✅ Feature availability: While the Risks page is included on all plans, Advanced Risk Management features are only available as an upgrade or add-on. Refer to Vanta Plans and Pricing for details.
The Action Tracker is where you manage the work tied to your approved risk assessments in Risk Management. It brings together the tasks and controls linked to your risk scenarios so you can deliver on treatment plans in one centralized place.
⚙️ User permissions: Admins and Editors can edit all risk tasks. Managers of a risk register can edit all tasks within the register. Collaborators can view and update tasks they are assigned to, as well as tasks tied to risks they own. Refer to Understanding User Roles and Permissions in Vanta for details.
Getting started
As part of a risk assessment, you define a treatment plan and identify the work needed to address the risk. Once the assessment is approved, that work can be assigned and completed over time.
We recommend the following workflow:
Define the treatment plan and related tasks during the risk assessment.
Approve the assessment to align on the treatment plan.
Track and complete the work in the Action Tracker.
💡 Tip: You can manage tasks directly in Vanta or connect a task tracker integration to work in the tools your team already uses. Use native Vanta tasks when you want to manage remediation entirely in Vanta. Use external tasks when the work is already being tracked in an external tool and you want your risk scenario to reference it.
Adding risk tasks in Vanta
Tasks carry out the work defined in your risk treatment plans and must be linked to a risk scenario. They're typically defined during a risk assessment and then tracked and completed over time in the Action Tracker.
You can add tasks in two places:
In a risk scenario as part of the treatment plan
In the Action Tracker where you manage all risk tasks
⚠️ Note: Define risk tasks before submitting risks for approval. If a risk is Pending approval, you can’t add new tasks. If a risk is Approved, adding a task moves it to Needs review.
Using task tracker integrations
If your team manages work outside of Vanta, tasks can be linked to supported task tracker integrations.
With Jira, you can link an existing issue to a risk task. With all other integrations, tasks must be created in Vanta first and are then synced to the external tool.
Integration | Description |
Create and sync native tasks, or link an existing Jira issue to a risk task in Risk Management. Linked tasks are read-only in Vanta and must be completed in Jira. | |
Tasks are created in Vanta and synced to the external tool. Synced tasks are read-only in Vanta and must be completed in the external system. |
External tasks can only be associated with one risk scenario. Task updates sync periodically and may not appear in Vanta immediately.
Managing risk tasks
The Action Tracker brings together the tasks and controls from across your risk scenarios in one place so you can track progress and follow up on open work. Use the filters above the table to find and prioritize work across your risks.
Tab | Description |
Tasks | View and manage all risk treatment tasks. Assign owners, set due dates, and mark work as complete. |
Controls | View controls linked to risk scenarios. Track control status, ownership, and framework mappings alongside the risks they support. |

