Use the Risk Register
The Risk Register is the organisation’s working list of material AI risks recorded through Swell.
Use filters and attention indicators to find risks that need confirmation, ownership, treatment, controls or acceptance. Open the risk before acting so you can read the full statement and supporting assessment.
How to use the Risk Register
- Open AI Risks and stay on Risk Register.
- Review the summary for current risks, AI uses awaiting assessment, risks outside tolerance and control or evidence gaps.
- Use Residual rating, Category or Overdue only to narrow the list.
- Select a risk statement to open its detail.
What happens next
The Risk detail shows its assessment, treatment and history.
Use the fixed 3×3 risk matrix
The risk matrix groups risks by likelihood and consequence so you can see their relative distribution and open the records behind each cell.
Swell uses a fixed 3×3 matrix. The visual grouping supports comparison; it does not replace the documented reasoning and authorised rating on each risk.
How to use the fixed 3×3 risk matrix
- Open AI Risks → Risk Matrix.
- Choose Residual or Inherent.
- Read the 3×3 cells from Low to High consequence and likelihood.
- Select a populated cell to open the matching filtered Risk Register.
Important: Swell uses a fixed 3×3 matrix that cannot be configured for individual organisations.
What happens next
The Risk Register opens with filters for the selected matrix cell.
Review a risk
A risk record explains the event or consequence the organisation is managing, its rating, owner, planned treatment and supporting controls.
Read the complete record before changing one part of it. A new control, changed treatment or material change may require the residual rating to be reconsidered.
How to review a risk
- Open a risk from the register, matrix or AI use.
- Read the reference, statement, category, AI use and current status.
- Compare inherent and residual ratings.
- Review appetite, owner, treatment and next review.
- Use Assessment, Treatment and History for the supporting detail.
Confirm or recalculate a risk rating
Risk rating is a business judgement based on the assessment, available evidence and the organisation’s risk approach.
Confirm the inherent rating before relying on controls, then confirm or recalculate the residual rating using only controls that are evidenced and working as intended.
Before you start
- You need authority to confirm the rating.
- Review the supporting facts and controls before changing the remaining-risk rating.
How to confirm or recalculate a risk rating
- On the Risk Assessment tab, review the suggested inherent and residual positions.
- Choose the Stage you are assessing.
- Choose a likelihood and consequence from the three-level scale.
- Enter the reason for the judgement.
- Select Confirm rating. Use Recalculate when changed controls or evidence may affect the remaining risk.
What happens next
The confirmed rating and reasoning are retained in risk history.
Assign ownership and choose treatment
The risk owner is accountable for ensuring the risk is understood and managed. Treatment records the organisation’s intended response, such as reducing, avoiding, transferring or accepting the risk.
Choose an owner with the authority to act and record a treatment that reflects the real plan. Naming an owner does not by itself reduce the risk.
How to assign ownership and choose treatment
- Open the Risk and choose Manage risk.
- Assign the Risk owner.
- Choose Mitigate, Avoid, Transfer or Accept.
- Set treatment status: Not started, Underway, Awaiting evidence, Ready for review or Completed.
- Set the next review date where appropriate.
- Choose Standard or Restricted visibility and save.
What happens next
The risk owner and treatment plan appear in the register and action queues.
Common situations
- Use Restricted only when the Risk contains genuinely sensitive information. Restricted visibility limits ordinary access but remains subject to privileged administrative and support boundaries.
- If ownership changes, update the risk owner and check that open treatment, control or acceptance work is assigned to the right people.
Add a treatment action
Use a treatment action for practical follow-up that helps manage the risk but is not itself a formal control assignment.
Describe a clear action, owner and expected timing. If the action becomes a safeguard relied on to reduce residual risk, record and evidence it through the control process.
How to add a treatment action
- On Manage risk, find Add a treatment action.
- Enter a short action title and clear description.
- Add an optional due date.
- Save the action.
What happens next
The action is tracked with the Risk. Use a Control assignment when the work is a formal control requiring evidence and governance status.
Add and review controls
Controls are the safeguards the organisation relies on to prevent, detect or reduce the risk.
Link only controls that genuinely apply to this risk. Residual-risk reduction should rely on controls with current evidence and an appropriate effectiveness decision.
How to add and review controls
- Open the Risk Treatment tab.
- Review linked controls and their eligibility.
- Under Recommended controls, select Add [control name] when the recommendation applies.
- When authorised and evidence supports it, select Confirm effective for this risk.
- Recalculate the remaining-risk rating when the recognised controls or their evidence change.
What happens next
Rely only on controls that apply to the risk, have current evidence and are working as intended.
Request risk acceptance
Risk acceptance is used when a risk will remain after available controls and treatment have been considered, and the organisation needs an authorised person to decide whether it is prepared to proceed.
It is different from approving the AI use itself. An AI use may have several risks, and accepting one residual risk does not automatically authorise the overall use.
Before requesting acceptance, make sure the risk rating, treatment and supporting evidence reflect the current situation.
Before you start
- Risk acceptance is separate from approving the AI use.
How to request risk acceptance
- Confirm that the remaining-risk rating and treatment plan are current.
- On the Risk, select Request Risk Acceptance.
- Choose the authorised assignee and explain why acceptance is being requested.
- Submit the request and monitor the resulting Risk Acceptance assignee action.
What happens next
The named assignee receives a decision task. The Risk remains outstanding until that decision is recorded.
Decide a risk acceptance request
The acceptance decision belongs to the authorised person assigned to the request. Review the risk, residual rating, treatment, controls and supporting rationale before deciding.
Accept only the remaining risk described in the request. Reject it when further treatment or clarification is needed; the decision does not approve the AI use as a whole.
How to decide a risk acceptance request
- Open the Risk Acceptance assignee action.
- Review the Risk statement, residual rating, treatment, controls and request rationale.
- Choose Accept, Accept with conditions, Return for changes or Reject.
- Enter the rationale. Add conditions when accepting with conditions.
- Select Record decision.
What happens next
The decision is retained with the Risk. It does not approve the underlying AI use.
Common situations
- Return the request for changes when the evidence or proposed treatment must be improved before the acceptance decision can be made.