Riskward documentation (public knowledge base draft)
Get started (5 minutes)
- Jira settings > Apps > Riskward. Pick the matrix (5 x 5, 4 x 4, 3 x 3 or your own labels), the level thresholds and colors, and your risk appetite: the highest score you accept without more treatment.
- Review cadence. Set how often each level is reviewed (default: critical and high every 30 days, medium 90, low 180) and whether owners get email reminders.
- Issue types that are risks. Tick the types your teams use for risks (for example a "Risk" type). Any other issue can still be rated from its panel.
- Who manages Riskward. Name a risk manager group so your risk lead can change settings, controls and imports without Jira admin rights.
- Bring your current register. Risk register > Import: download the template, paste or upload your CSV, check it, then create the risks.
Rating a risk
Open the issue and the Risk assessment panel. Click a cell for Inherent (before controls), Residual (with the controls in place today) and Target (where treatment should bring it). Add the treatment (reduce, avoid, transfer, accept), category and controls, and an optional note, then Save assessment. Saving counts as a review: the next review date moves on from today based on the risk's current level.
If nothing changed at a review, use Mark reviewed (no change). It restarts the clock and logs the review with your note.
Current exposure is the residual rating where there is one, otherwise the inherent rating. Risks whose current exposure is above your appetite are flagged and outlined on heat maps.
The register
Project sidebar > Risk register (or Apps > Risk register for every project). Filter by level, review state, category, owner or "outside appetite", sort any column, and export a CSV. Closed risks are hidden until you tick Show closed.
Heat maps
Switch between current exposure, inherent and target. As of replays the map on any past date from the audit trail. Compare with shows the change per cell since an earlier date and lists each risk that got worse, better, moved, was added or closed. The bar chart shows open risks per level at each month end, with the count outside appetite underneath.
Reviews and reminders
The Reviews tab lists overdue reviews (with days late), reviews due soon and risks not yet rated. Once a day Riskward emails the owner (assignee, or reporter when unassigned) of each risk due within your "due soon" window, repeats every N days until it is reviewed, and copies the groups you choose once a review is overdue. Emails are Jira notifications and only reach people who can see the issue.
Controls and Statement of Applicability
The Controls tab lists the ISO/IEC 27001:2022 Annex A controls (numbers and titles) and any custom controls you import (CSV: id, title, theme). For each control record whether it is applicable, its status and a justification. Gaps shows applicable controls that are not implemented and linked controls with no decision yet. Export the Statement of Applicability as CSV.
Evidence for auditors
Evidence builds one HTML file for a period: method (matrix, appetite, cadence), heat maps, movement, the full register, every review and rating change with who and when, and the Statement of Applicability. Open it in a browser and print to PDF. CSVs for the register, the review log and the SoA are on the same tab.
JQL
| Field | Example |
|---|---|
riskInherentScore, riskResidualScore, riskTargetScore | riskResidualScore > 12 |
riskLevel | riskLevel = critical |
riskOutsideAppetite | riskOutsideAppetite = yes |
riskNextReview | riskNextReview < "2026-11-01" |
riskCategory | riskCategory = "Information security" |
riskTreatment | riskTreatment = accept |
riskControl | riskControl = "A.8.13" |
Dashboards
Add Risk heat map (Riskward) to a dashboard. Pick a project, an optional JQL filter and which heat map to show. It shows open risks, how many are outside appetite and how many reviews are overdue. On the new Jira dashboards, changes apply when you save the dashboard.
Classic Jira dashboards and their gadgets stop working on 17 May 2027, when Atlassian retires them. Before then, add the widget to a new Jira dashboard and pick the same settings.
Per-project models
On a project's Risk register page, Project settings lets that project's admins use a different matrix (for example 3 x 3 for a small project) or review cadence. Heat maps never mix models: a scope with several models shows one map per model.