companies working towards SOC 2 or ISO 27001, with a risk register next to compliance automation Cloud only
As published on each vendor’s website on 1 October 2026. Check each vendor for current plans.

How do you choose risk management software?

If your risks belong to projects and the mitigation is project work, pick a tool that links the two, such as Orangescrum. Teams that live in Jira can add a risk app, but should check where their data must sit, because Jira Data Center is no longer sold to new customers. For one register across finance, operations and compliance, look at an enterprise risk platform such as LogicManager. When the goal is a SOC 2 or ISO 27001 report soon, Vanta pairs a register with automated evidence. Finally, if your data must stay on your own servers, Orangescrum Self-Hosted keeps the whole register on your infrastructure.

Whatever risk management software you pick, check five things:

  • It scores risk the way your auditor expects.
  • It keeps inherent and residual scores apart.
  • Treatment actions become work you can track.
  • Every change is recorded.
  • You can export your data in a format you can import elsewhere.

Risk management software use cases by industry

The examples below show how a team in each industry can set up Orangescrum risk management software. They are illustrations, not customer stories.

IT services companies

Risks: scope creep on fixed-price work, a key developer resigning mid-project, a client data leak, and a missed SLA.

What matters: many client projects at once, mitigation that must happen inside delivery, and proof for the client’s security review.

Example. An IT services firm keeps one register per client project. For example, delivery risks use the ISO 31000 5×5 method. Security risks use the ISMS 4-factor method and link to Annex A controls. The mitigation for “key developer resigns” is a linked task to document the module and pair a second developer on it. The client’s project manager has the Client role, so they can see the register and the dashboard, but cannot change anything. Before the client’s annual security review, the delivery manager exports the ISMS Risk Register and the Risk Treatment Plan.

IT services example: the delivery manager logs and scores a key-developer risk at 16, the tech lead links two mitigation tasks, the client's project manager views the register, and the ISMS reports are exported before the security review.
Illustration: an IT services firm’s risk register for one client project.

IT-enabled services and BPO

Risks: agent attrition before a peak season, exposure of client customer data, SLA penalties, and dependence on a single client.

What matters: GDPR and India’s DPDP Act apply to processors too, and clients audit their providers.

Example. A BPO provider logs “agent attrition above plan in Q4” as an operational risk with a review date every two weeks. The mitigation tasks, in turn, are a hiring drive and cross-training. A second risk, “client customer data copied to personal devices”, is a security risk linked to the Annex A controls for data leakage prevention and access rights. The owner gets an email three days before each review. Later, the client’s auditor receives the Residual Risk and Acceptance report.

BPO example: the operations manager logs an agent attrition risk with two-weekly reviews, the HR lead links hiring and cross-training tasks, and the security lead maps a data-handling risk to Annex A controls.
Illustration: a BPO provider tracks people risk and data risk in one register.

Software and product companies

Risks: a release that slips, a third-party library with a known vulnerability, a cloud region outage, and an API change that breaks customers.

What matters: risks move fast between sprints, and engineering, product and security must see the same picture.

Example. A SaaS team reviews its register at each sprint planning. A risk on an outdated library is linked to the upgrade task, which blocks the release. As a result, the dashboard shows it under “risks blocking tasks”. When the upgrade ships, the team rates the residual risk and moves the risk to Monitoring. For the SOC 2 audit, the history shows when the risk was raised, scored, treated and closed.

Software example: a security engineer logs an outdated library risk with a risk value of 85, the dev lead links the upgrade task that blocks the release, and the residual risk is rated after the upgrade.
Illustration: a product team treats a dependency risk inside the sprint.

Marketing agencies

Risks: scope creep on retainers, one client bringing most of the revenue, campaign data collected without clear consent, and stock images used outside their licence.

What matters: fast-moving work, thin margins, and no time for a separate risk tool.

Example. An agency keeps a small register per client account with the CIS RAM 3×3 method, because three levels are enough for its decisions. For instance, the account director owns “retainer scope keeps growing”. The treatment is a change-order step, tracked as a task linked to the risk. Each Monday, the leadership team opens the dashboard and checks which risks are overdue for review.

Agency example: the account director owns a retainer scope risk scored 9 with CIS RAM, a change-order step is a linked task, and leadership checks overdue reviews every Monday.
Illustration: an agency keeps a light register per client account.

Financial services and their technology suppliers

Risks: an outage at a critical ICT provider, too much work with one provider, a cyber incident, and a regulatory finding.

What matters: DORA in the EU, and the RBI and SEBI frameworks in India, ask for documented ICT risk management and third-party risk assessment.

Example. A technology supplier to banks uses the NIST SP 800-30 method that its largest client’s contract names. Next, third-party risks link to the tasks for exit plans and backup providers. Escalated and Accepted need their own permissions, so only the head of risk can accept a high risk, and the comment records why. The firm keeps the plugin on Orangescrum Self-Hosted, so the register stays on its own servers.

Financial services supplier example: a third-party outage risk scored Very High with NIST SP 800-30, exit plan and backup provider tasks, and the head of risk accepts the residual risk with a comment.
Illustration: a bank’s technology supplier manages third-party risk on its own servers.

Government and public sector

Risks: a programme running over budget, a supplier failing, a citizen data breach, and a policy change mid-project.

What matters: public bodies follow risk frameworks such as the UK Orange Book or US OMB Circular A-123, and must show their decisions later.

Example. A department runs each programme as a project with its own register and a workflow that adds a “Board Review” status before a high risk can be accepted. The move into that status needs a comment and the programme director’s role. As a result, every decision stays in the risk’s history. The data stays in the department’s own data centre on Orangescrum Self-Hosted.

Public sector example: a programme manager logs an over-budget risk scored 20, the programme director moves it through a Board Review status with a comment, and the board's decision is recorded.
Illustration: a public programme adds a board review before a high risk is accepted.

Construction and engineering firms

Risks: a design that is unsafe to build, a subcontractor that fails, weather delays, and material price changes.

What matters: safety risks must be designed out early, and schedule and cost impact must be visible to the project manager.

Example. An engineering firm records a budget impact and a schedule impact in days on each risk. However, only managers with the financial permission see the money. The heat map, filtered by the Schedule category, shows the weather and supplier risks ahead of the next milestone. A risk that happens moves to Materialised, so the history shows what was foreseen and what was not.

Engineering example: a project engineer records a supplier delay with 10 days of schedule impact, the project manager filters the heat map by Schedule, and the risk moves to Materialised when it happens.
Illustration: an engineering firm watches schedule and cost risk before a milestone.

Healthcare operations

Risks: medical equipment downtime, staff shortages on a shift, a supplier recall, and an outage of a clinical system.

What matters: continuity of care, and in the EU, the NIS2 directive lists health among its sectors of high criticality.

Example. A hospital’s operations team keeps a register for its IT and facilities projects. The risk “imaging system outage during migration” is linked to the tasks for a fallback plan and a weekend cutover. Reviews are due every week while the migration runs, and the owner gets a reminder before each one. After go-live, the risk closes as Resolved, with the evidence attached.

Hospital operations example: the IT operations lead logs an imaging system outage risk for a migration, fallback and cutover tasks are linked, weekly reviews are reminded, and the risk closes as Resolved.
Illustration: a hospital operations team manages the risk of a system migration.

Risk management best practices

Set up the register well

  • Agree the scales first. Pick one methodology per kind of risk before the first workshop, so scores mean the same thing to everyone.
  • Write risks as cause, event and effect. “Because the vendor’s API is in beta, it may change, which would delay integration by two weeks” is a risk. “API” is not.
  • Give every risk one owner. A second owner helps with cover, but one person is accountable.
  • Use templates for repeat risks. They make new registers faster and keep the wording consistent.

Keep it alive

  • Turn treatment into tasks. A mitigation plan without a task and a date is a wish.
  • Review on a rhythm. Set review dates by level, for example weekly for critical risks and quarterly for low ones, and let reminders do the chasing.
  • Score the residual risk. It shows whether the treatment worked, and it is what the owner accepts.
  • Close risks on purpose. Resolved, Accepted and Expired mean different things. Record which one, and why.
  • Watch the trend, not only the heat map. A map that is always red tells leaders little. The six-month trend and the overdue reviews show whether the register is working.