EM-RSK-01 · Subject model · W1
Risk, control and execution assessment
Risk in context, assessment, mitigation measure, control and execution. Requirement, policy and evidence are imported by reference.
Queued for research
Claude: not-started; Grok: not-started.
Research note, in Russian: Entire research brief pending
Subject boundary and candidate types
- Risk
- RiskAssessment
- RiskTreatment
- Control
- ControlExecution
Deep research questions
- How to compare assessments on different scales?
- How to separate control design from its execution?
- When do several risks share a common cause?
Verifiable invariants
- An assessment contains a scale and a horizon
- The presence of a control does not prove effectiveness
- Residual risk has grounds
End-to-end acceptance scenario
One control is linked to three risks; an execution failure changes assessments only where the link is justified.
Negative case
A green policy status automatically closes all related risks.
Approaches to compare
- NIST CSF/AI RMF: governance and risk functions
- ODRL/PROV: authority, grounds and evidence
- GRC/IAM/BCM practice and NIST SP 800-34 for recovery
Candidates in the live catalogue
- WM-KNW-015 · Risk / Opportunity · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card. - WM-XCT-027 · Risk / Control · 0.3.0-research.1 · installable
Semantic fit requires boundary research; a published model does not by itself complete this card.
Result requirements
Every card is executed together with the full research contract: definitions, fields and cardinalities, lifecycle, sources, data mastership, rights, the five object facets, at least eight invariants, positive and negative examples, dependencies, migration and applicability limits.