> For the complete documentation index, see [llms.txt](https://intuitem.gitbook.io/ciso-assistant/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://intuitem.gitbook.io/ciso-assistant/concepts/risk/risk-assessments.md).

# Risk assessments

A **risk assessment** (also called a *risk study*) is a scenario-based evaluation of risk over a perimeter. CISO Assistant supports qualitative approaches (configurable risk matrices), quantitative approaches (Monte Carlo over loss distributions), and the structured EBIOS RM methodology.

The platform follows the ISO 27005 risk-management workflow.

![ISO 27005 risk management workflow](https://629777851-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCqFeU3oPCgDWkkR386NK%2Fuploads%2Fgit-blob-c77f11a5da4cf70ef292c09d70c19a8bc74d1648%2Fiso27005.svg?alt=media)

## Mental model

```mermaid
graph LR
  D[Domain] -->|scopes| RA[Risk assessment]
  P[Perimeter] -.->|narrows| RA
  RM[Risk matrix] -->|scales| RA
  RA -->|comprises| RS[Risk scenario]
  RS -->|impacts| A[Assets]
  RS -->|materialises| T[Threats]
  RS -->|mitigated by| AC[Applied controls]
```

A risk assessment always lives inside a **domain** (the mandatory IAM scope) and is bound to one **risk matrix** that supplies the probability × impact scale (the matrix can be swapped later; existing scores are clamped to the new scale). A **perimeter** can optionally narrow the assessment to a specific service or process inside the domain. The assessment is composed of **risk scenarios**; each scenario links to the **assets** it impacts, the **threats** it materialises, and the **applied controls** that mitigate it (split between *existing* and *planned* to drive the three-tier risk model below).

| User-facing     | Internal         | Notes                                                                          |
| --------------- | ---------------- | ------------------------------------------------------------------------------ |
| Risk assessment | `RiskAssessment` | Also called "Risk study" in the UI                                             |
| Risk scenario   | `RiskScenario`   | A row inside the assessment                                                    |
| Risk matrix     | `RiskMatrix`     | Can be changed; existing scenario scores are clamped to the new scale's bounds |
| Domain          | `Folder`         | Required; drives IAM scoping                                                   |
| Threat          | `Threat`         | Catalog entry from a library                                                   |

## Risk assessment

A risk assessment encompasses three steps:

* **Risk identification** — defining the risk scenarios.
* **Risk analysis** — assessing probability, impact, and strength of knowledge for each scenario.
* **Risk evaluation** — done automatically based on the selected risk matrix.

In CISO Assistant, **risk treatment is combined with the risk assessment** rather than tracked as a separate phase.

## Risk scenario

Scenarios can be defined directly from the risk-assessment view or separately via the scenarios view. The same scenario can be reused across multiple studies.

## Risk levels: inherent, current, residual

CISO Assistant tracks three risk levels for each scenario, reflecting where the organisation stands along the treatment journey:

* **Inherent risk** — the natural level of the scenario *without any controls in place*. The starting point. Surfaced in the UI when the `inherent_risk` feature flag is on.
* **Current risk** — the level given the applied controls *already in place*. The state of risk today.
* **Residual risk** — the level expected once all *planned* applied controls have been implemented. The target state, and the figure used in risk-acceptance decisions.

Each level has its own probability, impact, and overall level fields. The assessment's consistency check flags a scenario whose **residual** risk exceeds its **current** risk (on level, probability, or impact), and also flags a residual lowered below current when no applied control justifies the reduction.

## Risk acceptance

Risk acceptance is when an organisation or individual decides to tolerate a certain level of risk without taking further action to reduce it. CISO Assistant provides a workflow to capture formal approval of risk acceptances by management — the approver must hold the **Approver** role.

For the formal definition, see [ISO 31073:2022, term 3.3.32 — risk acceptance](https://www.iso.org/obp/ui/#iso:std:iso:31073:ed-1:v1:en:term:3.3.32).

## Risk matrix

Risk levels are calculated as a function of the probability and impact of a scenario, using a configurable **risk matrix**. Matrices are imported from libraries — pick one of the built-in matrices or define your own via a custom library.

Most organisations define an official matrix to be used for all risk assessments, but CISO Assistant lets you choose a different matrix per assessment when needed. The matrix **can be changed** after the assessment has been created. When you do, each scenario's existing probability and impact values are clamped to the new scale's bounds — a score that falls outside the new range is clipped to the nearest valid value, and unrated scenarios stay unrated. There is no proportional rescaling, so review the scenarios afterwards and correct any score that no longer reflects your intent.

## Related

* [Assets](/ciso-assistant/concepts/assets-and-resilience/assets.md)
* [Applied controls](/ciso-assistant/concepts/operations/applied-controls.md)
* [Vocabulary → Threat / Risk assessment](/ciso-assistant/introduction/vocabulary.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://intuitem.gitbook.io/ciso-assistant/concepts/risk/risk-assessments.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
