Factors
A factor is one scored question. It owns exactly one job: turning an answer into a number. Find them under Settings → Factors.
Creating a factor
- Select Create factor.
- Name it as the question it asks — Asset criticality, Customers affected, Regulatory exposure.
- Choose the input type.
- Map each possible answer to a score, normally 1 to 5.
- Save.
Input types
| Type | How it is answered | Use for |
|---|---|---|
| Single select | Pick one option | Most factors. Each option carries a score. |
| Multi-select | Pick several | Where multiple conditions compound. |
| Boolean | Yes or no | A single condition — is this internet-facing? |
| Asset field | Read automatically from the selected asset | Anything already recorded about the asset. |
The asset field type
This is the one worth understanding properly. An asset-field factor does not ask the user anything — it reads an attribute off whichever asset was selected earlier on the form, and scores it.
To set one up:
- Create the factor and choose input type Asset field.
- Choose the field that holds the asset — for example Affected application.
- Choose the attribute to read — for example
criticality. - Map the attribute’s values to scores: Tier 1 → 5, Tier 2 → 3, Tier 3 → 1.
What this buys you. The risk manager picks Core Banking in step 1 of the Add Risk wizard, and in step 2 this factor is already answered and already scored. Re-tier that application once, in the asset list, and every risk raised against it from then on scores differently. One edit, applied consistently, forever.
The user can still override the value, and the override is marked.
Where factors are used
A factor does nothing on its own. It becomes part of a score when an assessment methodology puts it into a dimension and gives it a weight — see Assessment methodologies.
Each factor shows which methodologies currently use it. Check that before editing scores: changing a factor changes every methodology that references it, and therefore every register on those methodologies.
Editing a factor in use
Changing the score mapping of a factor that is already in use does not retrospectively rescore existing risks — their captured scores stand. New assessments will use the new mapping, so a register can contain risks scored two different ways. Record when you made the change so the difference is explainable later.