Articles on: Risks
This article is also available in:

Risks

🎯 Risk Management in Brainframe


"One flexible risk engine β€” configure it to your methodology, let AI accelerate discovery, and watch your risk reduction trend over time."
Brainframe's risk management is fully customizable per purpose (CIA, legal, supplier, and more), so you can run ISO 27005, EBIOS RM, NIST, or your own in-house method β€” all in the same workspace.


Risk management in Brainframe is built around configurable risk types. Each risk type is its own methodology: its matrix, scales, measures, formula, appetite levels, and vocabulary. Because everything is configurable, the same platform supports many recognised frameworks side by side:


  • ISO/IEC 27005 β€” asset/threat/vulnerability driven, CIA impact
  • EBIOS RM β€” feared events and severity/likelihood scales
  • NIST SP 800-30, ISO 31000, FAIR-style value scoring
  • Sector or in-house methods β€” legal risk, supplier/third-party risk, operational risk, safety, privacy


You are not locked into one model. You define as many risk types as you need, each aligned to a specific purpose.


πŸ’‘ A risk type in Brainframe = a complete, self-contained risk methodology (matrix + measures + formula + appetite + vocabulary + guidance). This guide uses "risk type" and "methodology" interchangeably.



βš™οΈ Section 1 β€” Configuration


All risk methodology settings live under Workspace Settings β†’ Risk types (each risk type opens in the risk type / KPI editor). Below is everything you can configure.


1.1 Multiple Risk Types β€” One per Purpose


Create a distinct risk type for each risk domain you manage:


Example risk type

Typical purpose

CIA

Information security β€” Confidentiality, Integrity, Availability

Legal / Compliance

Regulatory and contractual risk

Supplier / Third-party

Vendor and supply-chain risk

Operational

Business process disruption

Privacy

Data protection / DPIA risk

Safety

Physical / people safety


Each risk type has its own matrix, scales, and vocabulary, so a supplier risk and a CIA risk can be scored completely differently while living in the same workspace.


1.2 Matrix Size and Scale


Choose the risk matrix dimensions β€” 3Γ—3, 4Γ—4, 5Γ—5, or 10Γ—10.


πŸ“Œ Changing the scale does not affect existing risk readings. Readings are re-normalised to the new matrix scale. If you need a scale we do not offer yet, contact us.



1.3 Sequential vs Multiplication Cell Values


Choose how each matrix cell's value is derived:


Mode

Behaviour

Sequential

Each cell on the matrix gets a unique value, giving more importance to impact. Useful when you want a strict ordering of severities.

Multiplication

The impact and probability positions are multiplied to define the cell value (classic likelihood Γ— impact matrix).



1.4 Configurable Measures (e.g. C, I, A, P)


Measures are the axes' building blocks. For a CIA methodology you might define Confidentiality, Integrity, Availability, and Probability; for EBIOS you might define Severity and Likelihood with custom levels.


For each measure you configure:


  • Title (e.g. Confidentiality, Impact, Likelihood)
  • Type β€” Range (0–5), Number, Yes/No, or Percentage
  • Value list β€” the selectable levels with custom labels and ranges so they align exactly with your existing methodology (e.g. "Negligible / Minor / Moderate / Major / Catastrophic")


This lets you reproduce the precise wording and level count of ISO 27005, EBIOS, or your internal scale.


1.5 Formula & X/Y Positioning (Value / Min / Max / Product)


You define which measures drive the X (likelihood) axis and which drive the Y (impact) axis, and how they combine. The formula type determines positioning:


Formula type

How the axis value is calculated

Value

Uses the exact value of the selected measure

Min

Uses the lowest value among the selected measures

Max

Uses the highest value among the selected measures

Product

Multiplies all selected measures on the axis, then linearly normalizes the result to the matrix scale


Normalization across different ranges


When measures have different ranges (e.g. one is 0–5, another 0–100), Brainframe normalizes the combined result to fit the matrix size. For Product, the minimum and maximum possible values of the selectable measures are used as the normalization range, so the position always maps correctly onto your chosen 3Γ—3 / 5Γ—5 / 10Γ—10 grid.


1.6 Risk Appetite Levels


Configure the appetite bands shown as coloured zones on the matrix. Each level (typically Green / Yellow / Red / Black, extensible to Blue / White) supports:


  • Custom label (e.g. "Acceptable", "Tolerable", "Unacceptable") β€” and whether the label is shown
  • Configurable colour
  • Threshold range (the minimum cell value where the band starts)
  • Review frequency β€” how often risks in that band must be re-reviewed


Review frequencies that notify owners


Each appetite band has a review frequency (1–24 months). Risks sitting in a higher-severity band are scheduled for more frequent review, and owners are notified when a review becomes due β€” so critical risks never go stale.


1.7 Configurable Methodology Text (used by AI)


Each risk type has a rich methodology description (HTML). This text:


  • Documents how the methodology should be applied for readers and auditors
  • Is used by AI to guide risk identification and scoring in the wizards, keeping AI suggestions aligned with your chosen method (ISO 27005, EBIOS, etc.)


1.8 Default Document Type & Template


Set the default risk document type and its template for this risk type. When a new risk is created for this methodology, it starts from the right structure (description, causes, consequences, treatment) automatically.



A risk type can be linked to a process kanban board so that remaining work is tracked as workflow stages. This connects risk treatment progress to Brainframe's task/process system (Todo β†’ Doing β†’ Done), keeping mitigation execution visible.


1.10 Asset Impact / Consequence Configuration


Beyond the matrix, each risk type defines the impact/consequence dimensions used when assessing assets β€” for example Reputation, Operational, Legal, Financial, Personal. For each consequence you configure:


  • Title and order
  • Guidance / methodology description


These consequences and their guidance texts are shown on the Governance tab / Dependencies tab of documents, where you set an asset's or supplier's maximum impact. Those max impacts then feed asset & control risk readings as upper bounds.


1.11 Control Register


Define a control register β€” a structured vocabulary of potential controls to consider when evaluating risks. Organised by category, it can be edited manually, imported from text/JSON, or AI-assisted.


The register gives the AI a curated list of relevant controls to propose during risk assessment, so suggestions match your framework's control catalogue rather than generic guesses.


1.12 Risk Register


Define a risk register β€” a structured vocabulary of potential risks / threats to consider. Like the control register, it is grouped by category and used to steer the AI toward the risk scenarios relevant to your methodology (e.g. EBIOS feared events, ISO 27005 threat catalogue).


1.13 Mandatory & Optional Tags (Risk reading properties)


Configure the document properties (tags) collected during risk readings β€” marking each mandatory or optional. Common examples:


  • Origin (where the risk comes from)
  • Risk type / category
  • Risk action / treatment decision (mitigate, accept, transfer, avoid)
  • Any custom field your programme requires


Mandatory tags are enforced when saving a reading, ensuring consistent, audit-ready risk records.



🧭 Section 2 β€” Risk Management


2.1 Bulk Import of Risks (from Excel)


Migrating from spreadsheets? The bulk import tool (from a folder / table view) turns an existing Excel file into governed Brainframe risk documents.


The wizard walks through staged steps:


  1. Upload β€” drop your Excel (or ZIP) file
  2. Map content β€” map spreadsheet columns into the risk document template (e.g. description, causes, mitigations, owner) so each row becomes a fully documented risk
  3. Variables β€” map any reusable template variables
  4. Risks β€” optionally perform a direct risk reading during import, taking the impact/likelihood values straight from Excel columns so risks land on the matrix immediately with their score
  5. Validate & Import β€” review and create all documents in one go


This means you can import not just the narrative (description, mitigations) but also the initial risk position from your existing register β€” no manual re-scoring.


2.2 The Two Risk Wizards (AI-assisted)


Brainframe provides two AI wizards that share the same goal: quickly identify and document risks, mapped to your existing assets and controls, using your configured registers and methodology.


πŸ— New Asset Wizard


Launched when creating/onboarding an asset (Create asset wizard). It:


  1. Captures the asset details (AI-assisted description)
  2. Pulls in existing controls and risks already in the workspace and maps them to the asset
  3. Uses the risk register to identify compliance / control risks (gaps)
  4. Builds a mitigation plan (missing controls + optional linked plan document)


🎯 Risk Assessment Wizard


Launched from the risk matrix. It lets you select one or more existing assets (e.g. core business services) and then runs the same AI-assisted flow across all of them: map existing controls/risks, identify new risks from the register, and propose a combined mitigation plan.


Both wizards aim to get you from "blank register" to "documented, scored, mitigated risks" fast β€” with AI grounded in your methodology text and registers.


2.3 Where Risk Readings Happen


A risk reading (a scored assessment against a risk type) can be added to any document β€” an asset, supplier, employee, process, etc. This is powerful for quick, in-context scoring.


However, best practice (and what the wizards create) is a dedicated risk document that:


  • Describes the risk (scenario, causes, consequences)
  • Is linked to the related assets it affects and the controls that mitigate it
  • Carries the risk reading itself


Because the reading is on the risk document, that risk then appears on the relevant risk type matrix, and its evolution across successive readings is visible on the document's Risk tab.


2.4 The Add Risk Reading Screen


The reading screen has several core sections:


Section

What it does

Methodology

An info button opens the risk type's methodology guidance so assessors score consistently

Initial risk

The risk position before treatment β€” your starting baseline

Current risk

The risk as it stands now, based on the measure values you enter

Target risk

The risk position you aim to reach after mitigation

Description

Narrative for this reading (rich text)

Formula calculation

Live X/Y and final result computed from your measures using the configured formula, with the matrix cell colour

Remaining work

Unique to Brainframe β€” indicates how much treatment work is still outstanding for this risk (see below)

Document properties

The configured mandatory/optional tags (origin, risk type, risk action, …)


Remaining work (the Brainframe differentiator)


Each reading records a remaining work level that expresses how much of the treatment is done β€” from not started to fully mitigated/accepted:


Level

Meaning

Progress

⬛ Open β€” not yet assessed

Nothing done yet

0%

πŸ”΄ Risk assessed β€” negotiating solution

Just started

<33%

🟠 Solution agreed β€” waiting to implement

Planned

>33% <50%

🟑 Solution in progress

Underway

>50% <66%

🟒 Solution implemented β€” waiting acceptance

Almost done

>83%

βœ… Risk accepted and/or mitigated

Fully managed

100%


This drives the remaining-work colour of each risk on the matrix and the remaining-work trend chart (Section 3).



πŸ“ˆ Section 3 β€” Viewing Risk & Evolution


3.1 Table View β€” Risk Readings in Context


In any table view, as soon as at least one item has a risk reading, its reading is shown inline (impact, likelihood, final result, remaining work, reading date, measures, target, deadline).


  • Filter quickly by risk owner, criticality, and other document properties
  • Export the visible risk data to Excel for reporting


3.2 Risk Matrix Module


Open Risks β†’ Risk matrix. First select the risk type β€” the whole view reflects that methodology's matrix, appetite, and colours.


Summary cards


Above the matrix you get an at-a-glance overview:


  • Severity distribution of risks
  • Remaining work status
  • Planned mitigation status


The risk matrix visualization


The matrix shows:


  • Appetite ranges as coloured background zones (your configured colours and labels)
  • Individual current risk readings plotted on their cell, each marker coloured by its remaining work:
  • ⬛ Black = nothing done β†’ counts as risk Γ— 5 (full remaining work)
  • βœ… Green = fully mitigated or accepted β†’ counts as risk Γ— 0 (no remaining work)
  • intermediate colours for in-progress treatment


Hover over any risk marker to see its Initial / Current / Target risk positions together.


Remaining-work & risk-reduction trend


Below the matrix, a trend chart aggregates all risks over time:


  • Orange β€” remaining work / risk reduction trend (how the outstanding risk is coming down)
  • Blue β€” newly added risks
  • Green β€” all planned risks


The deadline set on a risk's Planning tab is treated as the date by which the risk should be maximally reduced or accepted β€” i.e. risk Γ— 0 for remaining work. Reaching that point means the risk is fully managed, not that it has disappeared.


Export


Below the trend you can export all risk readings, or just the latest reading per risk, for quick Excel reporting.


3.3 Per-Document Risk Evolution (Risk tab)


Open an individual risk document β†’ Risk tab. Here you can visualize every reading done for that risk over time, seeing how Initial β†’ Current β†’ Target evolved with each assessment and how remaining work progressed.



Putting It Together


  1. Configure a risk type per purpose (CIA, legal, supplier…) β€” matrix, measures, formula, appetite, registers, methodology, tags.
  2. Create risks β€” bulk import from Excel, or use the AI wizards to identify and document them against your assets and controls.
  3. Score with risk readings (initial / current / target + remaining work).
  4. Monitor on the matrix, trend chart, table view, and per-document Risk tab β€” and let review frequencies keep owners on track.


Because every layer is configurable, Brainframe adapts to ISO 27005, EBIOS RM, NIST, ISO 31000, or your own methodology β€” without changing tools.


For the assets and suppliers that risks attach to, see the Asset Management and Supplier & Third-Party Management guides.

Updated on: 13/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!