Define and Track Risk Treatments

Once controls are mapped to a risk, the next step is to define how you plan to treat that risk. Sprinto supports multiple treatment strategies, with optional task creation to ensure follow-through.

Access the Treatment Section

  1. Log in to the Sprinto dashboard and navigate to Risks.

  2. Click on the Risk Register tab.

  3. Open the relevant risk.

  4. In the left-side navigation panel, click Treatment.


Choose a Treatment Strategy

You can choose one of the following approaches for each risk:

  • Accept: Acknowledge the residual risk and take no further action.

  • Transfer: Shift responsibility (e.g. outsource or insure the risk).

  • Further Mitigate: Apply additional actions to reduce risk further.

  • Avoid: Discontinue the process or activity causing the risk.

For each strategy, you can:

  • Select a treatment reason (e.g. “Risk is insured”, “Work is outsourced”).

  • Add optional treatment notes to document your decision.

Click Save and close once you have selected the appropriate treatment strategy.


Create a Risk Treatment Task (Optional)

You can assign mitigation tasks to ensure that treatment actions are implemented.

To create a treatment task:

  1. In the Treatment section, click + Add Task.

  1. Enter the following details:

    • Task name

    • Assignee (Security Hub admin)

    • Due date

    • Optional notes or attachments

  2. Click Add Task to save.

circle-info

Tasks appear in the dashboard and are tracked until completion. Once completed, the task status is marked as Passing.


Control Weightages

Control weightages allow you to define how much each control and task contributes to the overall treatment effectiveness for a risk. Assigning custom weights ensures that high-impact controls influence the final score more than lower-impact items, resulting in a more accurate and realistic view of the organisation’s mitigation posture.

Here's a short video explaining how control weightages work.

Enable Control Weightages

Before assigning weights, you must enable this feature.

To enable control weightages:

  1. Sign in to Sprinto and select Risks from the left navigation panel.

  2. Open the Configuration tab.

  3. Locate Adjustable risk treatment weightage.

  4. Turn on the toggle.

Requirements

  • Risk Monitoring must be enabled.

  • Available only on the Enterprise (Plan 4) subscription.

When Risk Monitoring is off, weightages and treatment effectiveness values are hidden.


Add Weightages to Controls and Tasks

Once the feature is enabled, you can assign custom weightages to the controls and tasks associated with a risk.

To assign weightages:

  1. Go to Risks and open the Risk Register tab.

  2. Select any risk and open the Treatment tab.

  3. Scroll to the Risk treatment effectiveness section.

  4. Enter edit mode to update weight percentages.

circle-exclamation

Error States for Control Weightages


Understanding Weightage Buckets

Sprinto uses a two-level system to calculate treatment effectiveness: Level 1 (L1) and Level 2 (L2).

Your provided diagram illustrates this flow perfectly.


Level 1 (L1): Controls + Tasks Bucket (Must Equal 100%)

All mapped controls and the Tasks bucket must sum to exactly 100%.

Example:

Item
Weight

Control C1

30%

Control C2

30%

Tasks (bucket)

40%

Total

100%

This ensures the overall treatment effectiveness calculation is based on the relative importance of each main contributor.


Level 2 (L2): Sub-tasks Inside the Tasks Bucket (Must Equal 100%)

If the Tasks bucket contains multiple subtasks, you can optionally assign weights to each subtask.

All subtasks must total exactly 100%, independent of the L1 total.

Example:

Sub-task
Weight

Task T1

60%

Task T2

40%

Total

100%

Sprinto uses these L2 weights to compute the weighted completion percentage of the Tasks bucket before contributing it to the L1 calculation.


Set Equal Weightage

You can automatically distribute weights equally.

To apply equal weightage:

  1. Select Set equal weightage.

  2. Confirm in the dialogue box.

Sprinto resets all L1 weights equally, and all L2 weights (if any) equally.


Validation and Error Handling

Sprinto validates both L1 and L2 totals independently.

You will see an error when:

  • A weight field is blank

  • L1 total is not 100%

  • L2 total is not 100%

  • Weights exceed or fall short of 100%

The system highlights the problematic fields in red and displays the difference (for example, “exceeds by 3.34%” or “falling short by 0.66%”).

You cannot continue until all weightages are corrected.


Impact on Treatment Effectiveness

The treatment effectiveness score becomes a weighted average instead of a simple average, ensuring accurate representation of control importance.

Last updated