, 07/04/2026

Risk Management is Performance Management

By Xander Venske
Risk Management is Performance Management

A White Paper on the Case for Mathematically Traceable Residual Risk

Foreword

Risk Management is Performance Management is a white paper written for risk practitioners: for the professionals who own the register, facilitate the workshops, defend the ratings to the audit committee, and quietly know that the numbers they are presenting do not mean what everyone in the room believes they mean.

The purpose is not to critique the profession. It is to name a structural problem that most Enterprise Risk Management (ERM) practitioners already recognise, and to show that it is solvable.

A note on scope. Axiom Risk is deliberately scoped. It is not designed to replace actuarial modelling, probabilistic quantification, or the specialist risk frameworks required in sectors such as banking, insurance, or capital markets. It is designed for the organisations that need it most: those without specialist quant functions, without actuarial teams, and without the budget or internal expertise to build bespoke risk models from scratch. For those organisations, a traceable, derived, and continuously updated residual score is not a simplified version of a more complete model. It is a complete solution to the problem they actually have. Expanding the model to include variable inherent scoring, probabilistic loss distributions, and correlation modelling would also expand the judgment points, specialist assumptions, and expertise requirements that currently put rigorous ERM out of reach for most organisations. Scope is a design decision, not a gap.

1. The Problem with Residual Risk

Ask any experienced risk manager what residual risk means, and the answer will be consistent: it is the risk that remains after controls have been applied.

Ask them how it is calculated, and the answer becomes less consistent.

In qualitative ERM practice, which remains the dominant implementation model across most organisations and sectors, residual risk is not calculated. It is estimated. An analyst reviews the controls in place, forms a view on how well they are working, and then manually re-rates the residual likelihood and impact on a qualitative scale. The residual score that flows from this process is the analyst’s opinion, expressed in numbers. The ISACA Journal (2022)1 confirms that qualitative risk assessments, using predefined high, medium, and low ratings, remain the standard component of most enterprise risk assessments across industries.

This is not a practitioner failure. It is a methodology gap. The major frameworks do not mandate this approach, but they do not close it either.

ISO 31000:2018 specifies that risk analysis should consider the effectiveness of existing controls, but does not prescribe a mechanism for translating control effectiveness into a residual rating. COSO ERM 2017, one of the most widely adopted corporate governance standards globally, allows for quantitative approaches but in practice directs analysts to assess the degree to which the risk response has reduced inherent risk (a judgment call, not a calculation, in most implementations). NIST RMF, COBIT 2019, and RIMS all leave the same gap open: the link between how a control performs and what the residual rating should be is left to the implementing organisation to resolve. Most do not resolve it.

The consequence is not merely academic.

  • Residual risk scores that reflect analyst opinion rather than control evidence cannot be reliably compared across the register. Two analysts rating the same risk, reviewing the same controls, may arrive at materially different residual scores. When those scores sit side by side in a board report, they appear equivalent. They are not. Douglas Hubbard’s research into qualitative risk assessment methods, documented in The Failure of Risk Management (Wiley, 2nd ed., 2020), demonstrates that qualitative risk matrices produce inconsistent inter-rater results and that the terms used to describe probability and impact carry different meanings for different assessors, compounding the inconsistency.
  • Residual risk scores that are decoupled from control performance cannot update automatically. When a control fails, degrades, or is withdrawn, the risk rating should deteriorate immediately and visibly. In practice, it stays where the last analyst left it until the next review cycle (which may be months away).
  • Residual risk scores that are not derived from control evidence cannot be independently verified with mathematical traceability. An auditor can verify that a process was followed and that a rating was assigned. What cannot be verified is whether the number is correct, because there is no calculation to check. When a regulator or board member asks why a particular risk is rated as it is, the only available answer is: because the analyst assessed it that way. That is not a defensible position for a governance instrument.

The profession has named this gap without fully resolving it. The result is a generation of risk registers that function as reporting artefacts rather than management tools.

2. Why the Standard Answer Does Not Work

The conventional response to the subjectivity problem is process discipline. More structured assessment workshops. More detailed rating criteria. Mandatory calibration sessions between analysts. More frequent review cycles.

These measures reduce inconsistency at the margins. They do not solve the problem.

The problem is structural. As long as an analyst is required to look at the controls and then re-rate the residual likelihood and impact, the rating will carry that analyst’s assumptions, risk appetite, and in-the-room pressures. Calibration sessions are generally understood to reduce the variance between analysts. They cannot eliminate the judgment, because the judgment is what the methodology requires.

The deeper issue is that likelihood and impact ratings, as applied in qualitative matrices, are doing two jobs simultaneously and doing neither well.

The first job is to characterise the risk: to describe what kind of event this is, how frequently it might occur, and how damaging it could be. This is useful context. It belongs in the risk description.

The second job is to measure the current state of the organisation’s exposure: to reflect, in a number, how much residual risk remains given the controls in place. This is the governance function. This is what the board needs. And this is the job that qualitative likelihood and impact ratings, applied by an analyst after reviewing controls, cannot perform with any mathematical consistency.

When the same scale does both jobs, neither job gets done properly. The characterisation becomes contaminated by the control assessment, and the exposure measurement becomes contaminated by the characterisation.

Separating these two functions is the starting point for a different approach.

3. A Different Approach: Risk Management as Performance Management

If the purpose of a residual risk score is to measure the current state of the organisation’s exposure, then the only input that should drive it is the current state of the organisation’s controls.

Not an analyst’s interpretation of the controls. The controls themselves.

This reframe is the foundation of Axiom Risk: Risk Management is Performance Management. The only variable in a risk management system that can be actively managed is the performance of controls. Everything else (the risk description, the inherent severity, the causal pathway) is context. Context informs decisions. Performance drives the score.

This is not a radical idea. It is a principled operationalisation of what ISO 31000:2018 already states: that the purpose of risk management is to create and protect value through the management of uncertainty as it affects the achievement of objectives. ISO 31000 permits diverse analysis methods; Axiom Risk is one disciplined response to the question of how control performance should connect to residual risk measurement.

Axiom Risk operationalises this principle through a mathematically closed calculation chain.

This is also an important point about risk management maturity. ISO 31000:2018 is not the problem. It is a deliberately principles-based standard, designed to serve any organisation regardless of sector, size, or stage of development. A younger organisation can implement it at a qualitative scale, applying basic likelihood and impact criteria, and derive genuine governance value from that starting point. As the organisation matures its risk practice, the methodology can develop with it.

The shift to a control-performance model is not the natural next step on the same path. It is a deliberate methodological reframe. The organisation stops asking “how likely is this and how bad would it be?” and starts asking “how well are our defences performing?” Those are different questions, and they produce different governance instruments. The first produces a picture of what analysts fear. The second produces a continuous measure of the organisation’s actual defensive capability. Making that shift requires intent. It changes the posture of the entire risk function from reactive to proactive.

4. The Calculation Chain

The Axiom Risk methodology links five calculation nodes in an unbroken chain from control assessment to objective-level exposure. No human re-rating is inserted at any point. The chain is closed in the sense that once the control assessment is recorded, the residual score is derived automatically without further human interpretation. The quality of the outputs is, however, dependent on the quality of the register architecture established during onboarding: the completeness of the control inventory, the accuracy of the contributing factor structure, and the correct application of design principles such as the isolation of single-point-of-failure controls. A well-designed register produces outputs that are both traceable and meaningful. A poorly designed one produces outputs that are traceable but may not reflect the actual risk structure. This is why the onboarding engagement is a critical phase of any Axiom Risk deployment.

Axiom Risk: the calculation chain No human re-rating is possible between assessment and risk category CER Applied rating CES Numeric score %AC / %RE Weighted cover RRS IRS × %RE Level L · M · S · H CRC reliability rank Control category weighting CF criticality rank Contributing factor weighting Risk criticality rank Risk-level weighting CER = Control Effectiveness Rating · CES = Control Effectiveness Score · %AC = Assurance Cover · %RE = Risk Exposure RRS = Residual Risk Score · IRS = Inherent Risk Score (fixed at 25 for all risks by design)

4.1 The Five Nodes

Node 1: Control Effectiveness Rating (CER)
Each control is assessed against a defined ten-level rating scale, from No Controls (producing a CES of 0%) to Excellent (producing a CES of 90%). The scale uses equal 10-percentage-point intervals by design. Equal intervals were chosen for accessibility and transparency: a scale where each step represents the same increment is easier to apply consistently and harder to game than one with non-linear spacing. The ten levels provide finer discrimination between control performance states than a five-level scale, making the downstream %AC calculation more sensitive to realistic changes in control effectiveness. The scale does not reach 100% by design. Some degree of uncertainty always remains in any control environment, and a control rated at the top of the scale warrants scrutiny: it may indicate over-control, where more resources are being committed to this risk than the exposure justifies. The rating is applied by assessors through the structured voting mechanism described in Section 5.1. This is the only assessment judgment applied during the ongoing operation of the calculation chain. It is explicit, documented, and traceable. Three other human judgments feed into the calculation chain as design-time configuration decisions: the CRC Reliability Rank assigned to each control category, the Criticality Rank assigned to each Contributing Factor, and the Risk Criticality Rank assigned to each Risk relative to its parent objective. These are structural judgments made during onboarding and governed as register architecture decisions rather than applied repeatedly during operation. The distinction between these one-time configuration judgments and the recurring assessment judgment is explained in Node 3 of Section 4.1 and in Section 4.4.

Node 2: Control Effectiveness Score (CES)
The CES is the numeric score corresponding to the applied CER. When an assessment is completed, the CES is automatically written to the control record. This is the point at which the human judgment is converted to a number that propagates downstream without further interpretation.

Node 3: Assurance Cover (%AC) and Risk Exposure (%RE)
Contributing Factors sit between controls and risks. In the terminology of ISO 31073:2022, a Contributing Factor corresponds to a risk driver: a factor that has major influence on how a risk materialises. It is not a risk source (which sits further upstream, generating the risk itself), not the risk event (which is the realisation of harm), and not a sub-risk (which would independently threaten an objective). A Contributing Factor is a structural causal pathway: a mechanism through which the risk can materialise if controls fail to contain it. The scoping test during register design is: if this pathway were completely addressed through effective controls, would the risk be materially less likely to cause harm to this objective? If yes, it warrants its own Contributing Factor record.

Each Contributing Factor calculates a weighted average of the CES values of all linked controls, where each control’s CES is weighted according to the reliability of its Control Resource Category (CRC) Reliability Rank. This weighted average becomes the %AC for that factor: the proportion of causal exposure currently covered by controls, adjusted for how reliably those controls can be expected to perform. %RE (Risk Exposure) is the complement: 1 minus %AC.

The CRC Reliability Rank is applied once, at the Contributing Factor level. The weighted %AC values produced there then aggregate upward. At the Risk level, %AC is a weighted average of %AC across all linked Contributing Factors, where each Contributing Factor carries a Criticality Rank (1 to 5) reflecting its relative significance as a causal pathway to this risk. A Contributing Factor that represents the dominant causal mechanism carries a higher rank than a minor or supporting pathway. The default rank is 3 (moderate) until the organisation configures it during onboarding, which means the model degrades gracefully to a standard average when criticality has not yet been assessed. At the Objective level, %AC is a weighted average of %AC across all linked Risks, where each Risk carries a Risk Criticality Rank (1 to 5) reflecting its relative significance to the objective. A risk that represents the dominant threat to an objective carries a higher rank than a supporting or minor risk. The default rank is again 3 (moderate), producing a standard average until the organisation configures it. This completes a consistent three-level weighting hierarchy: CRC Reliability Rank at the control level, CF Criticality Rank at the contributing factor level, and Risk Criticality Rank at the risk level. All three levels use the same ordinal 1-5 ranking logic and the same weighted average formula. The CF Criticality Rank and Risk Criticality Rank share the same default behaviour: both default to rank 3, producing a standard average until the organisation configures them during onboarding. The CRC Reliability Rank does not have a default in the same sense: it is structurally assigned per CRC category at onboarding and fixed thereafter (Technologies = 5, Systems = 4, Tools and Equipment = 3, Processes = 2, People = 1).

The Criticality Rank is an ordinal judgment made during register design, not a calculation output. It acknowledges that not all causal pathways are equally significant to a risk’s materialisation, and that simple averaging across Contributing Factors could misrepresent the risk structure where one pathway dominates. Like the CRC Reliability Rank, the Criticality Rank is a declared, documented, and governable assumption: visible rather than hidden.

Node 4: Residual Risk Score (RRS)
RRS = IRS x %RE. IRS (Inherent Risk Score) is fixed at 25 for all risks.

Node 5: Risk Category
The RRS is mapped automatically to a qualitative category (Low, Medium, Significant, High) using the Risk Matrix criteria table. This is the output that appears in board reports and dashboards.

4.2 Why IRS is Fixed at 25

The decision to fix inherent risk at 25 for every risk in the register is intentional and principled.

By the time a risk is identified and documented, there is already a high probability that some form of control or mitigation is in place. The true inherent state (the exposure that would exist in the complete absence of any control) is, in most cases, not observable. Attempting to rate it produces a number that reflects assumption rather than evidence.

More fundamentally: all risk is undesirable. The register should not create a structural advantage for some risks over others by assigning them a lower starting point. Using the analogy of a race, every risk runs the same distance. The only legitimate differentiator is how well the controls perform.

A fixed IRS means that a risk can only improve if its controls improve. A risk cannot drift into an acceptable category through reassessment alone. This is the integrity mechanism that the closed chain requires.

The question a sceptical practitioner will raise is: how does a board distinguish between a catastrophic risk and a minor one if both start at 25? The answer is that the distinction sits at several other points in the system. First, each risk carries a Risk Category drawn from a configurable set (Strategic, Operational, Financial, Legal, Compliance, Reputational, Social/Community) that classifies the domain and nature of the risk. Second, the risk description and contributing factor structure communicate the scale and causality of the risk in plain language. Third, and most importantly, the Monetary Consequence Value (MCV) at the objective level expresses the financial scale of what is being protected in declared monetary terms. A board can see immediately that one objective carries an MCV of R50 million and another carries R500,000. Where multiple risks sit under the same objective and share the same MCV, Risk Category and risk description carry the differentiation burden that the fixed IRS deliberately does not. The size of the exposure and the nature of the risk are visible; they are simply not embedded in the IRS, where they would reintroduce the subjectivity the rest of the methodology is designed to remove.

4.3 The Monetary Dimension

Axiom Risk extends the calculation chain to include a monetary consequence layer at the objective level.

Each objective may carry a Monetary Consequence Value (MCV): the governance-agreed financial consequence of that objective failing entirely. This is not a probabilistic loss estimate. It is a declared value: what the organisation has agreed this objective is worth protecting. The process of setting MCV is itself a governance judgment, not a calculation, and organisations should treat it as such. For objectives where a monetary value cannot be meaningfully declared (reputational, safety, or compliance objectives, for example) a qualitative consequence descriptor may be used alongside or instead of a monetary figure to provide the board with an equivalent governance anchor.

From the MCV, two derived values calculate automatically:

  • MCV Protected: MCV x %AC (the monetary value currently covered by controls).
  • MCV Residual: MCV x %RE (the monetary value still exposed).

Action Cost is captured on each improvement action and aggregates upward through controls, Contributing Factors, risks, and objectives to produce a Total Action Cost at the objective level. This enables a direct comparison between the cost of control improvement and the monetary exposure being reduced: a return on risk investment calculation that any finance committee or board can evaluate. The calculation is as follows: before an action is completed, MCV Residual = MCV x %RE. When an action improves a control’s CES, %AC increases and %RE decreases, producing a new, lower MCV Residual. The reduction in MCV Residual (before minus after) represents the monetary exposure recovered by the action. The return on risk investment is therefore: RORI = (MCV Residual before – MCV Residual after) / Total Action Cost. Where RORI exceeds 1, the monetary exposure recovered exceeds the cost of the action. Where MCV has not been declared for an objective, RORI is expressed as a directional comparison rather than a monetary ratio.

4.4 CRC Reliability Weighting

Not all controls are equally reliable. A policy document and an automated detection system may both be rated as Good controls, but their likelihood of performing consistently at that level is materially different. The policy depends entirely on a person reading it, remembering it, and choosing to follow it under operational pressure. The automated system operates whether or not anyone is paying attention.

Axiom Risk formalises this distinction through CRC Reliability Rankings assigned to each Control Resource Category. The ranking draws on the principle underlying the Hierarchy of Controls: a concept from operational risk management and occupational health and safety that orders interventions by how much they depend on human behaviour to function. Axiom Risk applies this principle to the five CRC categories, ranking them ordinally from most to least reliable based on the degree of human involvement required during execution. The CRC taxonomy and the OHS hierarchy use different category structures; the principle being borrowed is the reliability ordering concept, not the specific taxonomy.

The five CRC categories and their assigned reliability ranks are:

Control Resource CategoryReliability RankBasis
Technologies5Fully automated. Operates independently of human behaviour during execution. The technology monitors, detects, or acts on its own; human involvement is only triggered when the technology flags an exception.
Systems4Software-driven but requires a person to actively use it. The system supports the control; a person still drives it. Reliable when used correctly; dependent on that use occurring.
Tools and Equipment3Physical and inspectable, but requires correct human operation to function as intended.
Processes2Written direction only: policies, procedures, plans, and contracts. Entirely dependent on human compliance to function. A process on paper cannot act.
People1Training, awareness, and behaviour. The most variable control type. People are governed by Process, not self-governing, and are subject to error, absence, and pressure.

The dependency chain runs in one direction: Technologies and Systems are put in place by People, acting under the direction of Processes. People require Processes to govern their behaviour. Tools and Equipment enable People to perform their work. Without the higher-ranked controls anchoring the control environment, the lower-ranked controls carry an exposure that an unweighted average would conceal.

In practical terms, the weighted average at the Contributing Factor level is: the sum of (CES multiplied by the CRC Reliability Rank of the linked control’s category) for each linked control, divided by the sum of those Reliability Ranks. The rank is a property of the control category, assigned at onboarding; the weighting calculation is performed at the Contributing Factor level when aggregating linked control CES values into %AC. A Technologies control (rank 5) rated at 70% CES contributes five times more to the %AC of its Contributing Factor than a People control (rank 1) rated at the same 70%. This reflects the material difference in reliability: the automated control will perform at that level more consistently than one that depends on a person choosing to act correctly under operational pressure.

This ranking does not change the structure of the calculation chain. Every node functions identically. The only change is that the aggregation at the Contributing Factor level now reflects the reliability of the control environment, not merely its average assessed effectiveness.

The ranks themselves are principled design choices grounded in the reliability ordering principle of the Hierarchy of Controls, not empirically derived constants. They represent an ordinal judgment: Technologies are more reliable than Systems, Systems more reliable than Tools and Equipment, and so on. The equal intervals between ranks (1, 2, 3, 4, 5) are a deliberate simplification that keeps the model transparent and configurable. Organisations may review and adjust them through governance agreement to reflect their specific operating context, industry norms, or risk profile. What matters is that the ranks are declared, documented, and applied consistently: visible assumptions, not hidden ones.

4.5 Risk Appetite

The calculation chain produces a Residual Risk Score and a Risk Category for every risk in the register. A category output of Low, Medium, Significant, or High describes where the risk currently sits. Risk appetite answers a different question: which of those positions is acceptable to the organisation, and which requires action?

Axiom Risk implements risk appetite at the category level through a governance-declared Appetite Threshold on the Criteria: Risk Matrix table. Each Risk Category carries one of three appetite positions:

Appetite ThresholdDescription
TolerableThe residual risk position is within the organisation’s accepted range. Existing controls are sufficient. Monitoring continues but no escalation is required.
CautionThe residual risk position requires attention. Controls should be reviewed, improvement actions considered, and ownership confirmed. This position warrants management-level visibility.
IntolerableThe residual risk position exceeds the organisation’s tolerance. Treatment action is required. This position demands escalation to the appropriate governance level and formal treatment response.

Appetite thresholds are configured once at the organisational level, not set risk by risk. Every risk that calculates to a given category automatically inherits the appetite position declared for that category. This means risk appetite is always visible alongside the RRS output, and any change in a risk’s category (triggered by a change in control performance) immediately updates the appetite signal without any human re-rating.

Risk appetite in Axiom Risk is a governance declaration, not a calculation. The organisation’s leadership and board agree which residual risk positions are acceptable and which are not, and that agreement is recorded in the Criteria table. The calculation chain then reports continuously against those declared thresholds.

4.6 Likelihood as Contextual Information

One question Axiom Risk does not answer through the calculation chain is: how frequently might this risk materialise? This is a deliberate choice. Introducing likelihood as a calculation input would reintroduce the estimation problem the methodology is designed to solve: who rates the likelihood, on what basis, and how is it updated when circumstances change? The moment likelihood enters the formula, an additional judgment point is created, and the residual score becomes partially dependent on an estimate rather than entirely dependent on measured control performance.

However, likelihood is not irrelevant. It informs how urgently a risk should be assessed, how frequently controls should be reviewed, and how a risk should be described to the board. For this reason, Axiom Risk captures likelihood as a contextual indicator on the Risk record: a declared, qualitative frequency band that sits alongside the RRS without entering the calculation.

The five Likelihood Indicator levels are:

Likelihood LevelLevel Description
Almost CertainThe risk is expected to materialise under current conditions. Assessment and control review should be continuous.
LikelyThe risk will probably materialise in the short to medium term. Assessment cadence should be high.
PossibleThe risk may materialise. Standard assessment cadence applies.
UnlikelyThe risk is not expected to materialise under current conditions but cannot be dismissed. Standard or reduced assessment cadence.
RareThe risk is only conceivable under exceptional circumstances. Reduced assessment cadence with periodic review.

The Likelihood Indicator informs the frequency of control assessments and the urgency of treatment actions. It informs board narrative and contextual communication. It does not affect the RRS. A board reviewing a risk register can see both the RRS (what the controls are currently delivering) and the Likelihood Indicator (how often this risk is expected to occur) and use both for governance decisions. The two signals are complementary, not competing.

4.7 The Risk Horizon

The calculation chain described in Sections 4.1 through 4.6 measures how well the organisation’s controls are performing against risks already in the register. It does not detect changes in the external environment. A regulatory shift, a geopolitical development, a sector disruption, or an emerging technology threat that has not yet entered the register produces no signal in the calculation chain. The organisation’s residual scores can remain stable and favourable while the threat landscape changes materially around them.

ISO 31000:2018 clause 6.3 requires that the organisation understand and monitor the external and internal context as the basis for risk identification and criteria-setting. The Risk Horizon is the operational implementation of that requirement: a governed pre-registration intelligence layer that continuously scans the external environment, captures signals of potential emerging risk, and provides a traceable pathway from first detection to formal adoption into the risk register.

The scanning mechanism.
An automated scanning service runs on a configured schedule against a curated and client-configurable set of external intelligence sources. The source list is maintained in the system and activated per deployment: each organisation enables the sources relevant to its sector, geography, and regulatory environment, and supplements them with a configurable keyword list. Scan results are evaluated by an AI layer that assesses relevance against the organisation’s registered Objectives, classifies the signal source category, generates a plain-language description of the potential risk pathway, and checks the incoming signal against previously dismissed records before creating a new entry. A manual capture path operates in parallel for signals that practitioners identify directly and that the automated scan may not surface. Every signal, regardless of how it entered the system, passes through the same governed lifecycle.

The signal lifecycle.
Every signal enters the system at Unreviewed status. AI-generated records are visible only to the Risk Champion pending human confirmation. The Risk Champion promotes genuine signals to Monitoring, assigns an owner, and establishes a review cadence proportional to the declared Signal Strength. Signals assessed as Almost Certain are reviewed on a short cycle; signals at Rare are reviewed periodically. The AI layer provides a suggested Signal Strength alongside the human-declared value. Where the two differ materially, the discrepancy is surfaced as a governance prompt. The human-declared value is authoritative in all downstream logic.

Axiom Risk Horizon: signal lifecycle From detection to formal risk record Automated scan AI-classified signal Manual capture Practitioner input Unreviewed Visible to Risk Champion only Monitoring Champion promotes signal Champion reviews Adopted Risk record created Dismissed History retained Governance decision Future match: re-flagged Re-flagged if matched On adoption, the signal links to a formal Risk record and the risk enters the calculation chain. Dismissed signals are retained for audit.

Signals that strengthen over the monitoring period are escalated formally to governance for an adoption decision. When a signal is Adopted, a formal Risk record is created, linked to the originating Horizon record, and the risk enters the calculation chain. The Horizon record remains permanently in the system. Dismissed signals are retained with their full history. When a future scan produces a result closely matching a Dismissed signal, the match is flagged automatically, requiring a conscious reactivation review rather than allowing the same threat to be dismissed without scrutiny a second time.

Where this sits in the architecture.
The Risk Horizon table sits outside the calculation chain. Horizon records carry no %AC, %RE, or RRS. They are not scored. They are governed. The adoption decision is the threshold between the intelligence layer and the risk register: the moment at which a detected signal becomes a formal risk with a defined causal structure, linked controls, and a live calculation. The Horizon record preserves the full provenance of that risk from its first appearance as an external signal to its entry into the governed register.

This operationalises the ISO 31000:2018 clause 6.3 requirement systematically rather than through practitioner initiative. The external context is continuously monitored. Signals are governed through a documented lifecycle. When they cross the threshold into the formal register, they do so through a traceable adoption decision, and the calculation chain then produces a residual score derived entirely from control performance against the updated risk architecture.

5. The Assessment Architecture

The separation of the assessment from the control record is a deliberate and important architectural decision.

In many ERM tools, control effectiveness is rated directly on the control record. This creates two problems. First, the control record holds only one score at a time (the current one). Historical assessments, if they are tracked at all, require separate records or workarounds. Second, if a control is linked to planned future assessments, a zero or placeholder score can contaminate the current calculation.

Axiom Risk uses a dedicated Assessments table as the calculation layer.

Each assessment is a standalone record, linked to the control being assessed, with a date, a CER, a CES, the assigned assessor, participants, notes, and linked evidence. When the assessment is marked complete, an automation writes the CES to the control record. The control record holds only the most recent completed score. Historical assessments are preserved in full in the Assessments table.

This architecture enables:

  • Full historical tracking without affecting the current calculation.
  • Multi-party assessment through a structured voting mechanism where multiple assessors rate independently and the consensus drives the CES.
  • Planned future controls recorded without contaminating present calculations: a future control with no completed assessment holds no CES score and is excluded entirely from the weighted average at the Contributing Factor level. Neither the numerator nor the denominator of the %AC calculation includes a control until its first assessment is completed and a CES value is written to its record.
  • Complete auditability: every change in a residual risk score is traceable to a specific assessment record, with a date, the assessors involved, their ratings, and an evidence trail.

5.1 Control Assessment Voting and the Governance of Judgment

A legitimate challenge to any control-effectiveness-driven model is that the CER applied at Node 1 is still a human judgment. This is true, and Axiom Risk does not claim otherwise. What it claims is more precise: that the judgment is isolated to a single, documented, and governed point in the process, and that it cannot cascade into a second re-rating downstream.

In traditional ERM, there are three judgment points. The first is setting the Inherent Risk Score: assessors estimate the likelihood and consequence of the risk in the absence of controls, producing a score on the qualitative matrix. The second is the control assessment: assessors review each control and form a view of how well it is performing. The third is the residual risk re-rating: having reviewed the controls, assessors then independently re-rate the residual likelihood and consequence based on their interpretation of the control picture. These three judgments are typically made in a risk workshop with participants from various departments. That is good governance practice. What it does not change is the structural problem: the third judgment (the residual re-rating) is not derived from the second (the control assessment). It is a separate opinion formed after reviewing the evidence, not a calculation from it. It is also structurally invisible in most registers: the register records the residual score, not the reasoning behind it.

Axiom Risk eliminates the first judgment point entirely by fixing IRS at 25 for all risks. It eliminates the third judgment point entirely by deriving residual risk mathematically from control performance. And at the one remaining operational judgment point, the control assessment, it replaces the workshop opinion with a structured, multi-party voting mechanism.

Multiple assessors rate the same control independently. Every participant’s individual rating is documented. The consensus rule is declared in advance. The default consensus rule is the median of all submitted ratings. The median is used rather than the mean because it is resistant to outliers: a single assessor rating a control at No Controls while four others rate it as Good will not pull the consensus disproportionately downward. The median reflects the central tendency of the assessment panel rather than being distorted by any single view. Where combined assurance levels are configured, a weighted median is applied: votes are weighted by the assurance level of the assessor before the median is determined, so that contributions from different lines of assurance are formally distinguished rather than treated as equivalent. Assessor assurance levels are declared on the Interested Party Directory record for each title. The output in either case is traceable to named people with named roles. That is not subjectivity relocated. That is subjectivity governed.

This aligns directly with King IV’s three lines model and the Combined Assurance principle: different assurance providers bring different perspectives on control effectiveness, and the governance outcome should reflect all of them rather than defaulting to the view of the most senior person in the room.

5.2 Assessment Frequency and Staleness

The model’s continuous recalculation depends on the currency of its inputs. A control assessed 18 months ago carries the same CES as one assessed yesterday. Axiom Risk addresses this through three complementary mechanisms.

The first is a configured assessment frequency on each control record. Organisations set the required assessment cadence per control (daily, weekly, monthly, quarterly, bi-annually or annually) based on the criticality of the control, the Likelihood Indicator of the risks it addresses, and the governance requirements of the organisation. This cadence drives automated notifications to the relevant assessors and control owner when reassessment is due.

The second is a staleness flag. When a control has not been reassessed within its configured frequency window, it is flagged as stale on the Controls Dashboard and in reporting. A stale control does not lose its CES score automatically, but its staleness is visible to risk managers, control owners, and governance reviewers. The Last Assessed date on every control record makes the age of every input to the calculation chain auditable.

The third is optional score decay, activated by governance agreement. Organisations that wish to reflect the degradation of unassessed controls in the calculation chain may configure a decay rate: after a defined overdue period, the CES of a stale control begins to decline at a governance-agreed rate until it reaches zero or until a new assessment is completed. The decay rate is an organisational decision, not a methodology constant, and should be set based on the organisation’s understanding of how quickly unmonitored controls degrade in their specific environment. This mechanism is optional because not all organisations will have the operational context to set a meaningful decay rate. Where it is not activated, the staleness flag serves as the governance prompt.

6. ISO 31000:2018 Alignment

Axiom Risk is built on ISO 31000:2018 as its governing standard. The standard is organised around three pillars: Principles (clause 4), Framework (clause 5), and Process (clause 6). The sections below confirm how Axiom Risk addresses each.

6.1 Principles (Clause 4)

ISO 31000:2018 establishes eight principles that effective risk management must embody. The table below confirms how the Axiom Risk methodology addresses each.

ISO 31000 PrincipleAxiom Risk Implementation
IntegratedObjectives, risks, contributing factors, controls, and assessments form a single connected data chain. Risk management is embedded in the operational cycle, not maintained as a separate exercise.
Structured and comprehensiveThe base provides a complete, consistent structure from objective to treatment action. No gaps exist in the chain between control performance and residual exposure.
CustomisedCriteria tables (CRC, Organisational Levels, Treatment Types) are configurable per organisation. The methodology is fixed; the context adapts.
InclusiveThe Interested Party Directory captures all relevant stakeholders. Ownership is assigned to titles, not individuals, ensuring continuity through personnel change. Actions, assessments, and ownership are traceable throughout.
DynamicResidual risk recalculates automatically as control assessments are completed. The register is never static between review cycles.
Best available informationControl effectiveness scores are derived from structured, documented assessments (not estimates). CES values flow directly into the residual calculation without reinterpretation.
Human and cultural factorsOwnership by title supports continuity. The voting mechanism captures diverse assessor perspectives. The Interested Party Directory includes representative bodies and union structures where relevant.
Continual improvementThe Actions table provides the mechanism for control improvement and gap closure. Treatment decisions are recorded, traceable, and linked to monetary impact.

6.2 Framework (Clause 5)

The ISO 31000:2018 framework describes the organisational conditions under which risk management operates: leadership and commitment, design, implementation, evaluation, and improvement. Axiom Risk is designed to operate within and reinforce this framework.

Leadership and commitment are expressed through the Objectives table, which requires that governance-agreed organisational objectives are formally registered as the anchor point of the entire risk chain. Risk management cannot begin in the system without declared objectives. This places accountability for the risk management foundation with those who own the objectives: executive leadership and the board.

Design is reflected in the Interested Party Directory and the Criteria tables. The system requires the organisation to define who its interested parties are, how controls are categorised by resource type, how organisational levels are structured, and what treatment types are available. These configuration decisions shape the entire system and must be made deliberately during the design phase of deployment.

Implementation is supported through the interface structure, which presents each user with only the records and actions relevant to their role. Risk Owners, Control Owners, and Risk Champions each interact with a purposefully scoped view of the system. Implementation does not require risk management expertise from every user; the interface guides behaviour through structure.

Evaluation is continuous rather than periodic. Because residual risk recalculates automatically from control assessments, the organisation’s risk position is always current. The dashboards provide the governance-level view at any point in time, not only at scheduled review dates.

Improvement is operationalised through the Actions table. Every improvement action is linked to a specific control, contributing factor, or risk, with an assigned owner, a due date, and a cost. The aggregation of action costs to the objective level makes the investment case for improvement visible and comparable against MCV Residual.

6.3 Process (Clause 6)

The ISO 31000:2018 process comprises seven activities: communication and consultation; scope, context, and criteria; risk assessment (identification, analysis, and evaluation); risk treatment; monitoring and review; and recording and reporting. The Axiom Risk interface is structured explicitly to support each of these activities in sequence.

Communication and consultation (clause 6.2) are supported through the Interested Party Directory, which registers all internal and external parties relevant to the risk management process. The assessment voting mechanism provides a formal, documented channel through which multiple stakeholders contribute to control effectiveness ratings. Assessment records capture all participants, creating a traceable record of who was consulted in each evaluation.

Scope, context, and criteria (clause 6.3) are established through the Context section of the interface. The Objectives page formalises the organisational context by requiring that objectives are registered, described, assigned to an organisational level, and owned before risk identification begins. The Criteria tables (CER scale, CRC taxonomy, Treatment Types, Risk Matrix, Organisational Levels) define the measurement and classification framework that will be applied consistently across the register. The ongoing monitoring of the external context required by clause 6.3 is operationalised through the Risk Horizon, described in Section 4.7: a continuously running intelligence layer that scans the external environment, governs detected signals, and provides the traceable pathway through which emerging external risks enter the register.

Risk identification (clause 6.4.2) is supported through the Risks and Contributing Factors pages. Each risk is defined as the negative effect of uncertainty on a specific objective. Contributing Factors capture the causal pathways through which the risk can materialise, providing the granular layer that connects the risk to its controls. This two-layer structure (risk and contributing factor) produces a richer and more actionable identification record than a flat risk description alone.

Risk analysis (clause 6.4.3) is the calculation chain described in Section 4 of this white paper. The analysis is not assessors’ judgment applied after the fact; it is the mathematical output of the CES values flowing from completed control assessments through contributing factors to the risk and objective level. The analysis is continuous, automatic, and fully traceable.

Risk evaluation (clause 6.4.4) is supported through the Risk Criteria table, which maps every RRS value from 1 to 25 to a risk category (Low, Medium, Significant, or High) and a corresponding %RE value. The risk category is updated automatically when the RRS changes. No manual categorisation is required. The Risks Dashboard and Objectives Dashboard present the evaluated risk position at summary and detail level for governance review.

Risk treatment (clause 6.5) is managed through the Actions and Treatment Decisions pages. Mitigating actions (linked to controls or contributing factors) represent the decision to invest in control improvement. Formal treatment decisions (Accept, Transfer, Avoid, Escalate) are recorded as separate records linked to the risk, with the treatment type drawn from the Criteria: Treatment Types table. The two surfaces are deliberately separated: improvement actions drive %AC upward through the calculation chain; formal treatment decisions are governance positions that sit outside the calculation.

Monitoring and review (clause 6.6) are continuous by design. Because residual risk recalculates automatically from the most recent completed assessment for each control, the register reflects the current state of the control environment at all times. The Last Assessed field on each control record makes it immediately visible when a control has not been assessed within an expected period, prompting review without requiring a scheduled audit cycle.

Recording and reporting (clause 6.7) are delivered through the Reporting section of the interface: the Objectives Dashboard, Risks Dashboard, and Controls Dashboard. These three views provide the board and governance layer with a current, objective, and auditable summary of the organisation’s risk position. Every number on every dashboard is derived from the same unbroken calculation chain. There are no manually entered summary figures.

ISO 31000:2018 is deliberately flexible. It does not prescribe a single implementation approach, and that flexibility is a design strength that allows the standard to serve organisations across every sector, size, and maturity level. Axiom Risk is one specific implementation choice within that flexibility, and it carries deliberate trade-offs: likelihood and impact ratings are absent by design, inherent risk is fixed rather than variable, and residual risk is derived entirely from control performance rather than from a combination of threat characterisation and control assessment. These are not oversights. They are the choices that make the methodology honest, governable, and accessible. Different implementation choices will suit different organisations and different risk cultures. Axiom Risk does not claim to be the only valid response to ISO 31000. It claims to be a rigorous and principled one.

7. What Axiom Risk Does Not Do

A methodology document that does not acknowledge its boundaries is a marketing document. The following are areas where Axiom Risk takes a deliberate position and where that position should be understood before deployment.

Scope of this methodology.
Axiom Risk is a control-performance-driven ERM platform. It does not perform actuarial loss quantification, probabilistic scenario modelling, or Monte Carlo simulation. These approaches are complementary, not competing: Axiom Risk produces the control performance foundation from which probabilistic inputs can be derived where an organisation has the data and expertise to support that layer.

The risk matrix is familiar. The methodology behind it is fundamentally different.
Axiom Risk produces a 5×5 risk matrix where scores run from 1 to 25, with a unique score assigned to every grid position. Every risk practitioner and board member will recognise the format immediately.

The standard 5×5 likelihood-times-consequence model has a structural mathematical problem that is worth stating plainly. Multiplying likelihood (1-5) by consequence (1-5) produces only 14 unique values from 25 possible grid positions. A risk rated at likelihood 2 and consequence 3 produces a score of 6, as does a risk rated at likelihood 3 and consequence 2. They are arithmetically identical but represent fundamentally different risk profiles: one is more frequent and less severe, the other is less frequent and more severe. The multiplication model cannot distinguish between them. Furthermore, the distribution is non-linear and skewed: 12 of the 25 grid positions produce scores of 6 or below, clustering most of the register in the low end of the scale regardless of the actual spread of risks. The corrected 1-25 model addresses both problems by assigning a unique score to every grid position through an additive rather than multiplicative approach, producing a complete, non-repeating distribution across the full range of the matrix. A companion article on this topic develops the mathematical argument in full.

What is different in Axiom Risk is how a risk arrives at its position on that matrix. In a traditional 5×5 implementation, an analyst estimates a likelihood rating and a consequence rating. The two axes of the grid represent those two dimensions, and the matrix produces a score from their intersection. The analyst’s estimates drive the position entirely. In Axiom Risk, the matrix functions as a single-dimension visual scale: the two axes retain their familiar labels for governance recognition, but the position of a risk on the grid is determined entirely by the RRS, not by separate likelihood and consequence estimates. The RRS is produced by the closed calculation chain flowing from control assessments through contributing factors to the risk level. The score drives the matrix position.

Because RRS = 25 x %RE and %RE is a continuous decimal, the calculation produces a continuous value rather than a whole number. The Criteria: Risk Matrix table maps each integer position from 1 to 25 to a risk category and a corresponding %RE value, with each position representing exactly 4% of risk exposure. The continuous RRS is rounded to the nearest integer to match the corresponding record in that table. The rounding step produces an approximation of at most half an RRS unit (2% of %RE), which is a reasonable and auditable precision for governance purposes.

One boundary condition is worth noting: with the CES scale capped at 90% (Excellent), the minimum achievable RRS is exactly 2.5 (25 x 10%), representing the state where every control in the chain is rated at maximum effectiveness. Whether this rounds to grid position 2 or 3 depends on the rounding convention applied to the 0.5 boundary: round-half-up produces position 3; round-half-to-even produces position 2. Grid positions 1 and 2 (representing 4% and 8% risk exposure respectively) both sit at or below the calculation floor. Position 1 is unreachable by calculation. Position 2 is reachable only as a rounding artefact under the round-half-to-even convention when the entire chain is at maximum effectiveness. Both are retained in the Criteria: Risk Matrix table as the theoretical ceiling of control performance rather than as expected operational outputs.

The visual output is familiar. The number behind it is derived, not estimated. Governance bodies do not need to learn a new reporting format. They need to understand that the number they are looking at now means something it did not mean before.

Inherent risk is not variable.
Some ERM frameworks and committees attach significance to the gap between inherent and residual ratings. In Axiom Risk, that gap exists (it is the RRS itself, expressed as IRS minus the protected portion), but the IRS does not change between risks. The scale of a risk in Axiom Risk is communicated through the risk description, the causal pathway structure, and the MCV at the objective level, not through a variable inherent score. This is a deliberate design decision; Section 4.2 sets out the reasoning in full.

Weighted averaging and the single-point-of-failure consideration.
The CRC-weighted average at the Contributing Factor level reflects the reliability of the control environment, not a weakest-link model. In causal pathways where a single control is genuinely non-negotiable (where its failure would render all other controls irrelevant), the appropriate design response is to isolate that control as the sole control linked to its own Contributing Factor. Its CES then becomes the %AC for that factor directly, with no averaging applied. This is a configuration principle to be applied during the onboarding and register design phase, not a formula override. The register structure is the model.

Pre-built control libraries are not included.
Axiom Risk does not ship with a pre-loaded control catalogue aligned to ISO 27001, NIST, or other framework control sets. The control register is built during the onboarding engagement, aligned to the organisation’s actual control environment. This produces a more accurate register than one populated from a library, but it requires structured onboarding effort.

Qualitative ERM implementations vary.
The problem this methodology addresses (residual risk scores that reflect analyst opinion rather than control evidence) is prevalent in qualitative ERM practice. It is not universal. Some sectors and organisations already apply quantitative or semi-quantitative approaches. Axiom Risk is designed for the broader organisational market where qualitative methods remain the standard and where the gap between control assessment and residual rating is real and material.

The calculation chain is scoped to control performance. External context monitoring is a separate and complementary layer.
The closed calculation chain measures how well the organisation’s controls are performing against risks already in the register. This is its design scope, not a gap. It does not detect changes in the external environment: a regulatory shift, a geopolitical development, a sector disruption, or an emerging threat that has not yet entered the register produces no signal in the chain. When the external context changes materially, the risk register must be reviewed and the contributing factor and risk structure updated to reflect the new landscape. The calculation chain then produces an updated residual score from the current control position against the revised risk architecture. External context monitoring and control performance measurement are two distinct governance functions. Axiom Risk implements both through separate, connected mechanisms. Section 4.7 describes the Risk Horizon, the pre-registration intelligence layer that continuously scans the external environment, governs detected signals through a documented lifecycle, and provides the traceable adoption pathway through which external signals enter the register and the calculation chain.

Validation against reality is the organisation’s responsibility.
Axiom Risk does not include a formal back-testing framework. The model produces traceable, derived residual scores; it does not automatically validate those scores against actual loss events. Organisations are encouraged to compare register scores against incidents, near-misses, and audit findings on a periodic basis to assess whether well-controlled risks are performing as the register predicts, and whether poorly controlled risks are producing the exposures the model indicates. Where a risk materialises despite a favourable register score, the incident review should examine whether the register architecture (control inventory, contributing factor structure, and CER ratings) accurately reflected the actual control environment at the time. Developing a structured validation methodology aligned to incident and audit cycles is on the Axiom Risk product roadmap.

Staleness visibility propagates upward through the chain.
The staleness flag described in Section 5.2 is visible at the control level on the Controls Dashboard and on individual control records. Where one or more controls linked to a Contributing Factor are stale, the staleness signal propagates upward: the linked Contributing Factor, Risk, and Objective records are flagged accordingly, making it immediately visible at every governance level that the residual scores for that risk chain are built on inputs that require reassessment. A risk or objective displaying a staleness flag should be treated with caution until the underlying control assessments are refreshed. The last calculated RRS remains visible alongside the staleness flag, providing both the current calculated position and the governance prompt to verify it. When Contributing Factors are added, removed, or restructured, downstream scores shift. When controls are added to or removed from a Contributing Factor, the %AC changes. These are not administrative updates: they are changes to the model that the register runs on. Organisations should treat structural register changes as governance events, subject to the same approval process as any model change. The risk committee or equivalent governance body should formally approve structural changes, and version records should be maintained so that the register’s architecture at any point in time can be reconstructed for audit or regulatory purposes. Simple updates to control ratings or assessment scores do not require this level of governance; structural changes to the register architecture do.

8. The Governance Case

The question that matters most to a Chief Risk Officer is not whether the methodology is elegant. It is whether the numbers can be defended.

In Axiom Risk, every residual risk score can be defended because every residual risk score is derived. The chain from control assessment to risk category is unbroken. The assessors’ ratings are on record. The date of the assessment is on record. The participants are on record. The evidence is linked. The formula that produced the residual score is fixed and auditable.

When an auditor, regulator, or board member asks why a risk is rated as it is, the answer is not “because the analyst assessed it that way.” The answer is: “Because these controls were assessed at this effectiveness level on this date by these people, producing this CES, which flows through this chain to produce this RRS. Here is the record.”

That is what a governance instrument should be able to say.

One distinction is worth stating plainly. Traceability is not the same as accuracy. Axiom Risk does not claim to prove that a control rating is correct. It claims to ensure that the rating is declared, documented, made through a governed multi-party process, and cannot cascade into a second undocumented judgment downstream. An auditor reviewing an Axiom Risk register can see who rated a control, at what level, on what date, against what evidence, and through what consensus process. Whether the rating was right is a question of assessor quality and organisational maturity, not of methodology. The governance improvement Axiom Risk delivers is structural accountability, not the elimination of human fallibility. No methodology eliminates that.

For the CRO who presents to an audit committee, the question is also about credibility over time. A risk register that updates only when an analyst reconsiders it is a risk register that can stay wrong for months without anyone noticing. A risk register that recalculates the moment a control assessment changes is one that reflects the actual state of the organisation’s defences as measured by the most recent completed assessments. The two instruments are not equivalent, even if they look the same on a slide.

Organisations that continuously measure how well their controls are performing are building resilience actively rather than discovering gaps after the event. For the purposes of this paper, resilience is understood as the capacity to absorb disruption and continue delivering on objectives, consistent with the definition adopted in ISO 22316:2017. A risk register that reflects control performance in continuous time gives leadership the information they need to respond to deterioration before it becomes an incident, not after.

9. Where Axiom Risk Fits

Axiom Risk is designed for organisations that currently rely on qualitative ERM and want a more defensible, traceable, and continuously updated residual risk position. It is not a replacement for sector-specific quantitative frameworks, actuarial models, or capital adequacy methodologies. The following describes where it adds value in practice.

For financial services organisations, Axiom Risk provides a control-performance layer that sits alongside, not instead of, the quantitative regulatory frameworks required under Basel, Solvency II, or FSCA guidance. Those frameworks require probability distributions, capital modelling, and actuarial inputs that Axiom Risk does not produce. What it does produce is a traceable, continuously updated view of how well the controls supporting each objective are performing, which complements and informs the quantitative layer. Organisations in this sector should position Axiom Risk as their governance and control assurance instrument, not their quantitative risk model.

For public sector bodies, SOEs, and entities subject to PFMA, MFMA, and King IV, the alignment with ISO 31000:2018 and the objectives-led architecture map directly to the governance requirements of those frameworks. King IV’s outcomes-based approach and its emphasis on combined assurance are supported through the voting mechanism, which captures multiple assessor perspectives across the three lines and creates a documented evidence trail traceable back to named roles. Where combined assurance levels are configured on the Interested Party Directory, votes are weighted by the assurance level of the assessor before the median is determined, formally aligning assessor contributions to their position in the three lines model. Axiom Risk does not claim to satisfy every King IV requirement: it addresses the risk management component specifically.

For professional associations, industry bodies, and sector regulators, the common challenge is that risk management exists in strategy documents but is not operationalised in a working register. The Axiom Risk structure forces that operationalisation: objectives must be declared, risks must be linked to them, controls must be assessed, and residual scores follow automatically. The value is not in the sophistication of the model. It is in the discipline the structure imposes.

For organisations new to formal ERM or working with limited risk management resources, the plain language design, configurable criteria tables, and role-based interface mean a small team can operate the system effectively. The methodology does not require specialist risk expertise from every user. It requires that assessors understand the controls they are rating, which is an operational rather than a risk management requirement.

Axiom Risk will not be the right fit for every organisation or every risk management context. Organisations with mature quant functions, bespoke risk models, or actuarial capabilities should evaluate whether a control-performance layer adds value to what they already have. Those without those capabilities, and who currently rely on qualitative estimation, will find a methodology that makes their numbers mean something they can defend.

10. Conclusion

The ERM profession has built capable frameworks and rigorous process disciplines. What most of those frameworks have not solved is the moment at which assessors look at a set of controls and are then asked to form a view (unaided by any calculation) of what the residual risk should be.

That moment is where opinion enters the register. And once opinion is in the register, the register can no longer be independently verified.

Axiom Risk removes that moment from the process. Assessors rate the controls. The chain calculates the rest. The register reflects the state of the controls, not the state of the assessors’ judgment on a given day.

This is not a critique of ISO 31000:2018 or of the practitioners who implement it. The standard is sound. It is principles-based by design, and that design serves organisations well across every level of maturity and every sector. The challenge has never been in the standard. It has been in one specific implementation gap that the standard deliberately leaves to the practitioner: how to connect control performance to residual risk without reintroducing the subjectivity that good risk management practice should remove. Different practitioners resolve that gap differently, based on their skills, their experience, and the maturity of the organisations they serve. Axiom Risk is one disciplined, evidence-based answer to that question, grounded in the same principles ISO 31000 establishes and designed for organisations ready to make the shift from reactive estimation to proactive measurement.

The methodology is transparent. The documentation is published. The numbers are traceable.

That is the standard that risk management should be held to.

Risk Management is Performance Management: A White Paper on the Case for Mathematically Traceable Residual Risk may be shared freely. The Axiom Risk methodology, base architecture, and system documentation are the intellectual property of Digital Marque.

11. References

  1. Ebersbach, J. and Powers, M. (2022) “Quantifying the Qualitative Technology Risk Assessment,” ISACA Journal, Volume 5, September 2022. https://www.isaca.org/resources/isaca-journal/issues/2022/volume-5/quantifying-the-qualitative-technology-risk-assessment
    ↩︎

5 1 vote
Article Rating
Subscribe
Notify of
1 Comment
Picture of Xander Venske
Xander Venske
I'm Xander Venske, founder of Digital Marque. I build businesses, break risk frameworks, and occasionally fix printers. My work spans Enterprise Risk Management, cloud-based management systems, and digital solutions for South African SMEs.