Risk register and matrix
The configurable NxN matrix, inherent versus residual risk, and how treatments are judged on cost-benefit.
The matrix is yours, not ours
The risk matrix crosses likelihood (annual frequency) with impact (in money) and is configurable per organization. You choose the size — 3×3, 4×4, or 5×5 — to match your risk management policy, and the band scale, which can be linear (equal widths) or exponential (geometric progression).
If you do not set the band boundaries, they are generated: impact from the BIA money bands, likelihood from a default frequency range. The three registers that use a matrix — organizational, cyber, and privacy — read the same configured size, so that two rulers never coexist inside one organization.
A level is a range
Axis labels show ranges, not points. The first level is open at the bottom ("under $50k"), the last is open at the top ("$5M or more"), and the middle ones are closed on both sides. The top level cannot be printed as a single number because that would assert a ceiling the configuration never declared.
Inherent and residual
Inherent risk — the exposure that would exist with no controls at all — is entered manually, with a suggestion from the platform. Residual varies by where the risk comes from.
For risks fed by a domain (supplier, cyber, and privacy), residual is read at query time from the surfaces that already exist — the worst case among completed supplier assessments, the cyber risk matrix, category RC07 for privacy. There is no parallel pipeline recomputing it: if there were, two numbers would answer the same question and the second would go stale.
For human risk and for pure organizational risks, residual is manual. Human risk is manual because the platform has no human scoring yet — honesty here is better than a number derived from nothing.
Treatments judged on cost-benefit
A treatment can be a control, a resilience strategy, or other. Each records its annual cost and the money exposure remaining after it. From those the platform derives whether it is justified: a treatment is justified when its annual cost is less than or equal to the exposure it removes. Cost greater than the damage avoided is flagged as unjustified — the calculation comes from FAIR, and is derived on read rather than stored.
Risks outside the library
Risks not in the library are entered manually and can be given related controls, either chosen by you from the library or suggested by Ara. Ara suggests and you accept — it does not link on its own. From the related controls the risk inherits, read-only, the associated vulnerabilities and attack techniques, and residual starts deriving from those controls' maturity. When there is no related control — the case of a pure disaster — it goes back to manual.