> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Risks

# 🎯 **Risk Management in Brainframe**

> **"One flexible risk engine — configure it to your methodology, let AI accelerate discovery, and watch your risk reduction trend over time."**
> *Brainframe's risk management is fully customizable per purpose (CIA, legal, supplier, and more), so you can run ISO 27005, EBIOS RM, NIST, or your own in-house method — all in the same workspace.*

Risk management in Brainframe is built around **configurable risk types**. Each risk type is its own methodology: its matrix, scales, measures, formula, appetite levels, and vocabulary. Because everything is configurable, the **same platform** supports many recognised frameworks side by side:

* **ISO/IEC 27005** — asset/threat/vulnerability driven, CIA impact
* **EBIOS RM** — feared events and severity/likelihood scales
* **NIST SP 800-30**, **ISO 31000**, **FAIR-style** value scoring
* **Sector or in-house methods** — legal risk, supplier/third-party risk, operational risk, safety, privacy

You are not locked into one model. You define **as many risk types as you need**, each aligned to a specific purpose.

> 💡 A **risk type** in Brainframe = a complete, self-contained risk methodology (matrix + measures + formula + appetite + vocabulary + guidance). This guide uses "risk type" and "methodology" interchangeably.

---
---

# ⚙️ **Section 1 — Configuration**

All risk methodology settings live under **Workspace Settings → Risk types** (each risk type opens in the risk type / KPI editor). Below is everything you can configure.

## 1.1 Multiple Risk Types — One per Purpose

Create a distinct risk type for each risk domain you manage:

| Example risk type | Typical purpose |
| ---- |
| **CIA** | Information security — Confidentiality, Integrity, Availability |
| **Legal / Compliance** | Regulatory and contractual risk |
| **Supplier / Third-party** | Vendor and supply-chain risk |
| **Operational** | Business process disruption |
| **Privacy** | Data protection / DPIA risk |
| **Safety** | Physical / people safety |

Each risk type has its **own matrix, scales, and vocabulary**, so a supplier risk and a CIA risk can be scored completely differently while living in the same workspace.

## 1.2 Matrix Size and Scale

Choose the risk matrix dimensions — **3×3, 4×4, 5×5, or 10×10**.

> 📌 Changing the scale does **not** affect existing risk readings. Readings are re-normalised to the new matrix scale. If you need a scale we do not offer yet, contact us.


## 1.3 Sequential vs Multiplication Cell Values

Choose how each matrix cell's value is derived:

| Mode | Behaviour |
| ---- |
| **Sequential** | Each cell on the matrix gets a **unique** value, giving **more importance to impact**. Useful when you want a strict ordering of severities. |
| **Multiplication** | The **impact and probability positions are multiplied** to define the cell value (classic likelihood × impact matrix). |


## 1.4 Configurable Measures (e.g. C, I, A, P)

Measures are the axes' building blocks. For a CIA methodology you might define **Confidentiality, Integrity, Availability, and Probability**; for EBIOS you might define **Severity** and **Likelihood** with custom levels.

For each measure you configure:

* **Title** (e.g. Confidentiality, Impact, Likelihood)
* **Type** — Range (0–5), Number, Yes/No, or Percentage
* **Value list** — the selectable levels with **custom labels and ranges** so they align exactly with your existing methodology (e.g. "Negligible / Minor / Moderate / Major / Catastrophic")

This lets you reproduce the **precise wording and level count** of ISO 27005, EBIOS, or your internal scale.

## 1.5 Formula & X/Y Positioning (Value / Min / Max / Product)

You define **which measures drive the X (likelihood) axis and which drive the Y (impact) axis**, and how they combine. The formula type determines positioning:

| Formula type | How the axis value is calculated |
| ---- |
| **Value** | Uses the exact value of the selected measure |
| **Min** | Uses the **lowest** value among the selected measures |
| **Max** | Uses the **highest** value among the selected measures |
| **Product** | **Multiplies** all selected measures on the axis, then **linearly normalizes** the result to the matrix scale |

### Normalization across different ranges

When measures have **different ranges** (e.g. one is 0–5, another 0–100), Brainframe normalizes the combined result to fit the matrix size. For **Product**, the minimum and maximum possible values of the selectable measures are used as the normalization range, so the position always maps correctly onto your chosen 3×3 / 5×5 / 10×10 grid.

## 1.6 Risk Appetite Levels

Configure the **appetite bands** shown as coloured zones on the matrix. Each level (typically Green / Yellow / Red / Black, extensible to Blue / White) supports:

* **Custom label** (e.g. "Acceptable", "Tolerable", "Unacceptable") — and whether the label is shown
* **Configurable colour**
* **Threshold range** (the minimum cell value where the band starts)
* **Review frequency** — how often risks in that band must be re-reviewed

### Review frequencies that notify owners

Each appetite band has a **review frequency** (1–24 months). Risks sitting in a higher-severity band are scheduled for **more frequent review**, and owners are **notified** when a review becomes due — so critical risks never go stale.

## 1.7 Configurable Methodology Text (used by AI)

Each risk type has a rich **methodology description** (HTML). This text:

* Documents **how the methodology should be applied** for readers and auditors
* Is **used by AI** to guide risk identification and scoring in the wizards, keeping AI suggestions aligned with your chosen method (ISO 27005, EBIOS, etc.)

## 1.8 Default Document Type & Template

Set the **default risk document type** and its **template** for this risk type. When a new risk is created for this methodology, it starts from the right structure (description, causes, consequences, treatment) automatically.

## 1.9 Link to Process Kanban

A risk type can be **linked to a process kanban board** so that **remaining work** is tracked as workflow stages. This connects risk treatment progress to Brainframe's task/process system (Todo → Doing → Done), keeping mitigation execution visible.

## 1.10 Asset Impact / Consequence Configuration

Beyond the matrix, each risk type defines the **impact/consequence dimensions** used when assessing assets — for example **Reputation, Operational, Legal, Financial, Personal**. For each consequence you configure:

* **Title** and **order**
* **Guidance / methodology description**

These consequences and their guidance texts are shown on the **Governance tab / Dependencies tab of documents**, where you set an asset's or supplier's **maximum impact**. Those max impacts then feed asset & control risk readings as upper bounds.

## 1.11 Control Register

Define a **control register** — a structured vocabulary of **potential controls** to consider when evaluating risks. Organised by category, it can be edited manually, imported from text/JSON, or AI-assisted.

The register gives the **AI a curated list of relevant controls** to propose during risk assessment, so suggestions match your framework's control catalogue rather than generic guesses.

## 1.12 Risk Register

Define a **risk register** — a structured vocabulary of **potential risks / threats** to consider. Like the control register, it is grouped by category and used to **steer the AI** toward the risk scenarios relevant to your methodology (e.g. EBIOS feared events, ISO 27005 threat catalogue).

## 1.13 Mandatory & Optional Tags (Risk reading properties)

Configure the **document properties (tags)** collected during risk readings — marking each **mandatory or optional**. Common examples:

* **Origin** (where the risk comes from)
* **Risk type / category**
* **Risk action / treatment decision** (mitigate, accept, transfer, avoid)
* Any custom field your programme requires

Mandatory tags are enforced when saving a reading, ensuring consistent, audit-ready risk records.

---
---

# 🧭 **Section 2 — Risk Management**

## 2.1 Bulk Import of Risks (from Excel)

Migrating from spreadsheets? The **bulk import tool** (from a folder / table view) turns an existing Excel file into governed Brainframe risk documents.

The wizard walks through staged steps:

1. **Upload** — drop your Excel (or ZIP) file
2. **Map content** — map spreadsheet columns into the **risk document template** (e.g. description, causes, mitigations, owner) so each row becomes a fully documented risk
3. **Variables** — map any reusable template variables
4. **Risks** — optionally perform a **direct risk reading during import**, taking the **impact/likelihood values straight from Excel columns** so risks land on the matrix immediately with their score
5. **Validate & Import** — review and create all documents in one go

This means you can import not just the **narrative** (description, mitigations) but also the **initial risk position** from your existing register — no manual re-scoring.

## 2.2 The Two Risk Wizards (AI-assisted)

Brainframe provides two AI wizards that share the same goal: **quickly identify and document risks**, mapped to your existing assets and controls, using your configured registers and methodology.

### 🏗 New Asset Wizard

Launched when creating/onboarding an asset (Create asset wizard). It:

1. Captures the **asset details** (AI-assisted description)
2. Pulls in **existing controls and risks** already in the workspace and **maps** them to the asset
3. Uses the **risk register** to identify **compliance / control risks** (gaps)
4. Builds a **mitigation plan** (missing controls + optional linked plan document)

### 🎯 Risk Assessment Wizard

Launched from the **risk matrix**. It lets you **select one or more existing assets** (e.g. core business services) and then runs the same AI-assisted flow across all of them: map existing controls/risks, identify new risks from the register, and propose a combined mitigation plan.

Both wizards aim to get you from **"blank register"** to **"documented, scored, mitigated risks"** fast — with AI grounded in your methodology text and registers.

## 2.3 Where Risk Readings Happen

A **risk reading** (a scored assessment against a risk type) can be added to **any document** — an asset, supplier, employee, process, etc. This is powerful for quick, in-context scoring.

However, **best practice (and what the wizards create)** is a **dedicated risk document** that:

* **Describes the risk** (scenario, causes, consequences)
* Is **linked to the related assets** it affects and the **controls** that mitigate it
* Carries the **risk reading** itself

Because the reading is on the risk document, that risk then appears on the **relevant risk type matrix**, and its **evolution across successive readings** is visible on the document's **Risk tab**.

## 2.4 The Add Risk Reading Screen

The reading screen has several core sections:

| Section | What it does |
| ---- |
| **Methodology** | An info button opens the risk type's methodology guidance so assessors score consistently |
| **Initial risk** | The risk position **before** treatment — your starting baseline |
| **Current risk** | The risk **as it stands now**, based on the measure values you enter |
| **Target risk** | The risk position you **aim to reach** after mitigation |
| **Description** | Narrative for this reading (rich text) |
| **Formula calculation** | Live X/Y and final result computed from your measures using the configured formula, with the matrix cell colour |
| **Remaining work** | **Unique to Brainframe** — indicates how much treatment work is still outstanding for this risk (see below) |
| **Document properties** | The configured mandatory/optional tags (origin, risk type, risk action, …) |

### Remaining work (the Brainframe differentiator)

Each reading records a **remaining work** level that expresses **how much of the treatment is done** — from *not started* to *fully mitigated/accepted*:

| Level | Meaning | Progress |
| ---- |
| ⬛ **Open — not yet assessed** | Nothing done yet | 0% |
| 🔴 **Risk assessed — negotiating solution** | Just started | <33% |
| 🟠 **Solution agreed — waiting to implement** | Planned | >33% <50% |
| 🟡 **Solution in progress** | Underway | >50% <66% |
| 🟢 **Solution implemented — waiting acceptance** | Almost done | >83% |
| ✅ **Risk accepted and/or mitigated** | Fully managed | 100% |

This drives the **remaining-work colour** of each risk on the matrix and the **remaining-work trend** chart (Section 3).

---
---

# 📈 **Section 3 — Viewing Risk & Evolution**

## 3.1 Table View — Risk Readings in Context

In any **table view**, as soon as **at least one item has a risk reading**, its reading is shown inline (impact, likelihood, final result, remaining work, reading date, measures, target, deadline).

* **Filter** quickly by **risk owner, criticality**, and other document properties
* **Export** the visible risk data to **Excel** for reporting

## 3.2 Risk Matrix Module

Open **Risks → Risk matrix**. First **select the risk type** — the whole view reflects that methodology's matrix, appetite, and colours.

### Summary cards

Above the matrix you get an at-a-glance overview:

* **Severity** distribution of risks
* **Remaining work** status
* **Planned mitigation** status

### The risk matrix visualization

The matrix shows:

* **Appetite ranges** as coloured background zones (your configured colours and labels)
* **Individual current risk readings** plotted on their cell, each marker coloured by its **remaining work**:
* ⬛ **Black** = nothing done → counts as **risk × 5** (full remaining work)
* ✅ **Green** = fully mitigated or accepted → counts as **risk × 0** (no remaining work)
* intermediate colours for in-progress treatment

**Hover** over any risk marker to see its **Initial / Current / Target** risk positions together.

### Remaining-work & risk-reduction trend

Below the matrix, a **trend chart** aggregates all risks over time:

* **Orange** — remaining work / risk reduction trend (how the outstanding risk is coming down)
* **Blue** — newly added risks
* **Green** — all planned risks

The **deadline** set on a risk's **Planning tab** is treated as the date by which the risk should be **maximally reduced or accepted** — i.e. **risk × 0 for remaining work**. Reaching that point means the risk is **fully managed**, not that it has disappeared.

### Export

Below the trend you can **export all risk readings**, or just the **latest** reading per risk, for quick **Excel reporting**.

## 3.3 Per-Document Risk Evolution (Risk tab)

Open an individual risk document → **Risk tab**. Here you can **visualize every reading done for that risk over time**, seeing how Initial → Current → Target evolved with each assessment and how remaining work progressed.

---

## Putting It Together

1. **Configure** a risk type per purpose (CIA, legal, supplier…) — matrix, measures, formula, appetite, registers, methodology, tags.
2. **Create risks** — bulk import from Excel, or use the AI wizards to identify and document them against your assets and controls.
3. **Score** with risk readings (initial / current / target + remaining work).
4. **Monitor** on the matrix, trend chart, table view, and per-document Risk tab — and let review frequencies keep owners on track.

Because every layer is configurable, Brainframe adapts to **ISO 27005, EBIOS RM, NIST, ISO 31000, or your own methodology** — without changing tools.

For the assets and suppliers that risks attach to, see the **Asset Management** and **Supplier & Third-Party Management** guides.
