Risk Analyses
A Risk Analysis is a formal, documented, point-in-time assessment of threats to your systems and the data they use, following NIST SP 800-30 — a standalone document you can hand an auditor.
This is distinct from the Risk Register: the register is the ongoing ledger of individual AI risks, each linked to the system it is about; a risk analysis is a formal document built from threat scenarios.
This module is being reworked for AI governance; until then it works as
described below.
Building an analysis
Create an analysis with a title, description, and scope (the system boundary it covers), plus a target review date. It starts in draft.
Then add threat scenarios, one per row. Each captures the asset, the threat source and threat event, the vulnerability, the existing controls, and a likelihood and impact (1–5) — the risk score is their product, mapped to a level from very-low to very-high. Record the risk decision (mitigate / accept / transfer / avoid), the recommended controls, the residual likelihood/impact after treatment, and a framework citation (type any reference, or pick a NIST AI 600-1 risk from the list).
Lifecycle & export
An analysis moves draft → in review → approved → archived, with fields for who prepared, reviewed, and approved it. Print / PDF produces an audit-ready version of the finished document. There's no automatic recurrence — set a review date and revisit it on your own cadence (annually is typical).
Who can do what
Creating, opening and editing risk analyses is org-admin only. Other members see the list of analyses; an auditor sees it only when their link grants the risk register scope. The document is meant to be authored deliberately, not generated — you enter the threat scenarios that reflect your environment.