Risk scoring explained
Everything in the app exists to produce, justify or act on a risk score. This page explains how a score is built.
The three scores
| Score | Means | Answers |
|---|---|---|
| Inherent | Before any controls | How bad would this be if we did nothing? |
| Residual | After the controls you actually have | How bad is it today? |
| Target | After the controls you plan to build | How bad will it be if we deliver the plan? |
The distance between residual and target is your treatment plan. The distance between residual and appetite is your problem.
How a score is built
- A factor is one scored question — for example How many customers are affected? Each answer maps to a score, typically 1 to 5.
- A dimension groups factors and weights them. Impact and Likelihood are the usual two, but you can define others. Weights within a dimension must total exactly 100%.
- The matrix and formula combine the dimensions into a single score.
- Bands turn that number into a label — Low, Medium, High, Critical — and each band carries an obligation, such as executive notification and a seven-day plan.
All four live in an assessment methodology, which a register then uses.
Why appetite is a band, not a number
Appetite is the threshold above which a risk needs a decision rather than just monitoring. It is expressed as a band — everything above High, say — and not as a raw number.
Comparability lives on the methodology. Two registers using the same methodology can have their scores added together. Two using different methodologies cannot: a score out of 25 and a score out of 16 must never be averaged. Because appetite is a band, those two registers can still be compared by counting how many risks sit above appetite in each — which is the comparison an executive actually wants.
Manual and automated residual
Residual score can be set two ways:
- Manual — a person judges it, with the control analytics on screen: total control effectiveness, the reduction from inherent, control health, and the gap to appetite.
- Automated — the factor inputs lock and the score is computed from the mitigation coverage of the attached controls.
Whenever a person overrides the calculated value, the override is marked on the record. That marker is what lets an auditor see where judgement replaced arithmetic, and it should never be removed from an export.