# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-02T21:32:16Z", "synthesisSha256": "8774203f540ffaf4ad634847594e91a85a95662e8dc114dc9f6492842ea6819c", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-KNW-015", "registryId": "vr.wm-knw-015", "name": "Risk / Opportunity", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "entity", "family": "World Models", "category": "Information and virtual systems", "industry": [ "Cross-industry" ], "domain": [ "INF.KNW.RSK" ], "tags": [ "risk", "opportunity", "inf.knw.rsk" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-knw-015-risk-opportunity/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-knw-015", "model": { "registry_id": "vr.wm-knw-015", "model_id": "WM-KNW-015", "name": "Risk / Opportunity", "entry_kind": "entity", "purpose": "Govern the identified risk or opportunity as a persistent, identified record of an uncertain future event or condition whose occurrence would affect stated objectives, carrying its articulation, classification, likelihood and consequence estimates, evaluation against criteria, response decision, lifecycle state, ownership and provenance.", "scope_statement": "This model covers the registered uncertainty item itself: how it is defined, identified, articulated as a source-event-consequence scenario, classified against versioned schemes, estimated for likelihood and consequence over a declared horizon, evaluated against risk criteria and an appetite or tolerance reference, assigned a response option, linked by reference to treatment actions and controls, moved through lifecycle states to realisation or closure, owned, provenanced, aggregated into registers and snapshots, validated, protected and projected into external schemas. It is deliberately symmetric: adverse (threat) and beneficial (opportunity) items share one identity, criteria and lifecycle machinery, with valence recorded as a coded field. It does not perform, execute or enforce anything: treatment execution, control assurance, incident handling, objective setting, decision authority, evidence capture, audit trails and retention execution belong to referenced sibling models or the adopting Dimension. The model is storage- and interface-neutral; register tables, documents, graphs and message payloads are projections of the same semantics.", "in_scope": [ "The identified risk or opportunity item as a governed record, threat-side and opportunity-side under one identity", "Scenario articulation: risk source or cause, uncertain event, consequence, and the exposed object", "Boundary tests separating an item from an issue, incident, hazard, control deficiency or assumption", "Classification against versioned schemes plus valence and inherent/current/residual/target framing", "Likelihood and consequence estimates with declared scales, units, horizon and conditionality", "Level of risk, combination rule, aggregation limits, evaluation outcome and priority candidate", "Assessment technique, assumptions, inputs, confidence and references to supporting evidence", "Response option selection and referenced treatment actions, controls and mitigating factors", "Lifecycle states, review cadence and triggers, realisation hand-off and closure outcomes", "Ownership, acceptance and escalation authority references, and assertion provenance", "Register membership, point-in-time snapshots and reporting extracts as artifacts", "Validation rules, sensitivity classification, and alignment or crosswalk records with recorded conflicts" ], "out_of_scope": [ "Execution, scheduling and change control of treatment actions and projects", "Control design, testing, effectiveness assurance and audit opinions", "Incident, issue and loss-event handling, investigation and post-event response", "Objective, strategy and target setting, and performance measurement of objectives", "Threat intelligence, hazard catalogues and vulnerability management", "Capture and lifecycle of observations and evidence records, including chain of custody", "Setting enterprise risk appetite and tolerance statements (referenced, not authored here)", "Delegated authority schemes, approval workflow engines and runtime policy evaluation or enforcement", "Platform audit-trail creation and retention or erasure execution, including legal hold mechanics", "AI-system conformity assessment, high-risk classification and regulatory enforcement", "Insurance contracts, actuarial pricing, risk transfer instruments and regulatory capital calculation", "Dashboards, business intelligence and board reporting cadence built on register extracts" ], "boundary_notes": [ { "neighbor": "Incident / loss-event record (sibling model)", "distinction": "An item ceases to be a risk when the uncertain event occurs. The materialised event, its measured losses and its response are owned by the incident or loss-event model; this model retains only the realisation flag, the event time and a reference.", "source_refs": [ "SRC-014", "SRC-005" ] }, { "neighbor": "Threat or hazard catalogue (sibling model)", "distinction": "Threats and hazards are reusable catalogue entries referenced by identifier, mirroring the OSCAL threat-id pattern. This model neither maintains threat taxonomies nor produces intelligence.", "source_refs": [ "SRC-011", "SRC-008" ] }, { "neighbor": "Control / safeguard model (sibling model)", "distinction": "Controls and mitigating factors are referenced with an effectiveness input recorded as evidence. Control design, testing and assurance opinions remain in the control model.", "source_refs": [ "SRC-011", "SRC-005" ] }, { "neighbor": "Observation / evidence record (sibling model)", "distinction": "Supporting observations are referenced, following the OSCAL related-observations pattern. Evidence capture, custody and lifecycle are not owned here; only reference, digest and relevance note are held.", "source_refs": [ "SRC-011" ] }, { "neighbor": "Objective / outcome model (parent WM-ACT-017 plane)", "distinction": "Risk is defined as an effect of uncertainty on objectives, so objectives are referenced, never authored here. Objective definition, targets and performance reporting stay with the parent action or objective model.", "source_refs": [ "SRC-005", "SRC-001" ] }, { "neighbor": "WM-AI-008 AI governance assessment", "distinction": "An AI governance assessment references items here as risk evidence. The AI-specific risk-management-system obligation, residual-risk acceptability determination, conformity assessment and enforcement remain with that model and the competent authority.", "source_refs": [ "SRC-013", "SRC-011" ] }, { "neighbor": "Decision and delegated-authority model (sibling model)", "distinction": "Acceptance, escalation and closure decisions are carried as decision references with the authority level asserted at the time. Delegation schemes, approval workflow and enforcement are not modelled here.", "source_refs": [ "SRC-005", "SRC-010" ] }, { "neighbor": "Enterprise reporting and analytics platform", "distinction": "Register snapshots and reporting extracts are defined as immutable artifacts of this model; dashboards, roll-up analytics and reporting cadence belong to the adopting Dimension.", "source_refs": [ "SRC-005", "SRC-006" ] }, { "neighbor": "Insurance, risk transfer and capital models", "distinction": "Only the sharing or transfer response option and its contract reference are recorded. Pricing, capital requirement calculation and loss-distribution modelling for capital are excluded.", "source_refs": [ "SRC-014" ] }, { "neighbor": "Platform audit trail and access enforcement", "distinction": "This model states what must be auditable and what sensitivity applies, but does not create, hold or enforce audit records or access decisions.", "source_refs": [ "SRC-011", "SRC-005" ] } ] }, "sources": [ { "id": "SRC-001", "title": "ISO 31000:2018 Risk management — Guidelines", "organization": "International Organization for Standardization (ISO/TC 262)", "url": "https://www.iso.org/standard/65694.html", "version_or_date": "Second edition, February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:05:00Z", "relevance": "Normative anchor for risk as the effect of uncertainty on objectives and for the scope/context/criteria, identification, analysis, evaluation, treatment, monitoring and recording process. Full text is paywalled and the ISO catalogue page blocks automated retrieval; content used here is corroborated by SRC-005 and SRC-008 restatements." }, { "id": "SRC-002", "title": "ISO 31073:2022 Risk management — Vocabulary", "organization": "International Organization for Standardization (ISO/TC 262)", "url": "https://www.iso.org/standard/79637.html", "version_or_date": "First edition, February 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:06:00Z", "relevance": "Controlled vocabulary for risk management terms (risk source, event, consequence, likelihood, criteria, owner, register, appetite, residual risk) used as the alignment target for term bindings. Paywalled; existence, date and scope verified via SRC-003." }, { "id": "SRC-003", "title": "Discover risk related vocabulary in ISO 31073", "organization": "ISO/TC 262 Risk management committee", "url": "https://committee.iso.org/sites/tc262/home/news/content-left-area/news-and-events-within-iso-tc-26/discover-risk-related-vocabulary.html", "version_or_date": "ISO/TC 262 news item, ISO 31073 published February 2022", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:20:00Z", "relevance": "First-party ISO confirmation of ISO 31073:2022 publication date and purpose, and explicit statement that integrated risk management is applied to improve the management of potential opportunities — primary support for the symmetric risk/opportunity subject." }, { "id": "SRC-004", "title": "IEC 31010:2019 Risk management — Risk assessment techniques", "organization": "International Electrotechnical Commission (joint IEC/ISO)", "url": "https://webstore.iec.ch/en/publication/59809", "version_or_date": "Edition 2.0, 2019-06-13", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:12:00Z", "relevance": "Authority for identifying the assessment technique, for planning/implementing/verifying/validating technique use, and for treating techniques as decision support under uncertainty rather than as the risk record itself." }, { "id": "SRC-005", "title": "The Orange Book: Management of Risk — Principles and Concepts (HTML edition)", "organization": "HM Treasury and Government Finance Function (United Kingdom)", "url": "https://www.gov.uk/government/publications/orange-book/the-orange-book-management-of-risk-principles-and-concepts", "version_or_date": "May 2023 edition; page last updated 29 July 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:15:00Z", "relevance": "Verified restatement of risk as effect of uncertainty on objectives with cause/event/consequence structure, risk criteria and likelihood-consequence analysis, appetite and evaluation, the response option set including taking or increasing risk to pursue an opportunity, ownership and three lines roles, escalation and reporting." }, { "id": "SRC-006", "title": "NIST IR 8286, Integrating Cybersecurity and Enterprise Risk Management (ERM)", "organization": "National Institute of Standards and Technology (US)", "url": "https://csrc.nist.gov/pubs/ir/8286/final", "version_or_date": "October 2020, with supplemental Risk Register and Risk Detail Record schemas", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:08:00Z", "relevance": "Primary support for the risk register and risk detail record as governed structures, for risk exposure and priority columns, and for rolling item-level risk up to an enterprise risk profile." }, { "id": "SRC-007", "title": "NIST IR 8286A Rev. 1, Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management", "organization": "National Institute of Standards and Technology (US)", "url": "https://csrc.nist.gov/pubs/ir/8286/a/r1/final", "version_or_date": "Revision 1, December 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:24:00Z", "relevance": "Primary support for scenario-based identification, documenting likelihood and impact of threat events, illustrating risk tolerance and appetite, and for register and detail-record schemas as exchange structures." }, { "id": "SRC-008", "title": "NIST Computer Security Resource Center Glossary — risk", "organization": "National Institute of Standards and Technology (US)", "url": "https://csrc.nist.gov/glossary/term/risk", "version_or_date": "Accessed 2026-09-03; aggregates SP 800-30 Rev.1, SP 800-39, CNSSI 4009-2022, OMB A-130, and ISO Guide 73 via SP 800-160v1r1", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:10:00Z", "relevance": "Documents the coexisting adverse-only definition (function of adverse impact and likelihood) and the neutral effect-of-uncertainty-on-objectives definition in one authority, which is the evidence for the mandatory definition-scheme field and the recorded definitional conflict." }, { "id": "SRC-009", "title": "NIST Computer Security Resource Center Glossary — risk register", "organization": "National Institute of Standards and Technology (US)", "url": "https://csrc.nist.gov/glossary/term/risk_register", "version_or_date": "Accessed 2026-09-03; sources NIST SP 800-221, NIST IR 8286, NIST IR 8170, OMB Circular A-11", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:11:00Z", "relevance": "Definition of a risk register as a repository of risk information including data understood about risks over time — support for register membership, temporal accumulation and snapshotting." }, { "id": "SRC-010", "title": "NIST Computer Security Resource Center Glossary — risk appetite", "organization": "National Institute of Standards and Technology (US)", "url": "https://csrc.nist.gov/glossary/term/risk_appetite", "version_or_date": "Accessed 2026-09-03; sources NIST SP 800-221, NIST SP 800-161r1-upd1, NIST IR 8286/8170, COSO ERM, OMB Circular A-123", "source_type": "registry", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:22:00Z", "relevance": "Appetite as the types and amount of risk an organization is willing to accept in pursuit of value, with multiple non-identical source definitions — support for referencing an appetite statement by identifier and version rather than embedding a value." }, { "id": "SRC-011", "title": "OSCAL Assessment Results Model — JSON Format Reference", "organization": "National Institute of Standards and Technology (US), OSCAL project", "url": "https://pages.nist.gov/OSCAL-Reference/models/latest/assessment-results/json-reference/", "version_or_date": "OSCAL v1.2.3", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-03T09:04:00Z", "relevance": "Verified machine-readable risk structure: uuid, title, description, statement, status, origins, threat-ids, characterizations, mitigating-factors, deadline, remediations, risk-log and related-observations — the principal alignment target and the evidence that mainstream schemas are threat-only." }, { "id": "SRC-012", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013; namespace http://www.w3.org/ns/prov#", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:07:00Z", "relevance": "Alignment target for assertion provenance: Entity, Activity and Agent with wasGeneratedBy, wasDerivedFrom, wasAttributedTo, wasAssociatedWith, actedOnBehalfOf, startedAtTime and endedAtTime." }, { "id": "SRC-013", "title": "Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng", "version_or_date": "OJ L, 12 July 2024; ELI http://data.europa.eu/eli/reg/2024/1689/oj", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:14:00Z", "relevance": "Legal instance of a continuous, iterative risk management system requiring identification of known and foreseeable risks, estimation and evaluation, adoption of measures and judgement of residual-risk acceptability — used to bound the WM-AI-008 reference, not to import conformity obligations." }, { "id": "SRC-014", "title": "Basel Framework OPE10 — Operational risk: definitions and application", "organization": "Basel Committee on Banking Supervision, Bank for International Settlements", "url": "https://www.bis.org/basel_framework/chapter/OPE/10.htm", "version_or_date": "Effective 1 January 2023; chapter last updated 5 July 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-03T09:26:00Z", "relevance": "Sectoral example of a normative, scoped risk taxonomy and loss-event orientation whose category set deliberately excludes some risk classes — evidence that classification schemes are versioned, bounded and non-universal, and that materialised loss events belong to a separate record." } ], "structure": { "bundles": [ { "id": "b-semantic-core", "name": "Semantic core: concept, articulation and identity", "description": "What a risk or opportunity item is, how it is stated, how it is distinguished from adjacent concepts, and how it is identified and kept continuous across revisions.", "rationale": "Every downstream operation depends on a stable answer to what the record asserts and which real thing it denotes; competing standard definitions make this the first place a model fails.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-011" ], "layers": [ { "id": "l-concept-articulation", "name": "Concept and articulation", "description": "The definitional binding of the item, the source-event-consequence articulation, and the tests that keep non-risks out of the register.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008" ], "findings": [ { "id": "f-concept-frame", "name": "Definitional frame and objective linkage", "description": "An item is a recorded assertion that an uncertain event or condition, if it occurs, would have an effect on stated objectives; the governing definition (neutral effect-on-objectives versus adverse likelihood-and-impact) must be declared because authoritative sources disagree.", "source_refs": [ "SRC-001", "SRC-005", "SRC-008", "SRC-003" ], "questions": [ { "id": "q-concept-definition-scheme", "text": "Under which definitional scheme was this item recorded — neutral effect of uncertainty on objectives, or adverse-only likelihood and impact?", "kind": "definition", "answer_data": [ "definition scheme code", "cited standard and clause", "scheme version" ] }, { "id": "q-concept-objective-link", "text": "Which stated objective or outcome does this item's uncertainty act upon?", "kind": "relationship", "answer_data": [ "objective reference identifier", "objective owner reference", "direction of effect on the objective" ] }, { "id": "q-concept-uncertainty-basis", "text": "What makes this item uncertain rather than a known present condition?", "kind": "state", "answer_data": [ "uncertainty basis statement", "occurrence status at assertion time", "distinguishing test applied" ] }, { "id": "q-concept-minimum-set", "text": "What minimum content must be present before the item may be registered at all?", "kind": "requirement", "answer_data": [ "mandatory field list", "registration gate rule", "authority for the gate" ] } ], "data_elements": [ { "id": "de-definition-scheme", "name": "Definition scheme", "description": "Coded declaration of the risk definition under which the item was recorded, with the standard reference it derives from.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-008", "SRC-001" ] }, { "id": "de-objective-ref", "name": "Affected objective reference", "description": "Reference to one or more objectives in the owning objective or activity model that the uncertainty acts upon.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-001" ] }, { "id": "de-uncertainty-basis", "name": "Uncertainty basis", "description": "Short statement of why occurrence is uncertain, used to distinguish an open item from a materialised condition.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "The definitional frame is a set of inline coded fields and references carried on every item record; it produces no separate document, and materialising it as an artifact would duplicate the objective and standard records owned elsewhere." }, { "id": "f-scenario-articulation", "name": "Scenario articulation: source, event, consequence", "description": "The item is stated as a chain of risk source or cause, an uncertain event, and the consequence on the exposed object, at a granularity that keeps items separable and assessable.", "source_refs": [ "SRC-005", "SRC-011", "SRC-007" ], "questions": [ { "id": "q-scenario-chain", "text": "How are risk source, uncertain event and consequence separated within the recorded statement?", "kind": "composition", "answer_data": [ "risk source or cause text and reference", "event description", "consequence description" ] }, { "id": "q-scenario-granularity", "text": "At what granularity does one item become distinct from a closely related item?", "kind": "identity", "answer_data": [ "granularity rule", "distinguishing attribute set", "related item references" ] }, { "id": "q-scenario-exposed-object", "text": "Which asset, process, population or system is exposed in this scenario?", "kind": "relationship", "answer_data": [ "exposed object reference", "exposure type", "reference model identifier" ] }, { "id": "q-scenario-structured-vs-narrative", "text": "Which parts of the statement are structured fields and which remain free narrative?", "kind": "interoperability", "answer_data": [ "structured field list", "narrative field list", "mapping to external statement fields" ] } ], "data_elements": [ { "id": "de-risk-source", "name": "Risk source or cause", "description": "The element which alone or in combination has the potential to give rise to the event, held as text plus optional reference to a threat or hazard catalogue entry.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] }, { "id": "de-event-description", "name": "Uncertain event description", "description": "Description of the occurrence or change of circumstances whose happening is uncertain.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] }, { "id": "de-consequence-description", "name": "Consequence description", "description": "Description of the outcome affecting objectives should the event occur.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] }, { "id": "de-exposed-object-ref", "name": "Exposed object reference", "description": "Reference to the asset, process, service or population exposed to the consequence.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-011" ] } ], "artifacts": [ { "id": "art-risk-statement-record", "name": "Risk or opportunity statement record", "description": "The canonical articulation of one item: source, event, consequence, exposed object and narrative statement, kept separate from its estimates so that re-assessment does not rewrite the statement.", "media_or_form": [ "structured record", "narrative statement" ], "serial": false, "identity_strategy": "Bound to the item identity: authoritative master-system register key where one exists, otherwise the governed item identifier; the statement record carries no identifier of its own beyond the item identity and revision.", "source_refs": [ "SRC-011", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "f-adjacent-concept-boundary", "name": "Boundary against adjacent concepts", "description": "Explicit tests separating an open risk or opportunity from an issue or incident, a threat or hazard, a control deficiency, an observation, and a planning assumption or dependency.", "source_refs": [ "SRC-014", "SRC-011", "SRC-005", "SRC-008" ], "questions": [ { "id": "q-boundary-issue-test", "text": "What test separates a still-uncertain item from a materialised issue or incident?", "kind": "definition", "answer_data": [ "occurrence test", "realisation evidence", "target model for materialised events" ] }, { "id": "q-boundary-threat-distinction", "text": "How is a referenced threat or hazard distinguished from the risk item itself?", "kind": "relationship", "answer_data": [ "threat or hazard identifier", "catalogue reference", "rule that a threat alone is not an item" ] }, { "id": "q-boundary-observation-promotion", "text": "When does a control weakness or observation become a registered item rather than remaining a finding?", "kind": "decision", "answer_data": [ "promotion criteria", "promoting role", "source observation reference" ] }, { "id": "q-boundary-excluded-concepts", "text": "Which concepts must never be stored as items in this model?", "kind": "constraint", "answer_data": [ "excluded concept list", "owning model for each excluded concept", "rejection handling rule" ] } ], "data_elements": [ { "id": "de-boundary-test-outcome", "name": "Boundary test outcome", "description": "Recorded result of the admissibility tests applied at registration, including which adjacent concept was ruled out.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-011" ] }, { "id": "de-related-concept-ref", "name": "Related adjacent-concept reference", "description": "Reference to a threat, control deficiency, observation, assumption or incident record that the item is related to but is not.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "Boundary tests are inline admissibility rules and their recorded outcomes; the adjacent records they point at are owned by sibling models, so creating a local artifact would copy content this model must only reference." } ] }, { "id": "l-identity-continuity", "name": "Identity and continuity", "description": "How an item is identified, how identity survives re-assessment, and how split, merge and supersession are recorded.", "source_refs": [ "SRC-011", "SRC-009", "SRC-006" ], "findings": [ { "id": "f-item-identity", "name": "Item identity, revision and continuity", "description": "Identity of the item is stable and separate from the identity of any assessment revision; re-estimation creates a revision, while split, merge or withdrawal are explicit continuity events.", "source_refs": [ "SRC-011", "SRC-006", "SRC-009", "SRC-012" ], "questions": [ { "id": "q-identity-authoritative-key", "text": "Which system of record holds the authoritative identifier for this item?", "kind": "identity", "answer_data": [ "master system identifier", "master system name and namespace", "assignment date-time" ] }, { "id": "q-identity-fallback-minting", "text": "Which identifier is minted when no authoritative master-system key exists?", "kind": "requirement", "answer_data": [ "governed IRI or UUID or ULID value", "minting authority", "minting rule reference" ] }, { "id": "q-identity-cross-register-mapping", "text": "How are identifiers from other registers carried without becoming the primary key?", "kind": "interoperability", "answer_data": [ "alternate identifier values", "source register name and version", "mapping confidence" ] }, { "id": "q-identity-new-versus-revision", "text": "Which changes force a new item identity rather than a new assessment revision?", "kind": "lifecycle", "answer_data": [ "identity-breaking change list", "split or merge event record", "superseded item references" ] }, { "id": "q-identity-point-in-time", "text": "How is the item's state at a past reporting date reconstructed?", "kind": "temporal", "answer_data": [ "revision series with effective times", "snapshot reference", "reconstruction rule" ] } ], "data_elements": [ { "id": "de-item-uid", "name": "Item identifier", "description": "Primary identifier of the item, assigned per the identity priority rule and opaque within its namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-006" ] }, { "id": "de-master-record-key", "name": "Master-system record key", "description": "Identifier held by the authoritative register system of record, where such a system exists.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-009" ] }, { "id": "de-alt-identifier", "name": "Alternate identifier", "description": "Identifier of the same item in another register or schema, carried with its source namespace and never used as the primary key.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-revision-number", "name": "Assessment revision identifier", "description": "Monotonic revision identifier for the assessment state of the item, distinct from the item identity.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "de-supersedes-ref", "name": "Supersession reference", "description": "Reference to items superseded, split from or merged into this item, with the continuity event type.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "Identity and continuity are inline key fields and reference links on the item record; issuing them as a separate artifact would create a second identifier surface and invite divergence from the master system of record." } ] } ] }, { "id": "b-classification-context", "name": "Classification, valence and context binding", "description": "How an item is categorised against versioned schemes, whether its effect is adverse, beneficial or two-sided, and the organisational, spatial and temporal context in which the assessment holds.", "rationale": "Category, valence and context determine which criteria apply and whether two items may ever be compared or aggregated; sectoral taxonomies are bounded and non-universal.", "source_refs": [ "SRC-014", "SRC-005", "SRC-003", "SRC-011" ], "layers": [ { "id": "l-classification-schemes", "name": "Classification and valence", "description": "Assignment of coded categories from versioned schemes, and the coded direction and framing of the assessed effect.", "source_refs": [ "SRC-014", "SRC-005", "SRC-003", "SRC-008" ], "findings": [ { "id": "f-taxonomy-classification", "name": "Classification against versioned schemes", "description": "Items are classified using one or more published schemes, each identified with a version; scheme boundaries are normative and category sets are not interchangeable between sectors.", "source_refs": [ "SRC-014", "SRC-005", "SRC-003" ], "questions": [ { "id": "q-class-scheme-identity", "text": "Which classification schemes classify this item, and at which scheme version?", "kind": "classification", "answer_data": [ "scheme identifier and version", "assigned category codes", "assigning role" ] }, { "id": "q-class-multi-scheme", "text": "May an item carry codes from more than one scheme at the same time, and under what rule?", "kind": "constraint", "answer_data": [ "multi-assignment rule", "primary scheme designation", "conflict handling" ] }, { "id": "q-class-scheme-reconciliation", "text": "How are non-equivalent categories across schemes reconciled for reporting?", "kind": "interoperability", "answer_data": [ "crosswalk reference", "equivalence strength", "unmapped category handling" ] }, { "id": "q-class-scheme-retirement", "text": "What happens to existing items when a scheme version is retired?", "kind": "lifecycle", "answer_data": [ "migration rule", "retention of historical codes", "effective date of the new version" ] } ], "data_elements": [ { "id": "de-category-assignment", "name": "Category assignment", "description": "Coded category with its scheme identifier, scheme version and assignment provenance.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-005" ] }, { "id": "de-scheme-version", "name": "Classification scheme version", "description": "Version of the scheme in force at the moment of assignment, retained even after the scheme is superseded.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-014", "SRC-003" ] } ], "artifacts": [ { "id": "art-taxonomy-binding-record", "name": "Classification scheme binding record", "description": "Record of which schemes and versions are in force for a register scope, their code lists, effective dates and crosswalks to superseded versions.", "media_or_form": [ "code list", "crosswalk table" ], "serial": false, "identity_strategy": "Identified by scheme namespace plus version; the binding record inherits the publishing authority's scheme identifier where one exists and otherwise a Dimension-governed IRI.", "source_refs": [ "SRC-014", "SRC-003" ] } ], "inline_only_rationale": null }, { "id": "f-valence-and-framing", "name": "Valence and assessment framing", "description": "Whether the item is adverse, beneficial or two-sided, and which framings (inherent, current, residual, target) the recorded estimates represent, since standards differ on both points.", "source_refs": [ "SRC-003", "SRC-005", "SRC-008", "SRC-011" ], "questions": [ { "id": "q-valence-direction", "text": "Is the recorded effect adverse, beneficial or two-sided, and on what basis was that determined?", "kind": "classification", "answer_data": [ "valence code", "basis statement", "definition scheme reference" ] }, { "id": "q-valence-framing-states", "text": "Which assessment framings are recorded for this item — inherent, current, residual or target?", "kind": "state", "answer_data": [ "framing code per estimate", "framing definition reference", "controls assumed present per framing" ] }, { "id": "q-valence-opportunity-fields", "text": "Which additional fields become mandatory when the item is an opportunity to be pursued?", "kind": "requirement", "answer_data": [ "opportunity-specific field list", "benefit definition", "pursuit authority reference" ] }, { "id": "q-valence-threat-only-export", "text": "How is a beneficial item represented when exported to a threat-only external schema?", "kind": "interoperability", "answer_data": [ "projection rule", "loss note", "fallback representation" ] } ], "data_elements": [ { "id": "de-valence-code", "name": "Valence", "description": "Coded direction of the assessed effect: adverse, beneficial, or two-sided.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-005" ] }, { "id": "de-framing-code", "name": "Assessment framing", "description": "Coded framing of a given estimate: inherent, current, residual or target, with the controls assumed in force.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Valence and framing are single coded fields governing interpretation of the estimates on the same record; separating them into an artifact would fragment one assessment into two documents that could disagree." } ] }, { "id": "l-context-scope", "name": "Context, scope and time horizon", "description": "The organisational, spatial and temporal scope within which the item and its estimates are valid.", "source_refs": [ "SRC-005", "SRC-001", "SRC-007" ], "findings": [ { "id": "f-objective-scope-binding", "name": "Register scope and context binding", "description": "Each item is registered against a scope (organisational unit, portfolio, system or programme) and records the internal and external context assumed when it was scoped, which determines the applicable criteria set.", "source_refs": [ "SRC-005", "SRC-001", "SRC-007" ], "questions": [ { "id": "q-scope-register-binding", "text": "Which organisational unit, portfolio or system is this item registered against?", "kind": "relationship", "answer_data": [ "register scope identifier", "owning unit reference", "escalation parent scope" ] }, { "id": "q-scope-location-applicability", "text": "Does the item apply to a specific site, territory or jurisdiction?", "kind": "spatial", "answer_data": [ "location or jurisdiction reference", "applicability rule", "geometry or area code where used" ] }, { "id": "q-scope-criteria-applicable", "text": "Which risk criteria set applies to this item given its scope?", "kind": "constraint", "answer_data": [ "criteria set identifier and version", "applicability rule", "exception approval reference" ] }, { "id": "q-scope-context-assumptions", "text": "Which internal and external context factors were assumed when the item was scoped?", "kind": "evidence", "answer_data": [ "context factor list", "dependency references", "review trigger if a factor changes" ] } ], "data_elements": [ { "id": "de-register-scope", "name": "Register scope", "description": "Identifier of the register, unit or portfolio the item belongs to, which drives criteria applicability and escalation.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-jurisdiction-code", "name": "Jurisdiction or location applicability", "description": "Coded jurisdiction, site or territory for which the item and its estimates hold.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-005" ] }, { "id": "de-context-factor", "name": "Assumed context factor", "description": "Recorded internal or external context factor or dependency assumed at scoping, with an optional reference to the source record.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Scope and context are reference fields resolving into unit, location and criteria records owned by other models; the model carries the binding and the assumption note only, never a copy of the context document." }, { "id": "f-time-horizon-validity", "name": "Time horizon, onset and assessment validity", "description": "Likelihood is meaningless without a horizon: the model records the exposure window the estimate refers to, the expected speed of onset, and the date until which the assessment is treated as current.", "source_refs": [ "SRC-005", "SRC-004", "SRC-007" ], "questions": [ { "id": "q-time-horizon-window", "text": "Over what time horizon or exposure window is the likelihood judged?", "kind": "temporal", "answer_data": [ "horizon start and end timestamps", "horizon type code", "rationale for the horizon" ] }, { "id": "q-time-assessment-expiry", "text": "From when until when is this assessment treated as current before it becomes stale?", "kind": "lifecycle", "answer_data": [ "assessment effective time", "valid-until time", "staleness rule" ] }, { "id": "q-time-onset-velocity", "text": "How quickly would consequences arrive after the event occurs?", "kind": "measurement", "answer_data": [ "speed of onset value and unit", "time-to-impact estimate", "basis for the estimate" ] }, { "id": "q-time-emergence-status", "text": "Is the item treated as emerging, with limited historical evidence for its horizon?", "kind": "classification", "answer_data": [ "emerging flag", "evidence limitation note", "re-review interval" ] } ], "data_elements": [ { "id": "de-horizon-window", "name": "Assessment horizon", "description": "Start and end of the exposure window over which likelihood and consequence are judged.", "value_kind": "duration", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "de-valid-until", "name": "Assessment valid-until", "description": "Timestamp after which the current assessment is considered stale and must be re-reviewed.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-onset-velocity", "name": "Speed of onset", "description": "Estimated interval between event occurrence and consequence materialisation, with unit.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Horizon, validity and onset are inline temporal qualifiers on the estimate; they have no standalone document form and must travel with the values they qualify to prevent misreading a likelihood without its window." } ] } ] }, { "id": "b-assessment-measurement", "name": "Assessment: likelihood, consequence, level and evidence", "description": "How likelihood and consequence are expressed, combined into a level of risk, evaluated against criteria and appetite, and supported by technique, assumptions, evidence references and a confidence statement.", "rationale": "This is the measurement surface where most defects occur: undeclared scales, ordinal arithmetic, missing horizons and unstated confidence all make items non-comparable and non-aggregable.", "source_refs": [ "SRC-004", "SRC-005", "SRC-006", "SRC-007", "SRC-011" ], "layers": [ { "id": "l-likelihood-consequence", "name": "Likelihood and consequence", "description": "Expression, typing and conditionality of the two primary estimates.", "source_refs": [ "SRC-005", "SRC-007", "SRC-008", "SRC-011" ], "findings": [ { "id": "f-likelihood-expression", "name": "Likelihood expression and scale binding", "description": "Likelihood may be an ordinal band, a probability or a frequency; whichever is used, the scale definition, version, exposure window and any conditionality must be recorded with the value.", "source_refs": [ "SRC-005", "SRC-007", "SRC-004", "SRC-011" ], "questions": [ { "id": "q-likelihood-representation", "text": "Is likelihood expressed as an ordinal band, a probability or a frequency?", "kind": "measurement", "answer_data": [ "representation code", "value", "unit or band label" ] }, { "id": "q-likelihood-window-basis", "text": "Over which exposure window or population is a frequency value defined?", "kind": "constraint", "answer_data": [ "denominator or population", "window reference", "normalisation rule" ] }, { "id": "q-likelihood-scale-provenance", "text": "Which scale definition and version produced this likelihood value?", "kind": "provenance", "answer_data": [ "scale identifier and version", "scale publisher", "band-to-range mapping" ] }, { "id": "q-likelihood-conditionality", "text": "Is the likelihood conditional on other events occurring or on controls remaining in place?", "kind": "relationship", "answer_data": [ "conditioning event references", "assumed controls", "conditional versus unconditional flag" ] } ], "data_elements": [ { "id": "de-likelihood-value", "name": "Likelihood value", "description": "The recorded likelihood expressed as a band label, probability or frequency, always paired with its representation code.", "value_kind": "quantity", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "de-likelihood-scale-ref", "name": "Likelihood scale reference", "description": "Identifier and version of the scale definition that gives the value its meaning.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-likelihood-conditions", "name": "Likelihood conditioning assumptions", "description": "Events or controls assumed present or absent when the likelihood was judged.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "Likelihood is an inline measured field with its scale reference; the scale definition itself is an artifact of the criteria finding, so publishing a separate likelihood artifact would duplicate that governed definition." }, { "id": "f-consequence-expression", "name": "Consequence dimensions and magnitude", "description": "Consequence is recorded per dimension (financial, safety, legal, service, environmental, reputational and others in force), with magnitude, unit or currency, valuation basis, case basis and who bears the effect.", "source_refs": [ "SRC-005", "SRC-007", "SRC-014", "SRC-011" ], "questions": [ { "id": "q-consequence-dimension-set", "text": "Which consequence dimensions are assessed for this item?", "kind": "classification", "answer_data": [ "dimension codes in force", "dimension scheme version", "dimensions explicitly not assessed" ] }, { "id": "q-consequence-magnitude", "text": "How is magnitude quantified, including unit, currency and valuation basis?", "kind": "measurement", "answer_data": [ "magnitude value", "unit or currency code", "valuation basis and reference date" ] }, { "id": "q-consequence-case-basis", "text": "Does the recorded consequence represent the expected, most likely or worst credible case?", "kind": "constraint", "answer_data": [ "case basis code", "distribution or range where held", "rule forbidding mixed bases in one comparison" ] }, { "id": "q-consequence-incidence", "text": "Who or what bears the consequence, and does any of it fall outside the organisation?", "kind": "relationship", "answer_data": [ "affected party references", "internal or external incidence code", "third-party or societal effect note" ] } ], "data_elements": [ { "id": "de-consequence-dimension", "name": "Consequence dimension", "description": "Coded dimension along which a consequence is assessed.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-007" ] }, { "id": "de-consequence-magnitude", "name": "Consequence magnitude", "description": "Magnitude per dimension with unit or currency code, valuation basis and reference date for monetary values.", "value_kind": "quantity", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-014" ] }, { "id": "de-consequence-case-basis", "name": "Case basis", "description": "Whether the magnitude is expected, most likely or worst credible, so that values are not silently compared across bases.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-004" ] }, { "id": "de-affected-party-ref", "name": "Affected party reference", "description": "Reference to parties or populations bearing the consequence, including external bearers.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Consequence values are inline measured fields tied to the same assessment revision as likelihood; the dimension scheme and severity scales are governed by the criteria artifact rather than restated here." } ] }, { "id": "l-level-criteria-evaluation", "name": "Level of risk, criteria and evaluation", "description": "Combination of estimates into a level, its documented limits, and comparison against criteria, appetite and tolerance references.", "source_refs": [ "SRC-005", "SRC-006", "SRC-010", "SRC-004" ], "findings": [ { "id": "f-level-and-aggregation", "name": "Level of risk, priority and aggregation limits", "description": "The level or exposure derives from a declared combination rule whose validity limits must be recorded, and aggregation or roll-up across items is permitted only under stated correlation and comparability conditions.", "source_refs": [ "SRC-006", "SRC-007", "SRC-004", "SRC-005" ], "questions": [ { "id": "q-level-combination-rule", "text": "Which rule combines likelihood and consequence into a level of risk or exposure?", "kind": "measurement", "answer_data": [ "combination rule identifier and version", "computed level or exposure value", "inputs used" ] }, { "id": "q-level-rule-limits", "text": "What are the documented validity limits of the combination rule as applied here?", "kind": "quality", "answer_data": [ "known limitation statements", "ordinal arithmetic caution", "conditions under which the level is not meaningful" ] }, { "id": "q-level-aggregation-conditions", "text": "Under what conditions may item-level values be aggregated or rolled up to a portfolio view?", "kind": "constraint", "answer_data": [ "comparability preconditions", "correlation and double-counting treatment", "prohibited aggregations" ] }, { "id": "q-level-priority-assignment", "text": "How is relative priority derived, and who confirms it?", "kind": "decision", "answer_data": [ "priority value", "derivation method", "confirming role and decision reference" ] } ], "data_elements": [ { "id": "de-risk-level", "name": "Level of risk", "description": "Derived level or exposure value with the identifier of the combination rule and framing that produced it.", "value_kind": "quantity", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-006", "SRC-005" ] }, { "id": "de-priority-value", "name": "Priority", "description": "Relative importance of the item within its register scope, recorded with the method used to derive it.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] }, { "id": "de-aggregation-eligibility", "name": "Aggregation eligibility", "description": "Flag and rationale stating whether the item's values may be aggregated with others, given scale and basis comparability.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-007" ] } ], "artifacts": [], "inline_only_rationale": "Level, priority and aggregation eligibility are derived inline values recomputed from the estimates and the criteria artifact; storing them as a separate artifact would create a second source of truth that could drift from its inputs." }, { "id": "f-criteria-appetite-evaluation", "name": "Risk criteria, appetite reference and evaluation outcome", "description": "Evaluation compares the level against a versioned criteria set and a referenced appetite or tolerance statement, yielding an outcome and, where the item sits outside appetite, an escalation record; appetite is authored elsewhere and only referenced here.", "source_refs": [ "SRC-005", "SRC-010", "SRC-006", "SRC-001" ], "questions": [ { "id": "q-criteria-set-applied", "text": "Which criteria set, scales and thresholds were applied at the moment of evaluation?", "kind": "requirement", "answer_data": [ "criteria set identifier and version", "threshold values", "effective period of the criteria" ] }, { "id": "q-appetite-statement-reference", "text": "Against which appetite or tolerance statement is this item evaluated?", "kind": "authority", "answer_data": [ "appetite statement reference and version", "approving body", "appetite versus tolerance distinction used" ] }, { "id": "q-evaluation-outcome-recorded", "text": "What was the evaluation outcome relative to the threshold, and when was it determined?", "kind": "decision", "answer_data": [ "outcome code", "evaluation timestamp", "evaluating role" ] }, { "id": "q-evaluation-outside-appetite", "text": "How is an item outside appetite recorded and escalated while a decision is pending?", "kind": "exception", "answer_data": [ "exception record reference", "escalation target", "interim disposition and review date" ] } ], "data_elements": [ { "id": "de-criteria-set-ref", "name": "Criteria set reference", "description": "Identifier and version of the risk criteria set applied, including the scales and thresholds in force.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-001" ] }, { "id": "de-appetite-ref", "name": "Appetite or tolerance reference", "description": "Reference to the externally authored appetite or tolerance statement, with its version and the term sense used.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010", "SRC-005" ] }, { "id": "de-evaluation-outcome", "name": "Evaluation outcome", "description": "Coded result of comparing the level of risk against criteria and appetite, with evaluation timestamp.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "art-risk-criteria-set", "name": "Risk criteria set record", "description": "Versioned definition of the scales, bands, band-to-range mappings, combination rule, thresholds and the appetite statement references in force for a register scope.", "media_or_form": [ "scale definition table", "matrix or rule definition", "threshold list" ], "serial": false, "identity_strategy": "Identified by criteria-set namespace plus version; where a governance body issues the criteria in a system of record, that system's key is authoritative and the local identifier mirrors it.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] }, { "id": "l-method-evidence", "name": "Technique, evidence and confidence", "description": "How the estimate was produced, what it assumed, what supports it, and how much confidence is claimed.", "source_refs": [ "SRC-004", "SRC-011", "SRC-005", "SRC-007" ], "findings": [ { "id": "f-technique-and-assumptions", "name": "Assessment technique, inputs and assumptions", "description": "The technique used to produce the estimate is identified with its assumptions, exclusions, data sources or expert inputs, so that the estimate is reproducible and its applicability can be challenged.", "source_refs": [ "SRC-004", "SRC-007", "SRC-005" ], "questions": [ { "id": "q-technique-identification", "text": "Which assessment technique produced this estimate, and why was it appropriate?", "kind": "process", "answer_data": [ "technique name and catalogue reference", "selection rationale", "applicability limits" ] }, { "id": "q-technique-assumptions", "text": "Which assumptions and exclusions condition the estimate?", "kind": "constraint", "answer_data": [ "assumption statements", "explicit exclusions", "invalidation triggers" ] }, { "id": "q-technique-inputs", "text": "Which data sources, models or expert inputs fed the estimate?", "kind": "provenance", "answer_data": [ "input source references", "expert or panel identity", "input date-times" ] }, { "id": "q-technique-reproducibility", "text": "Can the estimate be reproduced from the recorded inputs and parameters?", "kind": "validation", "answer_data": [ "reproducibility statement", "recorded parameters", "verification and validation record reference" ] } ], "data_elements": [ { "id": "de-technique-ref", "name": "Assessment technique reference", "description": "Identifier of the technique applied, referencing an external technique catalogue rather than defining techniques locally.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-004" ] }, { "id": "de-assumption-statement", "name": "Assumption or exclusion", "description": "Recorded assumption or exclusion conditioning the estimate, with an optional invalidation trigger.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-input-source-ref", "name": "Estimate input reference", "description": "Reference to a dataset, model run or expert elicitation used as input, with the time the input was obtained.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-007", "SRC-012" ] } ], "artifacts": [ { "id": "art-analysis-worksheet", "name": "Risk analysis worksheet", "description": "Working record of one analysis pass: technique, parameters, inputs, intermediate results, assumptions and the resulting estimates, retained so that the estimate can be re-derived or challenged.", "media_or_form": [ "structured record", "calculation worksheet", "narrative method note" ], "serial": false, "identity_strategy": "Identified by item identifier plus assessment revision; where an analysis tool is the system of record, its run identifier is authoritative and is carried as the master-system key.", "source_refs": [ "SRC-004", "SRC-007" ] } ], "inline_only_rationale": null }, { "id": "f-evidence-and-confidence", "name": "Evidence references, confidence and knowledge limits", "description": "The estimate carries a confidence statement on a declared scale, references to supporting observations or evidence held in their owning models, an account of knowledge limits and unquantified uncertainty, and a record of who challenged it.", "source_refs": [ "SRC-011", "SRC-005", "SRC-004", "SRC-007" ], "questions": [ { "id": "q-confidence-statement", "text": "What confidence is claimed in this estimate, and on which declared scale?", "kind": "quality", "answer_data": [ "confidence value", "confidence scale reference", "basis for the confidence judgement" ] }, { "id": "q-evidence-links", "text": "Which observations or evidence records support the estimate?", "kind": "evidence", "answer_data": [ "evidence or observation references", "evidence type", "relevance note and digest" ] }, { "id": "q-knowledge-limits", "text": "Which knowledge gaps or unquantified uncertainties remain unaddressed in the estimate?", "kind": "constraint", "answer_data": [ "knowledge limitation statements", "unquantified uncertainty note", "effect on the confidence claim" ] }, { "id": "q-estimate-challenge", "text": "Who independently challenged or reviewed the estimate before it was relied upon?", "kind": "validation", "answer_data": [ "challenger identity and role", "challenge outcome", "date-time of challenge" ] } ], "data_elements": [ { "id": "de-confidence-value", "name": "Confidence in estimate", "description": "Declared confidence in the estimate with the scale that gives it meaning; ordinal confidence must not be read as probability.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-005" ] }, { "id": "de-evidence-ref", "name": "Supporting evidence reference", "description": "Reference to an observation or evidence record in its owning model, carried with a digest and relevance note only.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-knowledge-limit", "name": "Knowledge limitation", "description": "Recorded gap, unquantified uncertainty or limit of available evidence affecting the estimate.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-004" ] } ], "artifacts": [], "inline_only_rationale": "Evidence and observation records are created and governed by the evidence model; this finding holds only inline references, digests, relevance notes and a confidence field, so producing a local evidence artifact would copy material this model must not own." } ] } ] }, { "id": "b-response-lifecycle", "name": "Response, treatment linkage and lifecycle", "description": "Selection of a response option, referencing of treatment actions and controls, movement through lifecycle states, monitoring and review, and the hand-off when the event materialises or the item closes.", "rationale": "Response and state are the operating surface an agent must reason over, and they are also where ownership most easily leaks into models that own execution, control assurance and incident handling.", "source_refs": [ "SRC-005", "SRC-011", "SRC-006", "SRC-014" ], "layers": [ { "id": "l-response-treatment", "name": "Response option and treatment linkage", "description": "The governed option set including opportunity-side options, and references to the actions and controls that implement them.", "source_refs": [ "SRC-005", "SRC-011", "SRC-006" ], "findings": [ { "id": "f-response-strategy", "name": "Response option selection", "description": "A response is selected from a governed option set that includes avoiding, taking or increasing the risk to pursue an opportunity, removing the source, changing the likelihood, changing the consequences, sharing and retaining, with rationale and, for retention, an authority reference.", "source_refs": [ "SRC-005", "SRC-006", "SRC-011" ], "questions": [ { "id": "q-response-option-selected", "text": "Which response option was selected from the governed option set?", "kind": "decision", "answer_data": [ "option code", "option set version", "selection timestamp" ] }, { "id": "q-response-opportunity-options", "text": "Which options apply when the item is a beneficial opportunity to be pursued rather than a threat?", "kind": "classification", "answer_data": [ "opportunity option codes", "pursuit conditions", "expected benefit statement" ] }, { "id": "q-response-rationale", "text": "What rationale, cost and expected benefit justified the selected option?", "kind": "evidence", "answer_data": [ "rationale text", "estimated response cost", "cost-benefit or proportionality note" ] }, { "id": "q-response-retention-authority", "text": "If the item is retained or accepted, on whose authority and until when?", "kind": "authority", "answer_data": [ "accepting authority reference", "acceptance decision identifier", "acceptance review date" ] } ], "data_elements": [ { "id": "de-response-option", "name": "Response option", "description": "Coded response option selected, from the governed option set in force for the register scope.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-response-rationale", "name": "Response rationale", "description": "Recorded justification for the selected option, including proportionality or cost-benefit reasoning.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-response-cost", "name": "Estimated response cost", "description": "Estimated cost of the selected response with currency code and basis date.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "The response option and its rationale are inline decision fields on the item; the plan that implements them is a separate artifact in the treatment-linkage finding, and the authorising decision record belongs to the decision model." }, { "id": "f-treatment-control-linkage", "name": "Treatment action and control references", "description": "Planned treatment actions, existing controls and mitigating factors are carried as references with expected effect and deadline; execution, scheduling and control assurance stay with their owning models.", "source_refs": [ "SRC-011", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-treatment-action-refs", "text": "Which treatment actions are referenced, and in which model do they execute?", "kind": "composition", "answer_data": [ "action references", "owning model identifier", "action owner reference" ] }, { "id": "q-control-refs", "text": "Which existing controls or mitigating factors are relied upon to reduce this item?", "kind": "relationship", "answer_data": [ "control references", "mitigating factor descriptions", "framing in which they are assumed" ] }, { "id": "q-control-effectiveness-input", "text": "How is control effectiveness recorded here without asserting a control assurance opinion?", "kind": "evidence", "answer_data": [ "effectiveness input value", "source assurance record reference", "date of the effectiveness evidence" ] }, { "id": "q-treatment-expected-effect", "text": "What change in likelihood or consequence is expected once the treatment is complete?", "kind": "measurement", "answer_data": [ "expected post-treatment values", "target framing reference", "measurement basis" ] }, { "id": "q-treatment-deadline", "text": "By when must the treatment be complete, and who tracks completion?", "kind": "temporal", "answer_data": [ "deadline timestamp", "tracking role", "completion status source" ] } ], "data_elements": [ { "id": "de-treatment-action-ref", "name": "Treatment action reference", "description": "Reference to a planned or in-flight action in the owning action or plan model, with its owner and status source.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-005" ] }, { "id": "de-control-ref", "name": "Control or mitigating factor reference", "description": "Reference to an existing control or a described mitigating factor relied upon in the current framing.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] }, { "id": "de-treatment-deadline", "name": "Treatment deadline", "description": "Timestamp by which the referenced treatment is required to be complete.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-006" ] }, { "id": "de-expected-post-treatment-level", "name": "Expected post-treatment level", "description": "Target level of risk expected once the referenced treatment is effective, recorded in the target framing.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [ { "id": "art-risk-treatment-plan", "name": "Risk treatment plan", "description": "Plan record binding one item to its selected response, referenced actions and controls, expected effect, deadlines and named owners; it plans and references but never executes.", "media_or_form": [ "structured record", "tabular plan", "narrative plan" ], "serial": false, "identity_strategy": "Identified by item identifier plus plan revision; where a work management system owns the actions, its plan or ticket key is the authoritative master-system identifier and is carried as a reference.", "source_refs": [ "SRC-005", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "l-lifecycle-monitoring", "name": "Lifecycle, monitoring and outcome", "description": "States and transitions, review cadence and triggers, and what happens when the uncertain event occurs or the item closes.", "source_refs": [ "SRC-011", "SRC-005", "SRC-014", "SRC-006" ], "findings": [ { "id": "f-lifecycle-states", "name": "Lifecycle states and permitted transitions", "description": "The item moves through a declared state set with gated transitions and a mapping to external status vocabularies, which are threat-oriented and therefore only partially expressive for opportunities.", "source_refs": [ "SRC-011", "SRC-005", "SRC-006" ], "questions": [ { "id": "q-lifecycle-state-set", "text": "Which lifecycle states may an item occupy in this model?", "kind": "lifecycle", "answer_data": [ "state code list", "state definitions", "terminal state designation" ] }, { "id": "q-lifecycle-transition-gates", "text": "Which transitions are permitted, and what preconditions gate each one?", "kind": "state", "answer_data": [ "permitted transition pairs", "precondition rules", "required fields per target state" ] }, { "id": "q-lifecycle-status-mapping", "text": "How do local states map onto external status vocabularies used for exchange?", "kind": "interoperability", "answer_data": [ "mapping table", "unmappable state handling", "target schema and version" ] }, { "id": "q-lifecycle-reopen", "text": "Under what conditions may a closed item be reopened rather than newly registered?", "kind": "exception", "answer_data": [ "reopen criteria", "authorising role", "link to the prior closure record" ] } ], "data_elements": [ { "id": "de-lifecycle-state", "name": "Lifecycle state", "description": "Current coded state of the item within the declared state set.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-005" ] }, { "id": "de-state-effective-time", "name": "State effective time", "description": "Time from which the current state applies, recorded separately from the time the state change was written.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-012" ] }, { "id": "de-external-status-code", "name": "External status code", "description": "Status value projected into an external vocabulary for exchange, with the target schema version.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011" ] } ], "artifacts": [], "inline_only_rationale": "State is a single inline coded field with effective and record times; transition history is appended to the review log artifact, so a separate state artifact would duplicate that append-only record." }, { "id": "f-monitoring-review", "name": "Monitoring, review cadence and indicators", "description": "Items are reviewed on a cadence and on trigger events; each review appends an immutable log entry recording who reviewed, what changed, the trend, and linked early-warning indicators.", "source_refs": [ "SRC-005", "SRC-011", "SRC-006" ], "questions": [ { "id": "q-review-cadence", "text": "How often must this item be reviewed, and by which role?", "kind": "process", "answer_data": [ "cadence rule", "next review date", "responsible reviewing role" ] }, { "id": "q-review-trigger-events", "text": "Which events trigger an out-of-cycle review of the item?", "kind": "event", "answer_data": [ "trigger event types", "trigger source references", "response time expectation" ] }, { "id": "q-review-trend", "text": "How is the direction of travel between reviews recorded?", "kind": "measurement", "answer_data": [ "trend code", "compared revisions", "interval between comparisons" ] }, { "id": "q-review-indicator-links", "text": "Which early-warning indicators are linked to this item, and at what thresholds?", "kind": "relationship", "answer_data": [ "indicator references", "threshold values", "indicator owner and data source" ] } ], "data_elements": [ { "id": "de-next-review-date", "name": "Next review due", "description": "Timestamp by which the next scheduled review must occur.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "de-trend-code", "name": "Trend", "description": "Coded direction of travel of the level of risk since the previous review.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005" ] }, { "id": "de-indicator-ref", "name": "Early-warning indicator reference", "description": "Reference to an indicator and its threshold in the owning measurement model, used as a review trigger.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-011" ] } ], "artifacts": [ { "id": "art-review-log-entry", "name": "Risk review log entry", "description": "Append-only entry recording one review or status change: reviewer, timestamps, what changed, trend, decisions noted and the resulting next review date.", "media_or_form": [ "append-only log entry", "structured record" ], "serial": true, "identity_strategy": "Identified by item identifier plus a zero-padded monotonic sequence number; the issue timestamp is metadata and never the key.", "source_refs": [ "SRC-011", "SRC-005" ] } ], "inline_only_rationale": null }, { "id": "f-realisation-closure", "name": "Realisation, benefit capture and closure", "description": "When the uncertain event occurs the item is marked realised and handed off to the incident or loss-event model; opportunities record realised benefit; closure records a permitted reason with supporting evidence.", "source_refs": [ "SRC-014", "SRC-011", "SRC-005" ], "questions": [ { "id": "q-realisation-detection", "text": "How is it recorded that the uncertain event has actually occurred?", "kind": "event", "answer_data": [ "realisation flag", "event occurrence time", "detection source reference" ] }, { "id": "q-realisation-handoff", "text": "Which model takes ownership of the materialised event and its losses?", "kind": "composition", "answer_data": [ "incident or loss-event record reference", "hand-off timestamp", "residual responsibility note" ] }, { "id": "q-closure-reason", "text": "Which closure reasons are permitted, and what evidence must accompany each?", "kind": "lifecycle", "answer_data": [ "closure reason code list", "required evidence per reason", "closing authority reference" ] }, { "id": "q-benefit-realised", "text": "For an opportunity, how is realised benefit recorded and attributed?", "kind": "measurement", "answer_data": [ "realised benefit value and unit", "attribution basis", "verification reference" ] } ], "data_elements": [ { "id": "de-realisation-flag", "name": "Realisation status", "description": "Whether the uncertain event has occurred, with the occurrence time and the detecting source.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-011" ] }, { "id": "de-materialised-event-ref", "name": "Materialised event reference", "description": "Reference to the incident or loss-event record that took ownership once the event occurred.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "de-closure-reason", "name": "Closure reason", "description": "Coded reason the item was closed, such as treated, realised and handed off, no longer applicable, or merged.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-011" ] } ], "artifacts": [ { "id": "art-outcome-closure-record", "name": "Outcome and closure record", "description": "Terminal record for an item: realisation or non-occurrence, closure reason, references to any materialised event or realised benefit, closing authority and lessons noted for reuse.", "media_or_form": [ "structured record", "narrative closure note" ], "serial": false, "identity_strategy": "Identified by the item identifier; where an incident or benefits system is the system of record for the outcome, its key is carried as the authoritative master-system identifier.", "source_refs": [ "SRC-014", "SRC-005" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-accountability-provenance", "name": "Accountability, authority and provenance", "description": "Who owns the item, who may accept or escalate it, who asserted each value and when, and how items accumulate into registers, profiles and reporting extracts.", "rationale": "Risk records are relied on for decisions, so every value needs an accountable owner, a traceable asserter and a distinction between event, observation and record time.", "source_refs": [ "SRC-005", "SRC-012", "SRC-009", "SRC-010" ], "layers": [ { "id": "l-ownership-authority", "name": "Ownership and acceptance authority", "description": "Accountable roles for the item and the authority references that permit acceptance, escalation and closure.", "source_refs": [ "SRC-005", "SRC-010", "SRC-006" ], "findings": [ { "id": "f-ownership-accountability", "name": "Ownership and role separation", "description": "A single accountable owner is recorded for the item alongside distinct assessor, action-owner and reviewer roles, each attributable to a party and to an assurance line.", "source_refs": [ "SRC-005", "SRC-006", "SRC-012" ], "questions": [ { "id": "q-owner-identity", "text": "Who is the accountable owner of this item, and how is that party identified?", "kind": "ownership", "answer_data": [ "owner party reference", "owner role code", "identifier namespace of the party record" ] }, { "id": "q-owner-role-separation", "text": "How are owner, assessor, action owner and reviewer roles kept separate on one item?", "kind": "relationship", "answer_data": [ "role assignment set", "separation-of-duty rule", "conflict handling where roles coincide" ] }, { "id": "q-owner-change-record", "text": "How is a change of owner recorded, and from when is it effective?", "kind": "provenance", "answer_data": [ "previous owner reference", "effective time and record time", "authorising role" ] }, { "id": "q-owner-assurance-line", "text": "Which assurance line does each recorded role belong to?", "kind": "classification", "answer_data": [ "assurance line code", "role-to-line mapping", "source governance model reference" ] } ], "data_elements": [ { "id": "de-owner-ref", "name": "Accountable owner reference", "description": "Reference to the party accountable for the item, resolved in the party or organisation model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-012" ] }, { "id": "de-role-assignment", "name": "Role assignment", "description": "Assignment of a party to a role on this item, with the role code, assurance line and effective period.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] } ], "artifacts": [], "inline_only_rationale": "Ownership is an inline reference to a party record owned by the party model, with a role code and effective period; a local artifact would duplicate identity data this model must resolve rather than hold." }, { "id": "f-acceptance-escalation-authority", "name": "Acceptance, escalation and authority references", "description": "The model records which authority level was relied upon, the decision reference that authorises the current disposition and the escalation path when the level exceeds local authority, without owning delegation schemes or approval workflow.", "source_refs": [ "SRC-005", "SRC-010", "SRC-013" ], "questions": [ { "id": "q-authority-level-required", "text": "Which authority level is required to accept an item at this level of risk?", "kind": "authority", "answer_data": [ "required authority level", "threshold that triggers it", "source governance rule reference" ] }, { "id": "q-authority-decision-reference", "text": "Which decision record authorises the item's current disposition?", "kind": "decision", "answer_data": [ "decision record identifier", "decision date-time", "deciding body or role" ] }, { "id": "q-authority-escalation-path", "text": "Where does the item go when it exceeds the authority of its current scope?", "kind": "process", "answer_data": [ "escalation target scope", "escalation trigger", "time limit for escalation" ] }, { "id": "q-authority-delegation-limits", "text": "What limits apply to delegated authority, and where are those limits defined?", "kind": "constraint", "answer_data": [ "delegation limit values", "defining document reference", "expiry or review of the delegation" ] } ], "data_elements": [ { "id": "de-authority-level", "name": "Relied-upon authority level", "description": "Coded authority level asserted as sufficient for the current disposition at the time it was recorded.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] }, { "id": "de-decision-ref", "name": "Authorising decision reference", "description": "Reference to the decision record that authorises acceptance, escalation or closure, held in the decision model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Only the authority level asserted and a reference to the authorising decision are carried inline; delegation schemes, approval workflow and enforcement are owned by the decision and authority models, so no local artifact may be created." } ] }, { "id": "l-provenance-recording", "name": "Provenance and register accumulation", "description": "Attribution and timing of every asserted value, and the register, snapshot and extract structures built from items.", "source_refs": [ "SRC-012", "SRC-009", "SRC-006", "SRC-011" ], "findings": [ { "id": "f-assertion-provenance", "name": "Assertion provenance and time separation", "description": "Every value is attributable to an agent and an activity, derived from identifiable prior records, with event time, observation time and record time held separately and never substituted for one another.", "source_refs": [ "SRC-012", "SRC-011", "SRC-007" ], "questions": [ { "id": "q-provenance-agent", "text": "Which agent asserted this value, and on whose behalf did they act?", "kind": "provenance", "answer_data": [ "asserting agent identifier", "delegating agent identifier", "agent type" ] }, { "id": "q-provenance-time-separation", "text": "How are event time, observation time and record time distinguished on this record?", "kind": "temporal", "answer_data": [ "event time value", "observation time value", "record or ingestion time value" ] }, { "id": "q-provenance-derivation", "text": "From which prior record or source was this value derived?", "kind": "relationship", "answer_data": [ "source record reference", "derivation activity identifier", "transformation note" ] }, { "id": "q-provenance-import-retention", "text": "How is an imported item's original provenance retained after ingestion?", "kind": "interoperability", "answer_data": [ "origin system identifier", "original assertion metadata", "ingestion activity reference" ] } ], "data_elements": [ { "id": "de-asserting-agent", "name": "Asserting agent", "description": "Identifier of the agent responsible for the asserted value, aligned to the PROV agent notion.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-011" ] }, { "id": "de-observation-time", "name": "Observation time", "description": "Time at which the estimate or evidence was obtained, distinct from the time the record was written.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-007" ] }, { "id": "de-record-time", "name": "Record or ingestion time", "description": "Time at which the value was written to the register or ingested from another system.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-011" ] }, { "id": "de-derived-from-ref", "name": "Derived-from reference", "description": "Reference to the prior record or source from which the value was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Provenance is inline metadata that must travel with each asserted value; splitting it into an artifact would allow a value to circulate without its attribution and timing, which is the failure this finding exists to prevent." }, { "id": "f-register-aggregation", "name": "Register membership, snapshots and extracts", "description": "A register is a scoped repository accumulating item information over time; membership rules, immutable point-in-time snapshots and derived reporting extracts are defined here, while retention execution and reporting cadence are not.", "source_refs": [ "SRC-009", "SRC-006", "SRC-005", "SRC-007" ], "questions": [ { "id": "q-register-membership", "text": "Which criteria determine whether an item belongs to a given register?", "kind": "composition", "answer_data": [ "membership criteria", "register scope identifier", "dual-membership handling" ] }, { "id": "q-register-snapshot", "text": "How is a point-in-time register snapshot produced and identified?", "kind": "temporal", "answer_data": [ "as-of timestamp", "snapshot sequence identifier", "content hash" ] }, { "id": "q-register-profile-derivation", "text": "How is a risk profile derived from register contents without recomputing item values?", "kind": "process", "answer_data": [ "derivation rule", "inclusion filters", "aggregation eligibility checks applied" ] }, { "id": "q-register-retention-class", "text": "How long are entries and snapshots retained, and under whose policy?", "kind": "retention", "answer_data": [ "retention class code", "policy reference and owner", "disposition state" ] } ], "data_elements": [ { "id": "de-register-membership", "name": "Register membership", "description": "Membership of the item in one or more registers, with the criteria version that admitted it.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-009", "SRC-006" ] }, { "id": "de-retention-class", "name": "Retention class", "description": "Coded retention class applied to the item and its artifacts, referencing the governing records policy.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-009", "SRC-005" ] } ], "artifacts": [ { "id": "art-risk-register", "name": "Risk register", "description": "Scoped repository of item records and the information understood about them over time, defined as a governed collection with membership rules rather than as a spreadsheet layout.", "media_or_form": [ "collection of structured records", "tabular view" ], "serial": false, "identity_strategy": "Identified by register scope namespace; where an enterprise risk system is the system of record, its register key is the authoritative master-system identifier.", "source_refs": [ "SRC-009", "SRC-006" ] }, { "id": "art-register-snapshot", "name": "Register snapshot", "description": "Immutable as-of view of a register used for reporting, comparison and reconstruction of a past position.", "media_or_form": [ "immutable structured extract", "tabular view" ], "serial": true, "identity_strategy": "Identified by register scope plus a zero-padded monotonic sequence; the as-of timestamp and content hash are metadata, not the key.", "source_refs": [ "SRC-006", "SRC-009" ] }, { "id": "art-reporting-extract", "name": "Reporting extract", "description": "Filtered, possibly redacted projection of register content prepared for a named audience, carrying its filter definition and sensitivity treatment.", "media_or_form": [ "filtered structured extract", "narrative summary" ], "serial": true, "identity_strategy": "Identified by audience and register scope plus a zero-padded sequence; derived from a named snapshot whose identifier it must cite.", "source_refs": [ "SRC-005", "SRC-006" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "b-assurance-interoperability", "name": "Assurance, protection and interoperability", "description": "Validation of record quality, sensitivity and access constraints on items and extracts, and alignment to external schemas with conflicts and losses recorded.", "rationale": "Records that are incomplete, stale, over-shared or silently reinterpreted during exchange are worse than absent ones; this bundle keeps those failures visible and falsifiable.", "source_refs": [ "SRC-011", "SRC-006", "SRC-005", "SRC-013" ], "layers": [ { "id": "l-quality-validation", "name": "Validation and record quality", "description": "Rules that decide whether a record is fit to be relied upon or exchanged.", "source_refs": [ "SRC-006", "SRC-011", "SRC-005" ], "findings": [ { "id": "f-validation-completeness", "name": "Validation, completeness and staleness rules", "description": "Records are checked for mandatory fields per lifecycle state, conformance of values to declared scales, duplicate or overlapping items, and stale assessments, producing a defect list rather than silently amending values.", "source_refs": [ "SRC-006", "SRC-011", "SRC-005", "SRC-007" ], "questions": [ { "id": "q-validation-mandatory-fields", "text": "Which fields are mandatory before an item may leave draft or change state?", "kind": "validation", "answer_data": [ "mandatory field list per state", "blocking rule", "waiver record reference" ] }, { "id": "q-validation-scale-conformance", "text": "How is conformance of recorded values to their declared scales checked?", "kind": "quality", "answer_data": [ "scale conformance rule", "non-conforming value handling", "scale version checked against" ] }, { "id": "q-validation-duplicate-detection", "text": "How are duplicate or substantially overlapping items detected and resolved?", "kind": "identity", "answer_data": [ "similarity criteria", "merge or link decision", "resulting supersession references" ] }, { "id": "q-validation-staleness", "text": "How are stale assessments detected and flagged for re-review?", "kind": "temporal", "answer_data": [ "staleness threshold", "flagged item list", "escalation on persistent staleness" ] } ], "data_elements": [ { "id": "de-validation-status", "name": "Validation status", "description": "Result of the most recent validation pass over the record, with the ruleset version applied.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-011" ] }, { "id": "de-validation-defect", "name": "Validation defect", "description": "Individual defect found, with severity, affected field and whether it blocks state transition or exchange.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-006", "SRC-005" ] } ], "artifacts": [ { "id": "art-validation-report", "name": "Record validation report", "description": "Report of one validation pass over an item or register: ruleset version, pass or fail outcome, defect list with severities, and which transitions or exchanges are blocked.", "media_or_form": [ "structured report", "defect list" ], "serial": true, "identity_strategy": "Identified by validated scope plus a zero-padded run sequence; the run timestamp and ruleset version are metadata carried with the report.", "source_refs": [ "SRC-006", "SRC-011" ] } ], "inline_only_rationale": null } ] }, { "id": "l-protection-interoperability", "name": "Protection and external alignment", "description": "Sensitivity, access constraints and redaction expectations for items and extracts, and mappings to external schemas with recorded conflicts.", "source_refs": [ "SRC-005", "SRC-013", "SRC-011", "SRC-008" ], "findings": [ { "id": "f-sensitivity-access", "name": "Sensitivity classification and access constraints", "description": "Items carry a sensitivity classification covering their statement, evidence references and owner identity, with audience rules, personal-data minimisation and an explicit treatment of aggregation sensitivity; enforcement belongs to the platform.", "source_refs": [ "SRC-005", "SRC-013", "SRC-011" ], "questions": [ { "id": "q-sensitivity-classification", "text": "What sensitivity classification applies to this item and to its evidence references?", "kind": "security", "answer_data": [ "sensitivity class code", "classification scheme reference", "classifying role and date" ] }, { "id": "q-access-audience-rules", "text": "Which audiences may see the full statement, and which receive a redacted summary?", "kind": "access", "answer_data": [ "audience list", "field-level redaction rules", "approval required for wider release" ] }, { "id": "q-access-personal-data", "text": "Does the item contain personal or identifying data, and how is that minimised?", "kind": "privacy", "answer_data": [ "personal data presence flag", "minimisation measures applied", "lawful basis reference where required" ] }, { "id": "q-access-aggregation-sensitivity", "text": "Does aggregating items produce a view more sensitive than any single item?", "kind": "exception", "answer_data": [ "aggregation sensitivity assessment", "uplifted class for the aggregate", "restricted extract handling" ] } ], "data_elements": [ { "id": "de-sensitivity-class", "name": "Sensitivity classification", "description": "Coded sensitivity of the item record, referencing the classification scheme in force.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-013" ] }, { "id": "de-personal-data-flag", "name": "Personal data presence", "description": "Whether the record contains personal or identifying data requiring minimisation and restricted handling.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "de-audience-rule", "name": "Audience release rule", "description": "Rule stating which audience may receive which fields, used to derive redacted reporting extracts.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-005" ] } ], "artifacts": [], "inline_only_rationale": "Classification and audience rules are inline governing fields; the access decision, its enforcement and the audit of access are performed by the adopting Dimension's platform, so this model must not materialise access records of its own." }, { "id": "f-external-alignment-conflicts", "name": "External alignment, lossy projection and recorded conflicts", "description": "Alignments to external vocabularies and schemas are declared as versioned mappings with known losses, and definitional conflicts between authorities are recorded rather than resolved by fiat; conformance is claimed only with evidence.", "source_refs": [ "SRC-011", "SRC-008", "SRC-001", "SRC-002", "SRC-014", "SRC-006" ], "questions": [ { "id": "q-alignment-targets", "text": "Which external schemas and vocabularies is this model aligned to, and at which versions?", "kind": "interoperability", "answer_data": [ "target schema identifiers and versions", "mapping direction", "mapping maintainer" ] }, { "id": "q-alignment-losses", "text": "Which fields or meanings are lost or approximated in each projection?", "kind": "quality", "answer_data": [ "lossy field list per target", "approximation notes", "reversibility statement" ] }, { "id": "q-alignment-conflict-record", "text": "How are definitional conflicts between standards recorded instead of being silently resolved?", "kind": "constraint", "answer_data": [ "conflict statements with citations", "affected fields", "local disambiguation rule" ] }, { "id": "q-alignment-conformance-evidence", "text": "What evidence is required before conformance to an external standard may be claimed?", "kind": "evidence", "answer_data": [ "conformance evidence type", "test or review reference", "claim scope and expiry" ] } ], "data_elements": [ { "id": "de-alignment-target", "name": "Alignment target", "description": "External schema, vocabulary or taxonomy this model maps to, with its version and mapping direction.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-002" ] }, { "id": "de-mapping-loss", "name": "Mapping loss note", "description": "Recorded loss or approximation introduced by a specific projection, tied to the affected field.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-008" ] }, { "id": "de-conflict-record", "name": "Definitional conflict record", "description": "Recorded disagreement between authoritative definitions affecting interpretation, with citations and the local disambiguation applied.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-008", "SRC-001", "SRC-014" ] } ], "artifacts": [ { "id": "art-alignment-crosswalk", "name": "Alignment crosswalk record", "description": "Versioned mapping between this model's elements and an external schema or vocabulary, listing equivalences, approximations, unmapped elements and recorded conflicts.", "media_or_form": [ "crosswalk table", "structured mapping record" ], "serial": false, "identity_strategy": "Identified by source and target schema namespaces plus target version; where the target publisher issues a registry key for the mapping, that key is authoritative.", "source_refs": [ "SRC-011", "SRC-002", "SRC-008" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "fn-register-item", "name": "Register risk or opportunity item", "description": "Admit a new item to a register scope with its statement, valence, definition scheme, objective reference and provenance, minting identity under the identity priority rule.", "inputs": [ "risk source, event and consequence statement", "affected objective reference", "valence and definition scheme codes", "register scope and asserting agent" ], "outputs": [ "registered item with identity and revision 1", "registration provenance record" ], "preconditions": [ "minimum registration set is complete", "register scope and applicable criteria set are declared", "boundary tests exclude an issue, incident, threat or observation being registered as an item" ], "effects": [ "mints or adopts the item identifier per identity priority", "sets lifecycle state to identified with effective and record times", "does not create treatment actions, controls or evidence records" ], "source_refs": [ "SRC-005", "SRC-011", "SRC-006" ] }, { "id": "fn-classify-item", "name": "Classify item against a scheme", "description": "Assign coded categories from one or more published, versioned classification schemes and retain superseded assignments.", "inputs": [ "item reference", "scheme identifier and version", "category code and assigning role" ], "outputs": [ "category assignment with scheme version", "superseded assignment history" ], "preconditions": [ "scheme is published and in force for the register scope", "code exists in the cited scheme version" ], "effects": [ "adds the coded assignment with provenance", "retains prior assignments rather than overwriting them", "does not alter estimates, level or state" ], "source_refs": [ "SRC-014", "SRC-005", "SRC-003" ] }, { "id": "fn-estimate-likelihood-consequence", "name": "Estimate likelihood and consequence", "description": "Produce a new assessment revision holding likelihood and consequence values with their scales, horizon, technique, assumptions, evidence references and confidence.", "inputs": [ "item reference", "technique reference and parameters", "scale references and horizon", "evidence and input source references" ], "outputs": [ "assessment revision with likelihood and consequence values", "confidence statement and assumption list" ], "preconditions": [ "scales, horizon and case basis are declared", "technique is identified and applicable", "input evidence references resolve in their owning models" ], "effects": [ "creates a new revision and never overwrites a prior revision", "records observation time separately from record time", "does not create or modify the evidence records it references" ], "source_refs": [ "SRC-004", "SRC-007", "SRC-005", "SRC-011" ] }, { "id": "fn-evaluate-against-criteria", "name": "Evaluate against criteria and appetite", "description": "Derive the level of risk from the current revision using the declared combination rule and compare it with criteria thresholds and the referenced appetite or tolerance statement.", "inputs": [ "assessment revision", "criteria set identifier and version", "appetite or tolerance statement reference" ], "outputs": [ "level of risk and priority candidate", "evaluation outcome with timestamp", "escalation flag where outside appetite" ], "preconditions": [ "criteria version is in force for the item's scope", "combination rule and its validity limits are documented", "values conform to the declared scales" ], "effects": [ "records the outcome and the thresholds compared against", "flags items outside appetite for escalation", "does not approve, accept or enforce any disposition" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-010" ] }, { "id": "fn-record-response-decision", "name": "Record response decision", "description": "Record the response option selected from the governed option set together with its rationale, cost estimate and the authorising decision reference.", "inputs": [ "item reference", "response option code and option set version", "rationale, cost and authority level", "authorising decision reference" ], "outputs": [ "response record on the item" ], "preconditions": [ "an evaluation outcome exists for the current revision", "the option belongs to the governed option set", "the decision reference resolves in the decision model" ], "effects": [ "records the selected option and its authorising reference", "does not execute treatment, grant authority or enforce acceptance" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-011" ] }, { "id": "fn-bind-treatment-control-references", "name": "Bind treatment and control references", "description": "Attach references to planned actions, existing controls and mitigating factors, with expected post-treatment effect and deadline.", "inputs": [ "item reference", "action and control references", "expected post-treatment values", "deadline and tracking role" ], "outputs": [ "treatment and control linkage set", "risk treatment plan revision" ], "preconditions": [ "referenced actions and controls exist in their owning models", "the selected response option supports the linkage type" ], "effects": [ "stores references, expected effect and deadline", "leaves execution, scheduling and control assurance with the owning models", "does not assert a control effectiveness opinion of its own" ], "source_refs": [ "SRC-011", "SRC-005", "SRC-006" ] }, { "id": "fn-transition-lifecycle-state", "name": "Transition lifecycle state", "description": "Move an item to a permitted target state, recording the trigger, effective time and record time, and appending the transition to the review log.", "inputs": [ "item reference", "target state and trigger", "effective time and acting role" ], "outputs": [ "state transition record", "updated lifecycle state" ], "preconditions": [ "the transition is permitted by the declared state model", "mandatory fields for the target state are present and valid", "reopen of a closed item carries an authorising role" ], "effects": [ "updates state with effective and record times", "appends an immutable transition entry to the review log", "freezes closed items against value edits except via reopen" ], "source_refs": [ "SRC-011", "SRC-005", "SRC-006" ] }, { "id": "fn-record-review-outcome", "name": "Record review outcome", "description": "Append an immutable review log entry capturing reviewer, changes, trend and next review date, following a scheduled cadence or a trigger event.", "inputs": [ "item reference", "reviewer identity and review timestamp", "observed changes, trend and indicator readings" ], "outputs": [ "serial review log entry", "updated next review due date" ], "preconditions": [ "cadence is due or a documented trigger has fired", "the item is not in a terminal state unless the review concerns closure" ], "effects": [ "appends an immutable, sequence-numbered log entry", "sets the next review due date", "may invoke re-estimation but does not itself change estimates" ], "source_refs": [ "SRC-005", "SRC-011", "SRC-006" ] }, { "id": "fn-hand-off-realised-item", "name": "Hand off realised item", "description": "Mark the item realised when the uncertain event occurs, record the occurrence time and the receiving incident, loss-event or benefit record, and move the item to closure.", "inputs": [ "item reference", "event occurrence time and detection source", "receiving record reference" ], "outputs": [ "realisation record", "closure record with reason and authority" ], "preconditions": [ "occurrence is evidenced by a resolvable detection source", "the receiving model has accepted ownership of the materialised event" ], "effects": [ "sets realisation status and hand-off reference", "closes the item with a permitted reason", "does not manage, investigate or quantify the materialised event" ], "source_refs": [ "SRC-014", "SRC-011", "SRC-005" ] }, { "id": "fn-compile-register-view", "name": "Compile register view or snapshot", "description": "Produce a register view for a scope and as-of time, or an immutable snapshot and audience-specific reporting extract derived from it.", "inputs": [ "register scope and as-of time", "membership and audience filters", "sensitivity and redaction rules" ], "outputs": [ "register view", "immutable snapshot with content hash", "redacted reporting extract" ], "preconditions": [ "member items pass validation", "aggregation eligibility is satisfied for any roll-up presented", "audience release rules are declared" ], "effects": [ "produces read-only projections that never recompute item values", "assigns snapshot and extract sequence identifiers", "does not perform analytics, dashboards or reporting distribution" ], "source_refs": [ "SRC-009", "SRC-006", "SRC-005" ] }, { "id": "fn-validate-record", "name": "Validate item or register record", "description": "Apply the published validation ruleset to check mandatory fields, scale conformance, duplicates and staleness, and emit a defect list.", "inputs": [ "item or register reference", "validation ruleset version" ], "outputs": [ "validation report with outcome and defect list" ], "preconditions": [ "the ruleset version is published and applicable to the scope" ], "effects": [ "flags incomplete, stale, duplicate and non-conforming records", "blocks state transitions or exchanges where a blocking defect exists", "never silently amends recorded values" ], "source_refs": [ "SRC-006", "SRC-011", "SRC-005" ] }, { "id": "fn-emit-alignment-projection", "name": "Emit alignment projection", "description": "Project selected items into an external schema or vocabulary using a published crosswalk and record the losses incurred.", "inputs": [ "item set", "target schema identifier and version", "crosswalk reference" ], "outputs": [ "projected representation for the target schema", "mapping loss report" ], "preconditions": [ "a published crosswalk exists for the target version", "conflicting definitions affecting the projection are recorded" ], "effects": [ "emits the mapped representation with a loss report", "records approximations such as beneficial items forced into threat-only structures", "asserts no conformance claim unless cited conformance evidence exists" ], "source_refs": [ "SRC-011", "SRC-008", "SRC-002", "SRC-014" ] } ], "composition": [ { "target": "WM-ACT-017", "relation": "CHILD", "purpose": "Register the model beneath its parent action and objective plane: objectives affected, treatment actions and the management activity that owns execution live in the parent, while this model owns only the uncertainty record that references them.", "required": true, "source_refs": [ "SRC-005", "SRC-001" ] }, { "target": "WM-AI-008 (AI governance assessment)", "relation": "REFERENCE", "purpose": "Carry a back-reference and context binding when an AI governance assessment cites items here as risk evidence. The assessment's own lifecycle, residual-risk acceptability determination, conformity assessment and enforcement remain entirely in WM-AI-008 and with the competent authority.", "required": false, "source_refs": [ "SRC-013", "SRC-011" ] }, { "target": "Threat and hazard catalogue model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Reference threat or hazard entries by identifier, following the OSCAL threat-id pattern, without maintaining catalogues, intelligence or hazard characterisation locally.", "required": false, "source_refs": [ "SRC-011", "SRC-008" ] }, { "target": "Control and safeguard model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Reference controls and mitigating factors relied upon in a given framing and carry effectiveness evidence references; control design, testing and assurance opinions stay in the control model.", "required": false, "source_refs": [ "SRC-011", "SRC-005" ] }, { "target": "Incident and loss-event model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Hand off ownership when the uncertain event materialises, carrying only the realisation flag, occurrence time and the receiving record reference.", "required": false, "source_refs": [ "SRC-014", "SRC-005" ] }, { "target": "Observation and evidence model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Reference supporting observations and evidence with digest and relevance note, mirroring OSCAL related-observations; capture, custody and evidence lifecycle are not owned here.", "required": false, "source_refs": [ "SRC-011" ] }, { "target": "Party, role and organisation model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Resolve risk owners, assessors, reviewers and accepting authorities as party references rather than storing identity data locally.", "required": true, "source_refs": [ "SRC-005", "SRC-012" ] }, { "target": "Decision and delegated-authority model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Carry the authorising decision reference and the authority level asserted at the time; delegation schemes, approval workflow and enforcement remain external.", "required": false, "source_refs": [ "SRC-005", "SRC-010" ] }, { "target": "Quantity, unit and currency model (sibling; identifier not yet assigned in the registry)", "relation": "REFERENCE", "purpose": "Type monetary and physical consequence magnitudes with governed unit and currency codes and valuation basis dates instead of defining measurement systems locally.", "required": false, "source_refs": [ "SRC-007", "SRC-014" ] }, { "target": "Versioned classification scheme and code-list mixin (sibling; identifier not yet assigned in the registry)", "relation": "MIX-IN", "purpose": "Reuse generic code-list semantics — scheme identity, version, effective dating, retirement and crosswalks — for risk taxonomies rather than reimplementing scheme governance in this model.", "required": false, "source_refs": [ "SRC-014", "SRC-003" ] }, { "target": "W3C PROV-O (http://www.w3.org/ns/prov#)", "relation": "ALIGN", "purpose": "Align assertion provenance to Entity, Activity and Agent with wasAttributedTo, wasDerivedFrom, wasGeneratedBy and actedOnBehalfOf, so that provenance is exchangeable without importing a separate provenance lifecycle.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "NIST OSCAL Assessment Results risk structure (OSCAL v1.2.3)", "relation": "ALIGN", "purpose": "Map item fields to the OSCAL risk object for exchange, recording known losses — notably the absence of an opportunity valence and the threat-oriented status vocabulary.", "required": false, "source_refs": [ "SRC-011", "SRC-008" ] }, { "target": "NIST IR 8286 risk register and risk detail record structures", "relation": "ALIGN", "purpose": "Map register membership, exposure and priority to the published register and detail-record structures for enterprise roll-up, without adopting the enterprise risk management process itself.", "required": false, "source_refs": [ "SRC-006", "SRC-007", "SRC-009" ] }, { "target": "IEC 31010:2019 risk assessment technique catalogue", "relation": "ALIGN", "purpose": "Identify assessment techniques by reference to a published catalogue so that technique definitions, applicability and limitations are cited rather than restated locally.", "required": false, "source_refs": [ "SRC-004" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Name one accountable owner package for each register namespace and record it in AGENTS.md, including which system of record holds authoritative item identifiers.", "Publish and version the criteria sets, likelihood and consequence scales, combination rule and response option set in force, with effective dates; items may not be evaluated against unpublished criteria.", "Declare the classification schemes and versions in force for the namespace, and publish crosswalks before retiring any scheme version.", "Declare the appetite or tolerance statements that items reference, their approving body and their version, acknowledging that the statements themselves are authored outside this model.", "Declare the retention classes, sensitivity classification scheme and audience release rules that apply to items, snapshots and extracts." ], "namespace_guidance": "Use one stable namespace per register scope, for example dim..risk., with opaque identifiers inside it. Identifiers must not encode dates, owners, category codes, valence, severity or sensitivity, because every one of those attributes changes independently of item identity. Scheme, scale and criteria namespaces are separate from item namespaces so that a criteria version can be retired without touching item identity.", "registry_links": [ "Vercy registry entry vr.wm-knw-015 (WM-KNW-015 Risk / Opportunity), nav path NAV.INF.KNW.RSK", "Parent registry entry WM-ACT-017 for objectives and treatment actions", "Referencing model WM-AI-008 for AI governance assessments that cite items as risk evidence", "External alignment registries: OSCAL assessment-results (v1.2.3), NIST IR 8286 register and detail-record schemas, ISO 31073 vocabulary, Basel Framework OPE taxonomy" ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical form orders fields deterministically, trims and NFC-normalises text, and renders every reference as a triple of target model, namespace and identifier.", "Coded values are canonicalised as scheme identifier plus version plus code; a bare code without its scheme version is not canonical.", "Quantities are canonicalised as value plus unit or ISO currency code plus valuation basis date; ordinal band labels carry their scale identifier and version and are never converted to numbers during canonicalisation.", "All time values are canonicalised to RFC 3339 date-time with seconds and an explicit offset or Z, with event, observation and record times kept as distinct fields." ], "patch_rules": [ "Patches address the immutable item identity; the item identifier, its registration provenance and all prior revisions are never rewritten by a patch.", "Changes to likelihood, consequence, technique, assumptions or confidence are applied by creating a new assessment revision, not by editing values in place.", "Lifecycle, ownership and classification changes are applied as effective-dated patches carrying both effective time and record time plus the asserting agent.", "Review log entries, snapshots and closure records are append-only; a correction is issued as a new entry that cites the entry it supersedes.", "Concurrent conflicting patches resolve in favour of the authoritative master system of record; where none exists, the patch with the earlier observation time is retained and the other is recorded as a conflict for review." ], "compatibility_rules": [ "Adding optional fields, new codes to an open code list, or a new alignment target is a minor, backward-compatible change.", "Changing the meaning of a scale band, the combination rule, a threshold, a valence code or a lifecycle state is a breaking change requiring a new criteria or model version and a stated migration for existing items.", "Retired codes and scheme versions are never reused; historical items keep the version they were assessed under.", "Projections into external schemas must be regenerated when either this model's version or the target schema version changes, and the loss report reissued with them." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier issued by the system of record for the register — for example the risk register entry key held by the owning enterprise risk or assessment system — is always preferred where such a system exists.", "A governed global identifier or IRI from a published namespace, such as an OSCAL uuid or a Dimension-published IRI, where no master-system key exists.", "A UUID or ULID minted by the adopting Dimension, recorded with its minting authority and time, as the last resort.", "A date, title, category code, owner name, severity band or file name is never an identifier; such values may only be metadata carried alongside the identifier." ], "timestamp_rule": "All time values are recorded in RFC 3339 date-time form including whole seconds (fractional seconds permitted) and an explicit UTC offset or Z; a business date without a time is additionally qualified with the applicable time zone. Event time (when the uncertain event is judged to occur, or did occur), observation time (when an estimate, review or evidence reading was obtained) and record or ingestion time (when the value was written or imported) are stored in separate fields whenever they differ, and none may be substituted for, or derived from, another. Horizons are recorded as an explicit start and end rather than as a duration alone.", "serial_naming_rule": "Serial artifacts — register snapshots, review log entries, reporting extracts and validation reports — are named --; the sequence within its namespace is the identifier, while the RFC 3339 issue timestamp, as-of time and content hash are metadata that must never be used as the key. Sequences are never reused, and a withdrawn serial artifact leaves a gap-marking tombstone rather than being renumbered.", "integrity_rule": "Every artifact carries a SHA-256 digest over its canonical form together with the identifier of the asserting agent and the record time. Snapshots, review log entries and closure records are immutable once issued: corrections are new artifacts citing the superseded one. A digest mismatch invalidates any evaluation outcome, register view, projection or conformance claim built on that artifact, and such derived outputs must be regenerated rather than repaired." }, "policies": [ "Definition-scheme policy: every item declares the definition of risk it was recorded under. Items recorded under the neutral effect-of-uncertainty-on-objectives definition and items recorded under an adverse-only likelihood-and-impact definition must not be compared, ranked or aggregated without an explicit, recorded reconciliation rule.", "Non-enforcement policy: this model records assertions, references, decisions taken elsewhere and states. It does not evaluate policy at runtime, execute treatment, enforce acceptance, decide access, or create or hold audit trails; those capabilities belong to referenced models and to the adopting Dimension's platform.", "Reference-not-copy policy: evidence, observations, controls, actions, objectives, parties, appetite statements and decisions are referenced with identifier, version and digest plus a relevance note; their content is never copied into an item record.", "Opportunity-symmetry policy: beneficial items use the same identity, criteria, lifecycle and provenance machinery as adverse items. Valence is a coded field, not a separate record type, and no projection may silently drop it.", "Scale-integrity policy: no value may be recorded without its scale identifier and version, no ordinal band may be arithmetically combined without a documented and cited combination rule, and aggregation requires a recorded comparability and correlation check.", "Conformance-evidence policy: alignment to an external standard is recorded as a versioned crosswalk with known losses; conformance to that standard is claimed only when cited conformance evidence exists, and the claim carries a scope and an expiry." ], "crud": { "read": [ "Read by item identifier, by register scope, or as of a past time reconstructed from the revision series or a named snapshot.", "Reads of full statements, evidence references and owner identity require the sensitivity scope for the item's classification; other readers receive the redacted projection defined by the audience release rules.", "Register views, profiles and reporting extracts are read-only projections regenerated from item records; they are never edited directly and never recompute item values." ], "create": [ "An item is created only with the minimum registration set: statement, affected objective reference, valence, definition scheme, register scope, owner and asserting agent; creation mints identity per the identity priority rule.", "Assessment revisions, review log entries, snapshots, extracts and validation reports are created as new records and never by overwriting an existing one.", "Bulk import retains the source system identifier, the original assertion metadata and the ingestion activity reference, and imported items enter a validation pass before they may be relied upon." ], "update": [ "Estimates are updated by issuing a new assessment revision; the item identifier, registration provenance and every prior revision remain immutable.", "Ownership, classification, sensitivity and lifecycle updates are effective-dated, recording both effective time and record time plus the asserting agent and, where required, the authorising decision reference.", "Updates that would breach scale integrity, remove a mandatory field for the current state, or contradict a published crosswalk are rejected and recorded as validation defects rather than applied." ], "delete": [ "Items are never hard-deleted while any register, snapshot, extract, projection or referencing model still cites them; a deletion request against a referenced item is rejected and recorded.", "Ordinary disposal is by terminal state plus retention: closed, realised, withdrawn or superseded items are retained for the retention class recorded on the item, after which disposition proceeds under the adopting Dimension's records-retention policy and any applicable sectoral or regulatory retention rule.", "Where erasure is mandated — for example personal data subject to a valid erasure obligation — the item is tombstoned rather than removed: identifier, lifecycle state, closure reason, retention class and provenance stubs are retained while narrative, evidence references and personal fields are redacted, and the redaction is itself recorded with its authorising reference.", "Execution of retention scheduling, legal hold, redaction and physical erasure is owned by the adopting Dimension's records-management and privacy policies and by its storage platform, not by this model; this model owns only the retention class, the disposition state, the tombstone contract and the policy reference that governs execution.", "Withdrawal of a serial artifact leaves a sequence tombstone so that gaps in a snapshot or log series are detectable and cannot be mistaken for loss." ] }, "roles": [ { "name": "Risk owner", "responsibilities": [ "Hold accountability for the item, its accuracy and its response within the register scope", "Confirm the response option and ensure referenced treatment actions have named owners", "Escalate items outside appetite and confirm closure or realisation hand-off" ] }, { "name": "Risk assessor or analyst", "responsibilities": [ "Select and record the assessment technique, assumptions and inputs", "Produce likelihood and consequence estimates with scale references, horizon and confidence", "Record knowledge limits and unquantified uncertainty rather than concealing them in a point value" ] }, { "name": "Register custodian", "responsibilities": [ "Maintain register membership rules, identity assignment and namespace hygiene", "Issue immutable snapshots and audience-specific extracts with correct sequence identifiers and digests", "Maintain crosswalks and reissue projections and loss reports when versions change" ] }, { "name": "Assurance reviewer", "responsibilities": [ "Independently challenge estimates, framings and evaluation outcomes and record the challenge result", "Run validation passes and track defects, staleness and duplicate items to resolution", "Report on the reliability of the register without taking ownership of the items reviewed" ] }, { "name": "Dimension data steward", "responsibilities": [ "Publish and version criteria sets, scales, code lists, option sets and validation rulesets", "Bind sensitivity classes, audience release rules and retention classes to register scopes", "Record definitional conflicts between adopted standards and the local disambiguation applied" ] } ], "access": { "default_rule": "Deny by default. Read access is granted per register scope and sensitivity class to named roles; write access is limited to the role that owns the specific field group (assessor for estimates, owner for response and closure, custodian for identity and membership, steward for schemes and criteria). Items evaluated as outside appetite are readable by the designated escalation authority by construction.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Items under legal hold or investigation may be restricted to a named list that excludes the ordinary register audience, with the restriction and its authority recorded.", "Items containing personal data, whistleblowing content or individual conduct matters are restricted and released only in redacted form, with the lawful basis recorded where required.", "Aggregation-sensitive extracts, where the collection reveals more than any single item, are classified above their constituent items and released only to the approved audience.", "Regulators, auditors and, where legally required, competent authorities may receive scoped access exceeding the default audience rules; the grant, its scope and its expiry are recorded.", "Emergency read access during a materialising event may be granted ahead of routine approval, subject to retrospective recording of the grant and its justification." ], "audit_requirements": [ "The adopting Dimension's audit facility must be able to record every read of a restricted item and every write, lifecycle transition, redaction and access-exception grant, each with actor identity, RFC 3339 timestamp with offset, item identifier and the rule relied upon.", "Snapshot and extract issuance, withdrawal and digest verification must be auditable, including which snapshot a given extract was derived from.", "This model specifies what must be auditable and supplies the identifiers and timestamps needed to audit it; it neither generates, stores, evaluates nor enforces audit records, which remain owned by the platform and its governing policy." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL" ], "read_order": [ "AGENTS.md at the package root, to obtain Name, Type and the four URLs before any read or write", "Specification URL, for the model scope, boundaries, findings and the definition-scheme requirement", "Storage type URL, for the concrete projection in use (document store, relational register, graph or message payload) and its canonicalisation rules", "Interface URL, for the callable surface, identity assignment and access scopes", "Processes URL, for registration, assessment, evaluation, review, hand-off, validation and disposition procedures", "Registry entry vr.wm-knw-015 and parent WM-ACT-017, plus any referencing model such as WM-AI-008, to confirm relation direction and ownership before writing" ] } }, "coverage": { "claim": "Audited the sole active provider result for WM-KNW-015 (6 bundles, 13 layers, 26 findings, 106 questions, 12 artifacts, 12 functions, 14 sources) against its own evidence pack, the frozen registry record vr.wm-knw-015, the single-edge relationship contract, the empty legacy source and the declared omissions. The plan accepts the delivered structure as a reviewable single-provider draft with holds; it does not claim universal completeness. Quantitative decomposition, calibrated probability language, opportunity-bearing external schemas, the asserted composition set, the WM-ACT-017 parent edge and the paywalled ISO, Open Group and Basel texts remain unverified and are carried as gaps, not as coverage.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Item identity is separated from assessment revision identity, with master-system key first, governed IRI second, minted UUID or ULID third, alternate identifiers carried as non-primary, and split, merge and supersession recorded as continuity events (f-item-identity, artifact_rules.identity_priority)." }, { "dimension": "lifecycle", "status": "covered", "notes": "Declared state set with gated transitions, reopen exception, review cadence and triggers, realisation hand-off and permitted closure reasons (f-lifecycle-states, f-monitoring-review, f-realisation-closure, fn-transition-lifecycle-state)." }, { "dimension": "relationships", "status": "covered", "notes": "Objectives, threats, controls, actions, evidence, parties, decisions and materialised events are all reference links resolved in owning models; fourteen composition links state direction and ownership (composition, f-treatment-control-linkage)." }, { "dimension": "temporal", "status": "covered", "notes": "Horizon start and end, assessment validity, speed of onset, effective versus record time on every change, and separate event, observation and ingestion times in the timestamp rule (f-time-horizon-validity, f-assertion-provenance, artifact_rules.timestamp_rule)." }, { "dimension": "provenance", "status": "covered", "notes": "Asserting agent, delegation, derivation, imported-origin retention and PROV-O alignment; every value is attributable and every artifact digest-bound (f-assertion-provenance, SRC-012, artifact_rules.integrity_rule)." }, { "dimension": "ownership", "status": "covered", "notes": "Single accountable owner plus separated assessor, action-owner and reviewer roles mapped to assurance lines, with effective-dated ownership change (f-ownership-accountability, service_layers.roles)." }, { "dimension": "validation", "status": "covered", "notes": "Mandatory fields per state, scale conformance, duplicate detection, staleness flags and a serial validation report that blocks rather than amends (f-validation-completeness, fn-validate-record)." }, { "dimension": "access", "status": "covered", "notes": "Deny-by-default with per-scope and per-sensitivity read grants, field-group write separation, five named exception classes and audit requirements stated without claiming audit ownership (f-sensitivity-access, service_layers.access)." }, { "dimension": "retention and deletion", "status": "covered", "notes": "No hard delete while referenced; terminal state plus retention class; tombstone contract preserving identifier, state, closure reason and provenance stubs under mandated erasure; execution explicitly owned by the adopting Dimension's records-management and privacy policy and its storage platform (crud.delete, de-retention-class)." }, { "dimension": "interoperability", "status": "covered", "notes": "Versioned crosswalks to OSCAL risk, NIST IR 8286 register and detail-record structures, ISO vocabulary and sectoral taxonomies, with mandatory loss reports and a conformance-evidence policy (f-external-alignment-conflicts, fn-emit-alignment-projection)." }, { "dimension": "classification", "status": "covered", "notes": "Versioned scheme assignment with multi-scheme rules, retirement migration and crosswalks, plus valence and inherent/current/residual/target framing as distinct coded fields (f-taxonomy-classification, f-valence-and-framing)." }, { "dimension": "measurement", "status": "covered", "notes": "Likelihood representation and scale binding, consequence dimensions with unit, currency, valuation basis and case basis, combination rule with documented limits, and aggregation eligibility (f-likelihood-expression, f-consequence-expression, f-level-and-aggregation)." }, { "dimension": "authority", "status": "covered", "notes": "Required authority level, authorising decision reference, escalation path and delegation limits are recorded as references only; delegation schemes and approval workflow remain external (f-acceptance-escalation-authority)." }, { "dimension": "evidence and confidence", "status": "covered", "notes": "Confidence on a declared scale, evidence references with digest and relevance note, recorded knowledge limits and unquantified uncertainty, and an independent challenge record (f-evidence-and-confidence)." }, { "dimension": "quantitative aggregation", "status": "gap", "notes": "A verified quantitative decomposition — such as Open FAIR loss event frequency and loss magnitude — could not be retrieved: The Open Group publication and pubs sites required authentication. The model therefore constrains aggregation and records rule limits but does not supply a validated quantitative factor taxonomy; a Dimension adopting quantitative methods must bind one explicitly." }, { "dimension": "calibrated probability language", "status": "gap", "notes": "IPCC and EFSA calibrated-language and probability-scale guidance were not retrievable (HTTP 403), so no canonical band-to-probability mapping is asserted. The model requires a scale identifier and version on every value and leaves the calibrated vocabulary to the adopting Dimension." }, { "dimension": "opportunity representation in external schemas", "status": "gap", "notes": "No verified external schema encodes beneficial valence: OSCAL risk objects and the NIST register structures are threat-oriented. Symmetric treatment is supported by ISO/TC 262 and the Orange Book at the conceptual level only, so every projection of an opportunity is recorded as lossy." } ], "known_omissions": [ "Full texts of ISO 31000:2018, ISO 31073:2022, ISO Guide 73:2009, ISO 14971, ISO/IEC 27005 and COSO ERM are paywalled and the ISO catalogue blocked automated retrieval; their content is used here via first-party ISO/TC 262 material and public-authority restatements (HM Treasury Orange Book, NIST glossary citing ISO Guide 73). Quoted definitions should be verified against purchased texts before ratification.", "The Open Group Risk Taxonomy (O-RT 3.0.1) and Risk Analysis (O-RA 2.0.1) standards were behind authentication, so the FAIR factor decomposition is referenced as a candidate alignment only and is not modelled.", "Basel OPE loss event type categories and the operational risk definition could not be read at chapter level; the Basel citation supports scheme boundedness and loss-event separation, not the specific category list.", "Sector-specific structures are not enumerated: medical device harm and hazardous-situation chains, safety integrity levels, food safety hazard characterisation, disaster risk exposure and vulnerability components, and project-management opportunity response verbs.", "Technique-specific record shapes (bow-tie, FMEA, HAZOP, event tree, Monte Carlo output) are referenced through the IEC 31010 catalogue but not structurally modelled.", "Insurance, risk transfer instruments, regulatory capital calculation, and quantitative correlation or portfolio modelling are excluded by scope and not merely unmodelled.", "Machine-readable enumerations for valence, framing, response options, lifecycle states and closure reasons are described as governed code lists but no canonical code list is asserted, because no single authority publishes one that spans threat and opportunity." ], "conflicts": [ "Definitional conflict: ISO 31000/31073 and the Orange Book define risk neutrally as the effect of uncertainty on objectives, admitting beneficial deviation, while NIST SP 800-30/SP 800-39/CNSSI 4009 and sectoral regimes define risk as a function of adverse impact and likelihood. The NIST glossary carries both simultaneously. Resolved here by a mandatory definition-scheme field and a policy forbidding unreconciled comparison, not by choosing one definition.", "Schema conflict: OSCAL risk objects and NIST register structures are threat-oriented with statuses such as open, investigating, remediating and closed, and have no valence concept; projecting a beneficial item into them is lossy and must be reported as such.", "Terminological conflict: risk appetite and risk tolerance are used inconsistently across ISO 31073, COSO, OMB Circular A-11 and A-123, and NIST IR 8286, with the NIST glossary alone showing several non-identical definitions. The model therefore references an appetite statement by identifier and version and records the term sense used rather than storing a comparable value.", "Framing conflict: inherent versus residual framing is standard in enterprise risk practice and used by many registers, but ISO 31000:2018 does not treat inherent risk as a required concept. The model records framing as a coded field instead of assuming a fixed pair.", "Method conflict: multiplying ordinal likelihood and consequence bands is widespread practice but is not a validated arithmetic operation; IEC 31010 treats technique selection and validation as an explicit step. The model requires the combination rule and its documented limits rather than endorsing matrix arithmetic.", "Scope conflict: sectoral taxonomies deliberately exclude categories other regimes include — the Basel operational risk perimeter is a clear example — so category codes are not portable across schemes without a crosswalk.", "Boundary conflict: EU AI Act Article 9 imposes a continuous, iterative risk management system with a residual-risk acceptability judgement for high-risk AI. That obligation belongs to WM-AI-008 and the provider; this model must supply evidence-quality risk records without absorbing the conformity or enforcement duty." ], "regional_assumptions": [ "The Orange Book, its three lines model and its response option vocabulary are UK central government guidance; they are used as a verified restatement of ISO-style concepts, not as universal law.", "NIST IR 8286 series conventions, including exposure and priority columns and enterprise roll-up, reflect US federal enterprise practice and OMB circulars; other jurisdictions may require different register fields.", "EU AI Act obligations apply to AI systems placed on the Union market or put into service in the Union; the WM-AI-008 reference must not be read as a global obligation.", "Basel Framework OPE applies to internationally active banks in adopting jurisdictions and is used here only as evidence about scheme boundedness.", "Monetary consequence values assume a currency code and a valuation basis date; multi-currency registers additionally require an exchange-rate policy that this model references but does not define.", "Personal-data handling in items assumes the adopting Dimension's privacy regime supplies the lawful basis, retention limit and erasure obligation; the tombstone contract is designed to survive an erasure regime but does not implement any particular one." ], "adversarial_checks": [ "Definition-imposition test: the model was checked against sources that contradict ISO's neutral definition (NIST SP 800-30, CNSSI 4009, sectoral loss-event regimes). Rather than asserting one definition, a mandatory definition-scheme field plus a no-unreconciled-comparison policy was adopted; a single normative definition would have been unsupported.", "Relation-ownership sweep: every bundle, layer, finding and function was compared with the WM-AI-008 REFERENCE rationale and with each outgoing reference or alignment. No function performs AI conformity assessment, runtime evaluation, treatment execution, control assurance, incident investigation, access enforcement or audit-record creation; those concepts were moved to out_of_scope, boundary_notes or composition links.", "Artifact-inflation test: findings that carry only inline fields — definitional frame, identity, likelihood, consequence, level, valence, scope, provenance, ownership, authority, sensitivity — were denied artifacts, and each records a rationale explaining why materialisation would duplicate an externally owned record or split a single assessment.", "Identifier hygiene test: every local identifier was checked for date-like components and none contains one; snapshot, log entry, extract and validation report identity is a namespace plus monotonic sequence, with timestamps demoted to metadata.", "Ordinal arithmetic test: the temptation to declare a canonical risk matrix was rejected. The combination rule is a referenced, versioned object whose validity limits must be recorded, and aggregation requires an explicit comparability and correlation check.", "Register-as-report test: dashboards, board reporting cadence, analytics and enterprise appetite setting were pushed to the parent model and the adopting Dimension; only snapshots and audience-scoped extracts with declared filters remain here.", "Opportunity-symmetry falsification: an attempt was made to find a verified schema encoding beneficial valence and none was found, so symmetry is claimed at the conceptual level with ISO/TC 262 and Orange Book support, and every external projection of an opportunity is marked lossy rather than presented as interoperable.", "Evidence-copying test: findings that touch evidence, controls, actions, parties, appetite statements and decisions were re-read to confirm they carry only identifier, version, digest and relevance note, with no local copy of externally owned content." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-08-29T09:06:27Z", "scope": "Queued subject-model research from WM-XCT-013 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-08-29T09:06:27Z", "reason": "The repository owner explicitly instructed the research queue to continue without Grok after repeated structured-output failures." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "entity", "status": "accepted", "rationale": "Two axes must be kept apart. The frozen registry value 'standalone-mm' with record_plane 'world-model' classifies how the registry record itself is carried in the registry plane — it says the model is a standalone meta-model record rather than a contained fragment — and it is not a member of the subject-model enum, so it can never be the subject kind. On the subject axis the governed thing is a persistent, identified register item: it holds a stable identifier separate from its assessment revisions, moves through gated lifecycle states, carries a single accountable owner, survives re-estimation, split, merge, withdrawal and closure, and is referenced by WM-AI-008 as a durable target. That is 'entity'. 'event' is rejected because the uncertain event is the item's referent, not the record — the model explicitly loses custody at realisation and hands the materialised event to the incident or loss-event model, so typing it as an event would erase the entire pre-occurrence lifecycle that is the model's substance. 'aggregate' and 'registry' are rejected at entry level because the risk register, its snapshots and its reporting extracts are declared artifacts and derived projections of the item, and making the register the root would make membership changes rewrite item identity; whether the register deserves a separate registry-kind sibling is recorded as deferred, not resolved here. The aggregate root is therefore the individual risk or opportunity item, with assessment revisions, review log entries, treatment plans and closure records composed under its identity." }, "decisions": [ { "concept": "Aggregate root: individual item versus the risk register", "disposition": "accepted — item is the root, register stays an artifact", "rationale": "Item identity is asserted to persist independently of register membership, and snapshots and extracts are derived, sequence-identified artifacts. Rooting the model on the register would make a membership or scope change mutate item identity and would contradict the identity-priority rule." }, { "concept": "Subject entry kind 'entity' versus frozen registry 'standalone-mm'", "disposition": "accepted as entity; registry value read as record-plane classifier only", "rationale": "The registry field classifies the record plane (a standalone meta-model record) and is absent from the subject-model enum. The provider's declared 'entity' is the defensible subject kind and no reclassification of the provider judgement is required, only an explicit two-axis note in the published draft." }, { "concept": "Alternative entry kind 'event'", "disposition": "rejected", "rationale": "The uncertain event is the referent of the record, not the record. The model surrenders the materialised event to the incident or loss-event model at realisation and keeps only a flag, an event time and a reference, so an event kind would discard the pre-occurrence lifecycle the model exists to govern." }, { "concept": "Alternative entry kinds 'aggregate' and 'registry'", "disposition": "rejected at entry level; register-as-sibling deferred", "rationale": "Register, snapshot and reporting extract are declared artifacts with their own serial identity rules, and f-register-aggregation owns membership rather than being owned by it. Whether a registry-kind sibling model should hold register scope, membership and retention is a real open question but does not change this entry's kind." }, { "concept": "Opportunity symmetry under one identity with valence as a coded field", "disposition": "accepted", "rationale": "Symmetry is claimed only at the conceptual level with ISO/TC 262 and Orange Book support, the falsification attempt for an opportunity-bearing external schema is recorded as failed, and every projection of a beneficial item is marked lossy. Splitting valence into two record types would duplicate identity, criteria and lifecycle machinery for no evidenced gain." }, { "concept": "Coverage checklist claim of 'fourteen composition links' under the relationships dimension", "disposition": "rejected as unsupported; downgrade relationships to partial pending delivery", "rationale": "The delivered payload contains no composition array, the frozen registry contains_ids is empty and the relationship contract carries a single WM-AI-008 REFERENCE edge. A covered status cannot rest on a structure that is not present in the evidence pack being audited." }, { "concept": "Dangling checklist identifier 'de-retention-class' in the retention and deletion note", "disposition": "rejected as a broken traceability pointer; must resolve to crud.delete and f-register-aggregation", "rationale": "No element with that identifier exists in the delivered bundle, layer, finding, artifact or function sets. Traceability citations in the coverage checklist must resolve to delivered identifiers or the checklist cannot be used as review evidence." }, { "concept": "Parent relation to WM-ACT-017 asserted in boundary notes and registry links", "disposition": "deferred pending relationship-contract ratification", "rationale": "The parent edge appears in registry parent_ids, in a boundary note and in the service-layer registry links, but the frozen relationship contract contains only the inbound WM-AI-008 REFERENCE. The draft may describe the intended parent plane but must not present the edge as ratified." }, { "concept": "Source support: ISO 31000 and ISO 31073 cited as primary tier-1 support without full-text retrieval", "disposition": "accepted with mandatory cited-but-unretrieved marking", "rationale": "The known_omissions honestly disclose that ISO texts are paywalled and that content is carried via ISO/TC 262 first-party material and public-authority restatements, but the source table still flags them primary_source true, which overstates evidentiary status for any downstream conformance claim." }, { "concept": "primary_source flag on aggregating NIST glossary entries and a TC 262 news item", "disposition": "reclassified as authoritative restatements rather than primary texts", "rationale": "SRC-008, SRC-009 and SRC-010 explicitly aggregate SP 800-30, SP 800-39, CNSSI 4009, OMB circulars and ISO Guide 73, and SRC-003 is a committee news item. They are legitimate support for the recorded definitional conflict but must not be published as primary sources of the definitions themselves." }, { "concept": "Access scopes declared as bundle, layer, finding and artifact", "disposition": "rejected as a research-plane leak; must map to item, register, revision and artifact scopes", "rationale": "Those four scopes describe this world-model document's own structure, not the governed subject records. A deny-by-default access rule that grants per register scope and sensitivity class needs subject-plane scopes, otherwise the interface specification cannot implement the stated field-group write separation." }, { "concept": "Retention, erasure and the tombstone contract", "disposition": "accepted", "rationale": "The model owns only retention class, disposition state, tombstone contract and policy reference, refuses hard deletion while any register, snapshot, extract or referencing model cites the item, preserves identifier, state, closure reason and provenance stubs under mandated erasure, and pushes scheduling, legal hold and physical erasure to the adopting Dimension. That is consistent with the non-enforcement policy and asserts no retention duration it cannot support." }, { "concept": "Artifact identity rules: serial naming, digest binding and timestamps demoted to metadata", "disposition": "accepted", "rationale": "Identity priority runs master-system key, governed IRI, minted UUID or ULID; no local identifier encodes a date, owner, category, severity or sensitivity; serial artifacts use namespace plus zero-padded monotonic sequence with tombstoned gaps; and a digest mismatch invalidates derived evaluations, views, projections and conformance claims rather than permitting repair." }, { "concept": "art-risk-statement-record carrying no identifier of its own beyond item identity and revision", "disposition": "accepted with a condition on the storage projection", "rationale": "A statement record with no independent key avoids a second identifier surface, but the integrity rule requires every artifact to carry a digest, asserting agent and record time, so the storage specification must state explicitly that the digest binds to item identifier plus revision or the artifact becomes unaddressable." }, { "concept": "Frozen registry purpose line 'Uncertain event/effect with likelihood and impact' versus the neutral definition-scheme design", "disposition": "deferred to registry update before ratification", "rationale": "The registry purpose is phrased in the adverse-only likelihood-and-impact frame while the model name is Risk / Opportunity and its central policy forbids unreconciled comparison across definition schemes. The registry record, its empty namespace_uri and its vague owner_or_maintainer must be corrected at ratification, not silently overridden by the draft." } ], "publicationHolds": [ "Single-provider hold: publish as a reviewable draft only. Independent second-provider review is absent under the repository owner's authorisation of 2026-08-29T09:06:27Z waiving Grok after repeated structured-output failures; every published artifact must display the waiver, its authoriser, its reason and the single-provider status alongside this no-tools adversarial audit.", "Live source and version verification hold: all fourteen source URLs, editions and access pins must be re-verified live before ratification, specifically the two ISO catalogue pages (SRC-001, SRC-002), the Orange Book page-updated pin of 29 July 2026 (SRC-005), the OSCAL v1.2.3 reference (SRC-011), the NIST IR 8286A Rev. 1 December 2025 pin (SRC-007) and the three NIST glossary entries pinned to access date 2026-09-03 (SRC-008 to SRC-010).", "Unretrieved primary text hold: mark SRC-001, SRC-002 and SRC-014 as cited-but-unretrieved. ISO texts are paywalled and Basel OPE10 was not read at category level, so quoted definitions rest on restatements in SRC-005 and SRC-008 and no conformance claim may be published against any of them.", "Composition evidence hold: withhold the relationships 'covered' status. The payload contains no composition relations, registry contains_ids is empty and the frozen contract carries only WM-AI-008 REFERENCE to WM-KNW-015, so the fourteen-link claim and the dangling 'de-retention-class' citation must be repaired or downgraded before the checklist is published as review evidence.", "Registry reconciliation hold: publish the entry-kind reconciliation explicitly, stating that the frozen 'standalone-mm' value classifies the record plane while the subject-model kind is 'entity', and keep review_state 'boundary-review-required', the empty namespace_uri and the adverse-only registry purpose line visible as open registry defects.", "Unratified parent hold: WM-ACT-017 may be described as the intended parent plane but must not be published as a ratified relation until an edge exists in the frozen relationship contract.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Acquire licensed ISO 31000:2018, ISO 31073:2022 and ISO Guide 73:2009 texts and verify every quoted definition, the neutral effect-of-uncertainty framing and the inherent-risk claim before ratification replaces the restatement-based support.", "Obtain The Open Group O-RT 3.0.1 and O-RA 2.0.1 and decide whether a quantitative loss-event-frequency and loss-magnitude decomposition is bound as an optional alignment or left explicitly unmodelled.", "Retrieve Basel Framework OPE10 at chapter level to confirm the loss-event-type category boundary claim that currently supports only scheme boundedness and loss-event separation.", "Locate or commission a citable calibrated probability-language mapping equivalent to the unreachable IPCC and EFSA guidance so ordinal bands can carry a referenceable probability scale.", "Re-test whether any external schema encodes beneficial valence, including project-management opportunity vocabularies and ISO 31073-derived registries, to reduce the recorded loss on every opportunity projection.", "Decide whether the risk register warrants a separate registry-kind sibling model owning membership, snapshot and retention semantics, or remains an artifact set composed under this entity.", "Expand protection-plane question coverage in the next revision: one access, one security, one privacy and one retention question across 106 is thin for a model that carries aggregation sensitivity, personal data and a tombstone contract.", "Confirm the nav placement NAV.INF.KNW.RSK against the WM-ACT-017 parent plane, since a governed operational register record under an action or objective parent may belong outside the knowledge branch." ] }, "statistics": { "sources": 14, "bundles": 6, "layers": 13, "findings": 26, "questions": 106, "artifacts": 12, "functions": 12 } }