ISO Alignment

Risk Register by ProjectBalm helps organisations implement and maintain structured risk management processes in Jira. It provides a central location for identifying risks, assessing their likelihood and impact, evaluating risk levels, recording treatments, tracking residual risk, monitoring changes and reporting risk information.

These capabilities can support risk management processes aligned with ISO 31000, ISO/IEC 27001, ISO 14971 and IEC 62304.

Risk Register is a supporting tool. Its use does not, by itself, establish conformity with an ISO or IEC standard, guarantee certification or replace the policies, procedures, governance, professional judgement and evidence required by an organisation’s management system.

Standards covered

  • ISO 31000:2018

  • ISO/IEC 27001:2022

  • ISO 14971:2019

  • IEC 62304:2006 with Amendment 1:2015

ISO 31000:2018

ISO 31000 provides principles, a framework and guidelines for managing risk across organisations of any size or sector. It is intended to help organisations integrate risk management into governance, planning, decision-making and operational activities.

Risk Register supports the risk management process described in Clause 6 of ISO 31000:2018.

Risk identification — Clause 6.4.2

Risks can be recorded as Jira work items with relevant contextual information, ownership, status and supporting details. This creates a consistent and traceable record of identified risks.

Risk analysis — Clause 6.4.3

Each risk can be assessed using defined probability and impact values. Organisations can configure risk models that reflect their own terminology, assessment scales and risk methodology.

Risk evaluation — Clause 6.4.4

Risk Register automatically determines the level of risk from the selected probability, impact and risk model. This helps teams compare assessed risks against their organisation’s risk criteria and identify risks requiring further action.

Risk treatment — Clause 6.5

Treatment activities can be represented by linked Jira work items. This allows organisations to assign actions, manage them through Jira workflows and maintain traceability between a risk and the work undertaken to address it.

Inherent and residual risk assessments can be recorded separately, helping teams evaluate the expected or actual effect of treatment.

Monitoring and review — Clause 6.6

Risk register, risk matrix and dashboard views provide different ways to monitor risk exposure. Risks can be sorted, filtered and grouped by risk level, probability, impact, status, owner and other relevant Jira fields.

Risk assessment history also helps organisations review how individual risks have changed over time.

Recording and reporting — Clause 6.7

Risk information is retained within Jira and can be presented through configurable registers, matrices and dashboard gadgets. Risk data can also be exported for further analysis or reporting.

ISO/IEC 27001:2022

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System, or ISMS. It requires organisations to assess information security risks, establish risk treatment processes and evaluate the effectiveness of the ISMS.

Risk Register can be configured to support an organisation’s ISO/IEC 27001 risk assessment and treatment methodology.

Information security risk assessment — Clauses 6.1.2 and 8.2

Information security risks can be recorded consistently within Jira and assessed using defined probability, impact and risk-level criteria.

Configurable risk models allow organisations to apply their own information security risk criteria. Risk registers may be based on a Jira project or saved filter, allowing organisations to create registers for particular systems, business units, security programmes or other areas within the scope of the ISMS.

Information security risk treatment — Clauses 6.1.3 and 8.3

Risk treatment activities can be recorded as linked Jira work items, assigned to responsible personnel and managed through appropriate workflows.

Inherent and residual risk assessments help organisations document risk exposure before and after treatment. Additional Jira fields may be used to record information such as treatment decisions, risk owners, target dates, control references and acceptance status.

Monitoring, measurement, analysis and evaluation — Clause 9.1

Risk registers, risk matrices and dashboards help organisations monitor information security risks and communicate their current status.

Filtering and grouping capabilities can be used to identify high-risk items, overdue treatments, risks assigned to particular owners or risks associated with specific systems and business areas.

Risk Register supports these activities as part of an ISMS, but the organisation remains responsible for defining its risk methodology, selecting controls, approving treatment decisions and maintaining the evidence required to demonstrate conformity with ISO/IEC 27001.

ISO 14971:2019

ISO 14971 specifies a risk management process for medical devices, including software as a medical device and in vitro diagnostic medical devices. The process covers the identification of hazards, estimation and evaluation of associated risks, implementation of risk controls and monitoring of control effectiveness throughout the product lifecycle.

Risk Register can support the recording, assessment, treatment and monitoring activities within an organisation’s medical-device risk management process.

Risk analysis — Clause 5

Hazards, foreseeable sequences of events, hazardous situations and associated harms can be recorded using Jira work items and configured fields.

Probability and impact fields can support risk estimation where those dimensions form part of the manufacturer’s documented risk management methodology. Jira fields may also be added to capture device-specific information required by the organisation.

Risk evaluation — Clause 6

Configurable risk models can be used to evaluate assessed risks against predefined risk criteria. The calculated risk level provides a consistent basis for prioritisation and further treatment.

The manufacturer remains responsible for establishing its criteria for risk acceptability and determining whether an assessed risk is acceptable.

Risk control — Clause 7

Risk control measures can be represented by linked Jira work items, providing traceability between a risk and the actions intended to reduce it.

Treatment items can be assigned, scheduled and progressed through Jira workflows. Residual probability, residual impact and residual risk can be recorded following the implementation of controls.

Evaluation of overall residual risk — Clause 8

Residual risk information can be viewed within risk registers and matrices, helping teams review the risk remaining after controls have been implemented.

The application supports the recording and presentation of this information; the required overall residual-risk evaluation and benefit-risk analysis remain decisions for the manufacturer.

Review and post-production monitoring — Clauses 9 and 10

Risk registers, matrices, dashboards and assessment history can support periodic review of the risk management file and the monitoring of risk information throughout the device lifecycle.

Post-production information, incidents, complaints or corrective actions can also be managed as Jira work items and associated with relevant risks where this forms part of the organisation’s configured process.

Risk Register does not replace the complete risk management file or the specialist clinical, engineering and regulatory analysis required by ISO 14971.

IEC 62304:2006 with Amendment 1:2015

IEC 62304 defines lifecycle processes, activities and tasks for the development and maintenance of medical-device software. Clause 4.2 requires the manufacturer to apply a risk management process consistent with ISO 14971.

Risk Register can support the software risk management activities described in Clause 7 of IEC 62304.

Analysis of software contributing to hazardous situations — Clause 7.1

Software items that could contribute to hazardous situations can be recorded as risks or associated Jira work items. Relevant causes, hazardous situations, possible harms and related software components can be captured using standard or configured Jira fields.

Risk control measures — Clause 7.2

Software risk control measures can be recorded as linked work items and traced back to the risks they address. Teams can assign implementation work, manage its status and associate supporting engineering activity with the relevant risk.

Verification of risk control measures — Clause 7.3

Verification activities and evidence can be managed through linked Jira work items. This allows organisations to trace a risk control measure to its implementation and to the work used to verify that the measure was correctly implemented.

Risk management of software changes — Clause 7.4

Jira workflows, linked work and change history can help teams assess and document risk implications arising from software changes.

Risk Register supports these activities as part of a broader software lifecycle and quality management system. It does not perform software safety classification, establish regulatory acceptability or replace the risk management process required by ISO 14971.

Summary

Across these standards, Risk Register helps organisations capture risk information, apply consistent assessment criteria, link treatment actions, record residual risk and monitor change over time within Jira.

Its value is in supporting a structured and traceable process. Conformity with any ISO or IEC standard still depends on the organisation’s documented management system, decision-making, governance, evidence and ongoing implementation.