Score a Risk
After you register a risk in Sprinto—whether via the risk library, manual entry, or bulk upload—you must score it to complete its configuration. Scoring helps quantify both the likelihood and impact of a risk, enabling informed prioritisation and treatment.
Access the Scoring Section
Go to Risks from the left navigation.
Click on the Risk Register tab.
Locate a risk with the status marked as Needs scoring.

Click on the risk name to open its details.
The scoring interface will automatically appear if the risk has not yet been scored.
Fill in Risk Profile Parameters
You will see separate sections for Inherent Risk Score and Residual Risk Score.
Inherent Risk
Represents the level of risk before any controls are applied.
Inherent Impact: Select a score between 0 (low) and 10 (high).
Inherent Likelihood: Choose a probability from 0% to 100%.
Residual Risk
Reflects the remaining risk after mitigation controls are applied.
Residual Impact: Select a post-mitigation impact score between 0 and 10.
Residual Likelihood: Choose a likelihood percentage after mitigation.
Sprinto automatically calculates:
Inherent Risk Score = Inherent Impact × Inherent Likelihood
Residual Risk Score = Residual Impact × Residual Likelihood
🧮 Scores are shown as "Unscored" until values are filled in. Once calculated, they help you visualise your risk posture on the dashboard heat map.

Add Notes (Optional)
Use the Notes section to document any assumptions or decisions behind your scoring selections. These notes will be preserved in audit logs and risk history.
Save and Proceed
Click Save and close to apply your scoring or select Next: Treatment to immediately move on to defining the treatment plan.
Once saved, the risk status changes from Needs scoring to Pending Approval or Complete, depending on your organisation's workflow configuration.
Scoring is an essential milestone in the risk lifecycle. It activates downstream steps like control mapping, treatment planning, and inclusion in periodic assessments. Make sure all risks are scored promptly to maintain compliance continuity.
Last updated