Aranisdocs
aranis.ai
Docs/Organizational Risk/Organizational Risk overview

Organizational Risk overview

The corporate risk register under ISO 31000: parent risk, per-domain child risks, and how they roll up.

Updated on August 17, 2026

What this layer is

Organizational Risk is your corporate risk register, following ISO 31000. It sits above the operational risks the other domains already compute — it does not replace them. The point is to have one place where "what is the company exposed to" has a single answer, fed by what each domain has already measured.

Parent risk and child risks

The register has two levels. The organizational risk, prefixed OR, exists by the simple fact that the company exists. Below it sit the operational risks, each fed by an already-computed domain: VR for supplier, CR for cyber, PR for privacy (which carries the legal dimension), and HR for human risk.

The four children are created automatically the first time you open the register. Deleting one erases nothing: it archives reversibly, and that domain's correlations are disconnected from the rollup. The interface warns you before it happens.

The identifier follows a prefix-sequence pattern per organization — OR-001, VR-003 — and is unique within your organization.

How the parent is computed

The parent rolls up as the worst case among its children, not the average. It is the same choice made throughout the platform: high exposure in one domain should not be diluted by three quiet ones.

Taxonomy

Each risk can be classified along two independent axes, both optional. Category: human, biological, technological, legal, or image. Impact type: disaster (a real event, such as a pandemic or earthquake — not IT disaster recovery), continuity (interruption), or reputational.

One distinction worth recording: resilience is not a risk, it is a continuity strategy. It enters the platform as a treatment, not as a line in the register.