You are on CAQA Risk
CAQA Risk - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Features
Features

Every function, in detail.

What each part of CAQA Risk does, and how the pieces work together on one governed register.

Strategic risks

Strategy fails quietly — a market shift here, a policy change there, a partnership that never delivers. CAQA Risk gives strategic risks their own governed register, owned at board and executive level, so the threats to your objectives are named, rated and revisited rather than assumed.

Each strategic risk links to the objective it threatens, the appetite statement that bounds it and the controls and treatments that answer it — so strategy conversations start from evidence.

  • Register risks against organisational objectives and direction
  • Assign executive and board-level ownership for each entry
  • Link every strategic risk to appetite, controls and treatments
  • Surface movement between reviews on the strategic heat map
Back to top ↑

Operational risks

Operations generate risk continuously — in processes, rosters, facilities, suppliers and service delivery. CAQA Risk lets teams capture operational risks where the work happens, in plain language, and routes them into the same governed register the executive sees.

Because operational entries share the organisation’s rating scales and appetite statements, a frontline hazard and a board-level exposure are finally comparable on the same map.

  • Capture risks from any team into one governed register
  • Rate likelihood and consequence on shared organisational scales
  • Attach the controls that already mitigate each exposure
  • Watch clusters form by unit, site or process on heat maps
Back to top ↑

Project risks

Every initiative carries its own weather — scope drift, schedule pressure, resourcing gaps, dependencies that slip. CAQA Risk gives each project its own risk view while keeping every entry inside the organisation-wide register.

Project sponsors see their initiative’s exposure in isolation; portfolio owners and executives see how project risk aggregates across everything in flight.

  • Maintain a per-project risk view inside the central register
  • Track scope, schedule, resourcing and dependency risk
  • Roll project exposure up to portfolio and executive views
  • Escalate automatically when a project risk breaches appetite
Back to top ↑

Financial risks

Financial exposure rarely announces itself — it accumulates in receivables, contracts, budgets and market movements. CAQA Risk records financial risks alongside every other category, rated on the same scales, so finance stops being a separate conversation.

Appetite statements give financial risks hard boundaries, and key risk indicators watch the numbers between reviews — so a drifting metric raises its hand before it becomes a write-down.

  • Register cashflow, credit, liquidity, budget and market risks
  • Bound each exposure with board-approved appetite statements
  • Watch financial indicators against thresholds between reviews
  • Evidence the control environment for auditors and committees
Back to top ↑

Cyber risks

Cyber risk is organisational risk — it belongs on the same register as everything else, not in a separate spreadsheet owned by IT. CAQA Risk records threats to systems, data, privacy and continuity with the same rigour as strategic or financial exposure.

Each cyber risk maps to the technical and procedural controls that defend against it, so security investment decisions trace back to rated, owned exposure rather than instinct.

  • Register threats to systems, data, privacy and continuity
  • Map each threat to its defending technical and procedural controls
  • Rate cyber exposure on the organisation’s shared scales
  • Escalate breaches of cyber appetite to the right owners fast
Back to top ↑

Controls

A risk register without controls is a worry list. CAQA Risk maintains a controls library — every safeguard the organisation already operates, mapped to the risks it mitigates, with an owner, an effectiveness rating and a testing history.

Inherent and residual ratings sit side by side, so leaders can see exactly how much work each control is doing — and which risks are relying on controls that have never been tested.

  • Maintain a single controls library across every risk category
  • Map each control to the risks it mitigates
  • Record effectiveness ratings and testing history
  • Compare inherent and residual ratings side by side
Back to top ↑

Treatments

Deciding to treat a risk is easy; finishing the treatment is where registers usually go quiet. CAQA Risk runs treatments as real work — discrete actions with named owners, due dates and progress states, tracked to completion.

Overdue treatments are visible the moment they slip, and a completed treatment flows straight back into the risk’s residual rating — so the register reflects what has actually been done, not what was intended.

  • Create treatment plans with named owners and due dates
  • Track each action through to evidenced completion
  • Surface overdue and stalled treatments automatically
  • Feed completed treatments back into residual ratings
Back to top ↑

Risk appetite

Most appetite statements live in a board paper nobody re-reads. CAQA Risk turns them into working boundaries — tolerance levels per category that the register applies to every rating automatically.

When an assessment lands outside appetite, the breach is flagged at the moment of rating — feeding escalation paths and review agendas without anyone having to notice manually.

  • Record board-approved appetite statements per risk category
  • Apply tolerance boundaries automatically to every rating
  • Flag out-of-appetite assessments the moment they are made
  • Feed appetite breaches into escalations and review agendas
Back to top ↑

Heat maps

The fastest way to understand a risk profile is to look at it. CAQA Risk renders live heat maps — likelihood by consequence — for any slice of the register: a category, a business unit, a project or the whole organisation.

Because the maps draw from the governed register rather than a quarterly export, what the board sees is what the register holds — today, not last quarter.

  • Render live likelihood-by-consequence maps from the register
  • Slice by category, unit, project or whole of organisation
  • Overlay appetite boundaries directly onto the map
  • Compare snapshots to see how the profile is moving
Back to top ↑

Key risk indicators

Between reviews, risk moves. Key risk indicators give each significant risk a measurable early-warning signal — a metric, a threshold and a direction — so drift is visible long before it becomes an incident.

Indicators sit on the risks they watch: when one crosses its threshold, the linked risk is flagged for re-assessment and the right owner is notified.

  • Attach measurable indicators to the risks they watch
  • Set thresholds and tolerance directions per indicator
  • Flag linked risks automatically when a threshold is crossed
  • Trend indicator history alongside the risk’s rating
Back to top ↑

Reviews

A register is only as good as its last honest look. CAQA Risk schedules reviews per risk — monthly, quarterly, annually or to any cadence the rating demands — and chases the owners until each review is done.

Every review is evidenced: who looked, what changed, what was re-rated and why. Auditors and regulators get a trail instead of a shrug.

  • Schedule review cadences per risk, control and treatment
  • Notify owners and chase overdue reviews automatically
  • Record what changed at each review, and why
  • Hand auditors an evidenced re-assessment trail
Back to top ↑

Escalations

When a rating breaches appetite or a treatment stalls, someone senior needs to know — reliably, not eventually. CAQA Risk routes escalations automatically: to the risk owner first, then up through committees and executives on defined paths.

Every escalation is logged with its trigger, its recipients and its resolution, so governance can demonstrate not just that problems were found, but that they were acted on.

  • Define escalation paths per category, unit and severity
  • Trigger automatically on appetite breaches and stalled work
  • Notify owners, committees and executives in order
  • Log every escalation from trigger to resolution
Back to top ↑
GRC Family

Part of the GRC family — CAQA Risk works alongside CAQA GRC, the umbrella governance platform.

Newsletter Subscription

To Receive Updates And Offers