Automate privacy and infosec risk management via Consentin Risk Register
Risks get added to the register automatically from submitted privacy and infosec assessments
Score risks on your own model, whether a 1–10 scale or a 5×5 impact × probability matrix
Close each risk with uploaded proof, or record who accepted it and why
Track privacy and Infosec risks in a single register
Automatic risk detection
When an assessment answer violates a rule, the risk is flagged into the register for you.
Manual risk entry
Add risks your team finds in manual review, alongside the automatic ones.
Traceability
Each risk links back to the assessment, question and response that produced it.
Audit-ready record
The register shows what you found, what you did, and who accepted the rest.
Score and label risks on your own model
Your team may have a specific model to score risks. Consentin lets you use that model.
1–10 scale — give each risk one severity score from 1 to 10
5×5 matrix — rate impact and probability from 1 to 5 each, and the risk scores out of 25
Severity bands — set the label, colour and score range of each of the four bands
Inherent, target and residual — every risk carries all three scores. Defaults come from the library, and residual is tracked against the target
Define each risk once in the risk library so that they can be flagged in future assessments automatically
Reusable risk definitions — define a risk once with its category, owner and default scores, and reuse it across assessments
Risk categories — group risks under your own categories
Library export and import — move risks, categories, questions and templates to another entity, tenant or environment via a JSON export
Close each risk with proof of mitigation, or a recorded acceptance
Mitigation tasks
Assign an owner and a due date for every risk you decide to fix.
Record acceptance
For risks you decide to live with, record who approved it and why.
Task view
Every mitigation task across all risks in one list, overdue ones flagged.
Proof of completion
The owner uploads evidence when the task is done.
See your own questionnaire running in Consentin
Bring your current assessment questionnaire to a 30-minute walkthrough.
We’ll build it in the platform, send it to a test responder, and show you the risks landing in the register.
Frequently asked questions
Does Consentin score vendors against each other?
No. Consentin scores risks, not vendors. Each risk gets a score and a severity band, and the register shows where exposure sits by entity, so you can work the high and very high risks first. There is no single composite score per vendor and no ranking of one vendor against another.
Can we use our own risk scoring methodology?
Yes. Choose the 1–10 or the 5×5 impact × probability model, and set the label, colour and range of each of the four severity bands. The two axes can be renamed to match your methodology.
Are internal systems scored the same way as vendors?
Yes. One register, one library and one scoring model cover vendor risks, internal system risks, and risks against a processing activity or purpose.
Is there a separate “Accepted” status on a risk?
No. Acceptance is recorded through the target score, a named risk approver and the written reasoning against the risk.
Can we bring in a risk library we already have?
Yes, as a JSON import of risks, categories, questions and templates.
Does Consentin check that a mitigation actually happened?
No. The task owner uploads proof and marks the task complete, and that proof stays attached to the risk. Consentin does not independently test a vendor’s environment or verify a control from the outside.
Do findings from an ISO 27001 or infosec assessment land in the same register?
Yes. Any assessment you run in Consentin feeds the same register, whatever the questionnaire behind it.