Aranisdocs
aranis.ai
Docs/Privacy Risk/Privacy risk register

Privacy risk register

The privacy risk library and matrix, on the same ruler as the other domains.

Updated on August 17, 2026

Same mechanics, different subject

The privacy risk register works like the cyber and organizational ones: a library of known risks you adopt, plus custom risks for whatever is specific to your operation. The matrix crosses likelihood and impact and uses the same size configured for the organization — there is no privacy ruler separate from everyone else's.

That is a choice, not a coincidence. A privacy risk shown on its own scale could not be compared against a cyber risk at prioritization time, which is exactly when the comparison is needed.

Inherent and residual

As in the other domains, inherent is entered and residual derives from the controls related to the risk. You relate controls by picking from the library or accepting Ara's suggestion — which suggests and does not link on its own.

Where it rises to

The domain's consolidated figure feeds the PR child risk in the corporate register, which is what carries the legal dimension in the organizational rollup. A severe privacy risk is therefore not contained on the privacy screen: it shows up in the exposure reading for the whole company.