RiskAlign methodology
The rules that every assessment, scenario and board pack is scored against. Versioned so historic decisions can be defended against the rules that applied at the time.
Residual risk
Residual is computed deterministically from inherent rating, control effectiveness, and evidence sufficiency. The formula is identical to RegAlign so a control rated in one system carries the same weight in the other.
round(inherent × (6 − control_effectiveness) × (6 − evidence_sufficiency) / 25)
Board-significance lift
RiskAlign extension on top of residual. Lifts (or dampens) the residual when a risk crystallises quickly and/or persists, because board attention scales with velocity × persistence, not residual alone.
residual × (1 + (avg(velocity, persistence) − 3) × 0.075), clamped to 1..25
1–5 scoring anchors (likelihood & impact)
Velocity — how fast a risk crystallises
Persistence — how long the impact endures
Evidence-confidence rubric
Seven criteria — shared with RegAlign. An evidence item only counts toward control effectiveness if it satisfies every criterion that applies.
Appetite cascade
Top-down. Board sets appetite at L1; the Risk Committee turns appetite into quantitative tolerance at L2; risk owners express tolerance as operational limits and KRI thresholds at L3.
Standards traceability
The methodology is consistent with ISO 31000 / 31010 (risk management & assessment techniques), ISO 22301 (business continuity), ISO 27001 (information security), ISO 37301 (compliance), ISO 37000 (governance), the COSO ERM framework, and the IIA Three Lines model. A clause-level mapping table will be published alongside the next methodology version bump.
Change control
Methodology is read-only in this release. Changing the residual formula, the 1–5 anchors, velocity/persistence definitions, the appetite cascade, or governance routing requires bumping METHODOLOGY_VERSION and stamping every new assessment, scenario run and board pack with the version it was produced under, so historic decisions can be defended against the rules that applied at the time.
For reviewers and auditors
This page is the canonical reference. The in-app methodology surface (/app/methodology) shows the same content to signed-in users and is stamped onto every board pack export.