openapi: 3.2.0 info: title: Tech Risk & Compliance - IT Risk Management Risk Templates… description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities. version: '1.0' contact: name: OneTrust Support url: https://my.onetrust.com/s/contactsupport license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{hostname} variables: hostname: default: hostname description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com. tags: - name: Risk Templates description: APIs to manage risk template retrieval operations, enabling users to access detailed risk template information including inherent and target risk levels, associated threats and vulnerabilities, control mappings, risk categories, and custom attribute values for comprehensive risk assessment and management. externalDocs: description: OpenAPI 3.1.0 - Download Definition url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json x-displayName: Risk Templates paths: /api/risk-template/v1/templates/{riskTemplateId}: get: operationId: getRiskTemplateUsingGET summary: Get Risk Template description: 'Use this API to retrieve the details for the specified risk template. > 🗒 Things to Know > > - The `templateId` can be obtained from the OneTrust application URL when accessing the Template Details screen for a risk template.' tags: - Risk Templates x-onetrust: spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json parameters: - name: riskTemplateId in: path description: The unique identifier used to retrieve a specific risk template. required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 responses: '200': description: OK content: application/json: schema: type: array items: $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskTemplateInformation' '400': description: Bad Request '401': description: Unauthorized '403': description: Forbidden '429': description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)." headers: Retry-After: schema: description: The number of seconds after which requests will be allowed again. format: int32 ot-period: schema: description: The unit of time for which the rate limit applies enum: - HOUR - MINUTE ot-ratelimit-event-id: schema: description: The unique identifier for the rate-limiting event. format: uuid ot-request-made: schema: description: The number of requests made within the specified period. format: int32 ot-requests-allowed: schema: description: The number of requests allowed within the specified period. format: int32 '500': description: Internal Server Error security: - TechRiskCompliance-RiskTemplate_OAUTH2: - INTEGRATION - RISK - RISK_READ components: schemas: TechRiskCompliance-RiskTemplate_RiskLevelDetails: type: object properties: levelId: description: The numeric identifier for target standard risk scoring. type: integer format: int64 example: 1 level: description: The target risk level name for standard scoring methodology. type: string example: Low impactLevelId: description: The numeric identifier for target impact in matrix scoring. type: integer format: int64 example: 1 impactLevel: description: The target impact level name for matrix methodology. type: string example: Low probabilityLevelId: description: The numeric identifier for target probability in matrix scoring. type: integer format: int64 example: 1 probabilityLevel: description: The target probability level name for matrix methodology. type: string example: Low riskScore: description: The target numeric risk score value after mitigation. type: number example: 2 TechRiskCompliance-RiskTemplate_RiskCategoryInformation: type: object properties: id: description: The unique identifier of the risk category. type: string format: uuid example: d7e5c1a2-42a0-4cd7-83b1-d0a2ff064cb7 name: description: The display name of the risk category. type: string example: Category Name nameKey: description: The translation key used for localizing the category name. type: string example: RiskCategory.Availability TechRiskCompliance-RiskTemplate_ThreatInformation: type: object properties: id: description: The unique identifier of the threat entity. type: string format: uuid example: f3e9e8b4-1c5e-4f3e-9c58-92d8d6d2ea7a name: description: The display name of the threat. type: string example: Threat Name identifier: description: The reference identifier of the threat. type: string example: '456' TechRiskCompliance-RiskTemplate_RiskTemplateInformation: type: object properties: id: description: The unique identifier of the risk template. type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000 name: description: The display name of the risk template. type: string example: Operational Risk Template riskName: description: The name of the risk associated with this template. type: string example: Operational Risk description: description: The detailed description of the risk template. type: string example: A structured template to identify, assess, and manage risks state: description: The current status indicating if the template is active or archived. type: string example: ACTIVE enum: - ACTIVE - ARCHIVED orgGroup: description: The organization group that owns this risk template. $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_BasicEntityDetail' treatmentPlan: description: The treatment plan text describing risk mitigation strategies. type: string example: Operational Risk treatment plan inherentRiskLevel: description: The inherent risk level assessment before controls are applied. $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskLevelDetails' targetRiskLevel: description: The target risk level assessment after implementing controls. $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskLevelDetails' threat: description: The threat information associated with this risk template. $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_ThreatInformation' vulnerabilities: description: The list of vulnerabilities associated with this risk template. type: array items: $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_VulnerabilityInformation' categories: description: The list of risk categories assigned to this template. type: array items: $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskCategoryInformation' controls: description: The list of controls associated with this risk template. type: array items: $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_ControlInformation' createdDate: description: The timestamp when the risk template was created. type: string format: date-time example: '2025-07-15T09:27:53.123Z' attributeValues: description: The custom attributes and their values specific to this risk template. type: object additionalProperties: type: array items: $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_AttributeValueInformation' TechRiskCompliance-RiskTemplate_VulnerabilityInformation: type: object properties: id: description: The unique identifier of the vulnerability entity. type: string format: uuid example: 6e4b2d9a-7fc7-4ef2-8129-3a4f84e7d314 name: description: The display name of the vulnerability. type: string example: Threat Name identifier: description: The reference identifier of the vulnerability. type: string example: '245' TechRiskCompliance-RiskTemplate_ControlInformation: type: object properties: id: description: The unique identifier of the control entity. type: string format: uuid example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q name: description: The display name of the control. type: string example: Control Name identifier: description: The reference identifier of the control. type: string example: '123' TechRiskCompliance-RiskTemplate_BasicEntityDetail: type: object properties: id: description: The unique identifier of the organization entity. type: string format: uuid example: 7009201b-3808-4eaa-8afa-97f50c6c3cf1 name: description: The display name of the organization entity. type: string example: Entity name TechRiskCompliance-RiskTemplate_AttributeValueInformation: type: object properties: id: description: Unique identifier for the attribute option type: string format: uuid example: a34ccec7-1ec0-4d65-9075-bdd0d923f1d1 value: description: Attribute value type: string example: Text Value valueKey: description: Translation key used for localizing the value type: string example: attribute.option.valueKey colorCode: description: Color code associated with the option. Used for score-based attributes. type: string example: red optionSelectionValue: description: Selection score value linked to the option. Used for score-based or numerical-based attributes. type: string example: '3.5' displayLabel: description: Display name for the option, used for external attributes managed by other systems type: string example: United State | San Francisco disabled: description: Indicates whether this attribute option is currently disabled. type: boolean example: false default: 'false' required: - value securitySchemes: TechRiskCompliance-ITRiskManagement_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: CONTROL: Access to Control Implementation operations for external systems ITRM: Access to ITRM operations for external systems TechRiskCompliance-RiskTemplate_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: INTEGRATION: Integration Scope RISK: Risk Scope RISK_READ: Risk read scope TechRiskCompliance-Risk_OAUTH2: type: oauth2 flows: clientCredentials: tokenUrl: https://{hostname}/api/access/v1/oauth/token scopes: RISK: Risk Scope RISK_READ: Risk read scope INTEGRATION: Integration scope x-readme: explorer-enabled: false proxy-enabled: false metrics-enabled: false x-onetrust: spec-label: OpenAPI 3.1.0