Risks & Issues
Welcome to the Risks & Issues user guide. This feature is a robust risk management tool designed to enhance team collaboration and streamline risk governance. Risks can be easily converted to issues (and vice versa), consolidating risk management and issue resolution into a single interface. It also allows teams to score impact and likelihood which automatically calculates the overall severity, further enhancing their risk and issue handling capabilities.
The risk and issue management solution integrated into Governance provides a central hub, making it simple for teams to control potential and current threats and vulnerabilities. Individual risks and issues can have their own associated tasks and be grouped together to form larger projects.
The risks and issues feature integrates seamlessly with the Governance Dashboard, through its dedicated Risk and Issue tabs, which helps teams generate insights and make informed decisions based on real-time data.
Access to Risks & Issues is included as part of the Governance licence. For further information contact [email protected].
Accessing risks and issues
Upon purchasing Governance and its associated features, all users have default access to the Risks & Issues feature. Your organisation's administrator(s) have the option to remove access via User Management, available to administrators in the header.
Only people assigned to a risk or issue can see it: its owner, members, notified users and attachment reviewers, along with anyone who has access to a project or project group it belongs to. Members and notified users can view and edit a record, but only the owner can delete it.
User Permission

Granting individual users access, does not automatically provide access to all moduleName within your organisation, but it allows users to create a new one. You can only view items to which you are assigned or have permissions.
A moduleName permissions include:
- Owner
- Member
- Notified user
- Attachment reviewer
There can only be a single owner but there are no limits to the number of members or notified users. Each attachment can also have one reviewer. Owners can edit and delete their assigned items, while all other roles have edit rights but cannot delete. When more than two members or notified users are added, the additional user details are combined into a single pill, which can be clicked to view further details. These pills are alphabetically ordered.
Info:
- A user cannot be assigned both the roles of owner and member but there are no restrictions on the notified users field.
- Owner fields are mandatory throughout the 9ine Platform.
- If a user's account has been disabled and they held the role of owner, you will be prompted to reassign upon next edit and prior to clicking Save.
Warning:
- A risk or issue owner, members, notified users, and attachment reviewers are automatically granted access to associated tasks.
- If a user is assigned the role of risk or issue owner and their account is deleted via User Management by your account administrator(s), the administrator will be prompted to reassign any risks and issues that are marked as Open and not marked as Closed.
Adding and removing notified users
Mention User (@)
To add a notified user, use the mention function in either the description field on the Details tab or the notes field on the Notes tab.
- To begin, click the @ symbol on your keyboard and type the first name of the user you wish to mention.
- A user can be mentioned at the start, in the middle, or at the end of the entered text.
- To remove a user as a notified user, simply delete their name from the relevant note.
- Mentioning a user sends an in-Platform notification and an email unless the user has disabled email notifications.
- The email notification sends a complete copy of the text entered by the user in the 9ine Platform, to the user’s registered email address.
Step 1:

Step 2:

Understanding how to create and edit risks and issues
Begin by clicking New and selecting the Type between risk and issue in the top right corner, to get started. You will then be presented with eight tabs, including:
- Details
- Checklist
- Controls
- KPIs
- Root Cause
- Notes
- Attachments
- Custom Data

The first tab allows you to capture and view key details associated with the risk or issue, including the title, number, description, project group, project, owner, members, notified users, category and sub-category, control and impact which calculates score, next review date, and status.
Tip:
This tab has six mandatory fields: title, owner, category, impact, likelihood and status. Prior to selecting Save you must enter the details in the six mandatory fields and also select type (risk or issue).
Number field
The Number field helps order items sequentially in the log. You can enter up to five-digit numbers, including decimals. The sequence number is visible to all users within the organisation and is not user-specific.
Warning:
Text values are not permitted in this field.
Description Field
The Description field offers additional formatting functionality. The formatting applied in the rich text editor is retained and displayed on the moduleName log when clicking the Description icon.


If a description has not been added, the field appears as grey and disabled on the moduleName log.
Selecting a project group and project for a risk or issue is optional; they can be designated as standalone items. If a project group and project are selected, their names will be displayed on the log. If these fields are left empty and the risk or issue remains standalone, the log will display a -. Users will only have visibility of risks or issues to which they have access, whether as an owner, member, notified user, or attachment reviewer.
Tip:
It is possible to move a risk or issue to a different project group or project by clicking on Edit and selecting your preferred project group and project titles.
The 9ine Platform offers a range of predefined risk and issue categories. If these predefined categories do not meet your organisation's specific needs, you can add custom categories using the +Other field. Any custom category created by a user in your organisation will be available for selection when creating or editing a risk or issue. Upon selecting a category, an additional button labelled Select Sub Categories will appear in the popup, allowing you to choose an unlimited number of subcategories for the selected category.

Risks and issues can be allocated one of four controls, including:
- Tolerating
- Treating
- Transferring
- Terminating

Risks and issues can be assigned impact and likelihood scores, which are automatically multiplied together to calculate the overall risk score.
![]()
![]()
The overall score is displayed on the log. The following rating system is used to calculate the score:
The score is impact multiplied by likelihood, banded as Critical (25 to 20), High (16 to 10), Medium (9 to 5), Low (4 and 3), and Very Low (2 and 1).

A risk and issue has two status options, including: open and closed. When marking a risk or issue status as Closed, it is no longer shown in the default (open) log.
Utilising the checklist, controls, KPIs, root cause and custom data tabs
Checklist Tab

To add an item in the respective tab, enter text in the field and click Add.
- The checklist tab accepts alphanumeric values and has no text limit.
- Duplicate entries are not permitted.
- When you enter more than one entry, you have the option to reorder them by dragging and dropping the items into your preferred sequence.
- Individual items can be marked as closed, with the option to undo this action at any time by unchecking the item.
- To mark an individual item as closed, you can either click the checkbox or the text. When an item is marked as closed, the text will be struck through. To uncheck an item, repeat this process.
You also have the option to edit and delete individual items.
Utilising the notes tab
Notes Tab
The Notes tab allows you to maintain a single repository of information. You can add multiple notes at once using the Add Another function, but these notes are not saved until you click the primary Save button at the bottom of the popup.

When adding a new note, a record of the user's details, date, and time of entry are added, and the most recent notes will automatically appear at the top of the list. If an individual note is edited, the time and date of the note are updated, and the note reordered.

Additional formatting functionality is provided on the notes tab. If entering large volumes of data, click the Full Screen option.

Warning:
- For security purposes, the 9ine Platform will log users out of their active sessions after 45 minutes of inactivity, with a reminder triggered at 30 minutes of inactivity.
- If you are in full screen mode, the reminder may not appear unless you have browser-based notifications enabled.
- Typing in the field is not considered activity; activity is only registered when clicking Cancel or Save.
Uploading and managing attachments
Attachments
The Attachments tab allows you to upload files or images using your native file explorer.
- Maximum file size: 10MB
- A maximum of five files can be uploaded at a time
- Supported file types: jpg, jpeg, tif, tiff, png, odg, otg, txt, rtf, doc, docx, pages, odt, ott, odm, pdf, xml, xmlx, numbers, ods, ots, ppt, pptx, key, keynote, odp, otp, xls, xlsx, tsv, csv, pst, eml, emlx, ost, oft, msg
- The file name cannot contain special characters: /?<>|"\ #+&'~

Each attachment uploaded can be assigned a reviewer, allocated a review date, and further information can be included. This process ensures that attachments added remain current and do not become obsolete. When an attachment is added and a reviewer is assigned, the reviewer is automatically granted access to the moduleName, enabling them to review the attachment.

Understanding how to use the risk and issue log
When creating a new risk or issue, or editing an existing one, the details entered are added to the log. Each risk or issue is automatically assigned a unique reference number (starting with RIS or ISS) that cannot be edited. The column Type helps quickly identify if an item in the log is a risk or issue.
To view only the items you are responsible for, use the My Risks & Issues toggle located in the top right corner of the log. This will filter and display items where you are the owner, member or notified user.
Sorting, View and Filter for log
Default sorting is applied to the No. column, which can be altered by clicking on the title of any other column. Clicking a column header once sorts the log by the selected column, and clicking it a second time reverses the order.
To remove individual columns, click View and deselect the columns you do not want to display, whilst retaining a minimum of one column. After selecting your preferred columns, click Apply. You also have the option to Save View.

You can also change the sequence order of the columns by dragging and dropping them into your preferred order. Any changes are automatically saved and retained on the next login.

Info:
- The changes applied to the sequence order of the log and in the View popup are user and log specific and only applied to your profile.
- The sequence order in the View popup does not update to reflect the order created through dragging and dropping.
- The log opens using your most recently saved filter and column view. If you have not saved any preferences, the organisation default view is applied, this is why the log can appear differently per user account.
To focus on specific items, you can use the Filter or Search functions. When a filter is active, an orange icon appears next to the filter icon for easy recognition.
- To quickly clear any filters, click the Clear Filters button in the popup.
- You can also apply a temporary filter without clicking Save Filter.
- To revert back to your saved filter, click Reset.
- Similarly, you can select data points and click Apply without saving your filter options.

To access the tasks associated with a risk or issue, click the count under the Task column, and then select View All or the specific filtered count. For instance, clicking 6 will direct you to the Tasks log, displaying a filtered view of the 6 tasks associated with the risk you selected.

When a risk or issue is associated with a form:
- Incident Management
- Records of Processing Activity
- Processing Operation Assessment
- Data Protection Impact Assessment (DPIA)
- Retention Management
- Contract Management
This field is populated with the title and reference number of the associated item. Associations must be created from the forms and cannot be created through the risk and issue log.
Bulk Operation in Governance
To bulk manage moduleName, select one or more checkboxes located on the far left side of the log. Once selected, a Manage button will appear above the log. Clicking this button offers four options: manage, duplicate, close, and delete. Choosing manage allows you to bulk modify the moduleName related data like owner, members, project group details, project details, due date or next review date, status of the records.

Users have the option to select individual record or select all records on any page by checking the box in the column header. For the selection of records, provide options as:
- Current Page: selects all records on the page you are viewing.
- All Pages: selects all records that match the current filters across all pages, excluding Closed records.
-
Clear Selection: removes all current selections
Understanding the quick actions for a risk or issue
The risk and issue log offers a suite of quick-access functions through its menu options, including:
-
Create Task
This allows you to directly create a task associated with the risk or issue. -
Add a Note
Opens the risk or issue popup directly on the Notes tab. -
Add Checklist Item
Opens the risk or issue popup directly on the Checklist tab. -
Add Control Item
Opens the risk or issue popup directly on the Controls tab. -
Add KPI Item
Opens the risk or issue popup directly on the KPIs tab. -
Add Root Cause Item
Opens the risk or issue directly on the Root Cause tab. -
Add Attachment(s)
Opens the risk or issue popup directly on the Attachments tab. -
Add Custom Data
Opens the risk or issue popup directly on the Custom Data tab. -
Add Member(s)
Opens a members popup to quickly grant users access to the risk or issue. -
Convert
Automatically converts the risk to an issue and vice versa. -
Duplicate
Duplicates the risk or issue along with all associated tasks with the prefix Copy of. The duplicated items do not include notes, attachments, logged time, or logged costs. -
Close
Marks the risk or issue and all its associated tasks as closed, so they are no longer shown in their default logs. -
Reopen
Marks a closed risk or issue as Open and restores it to its respective log. Any associated tasks are also restored and returned to Not Started status. -
Delete
Marks the risk or issue and all its associated tasks as deleted, effectively removing them from the Platform.

Info:
When closing or deleting a risk or issue, it is not possible to retain child tasks unless they are moved to a different risk or issue.
Downloading risks and issues
Download Governance Log Items
To download the data shown on the respective log, click the Download button located in the top right-hand corner. You can customise the download report to include or exclude data by using the search bar, filter, view options, or My moduleName functions. Upon clicking the Download button, an export will be saved to your local file explorer. The format of the exported moduleName is XLS.
Uploading risks and issues
Upload Governance Items
To upload data to the respective log, click the Upload button in the top right corner. Users can upload records in bulk using an optional template, which streamlines the data formatting and entry process. To access the template, click on Download Template. Each row in the uploaded file is treated as a separate record.
Once the file is uploaded, users will receive notifications via email and in-platform alerts, detailing the number of successfully uploaded items as well as any failed uploads, if applicable.
Configuring risks and issues notification settings
Global Due Date Notifications Alerts
To ensure you're always informed of key moduleName milestones, users can configure their personal notification preferences within the Notification Settings area of the 9ine Platform. This enables both email and in-Platform alerts for important events in the moduleName lifecycle such as end dates, due dates, renewal reminders, termination deadlines, and next review dates.
To activate alerts:
- Navigate to your Notifications (available in the header)
- Click the Notification Settings icon
Toggle Global Lifecycle Alerts on for both In Platform and Email to receive notifications through both channels.

Under Reminder, you can select how far in advance you would like to be notified of an upcoming milestone (e.g. 7, 14, or 30 days before the due date). This ensures you receive early warnings before deadlines approach. You can choose any period from 1 to 31 days in advance.
These reminders are designed to give moduleName owners and stakeholders enough lead time to review, act, or make decisions before renewal or termination windows close.

To receive multiple reminders, you can enable Repeat notifications.
- Repeats are available in weekly intervals and are only triggered if your chosen reminder period is 7 days or more.
- The number of notifications is based on your reminder window:

For example:
- If your reminder is set to 10 days, you’ll receive 1 notification.
- If it’s set to 16 days, you’ll receive 2 notifications.
This flexible notification system helps ensure key events never go unnoticed, especially in busy school environments where planning ahead is essential.