Hi there, we’ve defined our business risks with a mapping to the related compliance ID, risk acceptance and trelated business unit and application(s).
However, we did not manage to map an (external) audit finding tot the risk, so the risk owner can see from the risk module there is a finding in eg. either the policy or the control
regards,
Martin