{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-knw-015","code":"wm-knw-015-risk-opportunity","url":"https://ver.cy/models/wm-knw-015-risk-opportunity/","name":"Risk / Opportunity","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Information and virtual systems","entryKind":"entity","plane":"","domain":["INF.KNW.RSK"],"industry":["Cross-industry"],"navPath":"NAV.INF.KNW.RSK","tags":["risk","opportunity","inf.knw.rsk"],"facets":{}},"whatItIs":"This model covers the registered uncertainty item itself: how it is defined, identified, articulated as a source-event-consequence scenario, classified against versioned schemes, estimated for likelihood and consequence over a declared horizon, evaluated against risk criteria and an appetite or tolerance reference, assigned a response option, linked by reference to treatment actions and controls, moved through lifecycle states to realisation or closure, owned, provenanced, aggregated into registers and snapshots, validated, protected and projected into external schemas. It is deliberately symmetric: adverse (threat) and beneficial (opportunity) items share one identity, criteria and lifecycle machinery, with valence recorded as a coded field. It does not perform, execute or enforce anything: treatment execution, control assurance, incident handling, objective setting, decision authority, evidence capture, audit trails and retention execution belong to referenced sibling models or the adopting Dimension. The model is storage- and interface-neutral; register tables, documents, graphs and message payloads are projections of the same semantics.","purpose":"Govern the identified risk or opportunity as a persistent, identified record of an uncertain future event or condition whose occurrence would affect stated objectives, carrying its articulation, classification, likelihood and consequence estimates, evaluation against criteria, response decision, lifecycle state, ownership and provenance.","scope":{"in":["The identified risk or opportunity item as a governed record, threat-side and opportunity-side under one identity","Scenario articulation: risk source or cause, uncertain event, consequence, and the exposed object","Boundary tests separating an item from an issue, incident, hazard, control deficiency or assumption","Classification against versioned schemes plus valence and inherent/current/residual/target framing","Likelihood and consequence estimates with declared scales, units, horizon and conditionality","Level of risk, combination rule, aggregation limits, evaluation outcome and priority candidate","Assessment technique, assumptions, inputs, confidence and references to supporting evidence","Response option selection and referenced treatment actions, controls and mitigating factors","Lifecycle states, review cadence and triggers, realisation hand-off and closure outcomes","Ownership, acceptance and escalation authority references, and assertion provenance","Register membership, point-in-time snapshots and reporting extracts as artifacts","Validation rules, sensitivity classification, and alignment or crosswalk records with recorded conflicts"],"out":["Execution, scheduling and change control of treatment actions and projects","Control design, testing, effectiveness assurance and audit opinions","Incident, issue and loss-event handling, investigation and post-event response","Objective, strategy and target setting, and performance measurement of objectives","Threat intelligence, hazard catalogues and vulnerability management","Capture and lifecycle of observations and evidence records, including chain of custody","Setting enterprise risk appetite and tolerance statements (referenced, not authored here)","Delegated authority schemes, approval workflow engines and runtime policy evaluation or enforcement","Platform audit-trail creation and retention or erasure execution, including legal hold mechanics","AI-system conformity assessment, high-risk classification and regulatory enforcement","Insurance contracts, actuarial pricing, risk transfer instruments and regulatory capital calculation","Dashboards, business intelligence and board reporting cadence built on register extracts"],"boundaries":[{"neighbor":"Incident / loss-event record (sibling model)","distinction":"An item ceases to be a risk when the uncertain event occurs. The materialised event, its measured losses and its response are owned by the incident or loss-event model; this model retains only the realisation flag, the event time and a reference."},{"neighbor":"Threat or hazard catalogue (sibling model)","distinction":"Threats and hazards are reusable catalogue entries referenced by identifier, mirroring the OSCAL threat-id pattern. This model neither maintains threat taxonomies nor produces intelligence."},{"neighbor":"Control / safeguard model (sibling model)","distinction":"Controls and mitigating factors are referenced with an effectiveness input recorded as evidence. Control design, testing and assurance opinions remain in the control model."},{"neighbor":"Observation / evidence record (sibling model)","distinction":"Supporting observations are referenced, following the OSCAL related-observations pattern. Evidence capture, custody and lifecycle are not owned here; only reference, digest and relevance note are held."},{"neighbor":"Objective / outcome model (parent WM-ACT-017 plane)","distinction":"Risk is defined as an effect of uncertainty on objectives, so objectives are referenced, never authored here. Objective definition, targets and performance reporting stay with the parent action or objective model."},{"neighbor":"WM-AI-008 AI governance assessment","distinction":"An AI governance assessment references items here as risk evidence. The AI-specific risk-management-system obligation, residual-risk acceptability determination, conformity assessment and enforcement remain with that model and the competent authority."},{"neighbor":"Decision and delegated-authority model (sibling model)","distinction":"Acceptance, escalation and closure decisions are carried as decision references with the authority level asserted at the time. Delegation schemes, approval workflow and enforcement are not modelled here."},{"neighbor":"Enterprise reporting and analytics platform","distinction":"Register snapshots and reporting extracts are defined as immutable artifacts of this model; dashboards, roll-up analytics and reporting cadence belong to the adopting Dimension."},{"neighbor":"Insurance, risk transfer and capital models","distinction":"Only the sharing or transfer response option and its contract reference are recorded. Pricing, capital requirement calculation and loss-distribution modelling for capital are excluded."},{"neighbor":"Platform audit trail and access enforcement","distinction":"This model states what must be auditable and what sensitivity applies, but does not create, hold or enforce audit records or access decisions."}]},"distinguishingFeatures":["An uncertain future event affecting objectives, recorded with estimates, evaluation and response.","Treats opportunities symmetrically with risks.","Unlike an issue or incident, it has not occurred.","Records decisions made elsewhere; it does not execute treatment or test controls."],"structure":{"bundles":[{"id":"b-semantic-core","name":"Semantic core: concept, articulation and identity","description":"What a risk or opportunity item is, how it is stated, how it is distinguished from adjacent concepts, and how it is identified and kept continuous across revisions.","layers":[{"id":"l-concept-articulation","name":"Concept and articulation","description":"The definitional binding of the item, the source-event-consequence articulation, and the tests that keep non-risks out of the register.","findings":[{"id":"f-concept-frame","name":"Definitional frame and objective linkage","description":"An item is a recorded assertion that an uncertain event or condition, if it occurs, would have an effect on stated objectives; the governing definition (neutral effect-on-objectives versus adverse likelihood-and-impact) must be declared because authoritative sources disagree.","questions":[{"text":"Under which definitional scheme was this item recorded — neutral effect of uncertainty on objectives, or adverse-only likelihood and impact?","id":"q-concept-definition-scheme","kind":"definition"},{"text":"Which stated objective or outcome does this item's uncertainty act upon?","id":"q-concept-objective-link","kind":"relationship"},{"text":"What makes this item uncertain rather than a known present condition?","id":"q-concept-uncertainty-basis","kind":"state"},{"text":"What minimum content must be present before the item may be registered at all?","id":"q-concept-minimum-set","kind":"requirement"}]},{"id":"f-scenario-articulation","name":"Scenario articulation: source, event, consequence","description":"The item is stated as a chain of risk source or cause, an uncertain event, and the consequence on the exposed object, at a granularity that keeps items separable and assessable.","questions":[{"text":"How are risk source, uncertain event and consequence separated within the recorded statement?","id":"q-scenario-chain","kind":"composition"},{"text":"At what granularity does one item become distinct from a closely related item?","id":"q-scenario-granularity","kind":"identity"},{"text":"Which asset, process, population or system is exposed in this scenario?","id":"q-scenario-exposed-object","kind":"relationship"},{"text":"Which parts of the statement are structured fields and which remain free narrative?","id":"q-scenario-structured-vs-narrative","kind":"interoperability"}]},{"id":"f-adjacent-concept-boundary","name":"Boundary against adjacent concepts","description":"Explicit tests separating an open risk or opportunity from an issue or incident, a threat or hazard, a control deficiency, an observation, and a planning assumption or dependency.","questions":[{"text":"What test separates a still-uncertain item from a materialised issue or incident?","id":"q-boundary-issue-test","kind":"definition"},{"text":"How is a referenced threat or hazard distinguished from the risk item itself?","id":"q-boundary-threat-distinction","kind":"relationship"},{"text":"When does a control weakness or observation become a registered item rather than remaining a finding?","id":"q-boundary-observation-promotion","kind":"decision"},{"text":"Which concepts must never be stored as items in this model?","id":"q-boundary-excluded-concepts","kind":"constraint"}]}]},{"id":"l-identity-continuity","name":"Identity and continuity","description":"How an item is identified, how identity survives re-assessment, and how split, merge and supersession are recorded.","findings":[{"id":"f-item-identity","name":"Item identity, revision and continuity","description":"Identity of the item is stable and separate from the identity of any assessment revision; re-estimation creates a revision, while split, merge or withdrawal are explicit continuity events.","questions":[{"text":"Which system of record holds the authoritative identifier for this item?","id":"q-identity-authoritative-key","kind":"identity"},{"text":"Which identifier is minted when no authoritative master-system key exists?","id":"q-identity-fallback-minting","kind":"requirement"},{"text":"How are identifiers from other registers carried without becoming the primary key?","id":"q-identity-cross-register-mapping","kind":"interoperability"},{"text":"Which changes force a new item identity rather than a new assessment revision?","id":"q-identity-new-versus-revision","kind":"lifecycle"},{"text":"How is the item's state at a past reporting date reconstructed?","id":"q-identity-point-in-time","kind":"temporal"}]}]}]},{"id":"b-classification-context","name":"Classification, valence and context binding","description":"How an item is categorised against versioned schemes, whether its effect is adverse, beneficial or two-sided, and the organisational, spatial and temporal context in which the assessment holds.","layers":[{"id":"l-classification-schemes","name":"Classification and valence","description":"Assignment of coded categories from versioned schemes, and the coded direction and framing of the assessed effect.","findings":[{"id":"f-taxonomy-classification","name":"Classification against versioned schemes","description":"Items are classified using one or more published schemes, each identified with a version; scheme boundaries are normative and category sets are not interchangeable between sectors.","questions":[{"text":"Which classification schemes classify this item, and at which scheme version?","id":"q-class-scheme-identity","kind":"classification"},{"text":"May an item carry codes from more than one scheme at the same time, and under what rule?","id":"q-class-multi-scheme","kind":"constraint"},{"text":"How are non-equivalent categories across schemes reconciled for reporting?","id":"q-class-scheme-reconciliation","kind":"interoperability"},{"text":"What happens to existing items when a scheme version is retired?","id":"q-class-scheme-retirement","kind":"lifecycle"}]},{"id":"f-valence-and-framing","name":"Valence and assessment framing","description":"Whether the item is adverse, beneficial or two-sided, and which framings (inherent, current, residual, target) the recorded estimates represent, since standards differ on both points.","questions":[{"text":"Is the recorded effect adverse, beneficial or two-sided, and on what basis was that determined?","id":"q-valence-direction","kind":"classification"},{"text":"Which assessment framings are recorded for this item — inherent, current, residual or target?","id":"q-valence-framing-states","kind":"state"},{"text":"Which additional fields become mandatory when the item is an opportunity to be pursued?","id":"q-valence-opportunity-fields","kind":"requirement"},{"text":"How is a beneficial item represented when exported to a threat-only external schema?","id":"q-valence-threat-only-export","kind":"interoperability"}]}]},{"id":"l-context-scope","name":"Context, scope and time horizon","description":"The organisational, spatial and temporal scope within which the item and its estimates are valid.","findings":[{"id":"f-objective-scope-binding","name":"Register scope and context binding","description":"Each item is registered against a scope (organisational unit, portfolio, system or programme) and records the internal and external context assumed when it was scoped, which determines the applicable criteria set.","questions":[{"text":"Which organisational unit, portfolio or system is this item registered against?","id":"q-scope-register-binding","kind":"relationship"},{"text":"Does the item apply to a specific site, territory or jurisdiction?","id":"q-scope-location-applicability","kind":"spatial"},{"text":"Which risk criteria set applies to this item given its scope?","id":"q-scope-criteria-applicable","kind":"constraint"},{"text":"Which internal and external context factors were assumed when the item was scoped?","id":"q-scope-context-assumptions","kind":"evidence"}]},{"id":"f-time-horizon-validity","name":"Time horizon, onset and assessment validity","description":"Likelihood is meaningless without a horizon: the model records the exposure window the estimate refers to, the expected speed of onset, and the date until which the assessment is treated as current.","questions":[{"text":"Over what time horizon or exposure window is the likelihood judged?","id":"q-time-horizon-window","kind":"temporal"},{"text":"From when until when is this assessment treated as current before it becomes stale?","id":"q-time-assessment-expiry","kind":"lifecycle"},{"text":"How quickly would consequences arrive after the event occurs?","id":"q-time-onset-velocity","kind":"measurement"},{"text":"Is the item treated as emerging, with limited historical evidence for its horizon?","id":"q-time-emergence-status","kind":"classification"}]}]}]},{"id":"b-assessment-measurement","name":"Assessment: likelihood, consequence, level and evidence","description":"How likelihood and consequence are expressed, combined into a level of risk, evaluated against criteria and appetite, and supported by technique, assumptions, evidence references and a confidence statement.","layers":[{"id":"l-likelihood-consequence","name":"Likelihood and consequence","description":"Expression, typing and conditionality of the two primary estimates.","findings":[{"id":"f-likelihood-expression","name":"Likelihood expression and scale binding","description":"Likelihood may be an ordinal band, a probability or a frequency; whichever is used, the scale definition, version, exposure window and any conditionality must be recorded with the value.","questions":[{"text":"Is likelihood expressed as an ordinal band, a probability or a frequency?","id":"q-likelihood-representation","kind":"measurement"},{"text":"Over which exposure window or population is a frequency value defined?","id":"q-likelihood-window-basis","kind":"constraint"},{"text":"Which scale definition and version produced this likelihood value?","id":"q-likelihood-scale-provenance","kind":"provenance"},{"text":"Is the likelihood conditional on other events occurring or on controls remaining in place?","id":"q-likelihood-conditionality","kind":"relationship"}]},{"id":"f-consequence-expression","name":"Consequence dimensions and magnitude","description":"Consequence is recorded per dimension (financial, safety, legal, service, environmental, reputational and others in force), with magnitude, unit or currency, valuation basis, case basis and who bears the effect.","questions":[{"text":"Which consequence dimensions are assessed for this item?","id":"q-consequence-dimension-set","kind":"classification"},{"text":"How is magnitude quantified, including unit, currency and valuation basis?","id":"q-consequence-magnitude","kind":"measurement"},{"text":"Does the recorded consequence represent the expected, most likely or worst credible case?","id":"q-consequence-case-basis","kind":"constraint"},{"text":"Who or what bears the consequence, and does any of it fall outside the organisation?","id":"q-consequence-incidence","kind":"relationship"}]}]},{"id":"l-level-criteria-evaluation","name":"Level of risk, criteria and evaluation","description":"Combination of estimates into a level, its documented limits, and comparison against criteria, appetite and tolerance references.","findings":[{"id":"f-level-and-aggregation","name":"Level of risk, priority and aggregation limits","description":"The level or exposure derives from a declared combination rule whose validity limits must be recorded, and aggregation or roll-up across items is permitted only under stated correlation and comparability conditions.","questions":[{"text":"Which rule combines likelihood and consequence into a level of risk or exposure?","id":"q-level-combination-rule","kind":"measurement"},{"text":"What are the documented validity limits of the combination rule as applied here?","id":"q-level-rule-limits","kind":"quality"},{"text":"Under what conditions may item-level values be aggregated or rolled up to a portfolio view?","id":"q-level-aggregation-conditions","kind":"constraint"},{"text":"How is relative priority derived, and who confirms it?","id":"q-level-priority-assignment","kind":"decision"}]},{"id":"f-criteria-appetite-evaluation","name":"Risk criteria, appetite reference and evaluation outcome","description":"Evaluation compares the level against a versioned criteria set and a referenced appetite or tolerance statement, yielding an outcome and, where the item sits outside appetite, an escalation record; appetite is authored elsewhere and only referenced here.","questions":[{"text":"Which criteria set, scales and thresholds were applied at the moment of evaluation?","id":"q-criteria-set-applied","kind":"requirement"},{"text":"Against which appetite or tolerance statement is this item evaluated?","id":"q-appetite-statement-reference","kind":"authority"},{"text":"What was the evaluation outcome relative to the threshold, and when was it determined?","id":"q-evaluation-outcome-recorded","kind":"decision"},{"text":"How is an item outside appetite recorded and escalated while a decision is pending?","id":"q-evaluation-outside-appetite","kind":"exception"}]}]},{"id":"l-method-evidence","name":"Technique, evidence and confidence","description":"How the estimate was produced, what it assumed, what supports it, and how much confidence is claimed.","findings":[{"id":"f-technique-and-assumptions","name":"Assessment technique, inputs and assumptions","description":"The technique used to produce the estimate is identified with its assumptions, exclusions, data sources or expert inputs, so that the estimate is reproducible and its applicability can be challenged.","questions":[{"text":"Which assessment technique produced this estimate, and why was it appropriate?","id":"q-technique-identification","kind":"process"},{"text":"Which assumptions and exclusions condition the estimate?","id":"q-technique-assumptions","kind":"constraint"},{"text":"Which data sources, models or expert inputs fed the estimate?","id":"q-technique-inputs","kind":"provenance"},{"text":"Can the estimate be reproduced from the recorded inputs and parameters?","id":"q-technique-reproducibility","kind":"validation"}]},{"id":"f-evidence-and-confidence","name":"Evidence references, confidence and knowledge limits","description":"The estimate carries a confidence statement on a declared scale, references to supporting observations or evidence held in their owning models, an account of knowledge limits and unquantified uncertainty, and a record of who challenged it.","questions":[{"text":"What confidence is claimed in this estimate, and on which declared scale?","id":"q-confidence-statement","kind":"quality"},{"text":"Which observations or evidence records support the estimate?","id":"q-evidence-links","kind":"evidence"},{"text":"Which knowledge gaps or unquantified uncertainties remain unaddressed in the estimate?","id":"q-knowledge-limits","kind":"constraint"},{"text":"Who independently challenged or reviewed the estimate before it was relied upon?","id":"q-estimate-challenge","kind":"validation"}]}]}]},{"id":"b-response-lifecycle","name":"Response, treatment linkage and lifecycle","description":"Selection of a response option, referencing of treatment actions and controls, movement through lifecycle states, monitoring and review, and the hand-off when the event materialises or the item closes.","layers":[{"id":"l-response-treatment","name":"Response option and treatment linkage","description":"The governed option set including opportunity-side options, and references to the actions and controls that implement them.","findings":[{"id":"f-response-strategy","name":"Response option selection","description":"A response is selected from a governed option set that includes avoiding, taking or increasing the risk to pursue an opportunity, removing the source, changing the likelihood, changing the consequences, sharing and retaining, with rationale and, for retention, an authority reference.","questions":[{"text":"Which response option was selected from the governed option set?","id":"q-response-option-selected","kind":"decision"},{"text":"Which options apply when the item is a beneficial opportunity to be pursued rather than a threat?","id":"q-response-opportunity-options","kind":"classification"},{"text":"What rationale, cost and expected benefit justified the selected option?","id":"q-response-rationale","kind":"evidence"},{"text":"If the item is retained or accepted, on whose authority and until when?","id":"q-response-retention-authority","kind":"authority"}]},{"id":"f-treatment-control-linkage","name":"Treatment action and control references","description":"Planned treatment actions, existing controls and mitigating factors are carried as references with expected effect and deadline; execution, scheduling and control assurance stay with their owning models.","questions":[{"text":"Which treatment actions are referenced, and in which model do they execute?","id":"q-treatment-action-refs","kind":"composition"},{"text":"Which existing controls or mitigating factors are relied upon to reduce this item?","id":"q-control-refs","kind":"relationship"},{"text":"How is control effectiveness recorded here without asserting a control assurance opinion?","id":"q-control-effectiveness-input","kind":"evidence"},{"text":"What change in likelihood or consequence is expected once the treatment is complete?","id":"q-treatment-expected-effect","kind":"measurement"},{"text":"By when must the treatment be complete, and who tracks completion?","id":"q-treatment-deadline","kind":"temporal"}]}]},{"id":"l-lifecycle-monitoring","name":"Lifecycle, monitoring and outcome","description":"States and transitions, review cadence and triggers, and what happens when the uncertain event occurs or the item closes.","findings":[{"id":"f-lifecycle-states","name":"Lifecycle states and permitted transitions","description":"The item moves through a declared state set with gated transitions and a mapping to external status vocabularies, which are threat-oriented and therefore only partially expressive for opportunities.","questions":[{"text":"Which lifecycle states may an item occupy in this model?","id":"q-lifecycle-state-set","kind":"lifecycle"},{"text":"Which transitions are permitted, and what preconditions gate each one?","id":"q-lifecycle-transition-gates","kind":"state"},{"text":"How do local states map onto external status vocabularies used for exchange?","id":"q-lifecycle-status-mapping","kind":"interoperability"},{"text":"Under what conditions may a closed item be reopened rather than newly registered?","id":"q-lifecycle-reopen","kind":"exception"}]},{"id":"f-monitoring-review","name":"Monitoring, review cadence and indicators","description":"Items are reviewed on a cadence and on trigger events; each review appends an immutable log entry recording who reviewed, what changed, the trend, and linked early-warning indicators.","questions":[{"text":"How often must this item be reviewed, and by which role?","id":"q-review-cadence","kind":"process"},{"text":"Which events trigger an out-of-cycle review of the item?","id":"q-review-trigger-events","kind":"event"},{"text":"How is the direction of travel between reviews recorded?","id":"q-review-trend","kind":"measurement"},{"text":"Which early-warning indicators are linked to this item, and at what thresholds?","id":"q-review-indicator-links","kind":"relationship"}]},{"id":"f-realisation-closure","name":"Realisation, benefit capture and closure","description":"When the uncertain event occurs the item is marked realised and handed off to the incident or loss-event model; opportunities record realised benefit; closure records a permitted reason with supporting evidence.","questions":[{"text":"How is it recorded that the uncertain event has actually occurred?","id":"q-realisation-detection","kind":"event"},{"text":"Which model takes ownership of the materialised event and its losses?","id":"q-realisation-handoff","kind":"composition"},{"text":"Which closure reasons are permitted, and what evidence must accompany each?","id":"q-closure-reason","kind":"lifecycle"},{"text":"For an opportunity, how is realised benefit recorded and attributed?","id":"q-benefit-realised","kind":"measurement"}]}]}]},{"id":"b-accountability-provenance","name":"Accountability, authority and provenance","description":"Who owns the item, who may accept or escalate it, who asserted each value and when, and how items accumulate into registers, profiles and reporting extracts.","layers":[{"id":"l-ownership-authority","name":"Ownership and acceptance authority","description":"Accountable roles for the item and the authority references that permit acceptance, escalation and closure.","findings":[{"id":"f-ownership-accountability","name":"Ownership and role separation","description":"A single accountable owner is recorded for the item alongside distinct assessor, action-owner and reviewer roles, each attributable to a party and to an assurance line.","questions":[{"text":"Who is the accountable owner of this item, and how is that party identified?","id":"q-owner-identity","kind":"ownership"},{"text":"How are owner, assessor, action owner and reviewer roles kept separate on one item?","id":"q-owner-role-separation","kind":"relationship"},{"text":"How is a change of owner recorded, and from when is it effective?","id":"q-owner-change-record","kind":"provenance"},{"text":"Which assurance line does each recorded role belong to?","id":"q-owner-assurance-line","kind":"classification"}]},{"id":"f-acceptance-escalation-authority","name":"Acceptance, escalation and authority references","description":"The model records which authority level was relied upon, the decision reference that authorises the current disposition and the escalation path when the level exceeds local authority, without owning delegation schemes or approval workflow.","questions":[{"text":"Which authority level is required to accept an item at this level of risk?","id":"q-authority-level-required","kind":"authority"},{"text":"Which decision record authorises the item's current disposition?","id":"q-authority-decision-reference","kind":"decision"},{"text":"Where does the item go when it exceeds the authority of its current scope?","id":"q-authority-escalation-path","kind":"process"},{"text":"What limits apply to delegated authority, and where are those limits defined?","id":"q-authority-delegation-limits","kind":"constraint"}]}]},{"id":"l-provenance-recording","name":"Provenance and register accumulation","description":"Attribution and timing of every asserted value, and the register, snapshot and extract structures built from items.","findings":[{"id":"f-assertion-provenance","name":"Assertion provenance and time separation","description":"Every value is attributable to an agent and an activity, derived from identifiable prior records, with event time, observation time and record time held separately and never substituted for one another.","questions":[{"text":"Which agent asserted this value, and on whose behalf did they act?","id":"q-provenance-agent","kind":"provenance"},{"text":"How are event time, observation time and record time distinguished on this record?","id":"q-provenance-time-separation","kind":"temporal"},{"text":"From which prior record or source was this value derived?","id":"q-provenance-derivation","kind":"relationship"},{"text":"How is an imported item's original provenance retained after ingestion?","id":"q-provenance-import-retention","kind":"interoperability"}]},{"id":"f-register-aggregation","name":"Register membership, snapshots and extracts","description":"A register is a scoped repository accumulating item information over time; membership rules, immutable point-in-time snapshots and derived reporting extracts are defined here, while retention execution and reporting cadence are not.","questions":[{"text":"Which criteria determine whether an item belongs to a given register?","id":"q-register-membership","kind":"composition"},{"text":"How is a point-in-time register snapshot produced and identified?","id":"q-register-snapshot","kind":"temporal"},{"text":"How is a risk profile derived from register contents without recomputing item values?","id":"q-register-profile-derivation","kind":"process"},{"text":"How long are entries and snapshots retained, and under whose policy?","id":"q-register-retention-class","kind":"retention"}]}]}]},{"id":"b-assurance-interoperability","name":"Assurance, protection and interoperability","description":"Validation of record quality, sensitivity and access constraints on items and extracts, and alignment to external schemas with conflicts and losses recorded.","layers":[{"id":"l-quality-validation","name":"Validation and record quality","description":"Rules that decide whether a record is fit to be relied upon or exchanged.","findings":[{"id":"f-validation-completeness","name":"Validation, completeness and staleness rules","description":"Records are checked for mandatory fields per lifecycle state, conformance of values to declared scales, duplicate or overlapping items, and stale assessments, producing a defect list rather than silently amending values.","questions":[{"text":"Which fields are mandatory before an item may leave draft or change state?","id":"q-validation-mandatory-fields","kind":"validation"},{"text":"How is conformance of recorded values to their declared scales checked?","id":"q-validation-scale-conformance","kind":"quality"},{"text":"How are duplicate or substantially overlapping items detected and resolved?","id":"q-validation-duplicate-detection","kind":"identity"},{"text":"How are stale assessments detected and flagged for re-review?","id":"q-validation-staleness","kind":"temporal"}]}]},{"id":"l-protection-interoperability","name":"Protection and external alignment","description":"Sensitivity, access constraints and redaction expectations for items and extracts, and mappings to external schemas with recorded conflicts.","findings":[{"id":"f-sensitivity-access","name":"Sensitivity classification and access constraints","description":"Items carry a sensitivity classification covering their statement, evidence references and owner identity, with audience rules, personal-data minimisation and an explicit treatment of aggregation sensitivity; enforcement belongs to the platform.","questions":[{"text":"What sensitivity classification applies to this item and to its evidence references?","id":"q-sensitivity-classification","kind":"security"},{"text":"Which audiences may see the full statement, and which receive a redacted summary?","id":"q-access-audience-rules","kind":"access"},{"text":"Does the item contain personal or identifying data, and how is that minimised?","id":"q-access-personal-data","kind":"privacy"},{"text":"Does aggregating items produce a view more sensitive than any single item?","id":"q-access-aggregation-sensitivity","kind":"exception"}]},{"id":"f-external-alignment-conflicts","name":"External alignment, lossy projection and recorded conflicts","description":"Alignments to external vocabularies and schemas are declared as versioned mappings with known losses, and definitional conflicts between authorities are recorded rather than resolved by fiat; conformance is claimed only with evidence.","questions":[{"text":"Which external schemas and vocabularies is this model aligned to, and at which versions?","id":"q-alignment-targets","kind":"interoperability"},{"text":"Which fields or meanings are lost or approximated in each projection?","id":"q-alignment-losses","kind":"quality"},{"text":"How are definitional conflicts between standards recorded instead of being silently resolved?","id":"q-alignment-conflict-record","kind":"constraint"},{"text":"What evidence is required before conformance to an external standard may be claimed?","id":"q-alignment-conformance-evidence","kind":"evidence"}]}]}]}]},"agentConduct":{"may":["Register and classify items against a declared scheme.","Estimate likelihood and consequence with versioned scales.","Evaluate items against criteria and appetite.","Record review outcomes and bind treatment references."],"mustNot":["Record values without scale identifier and version.","Accept risk above appetite without an authorised decision.","Copy evidence or control content rather than referencing it.","Close risks without review.","Claim conformance to a risk standard without evidence."],"requiresHuman":["Accepting residual risk.","Changing risk appetite or criteria."]},"ethics":{"considerations":["Risk decisions often shift exposure to people who were not consulted.","Safety and environmental risks to the public deserve weight beyond financial impact."],"affectedParties":["People exposed to the risk","Risk owners","Boards and regulators"]},"owners":{"steward":"Name one accountable owner package for each register namespace and record it in AGENTS.md, including which system of record holds authoritative item identifiers.","roles":[{"name":"Risk owner","responsibilities":["Hold accountability for the item, its accuracy and its response within the register scope","Confirm the response option and ensure referenced treatment actions have named owners","Escalate items outside appetite and confirm closure or realisation hand-off"]},{"name":"Risk assessor or analyst","responsibilities":["Select and record the assessment technique, assumptions and inputs","Produce likelihood and consequence estimates with scale references, horizon and confidence","Record knowledge limits and unquantified uncertainty rather than concealing them in a point value"]},{"name":"Register custodian","responsibilities":["Maintain register membership rules, identity assignment and namespace hygiene","Issue immutable snapshots and audience-specific extracts with correct sequence identifiers and digests","Maintain crosswalks and reissue projections and loss reports when versions change"]},{"name":"Assurance reviewer","responsibilities":["Independently challenge estimates, framings and evaluation outcomes and record the challenge result","Run validation passes and track defects, staleness and duplicate items to resolution","Report on the reliability of the register without taking ownership of the items reviewed"]},{"name":"Dimension data steward","responsibilities":["Publish and version criteria sets, scales, code lists, option sets and validation rulesets","Bind sensitivity classes, audience release rules and retention classes to register scopes","Record definitional conflicts between adopted standards and the local disambiguation applied"]}],"masterSystems":[]},"relations":[{"target":"WM-ACT-017","type":"child","note":"Register the model beneath its parent action and objective plane: objectives affected, treatment actions and the management activity that owns execution live in the parent, while this model owns only the uncertainty record that references them."},{"target":"WM-AI-008 (AI governance assessment)","type":"references","note":"Carry a back-reference and context binding when an AI governance assessment cites items here as risk evidence. The assessment's own lifecycle, residual-risk acceptability determination, conformity assessment and enforcement remain entirely in WM-AI-008 and with the competent authority."},{"target":"Threat and hazard catalogue model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Reference threat or hazard entries by identifier, following the OSCAL threat-id pattern, without maintaining catalogues, intelligence or hazard characterisation locally."},{"target":"Control and safeguard model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Reference controls and mitigating factors relied upon in a given framing and carry effectiveness evidence references; control design, testing and assurance opinions stay in the control model."},{"target":"Incident and loss-event model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Hand off ownership when the uncertain event materialises, carrying only the realisation flag, occurrence time and the receiving record reference."},{"target":"Observation and evidence model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Reference supporting observations and evidence with digest and relevance note, mirroring OSCAL related-observations; capture, custody and evidence lifecycle are not owned here."},{"target":"Party, role and organisation model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Resolve risk owners, assessors, reviewers and accepting authorities as party references rather than storing identity data locally."},{"target":"Decision and delegated-authority model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Carry the authorising decision reference and the authority level asserted at the time; delegation schemes, approval workflow and enforcement remain external."},{"target":"Quantity, unit and currency model (sibling; identifier not yet assigned in the registry)","type":"references","note":"Type monetary and physical consequence magnitudes with governed unit and currency codes and valuation basis dates instead of defining measurement systems locally."},{"target":"Versioned classification scheme and code-list mixin (sibling; identifier not yet assigned in the registry)","type":"composes","note":"Reuse generic code-list semantics — scheme identity, version, effective dating, retirement and crosswalks — for risk taxonomies rather than reimplementing scheme governance in this model."},{"target":"W3C PROV-O (http://www.w3.org/ns/prov#)","type":"aligned","note":"Align assertion provenance to Entity, Activity and Agent with wasAttributedTo, wasDerivedFrom, wasGeneratedBy and actedOnBehalfOf, so that provenance is exchangeable without importing a separate provenance lifecycle."},{"target":"NIST OSCAL Assessment Results risk structure (OSCAL v1.2.3)","type":"aligned","note":"Map item fields to the OSCAL risk object for exchange, recording known losses — notably the absence of an opportunity valence and the threat-oriented status vocabulary."},{"target":"NIST IR 8286 risk register and risk detail record structures","type":"aligned","note":"Map register membership, exposure and priority to the published register and detail-record structures for enterprise roll-up, without adopting the enterprise risk management process itself."},{"target":"IEC 31010:2019 risk assessment technique catalogue","type":"aligned","note":"Identify assessment techniques by reference to a published catalogue so that technique definitions, applicability and limitations are cited rather than restated locally."},{"target":"Incident / loss-event record (sibling model)","type":"neighbor","note":"An item ceases to be a risk when the uncertain event occurs. The materialised event, its measured losses and its response are owned by the incident or loss-event model; this model retains only the realisation flag, the event time and a reference."},{"target":"Threat or hazard catalogue (sibling model)","type":"neighbor","note":"Threats and hazards are reusable catalogue entries referenced by identifier, mirroring the OSCAL threat-id pattern. This model neither maintains threat taxonomies nor produces intelligence."},{"target":"Control / safeguard model (sibling model)","type":"neighbor","note":"Controls and mitigating factors are referenced with an effectiveness input recorded as evidence. Control design, testing and assurance opinions remain in the control model."},{"target":"Observation / evidence record (sibling model)","type":"neighbor","note":"Supporting observations are referenced, following the OSCAL related-observations pattern. Evidence capture, custody and lifecycle are not owned here; only reference, digest and relevance note are held."},{"target":"Objective / outcome model (parent WM-ACT-017 plane)","type":"neighbor","note":"Risk is defined as an effect of uncertainty on objectives, so objectives are referenced, never authored here. Objective definition, targets and performance reporting stay with the parent action or objective model."},{"target":"WM-AI-008 AI governance assessment","type":"neighbor","note":"An AI governance assessment references items here as risk evidence. The AI-specific risk-management-system obligation, residual-risk acceptability determination, conformity assessment and enforcement remain with that model and the competent authority."},{"target":"Decision and delegated-authority model (sibling model)","type":"neighbor","note":"Acceptance, escalation and closure decisions are carried as decision references with the authority level asserted at the time. Delegation schemes, approval workflow and enforcement are not modelled here."},{"target":"Enterprise reporting and analytics platform","type":"neighbor","note":"Register snapshots and reporting extracts are defined as immutable artifacts of this model; dashboards, roll-up analytics and reporting cadence belong to the adopting Dimension."},{"target":"Insurance, risk transfer and capital models","type":"neighbor","note":"Only the sharing or transfer response option and its contract reference are recorded. Pricing, capital requirement calculation and loss-distribution modelling for capital are excluded."},{"target":"Platform audit trail and access enforcement","type":"neighbor","note":"This model states what must be auditable and what sensitivity applies, but does not create, hold or enforce audit records or access decisions."},{"target":"WM-ACT-017","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record for the register — for example the risk register entry key held by the owning enterprise risk or assessment system — is always preferred where such a system exists.","A governed global identifier or IRI from a published namespace, such as an OSCAL uuid or a Dimension-published IRI, where no master-system key exists.","A UUID or ULID minted by the adopting Dimension, recorded with its minting authority and time, as the last resort.","A date, title, category code, owner name, severity band or file name is never an identifier; such values may only be metadata carried alongside the identifier."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["A risk item has a statement, owner, likelihood, consequence, rating and response.","Often confused with an issue, an incident, a hazard catalogue entry and a control."]},"capabilities":{"applicability":"required","items":["Register risk or opportunity item: Admit a new item to a register scope with its statement, valence, definition scheme, objective reference and provenance, minting identity under the identity priority rule.","Classify item against a scheme: Assign coded categories from one or more published, versioned classification schemes and retain superseded assignments.","Estimate likelihood and consequence: Produce a new assessment revision holding likelihood and consequence values with their scales, horizon, technique, assumptions, evidence references and confidence.","Evaluate against criteria and appetite: Derive the level of risk from the current revision using the declared combination rule and compare it with criteria thresholds and the referenced appetite or tolerance statement.","Record response decision: Record the response option selected from the governed option set together with its rationale, cost estimate and the authorising decision reference.","Bind treatment and control references: Attach references to planned actions, existing controls and mitigating factors, with expected post-treatment effect and deadline.","Transition lifecycle state: Move an item to a permitted target state, recording the trigger, effective time and record time, and appending the transition to the review log.","Record review outcome: Append an immutable review log entry capturing reviewer, changes, trend and next review date, following a scheduled cadence or a trigger event.","Hand off realised item: Mark the item realised when the uncertain event occurs, record the occurrence time and the receiving incident, loss-event or benefit record, and move the item to closure.","Compile register view or snapshot: Produce a register view for a scope and as-of time, or an immutable snapshot and audience-specific reporting extract derived from it.","Validate item or register record: Apply the published validation ruleset to check mandatory fields, scale conformance, duplicates and staleness, and emit a defect list.","Emit alignment projection: Project selected items into an external schema or vocabulary using a published crosswalk and record the losses incurred."]},"hazards":{"applicability":"required","items":["Underestimated risks.","Scale misuse making ratings incomparable.","Stale registers."]},"interfaces":{"applicability":"required","items":["ISO 31000 risk management.","IEC 31010 risk assessment techniques.","COSO ERM framework.","ISO/IEC 27005."]},"context":{"applicability":"required","items":["The Orange Book, its three lines model and its response option vocabulary are UK central government guidance; they are used as a verified restatement of ISO-style concepts, not as universal law.","NIST IR 8286 series conventions, including exposure and priority columns and enterprise roll-up, reflect US federal enterprise practice and OMB circulars; other jurisdictions may require different register fields.","EU AI Act obligations apply to AI systems placed on the Union market or put into service in the Union; the WM-AI-008 reference must not be read as a global obligation.","Basel Framework OPE applies to internationally active banks in adopting jurisdictions and is used here only as evidence about scheme boundedness.","Monetary consequence values assume a currency code and a valuation basis date; multi-currency registers additionally require an exchange-rate policy that this model references but does not define.","Personal-data handling in items assumes the adopting Dimension's privacy regime supplies the lawful basis, retention limit and erasure obligation; the tombstone contract is designed to survive an erasure regime but does not implement any particular one."]}},"sources":[{"title":"ISO 31000:2018 Risk management — Guidelines","url":"https://www.iso.org/standard/65694.html","note":"International Organization for Standardization (ISO/TC 262)"},{"title":"ISO 31073:2022 Risk management — Vocabulary","url":"https://www.iso.org/standard/79637.html","note":"International Organization for Standardization (ISO/TC 262)"},{"title":"Discover risk related vocabulary in ISO 31073","url":"https://committee.iso.org/sites/tc262/home/news/content-left-area/news-and-events-within-iso-tc-26/discover-risk-related-vocabulary.html","note":"ISO/TC 262 Risk management committee"},{"title":"IEC 31010:2019 Risk management — Risk assessment techniques","url":"https://webstore.iec.ch/en/publication/59809","note":"International Electrotechnical Commission (joint IEC/ISO)"},{"title":"The Orange Book: Management of Risk — Principles and Concepts (HTML edition)","url":"https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts","note":"HM Treasury and Government Finance Function (United Kingdom)"},{"title":"NIST IR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM)","url":"https://csrc.nist.gov/pubs/ir/8286/final","note":"National Institute of Standards and Technology (US)"},{"title":"NIST IR 8286A Rev. 1, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management","url":"https://csrc.nist.gov/pubs/ir/8286/a/r1/final","note":"National Institute of Standards and Technology (US)"},{"title":"NIST Computer Security Resource Center Glossary — risk","url":"https://csrc.nist.gov/glossary/term/risk","note":"National Institute of Standards and Technology (US)"},{"title":"NIST Computer Security Resource Center Glossary — risk register","url":"https://csrc.nist.gov/glossary/term/risk_register","note":"National Institute of Standards and Technology (US)"},{"title":"NIST Computer Security Resource Center Glossary — risk appetite","url":"https://csrc.nist.gov/glossary/term/risk_appetite","note":"National Institute of Standards and Technology (US)"},{"title":"OSCAL Assessment Results Model — JSON Format Reference","url":"https://pages.nist.gov/OSCAL-Reference/models/latest/assessment-results/json-reference/","note":"National Institute of Standards and Technology (US), OSCAL project"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium (W3C)"},{"title":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng","note":"European Parliament and Council of the European Union"},{"title":"Basel Framework OPE10 — Operational risk: definitions and application","url":"https://www.bis.org/basel_framework/chapter/OPE/10.htm","note":"Basel Committee on Banking Supervision, Bank for International Settlements"}],"openQuestions":["Acquire licensed ISO 31000:2018, ISO 31073:2022 and ISO Guide 73:2009 texts and verify every quoted definition, the neutral effect-of-uncertainty framing and the inherent-risk claim before ratification replaces the restatement-based support.","Obtain The Open Group O-RT 3.0.1 and O-RA 2.0.1 and decide whether a quantitative loss-event-frequency and loss-magnitude decomposition is bound as an optional alignment or left explicitly unmodelled.","Retrieve Basel Framework OPE10 at chapter level to confirm the loss-event-type category boundary claim that currently supports only scheme boundedness and loss-event separation.","Locate or commission a citable calibrated probability-language mapping equivalent to the unreachable IPCC and EFSA guidance so ordinal bands can carry a referenceable probability scale.","Re-test whether any external schema encodes beneficial valence, including project-management opportunity vocabularies and ISO 31073-derived registries, to reduce the recorded loss on every opportunity projection.","Decide whether the risk register warrants a separate registry-kind sibling model owning membership, snapshot and retention semantics, or remains an artifact set composed under this entity.","Expand protection-plane question coverage in the next revision: one access, one security, one privacy and one retention question across 106 is thin for a model that carries aggregation sensitivity, personal data and a tombstone contract.","Confirm the nav placement NAV.INF.KNW.RSK against the WM-ACT-017 parent plane, since a governed operational register record under an action or objective parent may belong outside the knowledge branch.","Full texts of ISO 31000:2018, ISO 31073:2022, ISO Guide 73:2009, ISO 14971, ISO/IEC 27005 and COSO ERM are paywalled and the ISO catalogue blocked automated retrieval; their content is used here via first-party ISO/TC 262 material and public-authority restatements (HM Treasury Orange Book, NIST glossary citing ISO Guide 73). Quoted definitions should be verified against purchased texts before ratification.","The Open Group Risk Taxonomy (O-RT 3.0.1) and Risk Analysis (O-RA 2.0.1) standards were behind authentication, so the FAIR factor decomposition is referenced as a candidate alignment only and is not modelled.","Basel OPE loss event type categories and the operational risk definition could not be read at chapter level; the Basel citation supports scheme boundedness and loss-event separation, not the specific category list.","Sector-specific structures are not enumerated: medical device harm and hazardous-situation chains, safety integrity levels, food safety hazard characterisation, disaster risk exposure and vulnerability components, and project-management opportunity response verbs.","Technique-specific record shapes (bow-tie, FMEA, HAZOP, event tree, Monte Carlo output) are referenced through the IEC 31010 catalogue but not structurally modelled.","Insurance, risk transfer instruments, regulatory capital calculation, and quantitative correlation or portfolio modelling are excluded by scope and not merely unmodelled.","Machine-readable enumerations for valence, framing, response options, lifecycle states and closure reasons are described as governed code lists but no canonical code list is asserted, because no single authority publishes one that spans threat and opportunity."],"resources":{"spec":"/models/wm-knw-015-risk-opportunity/spec.yaml","agents":"/models/wm-knw-015-risk-opportunity/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-knw-015"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-knw-015-risk-opportunity/spec.yaml","ver-cy/world-models/card-supplements/wm-knw-015-risk-opportunity.json"],"providers":["Claude"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-02T21:32:16Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}