Aranisdocs
aranis.ai
Docs/Administration/Configurable methodology

Configurable methodology

What your organization can adjust in the calculation — and what is deliberately fixed.

Updated on August 18, 2026

The ruler is yours

Much of the methodology is parameterized per organization, because risk management policy varies and an imposed ruler would produce numbers nobody recognizes as their own.

You can adjust the risk matrix size and its axis bands, the impact weights per supplier profile, risk appetite, the money bands defining BIA criticality, the time checkpoints of the impact curve, the composition weights across domains, and which frameworks appear in the adherence view.

Changes apply going forward

Changes apply to subsequent calculations. Assessments already completed keep the result they had when they were closed — which preserves historical comparability, but also means changing the ruler does not rewrite the past.

What is not configurable, and why

Some things are fixed on purpose, and the criterion is worth knowing: what is not configurable is whatever, if configured, would let you improve the number without improving reality.

The clearest example is the threat floor in cyber risk. If it could be tuned, setting it to zero would be enough for the rule that "a treated threat does not become an absence of threat" to die by parameter, with nobody having to revoke it.

A floor is also not the same as appetite. Appetite has its own home — the appetite configuration, the approval tiers, and the risk acceptance letter. Conflating the two is the path by which someone tunes the parameter instead of treating the risk.