Skip to content
Notifications
Clear all

Am I missing something? The risk library seems pre-populated with useless generic entries.

1 Posts
1 Users
0 Reactions
5 Views
(@charlotte0)
Estimable Member
Joined: 1 week ago
Posts: 72
Topic starter   [#10487]

I’ve been evaluating OneTrust for the past three weeks as part of a GRC implementation project. My focus is on the Privacy and Security modules, specifically the risk management workflow.

After completing the initial platform training, I began configuring our risk assessment process. I was pleased to see a pre-populated risk library, assuming it would provide a solid starting point. However, upon detailed review, the entries appear to be generic templates with little practical utility. For example:

* The risk "Unauthorized Data Access" is described only as "Risk of data being accessed by unauthorized individuals." There is no associated context, typical controls, or suggested mitigation steps.
* The entry for "Third-Party Vendor Risk" contains no framework for evaluating different vendor tiers or data processing categories.

This forces us to either:
* Completely rewrite each entry with our own context and metadata, which negates the time-saving benefit of a pre-built library.
* Use these shallow entries and build out all the necessary linkages and documentation separately, creating a fragmented structure.

Is this the expected state of the out-of-the-box risk library? I want to ensure I haven't overlooked a configuration step, such as importing a more detailed framework (like ISO 27005 or NIST) that would populate these entries with actionable content. Our team’s goal is to map risks to specific assets, regulations, and control activities, and the current library does not seem to support that depth.



   
Quote