{"schema":"https://ver.cy/schemas/card/1.0.0","id":"vr.wm-xct-027","code":"wm-xct-027-risk-control","url":"https://ver.cy/models/wm-xct-027-risk-control/","name":"Risk / Control","alternateNames":[],"kind":"world-model","status":"published","version":"0.3.0-research.1","language":"en","classifiers":{"family":"World Models","category":"Cross-cutting context","entryKind":"mixin","plane":"","domain":["XCT.RSK"],"industry":["Cross-industry"],"navPath":"NAV.XCT.RSK","tags":["risk","control","xct.rsk"],"facets":{}},"whatItIs":"WM-XCT-027 is a mixin: a reusable set of fields attached to a host record so that record can carry a defensible, revision-pinned risk assessment context. It owns the reference and binding fields (risk reference and exact revision, objective/asset/process/context anchors, source-event-consequence anchors), the pinned assessment frame (category and taxonomy pins, scope, exclusions, time horizon, criteria set, method and technique with versions, expression mode), the estimate slots (likelihood and consequence dimension declarations, inherent estimate with its exclusion statement, residual estimate with change explanation), the evidential basis (assumptions, information sources, data currency, estimation basis kind, uncertainty and confidence qualification), the control-linkage references (relied-on control references and the effectiveness determinations cited for them), the governance stamps at assessment-context level (assessor, context owner, reviewer and acceptance-decision references, review-due timing), and the comparability surface (comparability verdicts, aggregation caveats, scenario dependence). It does not evaluate controls, does not run assessments, does not set or enforce appetite, does not grant acceptance or authorization, and does not define the internals of any pinned technique. Storage and interface are projections: the same field semantics must survive JSON, YAML, Markdown, HTML, Git, MCP and MongoDB representations.","purpose":"Provide an embeddable field group that binds one risk assessment context to a referenced risk, links it to referenced controls and their cited effectiveness determinations, and explains the residual position against referenced appetite or tolerance, without owning the risk entity, the control register or any treatment workflow.","scope":{"in":["Reference to one risk or opportunity entity together with an exact revision or version pin of the assessed statement.","Anchor references the assessment is scoped against: objectives, assets, processes, organizational units, contextual conditions and applicable jurisdiction or site.","Causal-chain references: risk source or threat source, the event or event class quantified, and the consequences included or explicitly excluded.","Category values with an explicit taxonomy scheme identifier and version pin.","Assessment scope statement, exclusions, likelihood time horizon, as-of time of the assessed state, recording time and validity or review-due time.","Criteria set, assessment method and technique pins with their versions, plus the expression mode (qualitative, ordinal, semi-quantitative, quantitative, probabilistic, scenario-based).","Likelihood and consequence dimension declarations with units, scale references, distribution parameters and support for multi-dimensional impact.","Inherent (pre-control) estimate together with an explicit statement of what 'inherent' excluded in this context, or a documented ground for omitting it.","Assumptions, information sources, data currency, estimation basis kind, analysis constraints and identification of critical assumptions.","Uncertainty representation, confidence or data-quality grading, unmeasurable aspects and precision caveats.","Control linkage: references to the controls relied on and to the effectiveness determinations cited for them, produced by the owning control assessment model.","Residual (post-control) estimate, the characterization state marking it as adjusted rather than initial, the changed-dimension set and the explanation of change.","References to the appetite or tolerance statement in force and the recorded outcome of comparing the residual estimate against it.","Assessment-context governance stamps: assessor, context owner, reviewer and acceptance-decision references, and review-due timing.","Comparability verdicts, mismatched-pin reporting, aggregation caveats, scenario identifiers and reference-case designation."],"out":["The risk or opportunity entity itself: its identity, statement, status, register membership and lifecycle transitions.","The control register: control identity, design, implementation records, control ownership and control lifecycle.","Evaluation or testing of control design or operating effectiveness and the production of effectiveness determinations.","Risk treatment options, treatment plans, milestones, remediation tracking, plan-of-action records and closure.","Incidents, realized loss events, issues, near misses and post-event investigation.","Objective, asset, process and organizational-unit master data.","Setting, approving, publishing or enforcing risk appetite and tolerance thresholds.","Granting acceptance, authorization or exception decisions on a residual position.","Assessment execution, observation capture and evidence collection procedures.","Audit-trail storage, log integrity and retention execution.","Technique internals and algorithm semantics of any pinned method, including simulation, fault-tree, event-tree and Bayesian computation.","Any fixed numeric risk matrix, default likelihood band, default impact scale or universal scoring rule.","Runtime evaluation or enforcement of thresholds by a policy engine."],"boundaries":[{"neighbor":"WM-KNW-015 risk / opportunity entity and lifecycle","distinction":"The parent model owns risk identity, statement, register status and lifecycle. This mixin attaches one assessment context to a pinned revision of that entity, carries no risk status transitions, and marks its own binding as stale when the pinned revision is superseded upstream."},{"neighbor":"Control implementation records and control assessment determinations","distinction":"This mixin stores control references and cites effectiveness determinations by reference; determining, testing or re-opening effectiveness belongs to the control assessment model, where assessment objectives, methods and satisfied / other-than-satisfied determinations are produced."},{"neighbor":"Risk treatment, remediation and plan-of-action records","distinction":"A residual estimate is an input to treatment planning. Treatment option selection, milestones, scheduling, cost tracking and closure are owned by the treatment model and are not represented here."},{"neighbor":"Assessment execution, observation and evidence records","distinction":"Observations and evidence are cited as the basis of an estimate. Collecting evidence, executing assessment procedures and logging assessment results are owned by the assessment-results model; this mixin holds references and a basis statement only."},{"neighbor":"Risk appetite and tolerance governance","distinction":"The mixin references a versioned tolerance statement and records the comparison outcome. Determining appetite, approving tolerance lines and enforcing them are enterprise governance acts held elsewhere."},{"neighbor":"Acceptance, authorization and exception decisions","distinction":"Accepting a residual position is an authorization act performed by a designated official and recorded in an authorization or decision model. This mixin carries only a reference to that decision and never grants, derives or enforces it."},{"neighbor":"Incident, loss event and issue records","distinction":"A realized event is not an assessment. Loss data may be cited as an information source for an estimate, but event records, their timelines and their consequences are owned by event models."},{"neighbor":"Risk assessment technique definitions (IEC 31010 technique catalogue and comparable method registries)","distinction":"The mixin pins which technique and version were applied and stores the technique's declared outputs. It never restates, parameterizes or re-implements the technique's internal semantics."},{"neighbor":"Alternative subject kind: relationship (a first-class risk-to-control association)","distinction":"Modelling this as a relationship was tested. A relationship entry would give each risk-control link its own identity, which suits relied-on-control attribution. It fails for the rest of the required content: assessment scope, horizon, criteria pin, likelihood and consequence dimensions, uncertainty and appetite comparison are properties of an assessment context attached to a host record, and one context routinely cites many controls and many consequences. The mixin kind is retained; the residual-change attribution is the part a Dimension may legitimately reify as a separate association record without altering this field group."}]},"distinguishingFeatures":["A mixin that attaches a revision-pinned risk assessment context to a host record, not the risk register entity itself.","Pins the method, taxonomy and criteria so estimates can be compared only when comparable.","Links risks to controls and records design, implementation and operating effectiveness separately.","Leaves acceptance, treatment plans and incidents to neighbouring models."],"structure":{"bundles":[{"id":"rctl-risk-binding-bundle","name":"Risk subject binding and assessment framing","description":"Everything that fixes what was assessed and under which declared frame: the referenced risk and its exact revision, the anchors the assessment is scoped against, the causal chain quantified, the category and taxonomy pins, the scope and horizon, and the criteria, method and expression-mode pins.","layers":[{"id":"rctl-risk-reference-layer","name":"Referenced risk, anchors and causal chain","description":"Reference-carrying fields that attach one assessment context to a pinned risk revision, to the objectives, assets, processes and contextual conditions it is scoped against, and to the risk source, event and consequences it quantifies.","findings":[{"id":"rctl-risk-subject-reference","name":"Referenced risk identity and exact revision pin","description":"Identifies which risk or opportunity entity this assessment context is bound to and which exact revision of its statement was assessed, so an estimate cannot silently drift when the referenced statement is later restated. The referenced entity's own status and lifecycle stay with the owning risk model; only the local binding validity state is held here.","questions":[{"text":"Which authoritative identifier designates the risk entity that this assessment context is bound to?","id":"rctl-risk-q-subject-identifier","kind":"identity"},{"text":"Which exact revision or version of the referenced risk statement was assessed?","id":"rctl-risk-q-subject-revision","kind":"provenance"},{"text":"How is this assessment context marked once the pinned risk revision is superseded upstream?","id":"rctl-risk-q-subject-staleness","kind":"state"},{"text":"Does the bound subject represent a threat, an opportunity, or both, and where is that reading declared?","id":"rctl-risk-q-subject-polarity","kind":"classification"}]},{"id":"rctl-risk-context-anchors","name":"Objective, asset, process and context anchors","description":"Records what the risk is assessed against - objectives, assets, processes, organizational units, fixed contextual conditions and applicable jurisdiction or site - as references, so the estimate is interpretable and comparable only within its declared anchor set. Master data for each anchor belongs to its own registry.","questions":[{"text":"Which objectives does this assessment measure the effect of uncertainty against?","id":"rctl-risk-q-anchor-objectives","kind":"relationship"},{"text":"Which assets, processes or organizational units are inside the assessed exposure?","id":"rctl-risk-q-anchor-exposure","kind":"composition"},{"text":"Which contextual conditions were treated as fixed rather than assessed for this estimate?","id":"rctl-risk-q-anchor-fixed-conditions","kind":"constraint"},{"text":"Where anchors are jurisdiction-specific or site-specific, how is the applicable location recorded?","id":"rctl-risk-q-anchor-location","kind":"spatial"}]},{"id":"rctl-risk-causal-anchors","name":"Risk source, event and consequence anchors","description":"Carries references to the risk source or threat source, the single event or event class whose likelihood is quantified, and the consequences included in the impact estimate, together with named exclusions. This makes likelihood and impact attach to a stated causal chain rather than to a bare label.","questions":[{"text":"Which risk source or threat source does this estimate attribute the event to?","id":"rctl-risk-q-causal-source","kind":"relationship"},{"text":"Which single event or event class does the likelihood dimension quantify?","id":"rctl-risk-q-causal-event","kind":"definition"},{"text":"Which consequences are inside the impact estimate and which named consequences are excluded?","id":"rctl-risk-q-causal-consequences","kind":"composition"},{"text":"Which vulnerability or predisposing condition is assumed present for the event to occur?","id":"rctl-risk-q-causal-preconditions","kind":"constraint"},{"text":"Which external threat or hazard catalogue entry is cited, and under which catalogue version?","id":"rctl-risk-q-causal-catalogue","kind":"interoperability"}]}]},{"id":"rctl-risk-frame-layer","name":"Classification, scope and method framing","description":"Fields that pin the interpretive frame of the estimate: category values against a versioned taxonomy, the assessment boundary and time structure, and the criteria set, method, technique and expression mode under which any recorded value must be read.","findings":[{"id":"rctl-risk-taxonomy-pin","name":"Category assignment with taxonomy and version pin","description":"Pins the category values used to classify the referenced risk within this assessment context, together with the taxonomy scheme identifier and version, because category labels are only comparable inside one pinned scheme and category lists differ materially between frameworks.","questions":[{"text":"Which taxonomy scheme and version supplies the category values asserted here?","id":"rctl-risk-q-taxonomy-scheme","kind":"classification"},{"text":"Which category values are asserted, and is more than one concurrent categorization permitted?","id":"rctl-risk-q-taxonomy-multiplicity","kind":"constraint"},{"text":"How is a category value mapped when the adopting Dimension and an external framework use different schemes?","id":"rctl-risk-q-taxonomy-mapping","kind":"interoperability"},{"text":"Who is authorized to change a pinned category value after an estimate has been recorded against it?","id":"rctl-risk-q-taxonomy-authority","kind":"authority"}]},{"id":"rctl-risk-assessment-scope","name":"Assessment scope, horizon and time structure","description":"Declares what the assessment covers and for how long: the assessment boundary and its exclusions, the time horizon over which likelihood is expressed, the as-of time of the assessed state, the time the estimate was recorded, the validity or review-due time, and the decision the assessment was produced for.","questions":[{"text":"What is the declared boundary of this assessment and what is explicitly excluded from it?","id":"rctl-risk-q-scope-boundary","kind":"constraint"},{"text":"Over what time horizon is the likelihood or frequency dimension expressed?","id":"rctl-risk-q-scope-horizon","kind":"temporal"},{"text":"What are the as-of time of the assessed state and the time the estimate was recorded, and do they differ?","id":"rctl-risk-q-scope-time-separation","kind":"provenance"},{"text":"Until when is this assessment treated as current, and what triggers an out-of-date state?","id":"rctl-risk-q-scope-currency","kind":"state"},{"text":"Which decision or reporting purpose was this assessment produced for?","id":"rctl-risk-q-scope-purpose","kind":"decision"}]},{"id":"rctl-risk-criteria-method-pin","name":"Criteria, method and expression-mode pin","description":"Pins the risk criteria set, the assessment method or technique and their versions, plus the expression mode under which values are recorded, so that a level of risk stays interpretable and so that comparison can be refused when pins differ. The mixin references method definitions and never restates technique semantics.","questions":[{"text":"Which risk criteria set, at which version, defines the scales and thresholds used here?","id":"rctl-risk-q-criteria-set","kind":"definition"},{"text":"Which assessment technique or method was applied, and where is its normative definition held?","id":"rctl-risk-q-method-identity","kind":"provenance"},{"text":"Is the expression qualitative, ordinal, semi-quantitative, quantitative, probabilistic or scenario-based?","id":"rctl-risk-q-expression-mode","kind":"classification"},{"text":"What must match before two records assessed under different pins may be compared?","id":"rctl-risk-q-pin-match-rule","kind":"validation"},{"text":"Who approved the criteria set for use in this assessment context?","id":"rctl-risk-q-criteria-approval","kind":"authority"}]}]}]},{"id":"rctl-risk-estimation-bundle","name":"Estimation and evidential basis","description":"The dimension declarations that give likelihood and consequence their meaning, the inherent estimate and its exclusion statement, and the assumptions, information sources, estimation basis and uncertainty qualification that make the estimate falsifiable.","layers":[{"id":"rctl-risk-dimension-layer","name":"Likelihood and consequence dimension declarations","description":"Declares the form, unit and scale of each side of the estimate, admitting ordinal bands, probabilities, frequencies, distributions and multi-dimensional impact without imposing any single matrix.","findings":[{"id":"rctl-risk-likelihood-dimension","name":"Likelihood and frequency expression","description":"Declares how the likelihood side is expressed - ordinal band, probability, frequency per unit time, qualitative descriptor or distribution - with its unit, scale reference, horizon dependency and the operations its scale type forbids.","questions":[{"text":"In what form is likelihood expressed and against which scale or unit?","id":"rctl-risk-q-likelihood-form","kind":"measurement"},{"text":"Does this record separate likelihood of event occurrence from likelihood of adverse consequence?","id":"rctl-risk-q-likelihood-decomposition","kind":"composition"},{"text":"If a range or distribution is used, which parameters, bounds and confidence level are stored?","id":"rctl-risk-q-likelihood-distribution","kind":"quality"},{"text":"Which operations on the likelihood value are prohibited by its scale type?","id":"rctl-risk-q-likelihood-operations","kind":"constraint"}]},{"id":"rctl-risk-consequence-dimension","name":"Impact and consequence dimensions","description":"Declares the impact side, which may be multi-dimensional across financial, safety, health, fundamental-rights, environmental, operational, reputational and regulatory effects, each with its own scale, and states how or whether dimensions are combined and which parties bear each consequence.","questions":[{"text":"Which impact dimensions are scored, and on which scale is each one expressed?","id":"rctl-risk-q-impact-dimensions","kind":"measurement"},{"text":"How are multiple impact dimensions combined, or is combination explicitly withheld?","id":"rctl-risk-q-impact-combination","kind":"constraint"},{"text":"Are safety, health, environmental or fundamental-rights harms represented as first-class dimensions rather than monetized proxies?","id":"rctl-risk-q-impact-nonfinancial","kind":"requirement"},{"text":"Which affected parties bear each recorded consequence?","id":"rctl-risk-q-impact-bearers","kind":"relationship"},{"text":"How are secondary or downstream consequences distinguished from primary consequences?","id":"rctl-risk-q-impact-order","kind":"classification"}]},{"id":"rctl-risk-inherent-estimate","name":"Inherent estimate and its exclusion statement","description":"Records the estimate produced before, or excluding, the effect of the referenced controls, together with an explicit statement of what inherent was taken to mean, because the term is not uniformly defined and some authorities do not require it at all. Omission must be recorded with a ground rather than left implicit.","questions":[{"text":"What definition of inherent or gross risk was used, and which control effects were excluded from it?","id":"rctl-risk-q-inherent-definition","kind":"definition"},{"text":"What is the recorded inherent level, and how does it relate the likelihood and impact dimensions?","id":"rctl-risk-q-inherent-value","kind":"measurement"},{"text":"Was an inherent estimate produced at all, and if not, on what documented ground was it omitted?","id":"rctl-risk-q-inherent-omission","kind":"exception"},{"text":"What derivation or evidence supports the inherent value?","id":"rctl-risk-q-inherent-evidence","kind":"evidence"}]}]},{"id":"rctl-risk-basis-layer","name":"Assessment basis, assumptions and uncertainty","description":"The evidential qualification of the estimate: assumptions that must hold, the information sources and their currency, whether the value came from judgement, data or a model, the constraints on the analysis, and how much confidence and precision the result can bear.","findings":[{"id":"rctl-risk-basis-and-uncertainty","name":"Assumptions, data basis and uncertainty qualification","description":"Captures the assumptions, information sources, data currency, estimation basis kind and analysis constraints behind the estimate, together with confidence or data-quality grading, uncertainty representation, unmeasurable aspects and precision caveats. This is what allows a reader to judge whether a value rests on incident history, expert judgement, modelled data or a vendor claim, and how far it may be trusted.","questions":[{"text":"Which explicit assumptions must hold for this estimate to remain valid?","id":"rctl-risk-q-basis-assumptions","kind":"constraint"},{"text":"Which information sources and datasets were used, and how current were they at the as-of time?","id":"rctl-risk-q-basis-sources","kind":"provenance"},{"text":"Was the estimate elicited from expert judgement, derived from historical data, or produced by a model run?","id":"rctl-risk-q-basis-kind","kind":"evidence"},{"text":"What confidence or data-quality grade is attached to this estimate, and on which scale?","id":"rctl-risk-q-basis-confidence","kind":"quality"},{"text":"What precision may downstream consumers infer from the stored notation, and which aspects are effectively unmeasurable?","id":"rctl-risk-q-basis-precision","kind":"validation"}]}]}]},{"id":"rctl-risk-residual-bundle","name":"Residual position and comparability","description":"The post-control estimate with its control linkage and change explanation, the comparison against referenced appetite or tolerance with its governance stamps, and the comparability, aggregation and scenario-dependence controls that stop values from being combined when their pins do not match.","layers":[{"id":"rctl-risk-residual-layer","name":"Residual estimate, control linkage and appetite comparison","description":"Fields that record the post-control estimate, the controls relied on and the effectiveness determinations cited for them, the explanation of change, and the outcome of comparing the residual position against a referenced tolerance statement.","findings":[{"id":"rctl-risk-residual-estimate","name":"Residual estimate, control linkage and change explanation","description":"Records the estimate after the referenced controls are taken into account, the control references relied on, the effectiveness determinations cited for each of them, which dimension changed, and why. Effectiveness is cited by reference and is produced by the control assessment model; this finding never derives, revises or re-opens it.","questions":[{"text":"Which controls were relied on when producing the residual estimate, and by which reference?","id":"rctl-risk-q-residual-controls","kind":"relationship"},{"text":"Which effectiveness determination is cited for each relied-on control, and who produced it?","id":"rctl-risk-q-residual-effectiveness","kind":"evidence"},{"text":"Which dimension changed between the inherent and residual estimates - likelihood, consequence, or both?","id":"rctl-risk-q-residual-change","kind":"composition"},{"text":"How is the residual value marked as an adjusted rather than an initial characterization?","id":"rctl-risk-q-residual-characterization","kind":"state"},{"text":"What is recorded when a control is referenced but no effectiveness determination exists for it?","id":"rctl-risk-q-residual-missing-determination","kind":"exception"}]},{"id":"rctl-risk-appetite-comparison","name":"Appetite or tolerance reference and comparison outcome","description":"References the appetite or tolerance statement in force, records the outcome of comparing the residual estimate against it, and stamps who recorded the comparison and which acceptance or authorization decision, if any, was taken elsewhere. Setting, approving and enforcing appetite are not performed here.","questions":[{"text":"Which appetite or tolerance statement, at which version, was the residual estimate compared against?","id":"rctl-risk-q-appetite-reference","kind":"relationship"},{"text":"What is the recorded comparison outcome and on which scale is it expressed?","id":"rctl-risk-q-appetite-outcome","kind":"measurement"},{"text":"Who recorded the comparison, and which decision record shows the residual position being accepted?","id":"rctl-risk-q-appetite-stamps","kind":"ownership"},{"text":"What is recorded when no applicable tolerance statement exists for the pinned criteria?","id":"rctl-risk-q-appetite-absent","kind":"exception"},{"text":"Which downstream consumers may read the comparison outcome without access to the underlying estimates?","id":"rctl-risk-q-appetite-disclosure","kind":"access"}]}]},{"id":"rctl-risk-comparability-layer","name":"Comparability, aggregation and scenario dependence","description":"The gate that decides whether two assessment contexts may be compared, rolled up or reported together, the caveats any permitted aggregate must carry, and how one risk assessed under several scenarios is represented without collapsing into a single false value.","findings":[{"id":"rctl-risk-comparability-limits","name":"Comparability verdicts, aggregation caveats and scenario dependence","description":"Records whether records may be placed on a common scale, which pins failed to match when they may not, which caveats must travel with any permitted aggregate, and how scenario variants and a designated reference case are represented. The model refuses to define a normalization algorithm it has no authority to assert.","questions":[{"text":"Under what conditions may two assessment contexts be placed on the same scale?","id":"rctl-risk-q-comparability-conditions","kind":"validation"},{"text":"Which caveats must travel with any aggregate produced from these records?","id":"rctl-risk-q-comparability-caveats","kind":"constraint"},{"text":"How is scenario dependence recorded when one risk is assessed under several scenarios?","id":"rctl-risk-q-comparability-scenarios","kind":"composition"},{"text":"Which scenario or variant is designated the reference case for reporting, and by which role?","id":"rctl-risk-q-comparability-reference-case","kind":"decision"},{"text":"How are records assessed under a superseded criteria version handled in a current roll-up?","id":"rctl-risk-q-comparability-superseded","kind":"lifecycle"}]}]}]},{"id":"rctl-control-definition-binding","name":"Control reference, classification and applicability","description":"What control is being talked about, how it is characterised, where it applies to the host subject, and who is accountable for it.","layers":[{"id":"rctl-control-authoritative-reference","name":"Authoritative control reference and characterisation","description":"The revision-pinned binding to an external control definition, and the objective and classification facets projected onto it for this subject.","findings":[{"id":"rctl-control-catalogue-binding","name":"Authoritative control reference and revision binding","description":"Binds this assertion set to exactly one control definition in an external catalogue, pinned to a named catalogue source and revision, with the parameter values selected and any tailoring declared for the host subject. Catalogue text, families, enhancements and parameter definitions remain owned by the catalogue model.","questions":[{"text":"Which single authoritative catalogue entry does this assertion set bind to, and under which identifier scheme?","id":"rctl-control-q-binding-identity","kind":"identity"},{"text":"Which catalogue release or revision was in force when the binding was made, and how is that pin preserved?","id":"rctl-control-q-binding-revision","kind":"provenance"},{"text":"Which control statement parts or enhancements are in scope for this binding, and which parameter values were selected?","id":"rctl-control-q-binding-parts","kind":"composition"},{"text":"What tailoring or deviation from the catalogue baseline does this binding assert, and on whose authority?","id":"rctl-control-q-binding-tailoring","kind":"constraint"},{"text":"How can a consumer resolve this binding without importing the catalogue text into local storage?","id":"rctl-control-q-binding-resolution","kind":"interoperability"}]},{"id":"rctl-control-objective-classification","name":"Control objective and classification projection","description":"The objective the control is claimed to achieve for the host subject plus classification facets: functional type (preventive, detective, corrective), execution mode (manual, automated, hybrid), operating level (entity or process/transaction) and key designation. Values are source-qualified; where a catalogue publishes its own attribute values they are carried unchanged.","questions":[{"text":"What control objective is the control claimed to achieve for this specific host subject?","id":"rctl-control-q-objective-statement","kind":"definition"},{"text":"Is the control preventive, detective or corrective, and which vocabulary and source supply that value?","id":"rctl-control-q-functional-type","kind":"classification"},{"text":"Is the control executed manually, automatically or as a hybrid, and which part is automated?","id":"rctl-control-q-execution-mode","kind":"classification"},{"text":"Does the control operate at entity level or at process and transaction level for this subject?","id":"rctl-control-q-operating-level","kind":"relationship"},{"text":"Has the control been designated key or non-key for this subject, and who made that determination?","id":"rctl-control-q-key-designation","kind":"decision"}]}]},{"id":"rctl-control-applicability-accountability","name":"Applicability, scope and accountability","description":"Whether and where the control applies to the host subject, and which parties own, operate, assess and approve the assertions about it.","findings":[{"id":"rctl-control-applicability-scope","name":"Applicability, covered population and exclusion determination","description":"Declares whether the control applies to the host subject, the population or boundary it covers, the basis for that determination, and any not-applicable or partially applicable determination with justification, approval and validity window.","questions":[{"text":"Does this control apply to the host subject, and on what documented basis was that determined?","id":"rctl-control-q-applies-basis","kind":"requirement"},{"text":"What population, boundary or component set does the control cover within the subject?","id":"rctl-control-q-covered-population","kind":"spatial"},{"text":"If the control is declared not applicable or only partially applicable, what justification and approval support that?","id":"rctl-control-q-not-applicable","kind":"exception"},{"text":"From when until when does this applicability determination hold?","id":"rctl-control-q-applicability-window","kind":"temporal"},{"text":"Which obligation or authority makes this control mandatory rather than discretionary for the subject?","id":"rctl-control-q-applicability-authority","kind":"authority"}]},{"id":"rctl-control-accountability-references","name":"Owner, operator, assessor and approver references","description":"Role-scoped references to the parties accountable for the control and its assertions, including shared, provided and inherited responsibility splits, competence and authority assertions for the performer, and independence flags for the assessor and approver. Party master data stays in the directory model.","questions":[{"text":"Which party is accountable for the control's continued operation for this subject?","id":"rctl-control-q-owner-party","kind":"ownership"},{"text":"Who is authorised to approve the effectiveness conclusion, and are they independent of the operator?","id":"rctl-control-q-approval-independence","kind":"authority"},{"text":"How is responsibility divided between the subject owner, a shared service and any external provider?","id":"rctl-control-q-responsibility-split","kind":"composition"},{"text":"What competence and authority are asserted for the party performing the control?","id":"rctl-control-q-performer-competence","kind":"quality"},{"text":"Which parties may read or amend this control assertion set, and under which role?","id":"rctl-control-q-assertion-access","kind":"access"}]}]}]},{"id":"rctl-control-linkage-topology","name":"Risk-to-control linkage, coverage and framework alignment","description":"The graph that connects risk statements to controls, the aggregate coverage it produces, dependency edges between controls, and crosswalks to other frameworks that carry no conformance meaning.","layers":[{"id":"rctl-control-treatment-linkage","name":"Treatment linkage and coverage topology","description":"Individual risk-to-control links with their claimed treatment mechanism, and the aggregate many-to-many coverage and dependency structure they form.","findings":[{"id":"rctl-control-link-record","name":"Risk-to-control link and claimed treatment mechanism","description":"One directed link from a risk statement reference to a control reference, carrying the claimed treatment mechanism, the risk-response type it serves, any claimed magnitude of reduction, the basis of the claim and its provenance. The risk record and its own lifecycle stay in the risk model.","questions":[{"text":"Which risk statement does this control link to, and in which direction does the treatment claim run?","id":"rctl-control-q-link-target","kind":"relationship"},{"text":"By what mechanism is the control claimed to treat the risk: likelihood, impact, detection latency or transfer support?","id":"rctl-control-q-link-mechanism","kind":"definition"},{"text":"What magnitude of reduction is claimed, on what scale, and is the claim estimated or demonstrated?","id":"rctl-control-q-link-magnitude","kind":"measurement"},{"text":"Who asserted this linkage, from which analysis, and at what event and observation times?","id":"rctl-control-q-link-provenance","kind":"provenance"},{"text":"What causes this linkage to be superseded or retired, and how is the prior link preserved?","id":"rctl-control-q-link-retirement","kind":"lifecycle"}]},{"id":"rctl-control-coverage-dependency","name":"Many-to-many coverage and control dependency structure","description":"The aggregate view over links: which control sets cover which risks and vice versa, coverage completeness and precision, uncovered risks and unlinked controls, plus dependency and reliance edges between controls including reliance on general IT controls, shared services and inherited controls.","questions":[{"text":"Which controls together are claimed to cover a given risk, and can any one of them cover it alone?","id":"rctl-control-q-coverage-set","kind":"composition"},{"text":"At what level of precision does the control set operate relative to the risk it is claimed to cover?","id":"rctl-control-q-coverage-precision","kind":"quality"},{"text":"Which other controls must operate for this control to be effective, and what happens when they fail?","id":"rctl-control-q-dependency-edges","kind":"relationship"},{"text":"Which linked risks currently have no operating control, and which controls have no linked risk?","id":"rctl-control-q-coverage-gaps","kind":"validation"},{"text":"How is the coverage set expressed so a consumer can traverse it without loading the full catalogue?","id":"rctl-control-q-coverage-traversal","kind":"interoperability"}]}]},{"id":"rctl-control-framework-crosswalk","name":"External framework alignment","description":"Secondary mappings from the bound control to entries in other catalogues and outcome frameworks, held strictly as alignment.","findings":[{"id":"rctl-control-crosswalk-alignment","name":"Framework crosswalk without conformance claim","description":"Mappings from the bound control to entries in other frameworks, each carrying relation strength, the target framework version, the mapping author and date, and an explicit disclaimer that the mapping asserts alignment only and never conformance, implementation or effectiveness.","questions":[{"text":"To which entries in other frameworks is this control mapped, and with what relation strength?","id":"rctl-control-q-crosswalk-targets","kind":"interoperability"},{"text":"Who authored each mapping, against which target framework version, and when?","id":"rctl-control-q-crosswalk-provenance","kind":"provenance"},{"text":"What does this mapping explicitly not assert about conformance, implementation or effectiveness?","id":"rctl-control-q-crosswalk-disclaimer","kind":"constraint"},{"text":"How is a mapping revalidated when either the source or the target framework version changes?","id":"rctl-control-q-crosswalk-revalidation","kind":"validation"}]}]}]},{"id":"rctl-control-assurance","name":"Design, implementation, operation, evidence and tested effectiveness","description":"The five separately recorded states of a control for the host subject, the assessment and evidence that support them, and the contribution the result makes to residual risk.","layers":[{"id":"rctl-control-state-assertions","name":"Design, implementation and operating assertions","description":"Three distinct status assertions about the control for this subject, each with its own basis, determining party and time, and none derivable from another.","findings":[{"id":"rctl-control-design-assertion","name":"Design adequacy assertion","description":"The assertion that the control, if operated as prescribed, would achieve its objective: design status, design rationale, the threshold or precision at which it would act, the determining party and time, and any recorded design limitation or design deficiency reference. Explicitly independent of whether the control is implemented or operating.","questions":[{"text":"What is the current design status of the control for this subject, and what does that value deliberately exclude?","id":"rctl-control-q-design-status","kind":"state"},{"text":"If operated exactly as prescribed, which part of the objective would the control achieve and which part would it not?","id":"rctl-control-q-design-coverage","kind":"requirement"},{"text":"At what threshold, tolerance or level of precision is the control designed to act?","id":"rctl-control-q-design-precision","kind":"measurement"},{"text":"Who determined that the design is adequate, on what date, and against which criteria?","id":"rctl-control-q-design-determination","kind":"decision"},{"text":"What known design limitation or design deficiency is recorded, and which external record tracks it?","id":"rctl-control-q-design-limitation","kind":"exception"}]},{"id":"rctl-control-implementation-assertion","name":"Implementation state, deviations, exceptions and compensating controls","description":"Whether the designed control is actually in place for the subject: implementation status and scope of partial implementation, recorded deviations from the design, approved exceptions or waivers with expiry, and references to compensating or alternative controls together with the documented constraint that justifies them. Compensating control definitions and remediation workflow stay in their owning models.","questions":[{"text":"What implementation status is recorded for the subject, and what scope does a partial status actually cover?","id":"rctl-control-q-implementation-status","kind":"state"},{"text":"Which approved exception or waiver permits a gap in implementation, who approved it, and when does it expire?","id":"rctl-control-q-implementation-exception","kind":"exception"},{"text":"Which compensating or alternative control is relied on, and against which defined requirement?","id":"rctl-control-q-compensating-control","kind":"relationship"},{"text":"What documented technical or business constraint justifies the compensating or alternative approach?","id":"rctl-control-q-implementation-constraint","kind":"constraint"},{"text":"Which change to the subject last altered the implementation state, and when was that change recorded?","id":"rctl-control-q-implementation-change","kind":"event"}]},{"id":"rctl-control-operating-cadence","name":"Operating status, frequency and triggers","description":"How the control actually runs: operating status kept distinct from implementation status, declared frequency or event triggers, the expected occurrence population for a stated period, observed occurrence counts obtained by reference, and suspension or dormancy handling. Execution records belong to the executing system.","questions":[{"text":"Is the control currently operating, and how does that value differ from being implemented?","id":"rctl-control-q-operating-status","kind":"state"},{"text":"At what frequency, or on which event triggers, is the control expected to operate?","id":"rctl-control-q-operating-frequency","kind":"temporal"},{"text":"How many occurrences were expected and how many observed in the stated period?","id":"rctl-control-q-operating-occurrences","kind":"measurement"},{"text":"Which system or party executes the control, and where is that execution recorded?","id":"rctl-control-q-operating-executor","kind":"process"},{"text":"What suspends or resumes operation of the control, and how is a dormant period represented?","id":"rctl-control-q-operating-suspension","kind":"lifecycle"}]}]},{"id":"rctl-control-evidence-assessment","name":"Assessment and evidence binding","description":"The binding between an effectiveness assertion and the assessment activity and evidence objects that support it, held as references, methods, times and digests only.","findings":[{"id":"rctl-control-assessment-evidence-binding","name":"Assessment method, timing and evidence binding","description":"Binds an effectiveness assertion to the assessment activity and its evidence: assessment method (examine, interview, test), depth and coverage attributes, sample or population basis, assessment event time and the operating period covered, assessor reference, and evidence references with integrity digests, collection times and expiry. Test cases, results and evidence payloads remain in their owning models.","questions":[{"text":"Which evidence objects support the assertion, and how is each referenced and integrity-bound?","id":"rctl-control-q-evidence-refs","kind":"evidence"},{"text":"Which assessment methods were applied, and at what depth and coverage?","id":"rctl-control-q-assessment-method","kind":"process"},{"text":"When was the assessment performed, and which period of control operation does its conclusion cover?","id":"rctl-control-q-assessment-timing","kind":"temporal"},{"text":"Why is the bound evidence sufficient given the risk associated with this control?","id":"rctl-control-q-evidence-sufficiency","kind":"quality"},{"text":"If testing was performed at an interim date, what supports extending the conclusion to the end of the period?","id":"rctl-control-q-interim-rollforward","kind":"validation"}]}]},{"id":"rctl-control-effectiveness-residual","name":"Tested effectiveness and residual contribution","description":"The conclusion drawn about operating effectiveness with its confidence and expiry, and the contribution that conclusion makes to the residual position of the linked risk.","findings":[{"id":"rctl-control-effectiveness-conclusion","name":"Tested effectiveness conclusion, confidence and validity","description":"The conclusion about operating effectiveness on a named vocabulary, with its scope, the assessment and evidence bindings that are its only permitted basis, an attached confidence and its limits, a validity window with invalidation triggers, and any deficiency severity with a reference to the record tracking remediation.","questions":[{"text":"What effectiveness conclusion was reached, on which named vocabulary, and over what scope?","id":"rctl-control-q-conclusion-value","kind":"decision"},{"text":"Which assessment and evidence bindings form the sole permitted basis for this conclusion?","id":"rctl-control-q-conclusion-basis","kind":"evidence"},{"text":"What confidence is attached to the conclusion, and what limits that confidence?","id":"rctl-control-q-conclusion-confidence","kind":"quality"},{"text":"Until when is the conclusion valid, and which events invalidate it before that time?","id":"rctl-control-q-conclusion-validity","kind":"temporal"},{"text":"If the conclusion is adverse, what deficiency severity is recorded and which external record tracks remediation?","id":"rctl-control-q-conclusion-deficiency","kind":"exception"}]},{"id":"rctl-control-residual-contribution","name":"Residual contribution and acceptance linkage","description":"How the assessed effectiveness of this control contributes to the residual position of the linked risk: the attributed change from inherent to residual, the attribution method and its effective time, the attribution status, and references to the residual risk record and any acceptance decision. Residual values, appetite thresholds and acceptance decisions are owned by the risk model.","questions":[{"text":"What change from the inherent to the residual position is attributed to this control, and on which scale?","id":"rctl-control-q-residual-delta","kind":"measurement"},{"text":"Which effectiveness conclusion and which attribution method produced the attributed change?","id":"rctl-control-q-residual-method","kind":"provenance"},{"text":"Which residual risk record does this contribution feed, and has the risk model accepted the attribution?","id":"rctl-control-q-residual-acceptance","kind":"relationship"},{"text":"What prevents an untested or ineffective control from reducing the recorded residual position?","id":"rctl-control-q-residual-guardrail","kind":"constraint"},{"text":"When the supporting conclusion expires, what happens to this residual contribution?","id":"rctl-control-q-residual-expiry","kind":"lifecycle"}]}]}]},{"id":"rctl-gov-accountability-bundle","name":"Accountability, authority and assurance basis","description":"Who is accountable for a risk-control binding, who may assert or accept it, which duties must stay separated, and on what criteria and assurance basis its conclusions rest.","layers":[{"id":"rctl-gov-ownership-authority-layer","name":"Ownership, assertion authority and duty separation","description":"Accountability assignment for the binding, the authority conditions governing its assertion and acceptance, and the incompatible-duty constraints applied to those acts.","findings":[{"id":"rctl-gov-accountable-owner","name":"Accountable owner of the projected risk and of each linked control","description":"Identifies the party accountable for the residual risk conclusion on this host and the party accountable for each linked control, distinguishes accountability from delegated operational execution, and places each party in a governance line.","questions":[{"text":"Which party holds accountability for the residual risk conclusion on this host record, and which party holds accountability for each linked control?","id":"rctl-gov-q-owner-party","kind":"ownership"},{"text":"How is operational execution delegated to another party without transferring accountability for the binding?","id":"rctl-gov-q-owner-delegation","kind":"authority"},{"text":"Which governance line does each named party occupy for this binding, and does any party occupy more than one line?","id":"rctl-gov-q-owner-line","kind":"classification"},{"text":"What becomes of the binding when the accountable owner role is vacant, reassigned, or the owning organisational unit is dissolved?","id":"rctl-gov-q-owner-vacancy","kind":"exception"}]},{"id":"rctl-gov-assertion-authority","name":"Authority to assert, change, accept or retire a binding","description":"Separates authority to assert a control linkage from authority to accept the residual risk that remains, ties each act to a versioned authority threshold table, and defines admissibility preconditions for changing an already accepted binding.","questions":[{"text":"Which authority level is required to accept a residual risk in each severity band, and in which versioned threshold table is that requirement defined?","id":"rctl-gov-q-authority-threshold","kind":"authority"},{"text":"What distinguishes authority to assert a control linkage from authority to accept the residual risk that remains after it?","id":"rctl-gov-q-authority-split","kind":"decision"},{"text":"Which preconditions must be satisfied before a change to an already accepted binding is admissible?","id":"rctl-gov-q-authority-precondition","kind":"constraint"},{"text":"How is an acceptance made under a superseded threshold table detected and re-validated?","id":"rctl-gov-q-authority-stale","kind":"validation"}]},{"id":"rctl-gov-duty-separation","name":"Segregation of duties and reviewer independence","description":"Declares which combinations of asserting, reviewing, approving and accepting the same binding are incompatible for one actor, what establishes reviewer independence from control design and operation, and how overrides and after-the-fact breaches are handled.","questions":[{"text":"Which combinations of asserting, reviewing, approving and accepting the same binding are declared incompatible for one actor?","id":"rctl-gov-q-sod-incompatible","kind":"constraint"},{"text":"What establishes that the reviewer of a binding is independent of the party that designed or operates the linked control?","id":"rctl-gov-q-sod-independence","kind":"evidence"},{"text":"Under what documented circumstances may a duty-separation constraint be overridden, and who may grant that override?","id":"rctl-gov-q-sod-override","kind":"exception"},{"text":"How are duty-separation breaches detected after the fact when they were not blocked at write time?","id":"rctl-gov-q-sod-detect","kind":"quality"}]}]},{"id":"rctl-gov-assurance-basis-layer","name":"Criteria, conflicts and assurance limitations","description":"The versioned criteria and scales against which residual risk and control effectiveness are judged, how competing criteria are resolved, and what limits reliance on the recorded conclusion.","findings":[{"id":"rctl-gov-criteria-basis","name":"Assessment criteria binding and conflict resolution","description":"Records which versioned criteria, scale and risk-appetite statement produced the residual conclusion, what makes those criteria suitable, and which verdict prevails when two applicable frameworks disagree on the same binding.","questions":[{"text":"Which versioned criteria, scale and risk-appetite statement were used to derive this residual risk conclusion?","id":"rctl-gov-q-criteria-version","kind":"measurement"},{"text":"When two applicable frameworks assign different acceptability verdicts to the same binding, which verdict prevails and on what recorded basis?","id":"rctl-gov-q-criteria-conflict","kind":"decision"},{"text":"What makes the chosen criteria suitable, and how are relevance, completeness, reliability and neutrality demonstrated?","id":"rctl-gov-q-criteria-suitability","kind":"quality"},{"text":"How does a change to the criteria or scale version affect conclusions already recorded under the previous version?","id":"rctl-gov-q-criteria-change","kind":"lifecycle"}]},{"id":"rctl-gov-assurance-limitation","name":"Assurance level, scope limitations and inherited reliance","description":"Records the level of assurance a control effectiveness conclusion carries, the methods and objects actually examined, what was excluded from scope, and the carve-outs limiting reliance on third-party reports.","questions":[{"text":"What level of assurance does this effectiveness conclusion carry, and what procedures produced it?","id":"rctl-gov-q-assurance-level","kind":"quality"},{"text":"Which parts of the control population, period or environment were excluded from the assessment scope?","id":"rctl-gov-q-assurance-scope","kind":"constraint"},{"text":"Which assessment methods and objects were applied, and what did each method actually examine?","id":"rctl-gov-q-assurance-method","kind":"process"},{"text":"When effectiveness is inherited from a third-party report, what carve-outs and complementary user-entity controls limit reliance?","id":"rctl-gov-q-assurance-inherited","kind":"evidence"}]}]}]},{"id":"rctl-gov-lifecycle-bundle","name":"Host-scoped lifecycle, currency, provenance and evidence","description":"How a binding moves through its host-scoped states, how long a conclusion stays current, how corrections are made by supersession, and how each assertion is attributed and bound to evidence.","layers":[{"id":"rctl-gov-state-currency-layer","name":"Binding state, assessment currency and supersession","description":"The permitted states of a binding on its host, the validity window and expiry of its assessment, and the rules for correcting a relied-upon assertion by issuing a successor.","findings":[{"id":"rctl-gov-binding-state","name":"Host-scoped lifecycle state of the binding","description":"Enumerates the states a risk-control binding may occupy on its host record, the permitted transitions, the constraint the host lifecycle imposes, and how duplicate active bindings between the same risk and control are resolved.","questions":[{"text":"Which lifecycle states may a risk-control binding occupy on its host record, and which transitions between them are permitted?","id":"rctl-gov-q-state-enum","kind":"state"},{"text":"How does the host record's own lifecycle constrain or terminate the state of the binding?","id":"rctl-gov-q-state-host","kind":"lifecycle"},{"text":"Which states are terminal, and which obligations survive after a binding leaves the active state?","id":"rctl-gov-q-state-terminal","kind":"requirement"},{"text":"May more than one active binding exist between the same risk and the same control on one host, and how is that resolved?","id":"rctl-gov-q-state-concurrent","kind":"relationship"}]},{"id":"rctl-gov-assessment-currency","name":"Assessment currency, expiry and reassessment triggers","description":"Defines how long a residual risk and effectiveness conclusion remains valid, which events force reassessment ahead of schedule, what status an expired but unreassessed binding carries, and which timestamp starts the currency clock.","questions":[{"text":"For how long is this residual risk conclusion valid, and what fixes the end of its validity window?","id":"rctl-gov-q-currency-window","kind":"temporal"},{"text":"Which events force reassessment of this binding before its scheduled expiry?","id":"rctl-gov-q-currency-trigger","kind":"event"},{"text":"What status does a binding carry once its assessment has expired but has not yet been reassessed?","id":"rctl-gov-q-currency-expired","kind":"state"},{"text":"Which timestamp starts the currency clock: the observed condition, the assessor's conclusion, or the recording of the assertion?","id":"rctl-gov-q-currency-clock","kind":"provenance"}]},{"id":"rctl-gov-supersession-correction","name":"Revision, supersession and correction of relied-upon assertions","description":"Determines whether a corrected assertion keeps its identifier with a new revision or receives a successor identifier, what a supersession record must state, which fields may never be edited in place, and who must be notified downstream.","questions":[{"text":"Does a corrected assertion keep the binding identifier and gain a new revision, or does it receive a new identifier that supersedes the prior one?","id":"rctl-gov-q-supersede-identity","kind":"identity"},{"text":"What must a supersession record state about the defect corrected and the period during which the superseded assertion was relied upon?","id":"rctl-gov-q-supersede-record","kind":"process"},{"text":"Which downstream consumers must be notified when an accepted binding is superseded, and within what interval?","id":"rctl-gov-q-supersede-downstream","kind":"interoperability"},{"text":"Which fields may never be edited in place, forcing correction by supersession instead?","id":"rctl-gov-q-supersede-mutate","kind":"constraint"}]}]},{"id":"rctl-gov-provenance-evidence-layer","name":"Provenance and evidence integrity","description":"Attribution of each assertion to an agent and activity, and the integrity binding between an assertion and the evidence it relies on.","findings":[{"id":"rctl-gov-provenance-attribution","name":"Provenance and attribution of the assertion","description":"Records which agent asserted the binding, on whose behalf it acted, which assessment activity generated the conclusion, what it was derived from, and whether the assertion is human-attested or machine-generated.","questions":[{"text":"Which agent asserted this binding, on whose behalf did that agent act, and was the agent human, organisational or automated?","id":"rctl-gov-q-prov-agent","kind":"provenance"},{"text":"Which assessment activity generated this conclusion, and which inputs did that activity use?","id":"rctl-gov-q-prov-activity","kind":"process"},{"text":"From which prior assertion or external report was this conclusion derived, and what changed relative to it?","id":"rctl-gov-q-prov-derivation","kind":"relationship"},{"text":"How is an automated or model-generated assertion distinguished from a human-attested one for reliance purposes?","id":"rctl-gov-q-prov-machine","kind":"classification"}]},{"id":"rctl-gov-evidence-integrity","name":"Evidence reference integrity and immutability","description":"Binds each item of supporting evidence to the assertion so that later substitution is detectable, fixes which attributes become immutable at approval, and defines the treatment of evidence that becomes unavailable or is lawfully destroyed.","questions":[{"text":"How is each item of supporting evidence bound to the assertion so that later substitution is detectable?","id":"rctl-gov-q-evidence-bind","kind":"evidence"},{"text":"Which evidence attributes become immutable once the assertion is approved, and what follows if the evidence store mutates them?","id":"rctl-gov-q-evidence-immutable","kind":"security"},{"text":"How is an assertion treated when referenced evidence becomes unavailable, unreadable or is lawfully destroyed?","id":"rctl-gov-q-evidence-missing","kind":"exception"},{"text":"What makes the referenced evidence sufficient and appropriate for the asserted assurance level?","id":"rctl-gov-q-evidence-sufficiency","kind":"quality"}]}]}]},{"id":"rctl-gov-stewardship-bundle","name":"Disclosure, interoperability and continuity stewardship","description":"How sensitive risk information is labelled, redacted and exported, which regional or sector profiles and exceptions apply, and how records are retained, held and tombstoned.","layers":[{"id":"rctl-gov-disclosure-layer","name":"Sensitivity, disclosure and external profiles","description":"Sensitivity labelling and field-level disclosure control over risk information, and the regional, sector and exchange profiles that govern a binding.","findings":[{"id":"rctl-gov-sensitivity-disclosure","name":"Sensitivity labelling and disclosure-profiled export","description":"Assigns handling labels to the binding and its parts, defines which fields are withheld, generalised or hashed for each audience, identifies personal data, and governs authorisation of out-of-profile release and re-identification checks.","questions":[{"text":"Which sensitivity label applies to this binding, and does the label differ between the risk statement, the control description and the evidence?","id":"rctl-gov-q-sens-label","kind":"classification"},{"text":"Which individual fields must be withheld, generalised or hashed when this record is disclosed to a less-privileged audience?","id":"rctl-gov-q-sens-field","kind":"privacy"},{"text":"Which audiences may receive which disclosure profile, and who authorises a release outside the profile?","id":"rctl-gov-q-sens-audience","kind":"access"},{"text":"How is it verified that a redacted export cannot be re-identified by combining it with previously released exports?","id":"rctl-gov-q-sens-reidentify","kind":"validation"}]},{"id":"rctl-gov-interop-profile","name":"Regional and sector profiles, exceptions and external mappings","description":"Declares which regional or sector profile is in force over what period, which profile requirements are formally excepted and on what compensating condition, how profile conflicts are resolved, and how the binding maps to external assessment exchange schemas.","questions":[{"text":"To which external assessment or risk exchange schema is this binding mapped, and which of its fields have no equivalent there?","id":"rctl-gov-q-interop-map","kind":"interoperability"},{"text":"Which regional or sector profile is in force for this binding, and over what effective period?","id":"rctl-gov-q-interop-profile","kind":"spatial"},{"text":"Which profile requirements are formally excepted for this binding, by whom, until when, and with what compensating condition?","id":"rctl-gov-q-interop-exception","kind":"exception"},{"text":"When a regional profile and a sector profile impose contradictory obligations on the same field, which one governs?","id":"rctl-gov-q-interop-conflict","kind":"decision"}]}]},{"id":"rctl-gov-continuity-layer","name":"Retention, legal hold and tombstoning","description":"Retention schedules and clock start for the mixin's own records, suspension of disposition under legal hold, and the minimum information that survives disposition.","findings":[{"id":"rctl-gov-retention-hold","name":"Retention, legal hold and tombstone semantics","description":"Records which retention schedule and disposition authority govern the binding, when the retention clock starts, how a hold suspends the normal disposition cycle, what survives in a tombstone, and which external owner actually executes destruction.","questions":[{"text":"Which retention schedule and disposition authority govern this binding's records, and when does the retention clock start?","id":"rctl-gov-q-ret-schedule","kind":"retention"},{"text":"How is a legal hold applied to a binding, who may apply and release it, and what does the hold suspend?","id":"rctl-gov-q-ret-hold","kind":"authority"},{"text":"What minimum information survives in a tombstone after disposition, and what must be irreversibly removed?","id":"rctl-gov-q-ret-tombstone","kind":"lifecycle"},{"text":"Which model or policy owner actually executes destruction, and how does this mixin record that the execution occurred?","id":"rctl-gov-q-ret-exec","kind":"process"}]}]}]}]},"agentConduct":{"may":["Record an estimate under a pinned method with assumptions.","Compare inherent and residual estimates under the same frame.","Link a control to a risk and record its applicability.","Explain the evidential basis of an effectiveness conclusion."],"mustNot":["Accept a risk on behalf of the organization.","Compare or aggregate estimates made under different methods or criteria.","Declare a control effective without evidence.","Lower a residual estimate without a recorded change in controls or evidence.","Hide a risk from owners who must be informed."],"requiresHuman":["Accepting residual risk or granting an exception.","Concluding that a key control is effective.","Retiring a risk-to-control link for a high risk."]},"ethics":{"considerations":["Risk assessments decide which harms are tolerated and who bears them.","Risks to people outside the organization, such as customers or neighbours, must not be discounted.","Optimistic estimates can hide safety problems."],"affectedParties":["People exposed to the risk","Risk and control owners","Auditors and regulators"]},"owners":{"steward":"The adopting Dimension must designate one accountable owner package for WM-XCT-027 records, name the responsible party in AGENTS.md, and keep that designation current; the mixin does not create or maintain party records itself.","roles":[{"name":"Risk owner","responsibilities":["Holds accountability for the residual risk conclusion recorded on the host record and for keeping it current.","Approves the treatment linkage and requests reassessment when a trigger fires.","Cannot discharge accountability by delegating operational execution."]},{"name":"Control owner","responsibilities":["Holds accountability for the design and operation of a linked control.","Supplies evidence of operation and notifies the risk owner of control failure or material change.","Is excluded from independently reviewing the effectiveness of the same control."]},{"name":"Independent reviewer or assurance provider","responsibilities":["Reviews assertions from a position independent of those who design or operate the controls, and records the basis of that independence with identified threats and safeguards.","Declares the assurance level reached, the methods and objects applied, and every scope limitation and carve-out.","Refuses or qualifies a conclusion where evidence is not sufficient and appropriate for the asserted level."]},{"name":"Risk acceptance authority","responsibilities":["Accepts residual risk only within the level the in-force threshold table assigns to that band, and records the table version used.","Re-takes acceptance when a binding is materially changed, expires or is superseded.","Escalates where the residual band exceeds the authority held."]},{"name":"Records and disposition steward","responsibilities":["Maintains retention schedule references, clock starts and disposition status for the mixin's records.","Applies and releases legal holds on written instruction from the authorised party and confirms that disposition executed elsewhere has completed.","Verifies that tombstones retain only the permitted minimum after disposition."]},{"name":"Disclosure steward","responsibilities":["Maintains disclosure profiles, sensitivity labels and field-level disclosure rules, and their versions.","Authorises or refuses out-of-profile releases and records the decision.","Checks that redacted exports cannot be re-identified by combination with prior releases."]},{"name":"Model steward","responsibilities":["Maintains the mixin schema version, profile registrations, external mappings and their lossiness statements.","Runs reconciliation against referenced registries and publishes the resulting reports.","Records unresolved boundary questions and conflicts rather than resolving them by local convention."]}],"masterSystems":[]},"relations":[{"target":"WM-KNW-015 - Risk / Opportunity entity and lifecycle","type":"child","note":"The parent model owns risk identity, statement, register membership, status and lifecycle transitions. This mixin attaches one assessment context to a pinned revision of that entity, carries only its own binding validity state, and reproduces no risk lifecycle or register operations."},{"target":"Host record of the adopting Dimension that carries risk-control linkage fields","type":"composes","note":"Defines how this field group is embedded on a host entity, event or decision record so a Dimension can carry a defensible assessment context without standing up a separate register."},{"target":"Control implementation and control assessment records (control register, implemented requirements, effectiveness determinations)","type":"references","note":"Supplies control identity, implementation statements and effectiveness determinations that the residual estimate cites. Assessment procedures, objectives, methods and the production of determinations remain wholly with that model; this mixin carries only the reference and the reliance parameters specific to this assessment."},{"target":"Risk criteria and assessment-method registry (criteria sets, scales, thresholds, technique definitions)","type":"references","note":"Supplies the versioned criteria scales and technique definitions that this mixin pins. The mixin stores the pin, the version token and the expression mode; it never defines, parameterizes or re-implements technique semantics."},{"target":"Risk appetite and tolerance statements","type":"references","note":"Supplies the versioned thresholds the residual estimate is compared against. Determining, approving, publishing and enforcing appetite and tolerance remain with enterprise governance; this mixin records the reference and the comparison outcome only."},{"target":"Objective, asset, process and organizational-unit registries","type":"references","note":"Supplies the anchors an assessment is scoped against. The mixin holds anchor references and assessment-specific scoping parameters; master data, anchor lifecycle and ownership stay in those registries."},{"target":"Acceptance, authorization and exception decision records","type":"references","note":"Receives a pointer from the comparison outcome to the decision in which a residual position was accepted. Decision authority, approval workflow and the validity of the decision belong to that model; this mixin never grants or derives acceptance."},{"target":"Risk treatment, remediation and plan-of-action records","type":"references","note":"Consumes the residual position as an input to treatment planning. Treatment option selection, milestones, scheduling, cost and closure are owned there and are not represented in this field group."},{"target":"Assessment observation and evidence records","type":"references","note":"Supplies observations and evidence cited as information sources for an estimate. Evidence collection, assessment execution and result logging are owned there; this mixin cites references and records their currency."},{"target":"IEC 31010:2019 risk assessment technique catalogue","type":"aligned","note":"External alignment for naming and selecting the applied technique. The mixin records which technique and version were used and makes no conformance claim to the standard, whose normative text is not reproduced here."},{"target":"NIST IR 8286 cybersecurity risk register and risk detail record schemas","type":"aligned","note":"External alignment for register field naming and for enterprise roll-up expectations. Adoption is a projection of this field group into that schema, not a conformance claim, and the register's own lifecycle stays with the register model."},{"target":"OSCAL Assessment Results risk characterization (characterization, facet, mitigating-factor)","type":"aligned","note":"External alignment for expressing initial versus adjusted characterizations and control-based mitigating factors in machine-readable form. The mixin maps its fields onto those assemblies without adopting the assessment-results model's observation, risk-log or remediation semantics."},{"target":"The Open Group Risk Taxonomy (O-RT) Version 3.1","type":"aligned","note":"Alignment for a frequency-and-magnitude decomposition where a Dimension pins a FAIR-family method. The mixin carries the pin and the resulting values; the taxonomy and its analysis process stay with the standard and its companion Risk Analysis standard."},{"target":"Regulation (EU) 2024/1689 Article 9 risk management system for high-risk AI systems","type":"aligned","note":"Jurisdiction-scoped alignment evidencing a legal requirement that residual risk per hazard be judged acceptable and that estimation cover reasonably foreseeable misuse. The mixin records the reference and the comparison outcome; conformity assessment and enforcement are outside it."},{"target":"WM-KNW-015 (registered parent model for vr.wm-xct-027)","type":"child","note":"Inherit record metadata, versioning, change-detection and provenance obligations that every control assertion record must satisfy, rather than restating them locally."},{"target":"Host subject model (system, process, service, supplier, asset or product to which this mixin attaches)","type":"composes","note":"Attach the risk-and-control assurance surface to a subject without altering that subject's own identity, classification or lifecycle."},{"target":"Control catalogue / control framework model","type":"references","note":"Resolve control definitions, families, enhancements, parameter definitions, baselines and revisions; this model carries the reference, revision pin, selected parameter values and declared tailoring only."},{"target":"Risk statement and risk register model","type":"references","note":"Resolve risk statements, response types, appetite and tolerance, residual values and acceptance decisions; this model carries the risk reference, treatment claim and attributed contribution only."},{"target":"Policy and procedure model","type":"references","note":"Point at the policy or procedure that documents a control without importing its text or approval lifecycle, and without letting its existence set any status value here."},{"target":"Technical configuration and baseline model","type":"references","note":"Identify the component or configuration by which a control is implemented, leaving configuration content, drift detection and enforcement in that model."},{"target":"Test and assessment execution model","type":"references","note":"Bind assessment activities, methods and timing by reference; assessment procedures, test cases, execution and raw results stay in that model."},{"target":"Evidence object model","type":"references","note":"Bind evidence by reference and digest with a local sufficiency rationale; evidence payloads, custody, integrity maintenance and retention execution stay in that model."},{"target":"Issue, deficiency and remediation model (plan of action and milestones)","type":"references","note":"Record a deficiency severity value and point at the record that tracks remediation; milestones, owners, workflow states and closure decisions stay in that model."},{"target":"Audit engagement and audit-trail model","type":"references","note":"Emit access and change events and retain the emission reference; audit records, log retention and trail immutability semantics are owned entirely by that model."},{"target":"Party, role and organisation directory model","type":"references","note":"Resolve owner, operator, assessor and approver identities; this model stores role-scoped references and independence flags only."},{"target":"Runtime enforcement, monitoring and telemetry model","type":"references","note":"Obtain observed occurrence counts and monitoring signals by reference; policy evaluation, enforcement decisions and execution records remain owned there."},{"target":"NIST SP 800-53 Rev. 5 control catalogue with the OSCAL implementation and assessment layers","type":"aligned","note":"Align local field semantics for control reference, parameter setting, implementation status, assessment method, finding and result expiry with a published machine-readable representation, without claiming conformance."},{"target":"COSO Internal Control - Integrated Framework (ICIF-2013) and GAO Standards for Internal Control in the Federal Government","type":"aligned","note":"Align the design, implementation, operation and deficiency vocabulary with recognised internal-control criteria; the frameworks' own assessment of an entity's internal control remains external."},{"target":"NIST Cybersecurity Framework 2.0 outcome taxonomy and NCSC Cyber Assessment Framework outcomes","type":"aligned","note":"Offer selectable outcome vocabularies for effectiveness conclusions and crosswalk targets, with an explicit rule that a mapping to an outcome is never evidence that the outcome is achieved."},{"target":"WM-KNW-015","type":"child","note":"Places the risk-control mixin under its registered parent knowledge model so that recorded risk information is governed as an organisational knowledge asset and remains traceable across the system and organisation levels."},{"target":"Host record model to which the mixin is applied","type":"composes","note":"Attaches the risk projection and control linkage to a system, process, asset, supplier, dataset, decision, product or organisational unit; the host owns the lifecycle that scopes the binding's lifecycle verbs."},{"target":"Risk register and risk taxonomy model","type":"references","note":"Supplies the identified risk that this mixin projects onto a host, together with its governed identifier. Risk identification, definition and register lifecycle stay with that model; only the host-specific framing, residual level and acceptance are carried here."},{"target":"Control catalogue and requirement source model","type":"references","note":"Supplies control identity, text and baselines by governed identifier. This mixin carries only the linkage, applicability and the justification for inclusion or exclusion on this host, and never reproduces catalogue content or catalogue versioning."},{"target":"Party, role and organisational-unit registry of the adopting Dimension","type":"references","note":"Resolves accountable owners, delegates, reviewers and acceptance authorities. Party identity and its lifecycle are owned there; this mixin carries only references, governance-line codes and effective periods."},{"target":"Evidence and document artifact model","type":"references","note":"Holds the evidence objects that support assertions. This mixin carries references, digests and observation instants for integrity binding; capture, storage and evidence lifecycle remain external."},{"target":"Authorization and policy-decision model of the adopting Dimension","type":"references","note":"Evaluates and enforces access and write decisions at runtime. This mixin declares the required authority level, incompatible-duty constraints and sensitivity conditions as parameters, and never performs evaluation, decision or enforcement."},{"target":"Audit trail and event record model of the adopting Dimension","type":"references","note":"Receives governance events emitted by this mixin and holds the durable audit entries referenced from bindings. Audit record structure, immutability guarantees, non-repudiation services, query and audit retention are owned there."},{"target":"Records retention schedule and disposition model","type":"references","note":"Supplies approved retention schedules and disposition authority and executes destruction. This mixin carries schedule references, clock starts, hold flags and tombstones, and issues disposition requests without executing them."},{"target":"PROV-O: The PROV Ontology (W3C Recommendation, 30 April 2013)","type":"aligned","note":"Aligns the mixin's attribution fields to entity, activity, agent, wasAttributedTo, wasGeneratedBy, wasDerivedFrom, wasRevisionOf and actedOnBehalfOf. The alignment is a mapping claim only; no conformance to the ontology is asserted."},{"target":"NIST OSCAL assessment results model","type":"aligned","note":"Maps residual conclusions, control linkage and evidence references onto observations, risks and findings for exchange with assessment tooling. Mapping is declared with an explicit lossiness statement; assessment execution is not owned here."},{"target":"FIRST Traffic Light Protocol version 2.0","type":"aligned","note":"Adopts a published label vocabulary and its handling and placement rules for sensitive risk information rather than inventing a local one. Recipient compliance and community definition remain outside this model."},{"target":"Assessment criteria, scale and risk appetite model of the adopting Dimension","type":"references","note":"Supplies the versioned criteria, severity and likelihood scales and appetite thresholds against which residual risk is judged acceptable. This mixin binds a conclusion to a criteria version and records precedence when criteria conflict."},{"target":"WM-KNW-015 risk / opportunity entity and lifecycle","type":"neighbor","note":"The parent model owns risk identity, statement, register status and lifecycle. This mixin attaches one assessment context to a pinned revision of that entity, carries no risk status transitions, and marks its own binding as stale when the pinned revision is superseded upstream."},{"target":"Control implementation records and control assessment determinations","type":"neighbor","note":"This mixin stores control references and cites effectiveness determinations by reference; determining, testing or re-opening effectiveness belongs to the control assessment model, where assessment objectives, methods and satisfied / other-than-satisfied determinations are produced."},{"target":"Risk treatment, remediation and plan-of-action records","type":"neighbor","note":"A residual estimate is an input to treatment planning. Treatment option selection, milestones, scheduling, cost tracking and closure are owned by the treatment model and are not represented here."},{"target":"Assessment execution, observation and evidence records","type":"neighbor","note":"Observations and evidence are cited as the basis of an estimate. Collecting evidence, executing assessment procedures and logging assessment results are owned by the assessment-results model; this mixin holds references and a basis statement only."},{"target":"Risk appetite and tolerance governance","type":"neighbor","note":"The mixin references a versioned tolerance statement and records the comparison outcome. Determining appetite, approving tolerance lines and enforcing them are enterprise governance acts held elsewhere."},{"target":"Acceptance, authorization and exception decisions","type":"neighbor","note":"Accepting a residual position is an authorization act performed by a designated official and recorded in an authorization or decision model. This mixin carries only a reference to that decision and never grants, derives or enforces it."},{"target":"Incident, loss event and issue records","type":"neighbor","note":"A realized event is not an assessment. Loss data may be cited as an information source for an estimate, but event records, their timelines and their consequences are owned by event models."},{"target":"Risk assessment technique definitions (IEC 31010 technique catalogue and comparable method registries)","type":"neighbor","note":"The mixin pins which technique and version were applied and stores the technique's declared outputs. It never restates, parameterizes or re-implements the technique's internal semantics."},{"target":"Alternative subject kind: relationship (a first-class risk-to-control association)","type":"neighbor","note":"Modelling this as a relationship was tested. A relationship entry would give each risk-control link its own identity, which suits relied-on-control attribution. It fails for the rest of the required content: assessment scope, horizon, criteria pin, likelihood and consequence dimensions, uncertainty and appetite comparison are properties of an assessment context attached to a host record, and one context routinely cites many controls and many consequences. The mixin kind is retained; the residual-change attribution is the part a Dimension may legitimately reify as a separate association record without altering this field group."},{"target":"WM-KNW-015","type":"parent"}],"interaction":{"identity":{"applicability":"required","items":["Authoritative master-system identifier issued by the system of record that owns the host record and its risk-control binding, such as the GRC, ISMS or assurance register key, used verbatim and never rewritten.","Governed global identifier or IRI from a normative registry or published namespace, such as a control catalogue IRI, a published risk register IRI or a governed assessment-result identifier.","UUID or ULID assigned by the adopting Dimension, used only where neither of the preceding exists, and recorded together with the party and instant of assignment.","A date, an assessment cycle label, a review period name, a version tag, a file name or a human-readable title is never an identifier and must not be used as one, alone or in combination."]},"properties":{"applicability":"not-applicable","items":[]},"recognition":{"applicability":"optional","items":["Risk fields carry a risk reference, a pinned method, likelihood and impact estimates and linked controls.","Often confused with an incident record, an issue and a compliance requirement."]},"capabilities":{"applicability":"required","items":["Bind an assessment context to a referenced risk: Creates a revision-pinned binding between one host record and one referenced risk, capturing anchors, taxonomy pin, scope, horizon and criteria/method pins. It establishes context only and never creates, alters or advances the referenced risk entity.","Record an estimate under a pinned method: Stores an estimate in either the inherent or residual role exactly as produced by the pinned method, together with its dimensions, units, scale references and expression mode. It performs no method-specific computation and invents no scale semantics.","Compare inherent and residual estimates: Records the difference between an inherent and a residual estimate, the dimensions that changed, the controls relied on and the effectiveness determinations cited, and the outcome of comparing the residual position with a referenced tolerance statement.","Explain assumptions and evidential basis: Assembles and records the assumptions, information sources, data currency, estimation basis kind, analysis constraints and uncertainty qualification behind an estimate, and emits the basis statement and derivation record artifacts.","Check comparability before comparison, reuse or aggregation: Compares the pin sets of two or more assessment-context records against a requested comparison or aggregation operation and returns a verdict, the mismatched pins and the caveat set that any permitted result must carry.","Link risk to control: Create a directed risk-to-control link carrying the claimed treatment mechanism, the risk response type it serves and the basis of the claim.","Retire risk-to-control link: Retire or supersede an existing link without destroying it, recording the reason and any replacement link.","Record control applicability: Record or revise an applicability, partial-applicability or not-applicable determination for a control against the host subject, with basis, covered population and approval.","Record design, implementation and operating assertion: Record or revise the three state assertions for a control and subject, each with its own basis, determining party and event time, including deviations, exceptions and compensating control references.","Bind assessment and evidence references: Bind assessment references, applied methods, depth, coverage, sample basis, timing and assessor to a control assertion, together with evidence references and their integrity digests.","Record effectiveness conclusion: Record an effectiveness conclusion with its vocabulary, scope, basis references, confidence, validity window, invalidation triggers and any deficiency severity.","Explain residual contribution: Produce a traceable explanation of how a control's assessed effectiveness contributes to the residual position of a linked risk, and submit the attribution to the risk model.","Authorize a binding change: Determines whether a proposed create, link, unlink, update, accept or retire action on a WM-XCT-027 binding is admissible, by checking the acting party's authority level against the versioned threshold table and the declared incompatible-duty set. This decides admissibility for this model's own records only; runtime policy evaluation and enforcement remain with the referenced authorization model.","Review and approve or reject an assertion: Records an independent review of an asserted binding and the resulting approval, rejection or return for rework, capturing the reviewer's independence basis, the assurance level reached and any scope limitation.","Reconcile bindings against host and referenced registries: Checks referential integrity of every binding against its host record, the referenced risk register, the control catalogue, the party registry and the evidence store, and reports orphans, retired references, duplicate active bindings and unjustified control exclusions.","Evaluate assessment currency and expire stale conclusions: Derives the currency status of each binding from its assessment instant, review interval, validity window and fired reassessment triggers, and marks conclusions approaching expiry, expired or invalidated.","Supersede or correct an assertion: Issues a successor revision that replaces a relied-upon assertion, records the defect corrected and the reliance period, and notifies declared downstream consumers. Immutable fields are never edited in place.","Produce a disclosure-profiled export: Generates an export of one or more bindings under a named disclosure profile, applying field-level withholding, generalisation or hashing, carrying the sensitivity label on the output and recording the release.","Apply or release a legal hold: Places a binding and its evidence manifest under a hold that suspends the normal disposition cycle, or releases that hold on written instruction from the authorised party.","Compute disposition eligibility and request disposition: Determines whether a binding's records have reached the end of their retention period with no active hold, issues a disposition request to the owning records capability, and records the confirmed outcome as a tombstone. This function never performs destruction itself."]},"hazards":{"applicability":"required","items":["Underestimated risks leave people exposed.","Incomparable scores aggregated into misleading dashboards.","Controls assumed to work that do not."]},"interfaces":{"applicability":"required","items":["ISO 31000 risk management guidelines.","IEC 31010 risk assessment techniques.","NIST SP 800-30 Rev. 1 risk assessments.","NIST SP 800-53 Rev. 5 controls.","NIST IR 8286 series on enterprise risk."]},"context":{"applicability":"required","items":["HM Treasury Orange Book material is UK central-government guidance; its category list, assurance construct and three-lines role separation are treated as one adoptable projection, not a universal taxonomy.","NIST publications are US federal guidance; their register field sets, risk model components and framework steps are alignment targets rather than obligations outside that context.","The EU AI Act residual-risk acceptability requirement applies only to high-risk AI systems in EU scope, with the referenced provisions applying from 2 December 2027 and 2 August 2028 for the respective categories; it is modelled as a scoped legal projection and not generalized.","Currency, monetary impact bands, fiscal-year horizons and working-day conventions are jurisdiction- and Dimension-specific and are carried as unit and scale references rather than fixed values.","Data-protection constraints on affected-party and narrative consequence fields vary by jurisdiction; the redaction rule delegates to the adopting Dimension's privacy policy rather than assuming one regime.","Retention periods, assessor independence requirements and management attestation duties are jurisdiction-specific. The model records a retention class and an independence flag but adopts no jurisdiction's schedule or threshold.","PCAOB AS 2201 and the GAO Green Book are United States sources whose deficiency-severity ladder and internal-control criteria are offered as one selectable vocabulary, not as the default for all adopters.","The NCSC Cyber Assessment Framework is a United Kingdom framework aimed at essential services and critical national infrastructure; its three-value outcome scale is offered as a selectable vocabulary rather than a global standard.","Financial-sector supervisory expectations and EU ICT resilience law may require explicit management-body approval of residual risk and additional independent review that the adopting Dimension must add locally; no such duty is assumed here.","The model assumes an adopting Dimension that operates at least one system of record capable of issuing authoritative identifiers; where none exists the identity priority falls through to governed IRIs and then to UUID or ULID.","Litigation hold and disposition-freeze semantics are drawn from a United States federal records practice in which counsel issues the hold and a written instruction is required to lift it. Other jurisdictions place the duty to preserve on different actors and at different trigger points; the hold reference and authority are therefore modelled as external references.","The ten-year documentation-retention assumption derives from European high-risk AI provisions and applies only where those provisions bind the host; it is not a general default.","Governance-line terminology assumes an organisation large enough to separate management, oversight and independent assurance. Small entities routinely combine these roles, so the model requires the overlap to be declared and mitigated rather than prohibited outright.","Certification-oriented statements about determining necessary controls and justifying exclusions assume an information-security management system context and may not transfer unchanged to safety, financial or clinical risk regimes.","Sensitivity label handling assumes a community whose members have agreed to the label vocabulary; where no such agreement exists, the labels carry no enforceable handling obligation."]}},"sources":[{"title":"NIST Special Publication 800-30 Revision 1, Guide for Conducting Risk Assessments","url":"https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"NIST Interagency Report 8286 Revision 1, Integrating Cybersecurity and Enterprise Risk Management (ERM)","url":"https://csrc.nist.gov/pubs/ir/8286/r1/final","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"NIST Interagency Report 8286A Revision 1, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management","url":"https://csrc.nist.gov/pubs/ir/8286/a/r1/final","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"NIST Interagency Report 8286C Revision 1, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight","url":"https://csrc.nist.gov/pubs/ir/8286/c/r1/final","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"OSCAL Assessment Results Model v1.1.2 JSON Format Metaschema Reference","url":"https://pages.nist.gov/OSCAL-Reference/models/v1.1.2/assessment-results/json-definitions/","note":"National Institute of Standards and Technology (OSCAL project)"},{"title":"NIST Special Publication 800-53A Revision 5, Assessing Security and Privacy Controls in Information Systems and Organizations","url":"https://csrc.nist.gov/pubs/sp/800/53/a/r5/final","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"The Orange Book: Management of Risk - Principles and Concepts","url":"https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts","note":"HM Treasury (United Kingdom)"},{"title":"IEC 31010:2019 Risk management - Risk assessment techniques","url":"https://webstore.iec.ch/en/publication/59809","note":"International Electrotechnical Commission (published jointly with ISO)"},{"title":"Risk Taxonomy (O-RT), Version 3.1 (Document C251)","url":"https://publications.opengroup.org/c251","note":"The Open Group"},{"title":"NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0)","url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"NIST Special Publication 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations","url":"https://csrc.nist.gov/pubs/sp/800/37/r2/final","note":"National Institute of Standards and Technology (U.S. Department of Commerce)"},{"title":"Article 9: Risk Management System, Regulation (EU) 2024/1689 (Artificial Intelligence Act)","url":"https://artificialintelligenceact.eu/article/9/","note":"Future of Life Institute (AI Act Explorer republication of the Official Journal text)"},{"title":"Guidance on Enterprise Risk Management - Enterprise Risk Management: Integrating with Strategy and Performance","url":"https://www.coso.org/guidance-erm","note":"Committee of Sponsoring Organizations of the Treadway Commission (COSO)"},{"title":"NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations","url":"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"OSCAL Implementation Layer: Component Definition Model","url":"https://pages.nist.gov/OSCAL/learn/concepts/layer/implementation/component-definition/","note":"National Institute of Standards and Technology (NIST)"},{"title":"OSCAL Assessment Layer: Assessment Results Model","url":"https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-results/","note":"National Institute of Standards and Technology (NIST)"},{"title":"OSCAL Implementation Layer: System Security Plan Model","url":"https://pages.nist.gov/OSCAL/learn/concepts/layer/implementation/ssp/","note":"National Institute of Standards and Technology (NIST)"},{"title":"OSCAL Assessment Layer: Assessment Plan Model","url":"https://pages.nist.gov/OSCAL/learn/concepts/layer/assessment/assessment-plan/","note":"National Institute of Standards and Technology (NIST)"},{"title":"AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements","url":"https://pcaobus.org/oversight/standards/auditing-standards/details/AS2201","note":"Public Company Accounting Oversight Board (PCAOB)"},{"title":"Standards for Internal Control in the Federal Government (Green Book), GAO-25-107721","url":"https://www.gao.gov/products/gao-25-107721","note":"U.S. Government Accountability Office (GAO)"},{"title":"Standards for Internal Control in the Federal Government (Green Book), GAO-14-704G","url":"https://www.gao.gov/assets/gao-14-704g.pdf","note":"U.S. Government Accountability Office (GAO)"},{"title":"NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0","url":"https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"NIST Computer Security Resource Center Glossary: compensating security control","url":"https://csrc.nist.gov/glossary/term/compensating_security_control","note":"National Institute of Standards and Technology (NIST)"},{"title":"NIST Computer Security Resource Center Glossary: assessment method","url":"https://csrc.nist.gov/glossary/term/assessment_method","note":"National Institute of Standards and Technology (NIST)"},{"title":"Introduction to the Cyber Assessment Framework (CAF) v4.0","url":"https://www.ncsc.gov.uk/collection/cyber-assessment-framework/introduction-to-caf","note":"National Cyber Security Centre (NCSC), United Kingdom"},{"title":"Internal Control - Integrated Framework (ICIF-2013), guidance page","url":"https://www.coso.org/guidance-on-ic","note":"Committee of Sponsoring Organizations of the Treadway Commission (COSO)"},{"title":"PCI DSS v4.0: Compensating Controls vs Customized Approach","url":"https://blog.pcisecuritystandards.org/pci-dss-v4-0-compensating-controls-vs-customized-approach","note":"PCI Security Standards Council"},{"title":"NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations","url":"https://csrc.nist.gov/pubs/sp/800/137/final","note":"National Institute of Standards and Technology (NIST)"},{"title":"Revisions to the Principles for the Sound Management of Operational Risk","url":"https://www.bis.org/bcbs/publ/d515.htm","note":"Basel Committee on Banking Supervision (BCBS), Bank for International Settlements"},{"title":"ISO 31000:2018 Risk management — Guidelines","url":"https://www.iso.org/standard/65694.html","note":"International Organization for Standardization"},{"title":"ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements","url":"https://www.iso.org/standard/27001","note":"International Organization for Standardization / International Electrotechnical Commission"},{"title":"PROV-O: The PROV Ontology","url":"https://www.w3.org/TR/prov-o/","note":"World Wide Web Consortium"},{"title":"Traffic Light Protocol (TLP) Version 2.0","url":"https://www.first.org/tlp/","note":"FIRST — Forum of Incident Response and Security Teams"},{"title":"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng","note":"European Union (European Parliament and Council)"},{"title":"The IIA's Three Lines Model: An Update of the Three Lines of Defense","url":"https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf","note":"The Institute of Internal Auditors"},{"title":"Federal Records Centers Program Freeze Process Overview / FAQ","url":"https://www.archives.gov/frc/arcis/freeze-faq","note":"National Archives and Records Administration (United States)"},{"title":"Government Auditing Standards, 2024 Revision (GAO-24-106786)","url":"https://www.gao.gov/yellowbook","note":"U.S. Government Accountability Office"}],"openQuestions":["Emit the composition-link set the coverage checklist claims (fifteen links) or correct the count to the nine delivered boundary notes, and bind each link to the neighbour model that owns the adjacent concept, since the split decision rests on that ownership evidence.","Define a precedence rule for the five access exceptions, specifically where unfettered reviewer access, statutory unredacted release to a competent authority, and restriction of a binding disclosing an exploitable unremediated weakness apply to the same record simultaneously.","Assess whether the tombstone rule is safe under erasure obligations: rctl-gov-art-tombstone-record retains the master-system identifier verbatim and the digest of the disposed record, and a digest over a low-entropy record is a confirmation and re-identification vector that the export-side re-identification check does not cover.","Specify the detection mechanism for upstream risk-revision supersession. Boundary note 1 promises the binding marks itself stale when the pinned revision is superseded, but no finding or function names how that change is detected; rctl-gov-fn-reconcile-bindings reports retired references only and rctl-gov-fn-evaluate-currency derives currency from time and fired triggers.","Obtain licensed or institutional access to ISO 31000:2018, ISO/IEC 27001:2022, ISO/IEC 27002:2022, the full COSO ICIF-2013 text, COBIT, and Regulation (EU) 2022/2554 with its ICT risk-management regulatory technical standards, all of which are currently declared unretrievable while several are cited as support.","Scope a projection-level accommodation for ordinal expression modes, since the model refuses implicit arithmetic while common matrix tooling multiplies and averages ordinal scores; without it, adopters will reintroduce the arithmetic the model forbids at the storage or interface layer.","Revisit quantified residual attribution as a targeted search rather than a standing gap: determine whether any sector-specific primary source (prudential, safety-integrity or actuarial) prescribes an attributable inherent-to-residual apportionment method that could be pinned by reference without the model endorsing a computation.","Numeric matrix definitions, band labels, threshold values and scoring rules are deliberately absent; they are supplied by reference from a Dimension-owned criteria registry.","No control-effectiveness rating vocabulary is defined; effectiveness determinations are cited from the control assessment model in whatever form that model publishes them.","Risk treatment options, treatment plans, milestones, cost tracking and closure are not modelled.","Realized loss events, incidents, issues and near misses are not modelled; loss data may only be cited as an information source.","Opportunity-side assessment is admitted through an effect-polarity field, but no upside-specific valuation dimensions or benefit scales are enumerated.","Sector-mandated methods such as prudential capital models, medical-device hazard analysis and safety-integrity-level assignment are not enumerated; they are treated as pinnable methods.","Technique internals for bow-tie, fault-tree, event-tree, Bayesian and simulation methods are referenced by name and version only.","Key risk indicator and key performance indicator definitions, monitoring thresholds and trend detection are not modelled here.","No guidance is given on how many scenarios constitute an adequate scenario set for a given method.","ISO/IEC 27001:2022 and ISO/IEC 27002:2022 could not be retrieved during research (iso.org and the ISO Online Browsing Platform returned HTTP 403). The Statement of Applicability pattern and the published control attribute set are therefore reflected structurally but not cited, and no ISO conformance is claimed.","COBIT (ISACA) and the full COSO ICIF-2013 text are paywalled; only COSO's public description of five components, seventeen principles and the present-and-functioning criterion was verified.","Regulation (EU) 2022/2554 (DORA) and its regulatory technical standards on ICT risk management tools could not be retrieved from EUR-Lex during research, so EU-specific duties to document residual ICT risk and have it approved by the management body are not modelled.","BCBS d515 was verified only at the publication landing page; three-lines-of-defence role allocation and risk and control self-assessment mechanics are therefore not asserted from it.","Statistical sampling methodology, sample size determination and confidence computation for control testing are referenced as a sample basis field but not modelled.","Continuous control monitoring schemas and control-as-code assertion formats are referenced conceptually; no single primary schema was adopted for automated effectiveness signals.","Control cost, benefit, rationalisation and portfolio optimisation are excluded entirely.","Sector-specific control taxonomies (for example safety instrumented functions or clinical controls) are not covered; adopters must extend the classification vocabulary locally.","Maturity models for control processes are not modelled; maturity and effectiveness are treated as different questions and only the latter is in scope.","No canonical vocabulary is prescribed for control linkage type beyond the preventive, detective and corrective distinction; sector taxonomies differ and none of the consulted primary sources is authoritative across sectors.","Aggregation semantics are not modelled: how many host-level residual conclusions roll up into a portfolio or entity-level risk position is left to the parent knowledge model and the adopting Dimension.","Cost, effort and benefit of treatment measures are excluded, although they influence acceptance decisions in practice, because no consulted primary source constrains their representation.","Bow-tie style causal decomposition of a risk into causes, events and consequences is referenced only through the risk model and is not represented here.","Threat and vulnerability intelligence linkage is not modelled; only the sensitivity handling of resulting risk information is.","Continuous control monitoring telemetry is out of scope; only the resulting conclusion and its currency are carried.","No opinion is offered on whether a binding constitutes a record subject to any particular statutory retention period; the schedule reference is supplied by the records model."],"resources":{"spec":"/models/wm-xct-027-risk-control/spec.yaml","agents":"/models/wm-xct-027-risk-control/AGENTS.md","source":"https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-027"},"provenance":{"origin":"world-models research","builtFrom":["models/wm-xct-027-risk-control/spec.yaml","ver-cy/world-models/card-supplements/wm-xct-027-risk-control.json"],"providers":["Claude"],"researchStatus":"reviewable-draft","generatedAt":"2026-09-03T09:18:19Z","builder":"tools/build_cards.py@1.0.0"},"completeness":{"sections":{"classifiers":"filled","whatItIs":"filled","purpose":"filled","distinguishingFeatures":"filled","structure":"filled","agentConduct":"filled","ethics":"filled","owners":"filled","relations":"filled","interaction.identity":"filled","interaction.properties":"not-applicable","interaction.recognition":"filled","interaction.capabilities":"filled","interaction.hazards":"filled","interaction.interfaces":"filled","interaction.context":"filled","sources":"filled"},"notes":{"interaction.properties":"Institutional or informational subject: no invented physical properties.","_supplement":"Sections authored in card supplement 1.0.0 by Claude (Opus 5.5) (2026-10-05, unreviewed). Written from the published specification and established practice in the field; no new sources were read. Unreviewed."},"score":1.0}}