Risks
π― Risk Management in Brainframe
"One flexible risk engine β configure it to your methodology, let AI accelerate discovery, and watch your risk reduction trend over time."
Brainframe's risk management is fully customizable per purpose (CIA, legal, supplier, and more), so you can run ISO 27005, EBIOS RM, NIST, or your own in-house method β all in the same workspace.
Risk management in Brainframe is built around configurable risk types. Each risk type is its own methodology: its matrix, scales, measures, formula, appetite levels, and vocabulary. Because everything is configurable, the same platform supports many recognised frameworks side by side:
- ISO/IEC 27005 β asset/threat/vulnerability driven, CIA impact
- EBIOS RM β feared events and severity/likelihood scales
- NIST SP 800-30, ISO 31000, FAIR-style value scoring
- Sector or in-house methods β legal risk, supplier/third-party risk, operational risk, safety, privacy
You are not locked into one model. You define as many risk types as you need, each aligned to a specific purpose.
π‘ A risk type in Brainframe = a complete, self-contained risk methodology (matrix + measures + formula + appetite + vocabulary + guidance). This guide uses "risk type" and "methodology" interchangeably.
βοΈ Section 1 β Configuration
All risk methodology settings live under Workspace Settings β Risk types (each risk type opens in the risk type / KPI editor). Below is everything you can configure.
1.1 Multiple Risk Types β One per Purpose
Create a distinct risk type for each risk domain you manage:
Example risk type | Typical purpose |
|---|---|
CIA | Information security β Confidentiality, Integrity, Availability |
Legal / Compliance | Regulatory and contractual risk |
Supplier / Third-party | Vendor and supply-chain risk |
Operational | Business process disruption |
Privacy | Data protection / DPIA risk |
Safety | Physical / people safety |
Each risk type has its own matrix, scales, and vocabulary, so a supplier risk and a CIA risk can be scored completely differently while living in the same workspace.
1.2 Matrix Size and Scale
Choose the risk matrix dimensions β 3Γ3, 4Γ4, 5Γ5, or 10Γ10.
π Changing the scale does not affect existing risk readings. Readings are re-normalised to the new matrix scale. If you need a scale we do not offer yet, contact us.
1.3 Sequential vs Multiplication Cell Values
Choose how each matrix cell's value is derived:
Mode | Behaviour |
|---|---|
Sequential | Each cell on the matrix gets a unique value, giving more importance to impact. Useful when you want a strict ordering of severities. |
Multiplication | The impact and probability positions are multiplied to define the cell value (classic likelihood Γ impact matrix). |
1.4 Configurable Measures (e.g. C, I, A, P)
Measures are the axes' building blocks. For a CIA methodology you might define Confidentiality, Integrity, Availability, and Probability; for EBIOS you might define Severity and Likelihood with custom levels.
For each measure you configure:
- Title (e.g. Confidentiality, Impact, Likelihood)
- Type β Range (0β5), Number, Yes/No, or Percentage
- Value list β the selectable levels with custom labels and ranges so they align exactly with your existing methodology (e.g. "Negligible / Minor / Moderate / Major / Catastrophic")
This lets you reproduce the precise wording and level count of ISO 27005, EBIOS, or your internal scale.
1.5 Formula & X/Y Positioning (Value / Min / Max / Product)
You define which measures drive the X (likelihood) axis and which drive the Y (impact) axis, and how they combine. The formula type determines positioning:
Formula type | How the axis value is calculated |
|---|---|
Value | Uses the exact value of the selected measure |
Min | Uses the lowest value among the selected measures |
Max | Uses the highest value among the selected measures |
Product | Multiplies all selected measures on the axis, then linearly normalizes the result to the matrix scale |
Normalization across different ranges
When measures have different ranges (e.g. one is 0β5, another 0β100), Brainframe normalizes the combined result to fit the matrix size. For Product, the minimum and maximum possible values of the selectable measures are used as the normalization range, so the position always maps correctly onto your chosen 3Γ3 / 5Γ5 / 10Γ10 grid.
1.6 Risk Appetite Levels
Configure the appetite bands shown as coloured zones on the matrix. Each level (typically Green / Yellow / Red / Black, extensible to Blue / White) supports:
- Custom label (e.g. "Acceptable", "Tolerable", "Unacceptable") β and whether the label is shown
- Configurable colour
- Threshold range (the minimum cell value where the band starts)
- Review frequency β how often risks in that band must be re-reviewed
Review frequencies that notify owners
Each appetite band has a review frequency (1β24 months). Risks sitting in a higher-severity band are scheduled for more frequent review, and owners are notified when a review becomes due β so critical risks never go stale.
1.7 Configurable Methodology Text (used by AI)
Each risk type has a rich methodology description (HTML). This text:
- Documents how the methodology should be applied for readers and auditors
- Is used by AI to guide risk identification and scoring in the wizards, keeping AI suggestions aligned with your chosen method (ISO 27005, EBIOS, etc.)
1.8 Default Document Type & Template
Set the default risk document type and its template for this risk type. When a new risk is created for this methodology, it starts from the right structure (description, causes, consequences, treatment) automatically.
1.9 Link to Process Kanban
A risk type can be linked to a process kanban board so that remaining work is tracked as workflow stages. This connects risk treatment progress to Brainframe's task/process system (Todo β Doing β Done), keeping mitigation execution visible.
1.10 Asset Impact / Consequence Configuration
Beyond the matrix, each risk type defines the impact/consequence dimensions used when assessing assets β for example Reputation, Operational, Legal, Financial, Personal. For each consequence you configure:
- Title and order
- Guidance / methodology description
These consequences and their guidance texts are shown on the Governance tab / Dependencies tab of documents, where you set an asset's or supplier's maximum impact. Those max impacts then feed asset & control risk readings as upper bounds.
1.11 Control Register
Define a control register β a structured vocabulary of potential controls to consider when evaluating risks. Organised by category, it can be edited manually, imported from text/JSON, or AI-assisted.
The register gives the AI a curated list of relevant controls to propose during risk assessment, so suggestions match your framework's control catalogue rather than generic guesses.
1.12 Risk Register
Define a risk register β a structured vocabulary of potential risks / threats to consider. Like the control register, it is grouped by category and used to steer the AI toward the risk scenarios relevant to your methodology (e.g. EBIOS feared events, ISO 27005 threat catalogue).
1.13 Mandatory & Optional Tags (Risk reading properties)
Configure the document properties (tags) collected during risk readings β marking each mandatory or optional. Common examples:
- Origin (where the risk comes from)
- Risk type / category
- Risk action / treatment decision (mitigate, accept, transfer, avoid)
- Any custom field your programme requires
Mandatory tags are enforced when saving a reading, ensuring consistent, audit-ready risk records.
π§ Section 2 β Risk Management
2.1 Bulk Import of Risks (from Excel)
Migrating from spreadsheets? The bulk import tool (from a folder / table view) turns an existing Excel file into governed Brainframe risk documents.
The wizard walks through staged steps:
- Upload β drop your Excel (or ZIP) file
- Map content β map spreadsheet columns into the risk document template (e.g. description, causes, mitigations, owner) so each row becomes a fully documented risk
- Variables β map any reusable template variables
- Risks β optionally perform a direct risk reading during import, taking the impact/likelihood values straight from Excel columns so risks land on the matrix immediately with their score
- Validate & Import β review and create all documents in one go
This means you can import not just the narrative (description, mitigations) but also the initial risk position from your existing register β no manual re-scoring.
2.2 The Two Risk Wizards (AI-assisted)
Brainframe provides two AI wizards that share the same goal: quickly identify and document risks, mapped to your existing assets and controls, using your configured registers and methodology.
π New Asset Wizard
Launched when creating/onboarding an asset (Create asset wizard). It:
- Captures the asset details (AI-assisted description)
- Pulls in existing controls and risks already in the workspace and maps them to the asset
- Uses the risk register to identify compliance / control risks (gaps)
- Builds a mitigation plan (missing controls + optional linked plan document)
π― Risk Assessment Wizard
Launched from the risk matrix. It lets you select one or more existing assets (e.g. core business services) and then runs the same AI-assisted flow across all of them: map existing controls/risks, identify new risks from the register, and propose a combined mitigation plan.
Both wizards aim to get you from "blank register" to "documented, scored, mitigated risks" fast β with AI grounded in your methodology text and registers.
2.3 Where Risk Readings Happen
A risk reading (a scored assessment against a risk type) can be added to any document β an asset, supplier, employee, process, etc. This is powerful for quick, in-context scoring.
However, best practice (and what the wizards create) is a dedicated risk document that:
- Describes the risk (scenario, causes, consequences)
- Is linked to the related assets it affects and the controls that mitigate it
- Carries the risk reading itself
Because the reading is on the risk document, that risk then appears on the relevant risk type matrix, and its evolution across successive readings is visible on the document's Risk tab.
2.4 The Add Risk Reading Screen
The reading screen has several core sections:
Section | What it does |
|---|---|
Methodology | An info button opens the risk type's methodology guidance so assessors score consistently |
Initial risk | The risk position before treatment β your starting baseline |
Current risk | The risk as it stands now, based on the measure values you enter |
Target risk | The risk position you aim to reach after mitigation |
Description | Narrative for this reading (rich text) |
Formula calculation | Live X/Y and final result computed from your measures using the configured formula, with the matrix cell colour |
Remaining work | Unique to Brainframe β indicates how much treatment work is still outstanding for this risk (see below) |
Document properties | The configured mandatory/optional tags (origin, risk type, risk action, β¦) |
Remaining work (the Brainframe differentiator)
Each reading records a remaining work level that expresses how much of the treatment is done β from not started to fully mitigated/accepted:
Level | Meaning | Progress |
|---|---|---|
β¬ Open β not yet assessed | Nothing done yet | 0% |
π΄ Risk assessed β negotiating solution | Just started | <33% |
π Solution agreed β waiting to implement | Planned | >33% <50% |
π‘ Solution in progress | Underway | >50% <66% |
π’ Solution implemented β waiting acceptance | Almost done | >83% |
β Risk accepted and/or mitigated | Fully managed | 100% |
This drives the remaining-work colour of each risk on the matrix and the remaining-work trend chart (Section 3).
π Section 3 β Viewing Risk & Evolution
3.1 Table View β Risk Readings in Context
In any table view, as soon as at least one item has a risk reading, its reading is shown inline (impact, likelihood, final result, remaining work, reading date, measures, target, deadline).
- Filter quickly by risk owner, criticality, and other document properties
- Export the visible risk data to Excel for reporting
3.2 Risk Matrix Module
Open Risks β Risk matrix. First select the risk type β the whole view reflects that methodology's matrix, appetite, and colours.
Summary cards
Above the matrix you get an at-a-glance overview:
- Severity distribution of risks
- Remaining work status
- Planned mitigation status
The risk matrix visualization
The matrix shows:
- Appetite ranges as coloured background zones (your configured colours and labels)
- Individual current risk readings plotted on their cell, each marker coloured by its remaining work:
- β¬ Black = nothing done β counts as risk Γ 5 (full remaining work)
- β Green = fully mitigated or accepted β counts as risk Γ 0 (no remaining work)
- intermediate colours for in-progress treatment
Hover over any risk marker to see its Initial / Current / Target risk positions together.
Remaining-work & risk-reduction trend
Below the matrix, a trend chart aggregates all risks over time:
- Orange β remaining work / risk reduction trend (how the outstanding risk is coming down)
- Blue β newly added risks
- Green β all planned risks
The deadline set on a risk's Planning tab is treated as the date by which the risk should be maximally reduced or accepted β i.e. risk Γ 0 for remaining work. Reaching that point means the risk is fully managed, not that it has disappeared.
Export
Below the trend you can export all risk readings, or just the latest reading per risk, for quick Excel reporting.
3.3 Per-Document Risk Evolution (Risk tab)
Open an individual risk document β Risk tab. Here you can visualize every reading done for that risk over time, seeing how Initial β Current β Target evolved with each assessment and how remaining work progressed.
Putting It Together
- Configure a risk type per purpose (CIA, legal, supplierβ¦) β matrix, measures, formula, appetite, registers, methodology, tags.
- Create risks β bulk import from Excel, or use the AI wizards to identify and document them against your assets and controls.
- Score with risk readings (initial / current / target + remaining work).
- Monitor on the matrix, trend chart, table view, and per-document Risk tab β and let review frequencies keep owners on track.
Because every layer is configurable, Brainframe adapts to ISO 27005, EBIOS RM, NIST, ISO 31000, or your own methodology β without changing tools.
For the assets and suppliers that risks attach to, see the Asset Management and Supplier & Third-Party Management guides.
Updated on: 13/07/2026
Thank you!