Edit a Risk

Sprinto allows users to edit risk details during different stages of the risk lifecycle. This helps ensure that your risk register remains accurate and up to date as your organisation evolves.

Access a Risk Entry

  1. Log in to the Sprinto dashboard and navigate to Risks.

  2. Click on the Risk Register tab.

  3. Locate and click the name of the risk you want to update.

  4. Click Edit to start editing the details.


Editable Fields

Depending on the risk’s current status, the following elements can be edited:

General Risk Information

  • Risk scenario

  • Risk owner

  • Applicable CIA

  • Risk source

  • Risk managers

  • Exposed threats

  • Exposed vulnerabilities

  • Monetary Value

  • Additional information

To edit these:

  1. Click the Edit icon in the top-right of the risk details section.

  2. Update the required fields.

  3. Click Save and close.

Scoring Parameters

  • Inherent Likelihood & Impact

  • Residual Likelihood & Impact

  • Notes related to scoring decisions

Scoring can only be edited before approval or during a new assessment cycle.

Treatment Plan

  • Change treatment approach (Accept, Transfer, Avoid, Further Mitigate)

  • Update treatment reason or notes

To make these changes:

  1. Navigate to the Treatment tab inside the risk.

  2. Click Edit Treatment Plan.

  3. Apply your changes and save.

Control Mappings

  • Add or remove mapped controls

To update:

  1. Navigate to the Controls tab.

  2. Use + Map Controls or click the bin icon to remove.

Risk Treatment Tasks

  • Edit task name, assignee, or due date

  • Add or update task notes.

All task edits are version-controlled and captured in the audit trail.


Restrictions on Editing

  • You cannot edit uploaded risk assessment documents.

  • Risks under final review by senior management are locked until the review is completed.

  • Audit logs and historical scoring events are view-only.

Last updated