---
title: "Risk assessment"
canonical: "https://auditbadger.com/de/funktionen/risikobewertung/"
last-updated: "2026-09-05"
---

# Risk assessment

Multi-dimensional risk register integrated with the SOC 2 / ISO 27001 control library. Treatment planning, control effectiveness mapping, point-in-time snapshots, and audit-ready history.

## What it does

| Capability | Detail |
|---|---|
| **Risk identification** | Guided assessment workflows; AI suggests risks based on industry, tech stack, and business operations |
| **Multi-dimensional scoring** | Risk evaluated across **8 impact categories** (financial, operational, regulatory, strategic, reputational, technical, people, supply chain) |
| **Treatment planning** | Four documented strategies — **Accept**, **Mitigate**, **Transfer**, **Avoid** — with rationale |
| **Risk-to-control mapping** | Each risk linked to the controls that mitigate it; shows residual risk after controls |
| **Point-in-time snapshots** | Historical risk register snapshots for each audit period |
| **Scheduled reviews** | Risk register reviews on a configurable cadence with reminders and attestations |
| **Compliance integration** | Risks tied to SOC 2 controls (especially CC3 — Risk Assessment) and ISO 27001 Clause 6 + 8.2 |
| **Trend analysis** | Historical view of risk score changes over time |

## Treatment strategies

| Strategy | Use when |
|---|---|
| **Accept** | Risk is within tolerance; documented and monitored |
| **Mitigate** | Implement controls to reduce likelihood or impact |
| **Transfer** | Shift risk to a third party (insurance, contractual indemnity) |
| **Avoid** | Eliminate the risk by changing or stopping the activity |

## Workflow

1. **Identify** — catalog risks via guided assessment or AI suggestions
2. **Assess** — score impact across the 8 dimensions; assign likelihood
3. **Treat** — choose treatment strategy, link to controls, set review cadence
4. **Snapshot** — capture point-in-time state for audit evidence

## Why it matters for audits

- SOC 2 CC3 (Risk Assessment) requires a documented risk identification and analysis process; AuditBadger's snapshots provide the evidence
- ISO 27001 Clauses 6.1 and 8.2 require a documented risk assessment and risk treatment plan; both are built into the workflow
- Risk-to-control linkage shows auditors why specific controls exist and how their effectiveness is tracked

## Useful links

- Sign up: [auth.auditbadger.com/signup](https://auth.auditbadger.com/signup)
- All features: [/features](/features)
- SOC 2 deep dive: [/compliance/soc2](/compliance/soc2)
- ISO 27001 deep dive: [/compliance/iso27001](/compliance/iso27001)
- Business continuity (companion module): [/features/business-continuity](/features/business-continuity)
