The Risk Register

The Risk Register turns contract risk from a gut feeling into a tracked list — which agreements carry exposure, why, and what’s being done about it.

When to use

Use it during and after review to record risky clauses, and later to see which risks are still open across all contracts.

Before you start

  • contract_management:view to read the register; adding or changing risks needs review rights.
  • The toggle legal.risk_blocks_activation (off by default) prevents a standalone contract from being activated while a severe risk is open.

Steps

Review flagged risks

Go to Contract Management → Risk Register (/contracts/risk-register) to see contracts with elevated risk, including clauses the AI flagged.

Assess and assign

For each risk, record its severity and assign an owner to mitigate it. Others can follow a risk as watchers.

Track mitigation

Update the risk as it’s negotiated out, accepted, or resolved, keeping a clear audit trail. Close it when done.

Contract Management — Risk Register with flagged clauses and severity
Contract Management — Risk Register with flagged clauses and severity

Tips & common mistakes

  • Close risks once handled; open severe risks can block activation when the toggle is on.
  • The Open Risks report (/contracts/reports/risks) gives a portfolio-wide view.
  • The AI suggests; people decide on severity and mitigation.
  • Open a risk’s detail page to see its watchers and history.