Risk framework

Risk framework

Define how your organisation measures, accepts and governs risk. The methodology sets rating scales and severity bands; appetite sets the thresholds you are willing to accept; governance shows who assesses and approves; attestation records sign-off of the framework itself.

Active methodology

Version 1
Published by seed on 2026-07-18Matrix size: 5×5

Likelihood scale

LevelLabelDescriptorWeight
1RareMay occur only in exceptional circumstances1
2UnlikelyCould occur at some time2
3PossibleMight occur at some time3
4LikelyWill probably occur in most circumstances4
5Almost certainExpected to occur in most circumstances5

Impact scale

LevelLabelDescriptorWeight
1MinimalNegligible impact on operations, no regulatory interest1
2MinorLimited impact, contained within a team2
3ModerateNotable impact, management attention required3
4MajorSignificant impact on important business services or regulatory standing4
5SevereThreatens business viability or brings severe regulatory consequence5

Severity labels & score bands

SeverityLabelWeightScore fromScore to
criticalCritical41725
highHigh31016
mediumMedium259
lowLow114

Control credit — how linked controls reduce residual risk

Each linked control's live effectiveness earns credit toward reducing residual risk. Preventative controls reduce likelihood; detective and corrective controls reduce impact. Credit is summed across all controls of that type and capped — residual likelihood and impact never drop below 1.

Effective-control creditFull credit — an Effective control earns the most reduction.
1
Needs-improvement creditHalf credit — a control needing improvement still earns partial reduction.
0.5
Not-tested creditNo credit — an untested control reduces nothing until it is tested.
0
Max level reductionThe most levels likelihood or impact can drop, however many effective controls are linked.
2
Effective pool needed for max reductionThe combined credit needed across linked controls to reach the full reduction above.
2

Review cadence by tier

Review months = how often risks assessed at each tier are re-reviewed. The tier comes from the triage step of the assessment wizard.

TierReview months
rapid
Light-touch review for well-understood, stable risks (assessed via the rapid intake tier).
12
standard
The default review depth for most risks.
12
deep
Full re-assessment for high-severity, volatile, or heavily-regulated risks.
6

Locked compliance scales

These scales gate compliance and control logic directly and are not tenant-customizable here — the boundary is visible, not hidden. Changing them is its own locked-algorithm decision gate.

  • Requirement status — Compliant · Partial · Gap · N/A
  • Control effectiveness — Effective · Needs improvement · Not tested
  • Evidence description quality — 0–10 rating band

Issue SLA (read-through)

The tenant's action-plan SLA, in force today — edited in Settings → Issue management, not here.

Critical
5d
High
10d
Medium
20d
Low
30d
Edit in Settings