Register and governance# Risk register and governance ## Purpose and users The **Risks** menu transforms the context into evaluated scenarios. Risk manager creates and modifies; readers, listeners and managers consult according to their rights. ## Create a scenario Enter title, description, family, method (simplified, ISO 27005 or EBIOS RM), scope, asset, threat, vulnerabilities, existing measures, responsible, processing, status and revision date. All relationships must belong to the tenant. ## Understanding scores Each rating uses likelihood and impact from 1 to 5. Their product gives the score. The **raw** precedes the controls, the **current** reflects the observed situation and the **residual** the target after treatment. ## Governance The policies define appetite, tolerance and capacity by domain/family. The portfolio consolidates risks; recommendations compare cost, burden and reduction. Formal acceptance requires decision, authorship and expiration. A campaign freezes a review snapshot. The