Help & documentation
How ARC Risk scores, tracks and reports risk, and how to keep the register connected to ARC Terminal.
Frequently asked questions
What does I × L × V mean?▾
Each risk is scored on three 1–5 scales: Impact, Likelihood and Vulnerability. Multiplying them gives a severity between 1 and 125. The band is then Low (≤15), Medium (16–40), High (41–80) or Critical (>80).
What is the difference between inherent and residual risk?▾
Inherent is the raw score before any controls or treatments. Residual is the score left after treatments, controls and exceptions are applied. ARC Risk tracks both so you can show reduction over time.
Who can change appetite or tolerance?▾
Workspace administrators can edit appetite and tolerance thresholds on the Appetite page. Everyone else can view the live comparison against register scores.
How do risks get sent to ARC Terminal?▾
On the ARC Terminal page, set Mode to Linked, enter your Terminal base URL and API key, and press Test connection. Once linked, flag a risk or set the sync threshold and scores flow back to Terminal as tickets.
Can I score a vendor before they enter the register?▾
Yes. Use the public vendor intake form linked from the Vendor register to record name, service, contacts and an I × L × V score. Vendors scoring above the threshold are automatically raised as register risks.
Where are reports exported?▾
Reports and mandated assessments can be printed or saved as PDF from the browser. Most assessment and executive pages include a print button that removes navigation and uses a compact layout.
Getting started
- Invite members in Settings and assign roles. The first user in an empty workspace becomes the administrator automatically.
- Set appetite per category on the Appetite page so the register can warn when residual scores exceed board tolerance.
- Raise risks from the Risk register or directly from ARC Terminal. Record inherent and residual I/L/V scores, owner and review date.
- Add treatment plans with owner, deadline and progress. Completing a plan records the outcome and updates the risk history.
- Track actions and indicators from the Risk lifecycle page so risks move from raised to closed with evidence.
- Connect Terminal on the ARC Terminal page to keep controls, assets and vendors in sync.
Scoring & bands
Severity = Impact × Likelihood × Vulnerability. Each factor is rated 1 (minimal) to 5 (severe). The resulting band drives colour, escalation and appetite checks.
| Band | Score range | Typical response |
|---|---|---|
| Low | 1 – 15 | Accept and monitor |
| Medium | 16 – 40 | Plan treatment within review cycle |
| High | 41 – 80 | Treat actively, escalate to owner |
| Critical | 81 – 125 | Immediate action and board visibility |
Terminal sync
ARC Risk can pull controls, assets and vendors from ARC Terminal and push back residual scores, treatments and corrective actions.
- Inbound pull — on demand from the Terminal page; requires a Terminal API key with read access.
- Flag to Terminal — raises a register risk as a Terminal ticket when severity crosses the threshold.
- Write-back — pushes residual I/L/V scores, treatment status and corrective actions to Terminal so both systems stay current.
All sync events are logged in the Terminal write-back log for audit. If the connection test fails, check the base URL and API key before retrying.
Support
For questions about your workspace, authentication or data, contact the workspace administrator. For product or integration issues, include the page code (top-left of each screen) and the UTC timestamp shown in the header.