IT Risk Assessment
| Ref | Risk / event | Likelihood | Impact | Response | Owner | Status |
|---|---|---|---|---|---|---|
| Ref | Risk / event | Likelihood | Impact | Response | Owner | Status | |
|---|---|---|---|---|---|---|---|
Auto-saved in your browser Β· β members can white-label & sync across devices
An IT Risk Assessment is a structured evaluation of threats to your information systems, data, and infrastructure, scoring each by likelihood and impact so you can prioritize mitigation. It underpins compliance frameworks like ISO 27001, NIST, and SOC 2, and gives stakeholders a defensible record of how technology risk is being managed.
It's part of My QMS, MyPMP's Quality Management System: fill it in online, personalize it with your name and logo, then export a clean, branded PDF. Your work auto-saves in your browser.
The interactive form above gives you:
Inherent risk is the exposure before any controls are applied; residual risk is what remains after your existing safeguards. Treatment decisions should be based on residual risk against your appetite threshold.
Multiply the likelihood rating by the impact rating (commonly on 1-5 scales) to produce a score, then map it onto a heat-map or tiered band such as low, medium, high, or critical.
Review it at least annually and additionally after major changes such as new systems, incidents, vendor changes, or regulatory updates. Frameworks like ISO 27001 expect ongoing, documented reassessment rather than a one-off exercise.
Membership unlocks white-label export (remove the MyPMP footer), cloud sync across devices, plus all apps & ScheduleX.
See membership