OneTrust Risk Templates API

APIs to manage risk template retrieval operations, enabling users to access detailed risk template information including inherent and target risk levels, associated threats and vulnerabilities, control mappings, risk categories, and custom attribute values for comprehensive risk assessment and management.

Operations 1

GET /api/risk-template/v1/templates/{riskTemplateId} Get Risk Template #

Documentation

📖
Documentation
https://developer.onetrust.com/onetrust/reference/attribute-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/activity-log
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/banner
📖
Documentation
https://developer.onetrust.com/onetrust/reference/consent-receipts
📖
Documentation
https://developer.onetrust.com/onetrust/reference/applications
📖
Documentation
https://developer.onetrust.com/onetrust/reference/categorizations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/domain-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/preferences
📖
Documentation
https://developer.onetrust.com/onetrust/reference/mobile-app-data
📖
Documentation
https://developer.onetrust.com/onetrust/reference/privacy-notice-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/collection-points
📖
Documentation
https://developer.onetrust.com/onetrust/reference/catalog-search-v1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/classification
📖
Documentation
https://developer.onetrust.com/onetrust/reference/custom-scan
📖
Documentation
https://developer.onetrust.com/onetrust/reference/carbon-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audit-records
📖
Documentation
https://developer.onetrust.com/onetrust/reference/bulk-export
📖
Documentation
https://developer.onetrust.com/onetrust/reference/attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/system-credentials
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-relationships-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/model-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/tasks
📖
Documentation
https://developer.onetrust.com/onetrust/reference/groups-v2
📖
Documentation
https://developer.onetrust.com/onetrust/reference/assessment-actions
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory
📖
Documentation
https://developer.onetrust.com/onetrust/reference/inventory-1
📖
Documentation
https://developer.onetrust.com/onetrust/reference/drop-management
📖
Documentation
https://developer.onetrust.com/onetrust/reference/incidents
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-controller
📖
Documentation
https://developer.onetrust.com/onetrust/reference/audits
📖
Documentation
https://developer.onetrust.com/onetrust/reference/initiatives
📖
Documentation
https://developer.onetrust.com/onetrust/reference/document-attachments
📖
Documentation
https://developer.onetrust.com/onetrust/reference/issues
📖
Documentation
https://developer.onetrust.com/onetrust/reference/control-implementations
📖
Documentation
https://developer.onetrust.com/onetrust/reference/training
📖
Documentation
https://developer.onetrust.com/onetrust/reference/contracts

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/onetrust-risk-templates-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

onetrust-risk-templates-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Tech Risk & Compliance - IT Risk Management Risk Templates…
  description: The IT Risk Management API provides comprehensive REST endpoints for managing enterprise security controls, threats, vulnerabilities, and their implementations with OAuth2 security and extensive customization capabilities.
  version: '1.0'
  contact:
    name: OneTrust Support
    url: https://my.onetrust.com/s/contactsupport
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: https://{hostname}
  variables:
    hostname:
      default: hostname
      description: The OneTrust hostname such as app.onetrust.com, app-eu.onetrust.com, app-de.onetrust.com, app-uk.onetrust.com, app-apac.onetrust.com, trial.onetrust.com, or uat.onetrust.com.
tags:
- name: Risk Templates
  description: APIs to manage risk template retrieval operations, enabling users to access detailed risk template information including inherent and target risk levels, associated threats and vulnerabilities, control mappings, risk categories, and custom attribute values for comprehensive risk assessment and management.
  externalDocs:
    description: OpenAPI 3.1.0 - Download Definition
    url: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json
  x-displayName: Risk Templates
paths:
  /api/risk-template/v1/templates/{riskTemplateId}:
    get:
      operationId: getRiskTemplateUsingGET
      summary: Get Risk Template
      description: 'Use this API to retrieve the details for the specified risk template.


        > 🗒 Things to Know

        >

        > - The `templateId` can be obtained from the OneTrust application URL when accessing the Template Details screen for a risk template.'
      tags:
      - Risk Templates
      x-onetrust:
        spec-label: https://developer.onetrust.com/onetrust/openapi/tech-risk-compliance-it-risk-management.json
      parameters:
      - name: riskTemplateId
        in: path
        description: The unique identifier used to retrieve a specific risk template.
        required: true
        schema:
          type: string
          format: uuid
        example: 123e4567-e89b-12d3-a456-426614174000
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskTemplateInformation'
        '400':
          description: Bad Request
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '429':
          description: "Too Many Requests. \nFor more information, see [API Rate Limits](https://developer.onetrust.com/onetrust/reference/rate-limits-overview)."
          headers:
            Retry-After:
              schema:
                description: The number of seconds after which requests will be allowed again.
                format: int32
            ot-period:
              schema:
                description: The unit of time for which the rate limit applies
                enum:
                - HOUR
                - MINUTE
            ot-ratelimit-event-id:
              schema:
                description: The unique identifier for the rate-limiting event.
                format: uuid
            ot-request-made:
              schema:
                description: The number of requests made within the specified period.
                format: int32
            ot-requests-allowed:
              schema:
                description: The number of requests allowed within the specified period.
                format: int32
        '500':
          description: Internal Server Error
      security:
      - TechRiskCompliance-RiskTemplate_OAUTH2:
        - INTEGRATION
        - RISK
        - RISK_READ
components:
  schemas:
    TechRiskCompliance-RiskTemplate_RiskLevelDetails:
      type: object
      properties:
        levelId:
          description: The numeric identifier for target standard risk scoring.
          type: integer
          format: int64
          example: 1
        level:
          description: The target risk level name for standard scoring methodology.
          type: string
          example: Low
        impactLevelId:
          description: The numeric identifier for target impact in matrix scoring.
          type: integer
          format: int64
          example: 1
        impactLevel:
          description: The target impact level name for matrix methodology.
          type: string
          example: Low
        probabilityLevelId:
          description: The numeric identifier for target probability in matrix scoring.
          type: integer
          format: int64
          example: 1
        probabilityLevel:
          description: The target probability level name for matrix methodology.
          type: string
          example: Low
        riskScore:
          description: The target numeric risk score value after mitigation.
          type: number
          example: 2
    TechRiskCompliance-RiskTemplate_ControlInformation:
      type: object
      properties:
        id:
          description: The unique identifier of the control entity.
          type: string
          format: uuid
          example: 1a2b3c4e-5f6g-7h8i-9j0k-1l2m3n4o5p6q
        name:
          description: The display name of the control.
          type: string
          example: Control Name
        identifier:
          description: The reference identifier of the control.
          type: string
          example: '123'
    TechRiskCompliance-RiskTemplate_ThreatInformation:
      type: object
      properties:
        id:
          description: The unique identifier of the threat entity.
          type: string
          format: uuid
          example: f3e9e8b4-1c5e-4f3e-9c58-92d8d6d2ea7a
        name:
          description: The display name of the threat.
          type: string
          example: Threat Name
        identifier:
          description: The reference identifier of the threat.
          type: string
          example: '456'
    TechRiskCompliance-RiskTemplate_VulnerabilityInformation:
      type: object
      properties:
        id:
          description: The unique identifier of the vulnerability entity.
          type: string
          format: uuid
          example: 6e4b2d9a-7fc7-4ef2-8129-3a4f84e7d314
        name:
          description: The display name of the vulnerability.
          type: string
          example: Threat Name
        identifier:
          description: The reference identifier of the vulnerability.
          type: string
          example: '245'
    TechRiskCompliance-RiskTemplate_AttributeValueInformation:
      type: object
      properties:
        id:
          description: Unique identifier for the attribute option
          type: string
          format: uuid
          example: a34ccec7-1ec0-4d65-9075-bdd0d923f1d1
        value:
          description: Attribute value
          type: string
          example: Text Value
        valueKey:
          description: Translation key used for localizing the value
          type: string
          example: attribute.option.valueKey
        colorCode:
          description: Color code associated with the option. Used for score-based attributes.
          type: string
          example: red
        optionSelectionValue:
          description: Selection score value linked to the option. Used for score-based or numerical-based attributes.
          type: string
          example: '3.5'
        displayLabel:
          description: Display name for the option, used for external attributes managed by other systems
          type: string
          example: United State | San Francisco
        disabled:
          description: Indicates whether this attribute option is currently disabled.
          type: boolean
          example: false
          default: 'false'
      required:
      - value
    TechRiskCompliance-RiskTemplate_RiskTemplateInformation:
      type: object
      properties:
        id:
          description: The unique identifier of the risk template.
          type: string
          format: uuid
          example: 123e4567-e89b-12d3-a456-426614174000
        name:
          description: The display name of the risk template.
          type: string
          example: Operational Risk Template
        riskName:
          description: The name of the risk associated with this template.
          type: string
          example: Operational Risk
        description:
          description: The detailed description of the risk template.
          type: string
          example: A structured template to identify, assess, and manage risks
        state:
          description: The current status indicating if the template is active or archived.
          type: string
          example: ACTIVE
          enum:
          - ACTIVE
          - ARCHIVED
        orgGroup:
          description: The organization group that owns this risk template.
          $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_BasicEntityDetail'
        treatmentPlan:
          description: The treatment plan text describing risk mitigation strategies.
          type: string
          example: Operational Risk treatment plan
        inherentRiskLevel:
          description: The inherent risk level assessment before controls are applied.
          $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskLevelDetails'
        targetRiskLevel:
          description: The target risk level assessment after implementing controls.
          $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskLevelDetails'
        threat:
          description: The threat information associated with this risk template.
          $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_ThreatInformation'
        vulnerabilities:
          description: The list of vulnerabilities associated with this risk template.
          type: array
          items:
            $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_VulnerabilityInformation'
        categories:
          description: The list of risk categories assigned to this template.
          type: array
          items:
            $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_RiskCategoryInformation'
        controls:
          description: The list of controls associated with this risk template.
          type: array
          items:
            $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_ControlInformation'
        createdDate:
          description: The timestamp when the risk template was created.
          type: string
          format: date-time
          example: '2025-07-15T09:27:53.123Z'
        attributeValues:
          description: The custom attributes and their values specific to this risk template.
          type: object
          additionalProperties:
            type: array
            items:
              $ref: '#/components/schemas/TechRiskCompliance-RiskTemplate_AttributeValueInformation'
    TechRiskCompliance-RiskTemplate_BasicEntityDetail:
      type: object
      properties:
        id:
          description: The unique identifier of the organization entity.
          type: string
          format: uuid
          example: 7009201b-3808-4eaa-8afa-97f50c6c3cf1
        name:
          description: The display name of the organization entity.
          type: string
          example: Entity name
    TechRiskCompliance-RiskTemplate_RiskCategoryInformation:
      type: object
      properties:
        id:
          description: The unique identifier of the risk category.
          type: string
          format: uuid
          example: d7e5c1a2-42a0-4cd7-83b1-d0a2ff064cb7
        name:
          description: The display name of the risk category.
          type: string
          example: Category Name
        nameKey:
          description: The translation key used for localizing the category name.
          type: string
          example: RiskCategory.Availability
  securitySchemes:
    TechRiskCompliance-ITRiskManagement_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            CONTROL: Access to Control Implementation operations for external systems
            ITRM: Access to ITRM operations for external systems
    TechRiskCompliance-RiskTemplate_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            INTEGRATION: Integration Scope
            RISK: Risk Scope
            RISK_READ: Risk read scope
    TechRiskCompliance-Risk_OAUTH2:
      type: oauth2
      flows:
        clientCredentials:
          tokenUrl: https://{hostname}/api/access/v1/oauth/token
          scopes:
            RISK: Risk Scope
            RISK_READ: Risk read scope
            INTEGRATION: Integration scope
x-readme:
  explorer-enabled: false
  proxy-enabled: false
  metrics-enabled: false
x-onetrust:
  spec-label: OpenAPI 3.1.0