Reference · Public

RiskAlign methodology

The rules that every assessment, scenario and board pack is scored against. Versioned so historic decisions can be defended against the rules that applied at the time.

Version v2026.1.0Published 2026-06-13How this aligns with RegAlign →

Residual risk

Residual is computed deterministically from inherent rating, control effectiveness, and evidence sufficiency. The formula is identical to RegAlign so a control rated in one system carries the same weight in the other.

round(inherent × (6 − control_effectiveness) × (6 − evidence_sufficiency) / 25)

Board-significance lift

RiskAlign extension on top of residual. Lifts (or dampens) the residual when a risk crystallises quickly and/or persists, because board attention scales with velocity × persistence, not residual alone.

residual × (1 + (avg(velocity, persistence) − 3) × 0.075), clamped to 1..25

1–5 scoring anchors (likelihood & impact)

1
Very low
Negligible exposure; well-evidenced controls; no recent issues.
2
Low
Limited exposure; controls operating; minor issues only.
3
Moderate
Material exposure; controls broadly effective; some issues open.
4
High
Significant exposure; control weaknesses; recurring issues.
5
Very high
Severe exposure; controls absent or failing; unresolved breaches.

Velocity — how fast a risk crystallises

1
Glacial
Crystallises over years; ample time to react.
2
Slow
Crystallises over quarters.
3
Moderate
Crystallises over months.
4
Fast
Crystallises over weeks; limited response window.
5
Flash
Crystallises over hours/days; recovery, not prevention.

Persistence — how long the impact endures

1
Transient
Impact resolved within days.
2
Short
Impact endures weeks.
3
Medium
Impact endures months.
4
Long
Impact endures over a year.
5
Enduring
Permanent reputational or structural impact.

Evidence-confidence rubric

Seven criteria — shared with RegAlign. An evidence item only counts toward control effectiveness if it satisfies every criterion that applies.

Exists
An evidence item has been attached.
Current
Dated within the retention/refresh window.
Complete
Covers the period and scope being assessed.
Reliable
Source is authoritative and tamper-resistant.
Supports the conclusion
What the evidence shows matches the rating given.
Traceable
Linked back to the risk, control and test it supports.
Reviewed
A named human has reviewed the evidence and signed off.

Appetite cascade

Top-down. Board sets appetite at L1; the Risk Committee turns appetite into quantitative tolerance at L2; risk owners express tolerance as operational limits and KRI thresholds at L3.

Board
Risk Appetite Statement (RAS) per L1 category
Board
Committee
Quantitative tolerance per L2 sub-risk
Risk Committee
Owner
Operational limits per L3 risk and KRI
Risk Owner

Standards traceability

The methodology is consistent with ISO 31000 / 31010 (risk management & assessment techniques), ISO 22301 (business continuity), ISO 27001 (information security), ISO 37301 (compliance), ISO 37000 (governance), the COSO ERM framework, and the IIA Three Lines model. A clause-level mapping table will be published alongside the next methodology version bump.

Change control

Methodology is read-only in this release. Changing the residual formula, the 1–5 anchors, velocity/persistence definitions, the appetite cascade, or governance routing requires bumping METHODOLOGY_VERSION and stamping every new assessment, scenario run and board pack with the version it was produced under, so historic decisions can be defended against the rules that applied at the time.

For reviewers and auditors

This page is the canonical reference. The in-app methodology surface (/app/methodology) shows the same content to signed-in users and is stamped onto every board pack export.