Automate privacy and infosec risk management via Consentin Risk Register

Risks get added to the register automatically from submitted privacy and infosec assessments

Score risks on your own model, whether a 1–10 scale or a 5×5 impact × probability matrix

Close each risk with uploaded proof, or record who accepted it and why

Track privacy and Infosec risks in a single register

Automatic risk detection

When an assessment answer violates a rule, the risk is flagged into the register for you.

Manual risk entry

Add risks your team finds in manual review, alongside the automatic ones.

Traceability

Each risk links back to the assessment, question and response that produced it.

Audit-ready record

The register shows what you found, what you did, and who accepted the rest.

Score and label risks on your own model

Your team may have a specific model to score risks. Consentin lets you use that model.

1–10 scale — give each risk one severity score from 1 to 10

5×5 matrix — rate impact and probability from 1 to 5 each, and the risk scores out of 25

Severity bands — set the label, colour and score range of each of the four bands

Inherent, target and residual — every risk carries all three scores. Defaults come from the library, and residual is tracked against the target

Risk scoring modelSettings · impact × probability · out of 25
Impact
Probability
Severity bands
Very high18–25
High11–17
Medium6–10
Low1–5
Encryption at rest — Meridian LogisticsHigh16 / 25
An answer violates a rule — the risk lands, scored on your bands

Define each risk once in the risk library so that they can be flagged in future assessments automatically

Reusable risk definitions — define a risk once with its category, owner and default scores, and reuse it across assessments

Risk categories — group risks under your own categories

Library export and import — move risks, categories, questions and templates to another entity, tenant or environment via a JSON export

Close each risk with proof of mitigation, or a recorded acceptance

Mitigation tasks

Assign an owner and a due date for every risk you decide to fix.

Record acceptance

For risks you decide to live with, record who approved it and why.

Task view

Every mitigation task across all risks in one list, overdue ones flagged.

Proof of completion

The owner uploads evidence when the task is done.

See your own questionnaire running in Consentin

Bring your current assessment questionnaire to a 30-minute walkthrough.

We’ll build it in the platform, send it to a test responder, and show you the risks landing in the register.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Frequently asked questions

No. Consentin scores risks, not vendors. Each risk gets a score and a severity band, and the register shows where exposure sits by entity, so you can work the high and very high risks first. There is no single composite score per vendor and no ranking of one vendor against another.

Yes. Choose the 1–10 or the 5×5 impact × probability model, and set the label, colour and range of each of the four severity bands. The two axes can be renamed to match your methodology.

Yes. One register, one library and one scoring model cover vendor risks, internal system risks, and risks against a processing activity or purpose.

No. Acceptance is recorded through the target score, a named risk approver and the written reasoning against the risk.

Yes, as a JSON import of risks, categories, questions and templates.

No. The task owner uploads proof and marks the task complete, and that proof stays attached to the risk. Consentin does not independently test a vendor’s environment or verify a control from the outside.

Yes. Any assessment you run in Consentin feeds the same register, whatever the questionnaire behind it.

Compliance Deadline:

0 weeks away