Enterprise Risk Management - User Manual
Introduction
The Enterprise Risk Management module provides a comprehensive solution for organisations to identify, assess, treat and monitor risks in accordance with ISO 31000:2018 standards. This manual will guide you through the features and functionality to effectively manage your organisation's risk landscape.
Getting Started
After installing the module, a new "Risk Management" menu will appear in your Odoo navigation. This menu provides access to all risk management functions.
User Roles
The module includes three levels of access:
- Viewer: Can view risks and related data
- User: Can create and edit risks, controls, treatments and reviews
- Manager: Has full access including configuration options
Core Concepts
Risk Register
The risk register is the central repository for all identified risks. Each risk includes:
- Basic information (title, owner, category)
- Detailed description, causes and consequences
- Risk assessment (inherent, residual and target risk levels)
- Controls, treatments and review history
Risk Assessment Process
Risk assessment follows a structured approach:
- Identify the Risk: Create a new risk entry with basic details
- Assess the Risk: Evaluate likelihood and impact using the assessment matrix
- Treat the Risk: Define treatment strategy and actions
- Monitor the Risk: Regular reviews and reassessments
Risk Matrix
The risk matrix provides a framework for consistent risk assessment across the organisation. The standard matrix includes:
- 5 levels of likelihood (Rare to Almost Certain)
- 5 levels of impact (Insignificant to Catastrophic)
- Calculated risk scores and corresponding risk levels (Low, Medium, High, Very High)
Managing Risks
Creating a New Risk
- Navigate to Risk Management > Risk Register
- Click "Create" to open a new form
- Fill in the required information:
- Risk title
- Category
- Risk owner
- Description, causes and consequences
- Save the form to create the risk in "Draft" status
Assessing a Risk
- Open the risk record
- Go to the "Risk Assessment" tab
- Select an assessment matrix
- Enter likelihood and impact values for:
- Inherent risk (before controls)
- Residual risk (current state with existing controls)
- Target risk (desired future state)
- Click "Assess" to move the risk to "Assessed" status
Adding Controls
- Open the risk record
- Go to the "Controls" tab
- Click "Add a line" to create a new control
- Fill in the control details:
- Title
- Type (Preventive, Detective, Corrective, Directive)
- Owner
- Description
- Implementation details
- Save the form
Controls follow their own lifecycle:
- Draft > Implemented > Effective/Ineffective
Creating Treatment Actions
- Open the risk record
- Go to the "Treatment Plan" tab
- Click "Add a line" to create a new treatment action
- Fill in the action details:
- Title
- Priority
- Owner
- Due date
- Description and expected outcomes
- Save the form
Treatment actions follow their own lifecycle:
- Draft > In Progress > Completed/Cancelled
Scheduling Reviews
- Open the risk record
- Click "Schedule Review" button
- Fill in the review details:
- Review date
- Reviewer
- Next review date
- Assessment changes (if applicable)
- Save the form
Dashboard and Reporting
The risk register provides various views to analyse your risk landscape:
- Kanban View: Visual representation of risks by status
- List View: Table of risks with colour coding by risk level
- Search Filters: Find risks by various criteria including level, category, owner, etc.
Configuration
Risk Categories
Define categories to organise risks by type:
- Navigate to Risk Management > Configuration > Risk Categories
- Create categories relevant to your organisation (e.g., Strategic, Operational, Financial)
Assessment Matrices
Customise risk assessment matrices:
- Navigate to Risk Management > Configuration > Assessment Matrices
- Define likelihood levels, impact levels and scoring rules
Control Types
Define the types of controls used in your organisation:
- Navigate to Risk Management > Configuration > Control Types
- Create new types or modify existing ones
Impact Types
Specify different impact dimensions for risk assessment:
- Navigate to Risk Management > Configuration > Impact Types
- Define impact areas relevant to your organisation (e.g., Financial, Reputation, Safety)
Best Practices
- Regularly review and update the risk register
- Ensure risk owners are responsible for monitoring their assigned risks
- Conduct formal risk reviews according to the schedule determined by risk level
- Document the effectiveness of controls to support risk assessment
- Track treatment actions to completion
- Use risk categories and tags to enable effective filtering and reporting
Support
For additional support with the Enterprise Risk Management module, please contact Cyder Solutions at info@cyder.com.au.