<!-- RTOSafe Help — rendered version: https://rtosafe.com.au/help/risk-register-controls -->

# Add Risk Controls

***

## When to Use This

After you've created a risk, add controls to document what you're doing to reduce it. Controls are the actions, policies, or procedures that make the risk less likely or less severe.

***

## Steps

<div class="help-stepper">

<div class="help-step">
<div class="help-step-number">1</div>
<div class="help-step-content">

**Open the risk**

From [**Registers → Risk**](https://app.rtosafe.com.au/Risk), click on the risk you want to add controls to. Click **Edit Controls**.

</div>
</div>

<div class="help-step">
<div class="help-step-number">2</div>
<div class="help-step-content">

**Add your controls**

Describe each control — what are you doing to reduce this risk?

Examples:

* "Annual trainer qualifications audit"
* "Student feedback surveys after each course"
* "Weekly backup of student records"

You can click **Suggest Controls** to get AI-generated ideas based on your risk.

</div>
</div>

<div class="help-step">
<div class="help-step-number">3</div>
<div class="help-step-content">

**Assess residual risk**

After adding controls, rate the risk _with_ controls in place:

* **Residual Likelihood**: How likely is this now?
* **Residual Impact**: How severe would it be now?

This should typically be lower than your inherent rating — that's the point of having controls.

</div>
</div>

<div class="help-step">
<div class="help-step-number">4</div>
<div class="help-step-content">

**Set a review date**

Choose when you'll next review this risk. This is required to activate the risk.

<div class="help-hint bg-green-50 border-green-300 text-green-800">
<svg class="w-5 h-5 shrink-0" fill="currentColor" viewBox="0 0 20 20"><path fill-rule="evenodd" d="M10 18a8 8 0 100-16 8 8 0 000 16zm3.707-9.293a1 1 0 00-1.414-1.414L9 10.586 7.707 9.293a1 1 0 00-1.414 1.414l2 2a1 1 0 001.414 0l4-4z" clip-rule="evenodd"></path></svg>
<div class="help-hint-content">

Once you set a review date, you can change it but you can't remove it.

</div>
</div>

</div>
</div>

<div class="help-step">
<div class="help-step-number">5</div>
<div class="help-step-content">

**Save**

Click **Save**. The risk status changes from `Pending` to `Active`.

</div>
</div>

</div>

***

## What Happens Next

* The risk matrix on the details page shows both your inherent risk (before controls) and residual risk (after controls)
* The risk appears as `Active` on your register
* You'll receive reminders as the review date approaches
* RTOSafe updates the AI analysis to reflect your controls

***

## Reviewing Risks

When a review is due, open the risk and check if anything has changed. Update ratings or controls if needed, then set the next review date. RTOSafe tracks all changes in the risk history for your audit trail.

***

## Common Issues

<details>

<summary><strong>Residual risk is the same as inherent risk</strong></summary>

Your controls may not be effective enough, or you may need to reconsider your ratings

</details>

<details>

<summary><strong>Can't save without a review date</strong></summary>

A review date is required to activate the risk. Choose a realistic review period based on how volatile the risk is

</details>

<details>

<summary><strong>Want to add more controls later</strong></summary>

You can edit controls at any time from the risk details page

</details>