06.02 Running a Self-Assessment
Assess your program against a Secure Controls Framework, answer each control Yes/No/N/A, and let the failing controls become tracked pending risks you can push into the register — a Core feature, once your instance is registered and the SCF Extra is installed.
Core feature — no Extra to buy. This page is where you answer an assessment yourself, inside SimpleRisk, and let the controls you fail become tracked risks. Building your own question sets and emailing them out to vendors or colleagues to collect responses is a separate feature (the Assessments Extra), and that questionnaire workflow is covered in Third-Party and Vendor Risk Assessments. The two get confused because they share the Assessments menu, but the self-assessment you run here is Core.
Why this matters
A self-assessment is you holding your own program up against a recognized control set and writing down, honestly, where it falls short. There's no recipient to chase and no email to send. You pick a framework, answer its control questions the way they're actually true today, and mark the run complete. The payoff isn't the score. It's that every control you answer No turns into a candidate risk sitting in a queue, ready to push into your register instead of living in your head.
The version of this feature you may remember shipped four fixed questionnaires: Critical Security Controls, NIST 800-171, PCI DSS, and HIPAA. Those are gone. Self-Assessments is now driven by the Secure Controls Framework (SCF), the free control catalog SimpleRisk publishes as an Extra. Instead of four hard-coded sets, you assess against any authoritative source the SCF maps (hundreds of frameworks), and each failing control carries its own risk mapping and weighting, so the risks that come out the other side are pre-scored and pre-linked to the controls that produced them.
Before you start
- The Assessments menu permission. The gate is Allow Access to "Assessments" Menu. Without it the Assessments entry never appears in the sidebar.
- Two prerequisites, or you get a setup panel instead of the app. Self-Assessments only runs once your instance is registered and the Secure Controls Framework Extra is installed. If either is missing, the page shows a two-step guidance panel with a Go to Registration and/or Go to Secure Controls Framework button. Register first (registration is what lets you download the free SCF), then install the SCF; the install runs in the background and takes a few minutes.
- The risk-submission permission, to push gaps into the register. Promoting a pending risk into a real risk needs Able to Submit New Risks. You can run an assessment and review its pending risks without it; you just can't finalize them.
- The modify-controls permission, if you want the answers to update control statuses. With Able to Modify Existing Controls, completing a run writes each answer back to the native control (Yes marks it Pass, No marks it Fail). Without it, the run still completes and still generates risks — the control statuses are simply left alone.
Step-by-step
1. Open Self-Assessments
In the sidebar, expand Assessments and click Self-Assessments. The page opens on three tabs (Self-Assessments, Pending Risks, and Failed controls), with the breadcrumb in the grey title strip at the top. The first tab lists your runs: their framework, date, status (In Progress or Completed), how many controls you've answered, and who started them.

2. Start a new run and pick a framework
Click + New Self-Assessment at the top-right. The framework picker opens, listing every SCF framework you can assess against, each with its question count. Search by name to narrow the list, then click Start on the one you want. If you hold the Governance permission, a toggle lets you switch between Enabled frameworks (a short curated list an admin has turned on under Governance) and All SCF frameworks, the full catalog. Everyone else sees the full catalog directly.

3. Answer the questions, domain by domain
The questionnaire is grouped by SCF domain, with a chip for each domain across the top and one domain's controls shown at a time. Every control states its question ("Does the organization…?") and you answer with one of three buttons: Yes, No, or N/A. Internally Yes is a pass and No is a fail; the risk generation keys on the fails. Use Save Progress to persist without finishing, Back and Next to move between domains, and the domain chips to jump around. An answered counter at the top — "0 / 51 answered" — tracks how far you've come.
Answer honestly rather than aspirationally. A self-assessment whose answers describe the program you wish you had produces risks that don't exist and hides the ones that do.

4. Mark the run complete
On the last domain the Next button turns into a green Mark Complete (there's also a Mark Complete at the top throughout). Confirm, and SimpleRisk does two things. For every control you answered No that the SCF maps to a risk, it generates a pending risk — its subject is the mapped SCF risk-catalog entry's name, and its score is the highest failing control's weighting doubled, so a 1–5 weighting lands as a 2–10 score. And if you hold Able to Modify Existing Controls, it writes each answer back to the native control status. The run then shows as Completed on the first tab.
5. Review and push the pending risks
Switch to the Pending Risks tab. Each row shows the risk Subject with the SCF risk-catalog description beneath it, a Score rendered as a colored severity chip like "10 · High" (the level name and color come from your Risk Levels under Risk Configuration), and the failed control number that drove it. A search box and a Filter by control multi-select help you work a long queue. Per-row Push to Risk and Delete icon buttons sit at the end; tick the checkboxes and a bulk bar offers the same two actions across your selection.
Push to Risk promotes the candidate into the live register and pre-populates it: the Risk Assessment field from the SCF risk-catalog description, Additional Notes with a provenance block (the assessment name, framework, completed date, and the failed controls with their questions), the Risk Mapping set to the SCF risk-catalog entry, and a Mitigation Planned mitigation that links the failed controls as its mitigation controls. Pushing needs Able to Submit New Risks; without it, the rows are read-only.

6. Check the Failed controls tab
The Failed controls tab is a paginated record of every answered control across your completed runs — columns for Date, Framework, Control ID, Control, Question, Answer, and Control Status. A status filter (Fail, Pass, N/A, or All) and a search box let you audit exactly what was answered and when. Back on the first tab, a completed run's View (eye) icon opens a read-only, domain-by-domain view of the answers, while an in-progress run shows a Resume (pencil) icon that reopens the editable questionnaire.
Common pitfalls
-
Confusing answering an assessment with sending one. This is the single most common mix-up, and it's why this article exists. Self-Assessments is for answering an assessment yourself, in-app. Building question sets and emailing tokenized questionnaires out to vendors or colleagues is the Assessments Extra — a different feature on the same menu. If you're collecting answers from other people, you want Third-Party and Vendor Risk Assessments, not this page.
-
Landing on the setup panel. If you see a two-step guidance card instead of the app, the prerequisites aren't met. Register the instance, then install the Secure Controls Framework Extra. The SCF install runs in the background, so give it a few minutes before you refresh.
-
Leaving pending risks in the queue. A completed run that surfaces gaps hasn't touched your register yet. The candidates sit on the Pending Risks tab until someone with Able to Submit New Risks clicks Push to Risk. Skip that and the gap you just found never becomes a tracked risk.
-
Reading a clean result as good news. Only a No answer that maps to an SCF risk generates anything. A run that produces no pending risks might mean solid controls — or it might mean the controls you failed have no SCF risk mapping, or you answered around every gap. Zero pending risks is not automatically a passing grade.
-
Treating the generated score as final. The score is derived from the failing control's weighting; it's a starting point, not your methodology's verdict. Score the resulting risk properly (Risk Scoring Methodologies) before you rely on it. Likewise, the control-status writeback only happens if you hold Able to Modify Existing Controls — without it, your compliance view won't reflect the answers you just gave.