SmartSuite for the Risk Manager
The Risk Manager conducts risk assessments, maintains the register and tracks mitigation for their scope. They score likelihood and impact with the enterprise method, link risks to the controls and obligations that treat them, and keep owners accountable for treatment plans.
What you own
- Facilitate risk identification and assessment workshops
- Score risks for likelihood, impact and velocity using the enterprise methodology
- Document risks, gaps and related issues in the register
- Assign mitigation owners, deadlines and track progress
- Monitor key risk indicators and residual risk
- Map compliance obligations and controls to the risks they treat
- Prepare risk reporting for committees and leadership
Where the role sits
Each name opens that role's page.
Reports to
Direct reports
Works closely with
GRC processes
The shared GRC process map, highlighted for this role.
Owns
accountable for the process
Touches
contributes or approves
Depends on
consumes its output
How SmartSuite helps, suite by suite
Each card is the persona record from that suite's Users tab.
How they use SmartSuite
How they use the Project & Program Execution suite
Risk identification
Logs and categorizes project risks early.
Mitigation tracking
Assigns actions and monitors progress to closure.
Trend analysis
Identifies recurring risks across projects.
How they use SmartSuite
Risk Tracking
Logs and monitors physical security risks.
Mitigation Oversight
Tracks corrective actions and deadlines.
Reporting
Provides risk summaries to leadership.
How they use the Enterprise Risk Management suite
Risk scoring
Evaluates likelihood, impact, and velocity using standardized methodologies.
Findings & issues
Documents identified risks, gaps, and related issues.
Mitigation tracking
Assigns owners, sets deadlines, and tracks mitigation progress.
How they use the Compliance Management suite
Risk mapping
Links compliance obligations to enterprise risks.
Issue monitoring
Tracks remediation progress and residual risk.
Assurance coordination
Aligns compliance outcomes with audit and risk reporting.
Suites that serve this role
How SmartSuite supports this role
Risk management. Runs scoring workflows for likelihood, impact and velocity, documents risks and gaps, and tracks mitigation with owners and deadlines in one register.
Compliance management. Links compliance obligations to enterprise risks so residual risk and control coverage are visible together.
Internal audit. Aligns compliance outcomes and audit results with risk reporting through shared records.
Issues and actions. Monitors remediation progress and residual risk through linked issue records with automated reminders.
Reporting. Builds committee-ready risk reports from the register with filters by business unit, category and owner.
Industry reference
ISO 31000:2018 defines the process the Risk Manager runs: identification, analysis, evaluation, treatment and monitoring, with the IRM and RIMS competency frameworks describing the skills. COSO ERM (2017) links each risk to strategy and to the controls and obligations that treat it.
Sector rules shape the register. Banks apply Basel operational risk principles and RCSAs; healthcare organisations must perform the HIPAA Security Rule risk analysis; US federal agencies follow NIST SP 800-30 and OMB Circular A-123; technology companies run information security risk assessments under ISO/IEC 27005 and SOC 2.
In their words
Related roles
See SmartSuite for your role
Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.







