Findings Triage & Risk Quick View

Triage findings and review risk scoring from the web Reviewer Dashboard or the mobile GRC tabs.

5 min readArticle 3 of 6 in Governance, Risk & Compliance

Findings Triage & Risk Quick View

Findings record gaps surfaced during a review. Risks live in the Risk Register and are scored using inherent and residual ratings. Both are reviewable on the web and on mobile.

Findings — list & filters

Open Findings on mobile (/grc/findings) or the Reviewer Dashboard on web. Filters available on mobile:

  • Severity — Critical, High, Medium, Low, Info
  • Status — Open, Acknowledged, Resolved, Accepted Risk
  • Search — text search across title and description

Each row shows:

  • Title
  • Severity badge
  • Status badge
  • Date created
  • Linked assessment and question

Triaging a finding

Open a finding to see its full description and the originating response. From the detail view you can:

  • Change severity via chip selector (Critical → Info) — mobile and web
  • Change status via chip selector (Open → Acknowledged → Resolved or Accepted Risk) — mobile and web

The mobile finding detail pane only exposes severity and status edits; longer-form reviewer notes are managed from the web finding detail. Status transitions are logged to the activity log and trigger finding.status_changed and finding.resolved webhook events where applicable.

Risk Register & quick view

Open Risks on mobile (/grc/risks) or the Risk Register on web. Filters:

  • Severity (Inherent) — Critical, High, Medium, Low
  • Treatmentmitigate, accept, avoid, transfer
  • Search

List rows show: title, category, type, owner, identified date.

Risk quick view fields

Tap a risk to open the score card. It surfaces:

  • Inherent score — value, severity label, and the formula Impact × Likelihood (each 1–5) — read-only in the mobile quick view
  • Residual score — value, severity label, and the same formula applied after treatment — read-only in the mobile quick view
  • Treatment type — chip selector for mitigate, accept, avoid, transfer (editable)
  • Status — chip selector for Active, Closed, Archived (editable)

The mobile quick view edits treatment and status only; impact, likelihood, and severity ratings are managed from the full Risk editor on web. Saving a treatment or status change persists immediately and refreshes the score card.

Tips

  • Set a severity before changing status — the dashboard groups by severity, so consistent grading keeps the queue meaningful.
  • Use Accepted Risk sparingly; it removes the finding from the open queue but is preserved for the auditor trail.
  • For risks, always record the treatment type even when accepting, so the residual score reflects reality.