Skip to main content

Work with ICS risk data

Record ICS risk data: link the risk to the risk-relevant objects it applies to, then add dated data points per object.

Prerequisites

  • The ICS Style Risks Early Access feature, enabled by an administrator under Admin → Server Settings → Early Access — see ICS risks.
  • A repository administrator has designated risk-relevant objects and set their materiality thresholds — see Configure ICS risks.
  • The risk's Data Type is set to Internal Control System, and a risk category is set (an ICS risk needs exactly one).
  • The Add Risk Data item role permission (Modify Risk Data to change existing data points).

Steps

  1. Open the ICS risk and select the Data tab. The tab is headed Current Risk Data.
  2. Click Add, then click the input field and search for the object to link. Only objects designated as risk relevant in the repository configuration are offered.
  3. Click Add. A section for the object appears on the tab; you can link more objects at any time.

Add a data point

  1. Expand the object's section and click the add button at its bottom right.
  2. Fill in the data point. The date, the Reason, and the Initial and Residual rows of Financial Impact, Likelihood, Regulatory Impact, and Reputational Impact are required; the Target row is optional. The residual values record your own evaluation of the controls' effect — unlike standard risks, ICS risks don't compute them from control ratings.
  3. Click Save.

The ICS data point form, with Initial, Residual, and Target rows for Financial Impact, Likelihood, Regulatory Impact, and Reputational Impact, plus a Reason field.

The form validates before saving: the initial financial impact can't be less than the residual one, likelihood values must be between 0 and 100, and the reason is limited to 2,500 characters.

Use the date dropdown in the object's section to switch between the saved data points.

Edit or delete a data point

  • To edit, select the data point's date and select Edit. Every field can be changed except the date and who saved it. Save applies the changes; Cancel discards them.
  • To delete, select the three-dot menu and choose Delete Data Point, then confirm. Deleting can't be undone; the view returns to the currently effective data point.

Select the three-dot menu and choose Unlink Object, then confirm. The object's section leaves the Data tab, and its data points stop appearing in reports. Delete and unlink are unavailable while you're adding or editing a data point.

Verify

Each data point shows three icons next to its date: a materiality indicator (green for not material, red for material) and the initial and residual risk values, colored by the object's impact class definition ranges. Hover over an icon to see what it represents. A warning icon in their place means no materiality threshold or impact class definition is configured for that time range — ask your repository administrator to extend the configuration.

The materiality, initial risk value, and residual risk value icons next to an ICS data point's date.

Materiality updates shortly after you save — changes are applied once nothing else has changed for about 15 seconds, so allow a moment before checking.