Risk management software
The risk module records an information security risk from the threat, the vulnerability, and the asset, then keeps the response and the report.
What the assessment stores
The module description is specific: threats, vulnerabilities, assets, risk-level calculation, response measures, and reports, including scheduled reports. Assets come from the asset registry, with confidentiality, integrity, availability, owners, and administrators. This is the information-security risk record used by the ISMS, not a payment-transaction score.
Where the result is used
ISO 27001 treatment points at this module. A separate product, RiskBoard, scores payment operations from 0 to 100. That score is not this risk register. Vendor risk has its own TPRM module.