Appearance
Risk Methodology
Where to find it: Administration, then Risk Methodology (/settings/risk-methodology).
Risk methodology is tenant configuration: how your organisation scores risk, what it considers within appetite, and how often risks are reviewed.
What is configured
| Element | Purpose |
|---|---|
| Impact scale | The levels used to describe consequence |
| Likelihood scale | The levels used to describe probability |
| Scoring matrix | How impact and likelihood combine into a rating |
| Risk appetite | The thresholds beyond which a risk requires escalation or acceptance |
| Review cadence | How often risks of each rating are reviewed |
Why methodology is tenant-configured
Risk scales are organisational policy, not platform behaviour. A retail bank, an insurer and a payments processor describe impact in different terms and set appetite at different levels.
OrviQ does not impose a scale. It applies whatever your organisation has agreed, consistently, and records that the configuration was applied.
Risk appetite
Appetite thresholds define the boundary between risks that are carried in the normal course and risks requiring an explicit decision.
Configuring appetite has consequences beyond reporting:
- A residual rating beyond appetite is a signal that the risk needs treatment or formal acceptance
- Acceptance requests for risks beyond appetite naturally escalate to a more senior approval stage
- Appetite breaches are reportable to the board as breaches, not as amber items
Appetite is a decision, not a calculation
Setting appetite at a level where nothing ever breaches makes the concept meaningless. Setting it where everything breaches makes it noise. It should be set where the organisation genuinely wants a conversation.
Review cadence
Review cadence sets how often risks of each rating come back for review. Higher-rated risks are reviewed more frequently.
Scheduled risk review dates project into the GRC Calendar as governance events.
The derivation sweep
The derivation sweep recalculates derived values and takes snapshots across the register according to the configured methodology.
It is a maintenance operation: it applies the methodology consistently and records the resulting state. It does not make judgements, and it does not overwrite human ratings with computed ones.
Requires risk.methodology_manage.
Changing methodology
Changing the scoring matrix or appetite thresholds changes how existing risks are read.
Before changing:
- Understand how many risks move band under the new configuration.
- Decide whether to communicate the change as a change in exposure or a change in measurement — they are very different messages to a board.
- Record the rationale. Someone will ask why the number of Critical risks halved between two quarters.
Historical snapshots preserve the ratings that were in force at the time they were taken, so a methodology change does not retroactively rewrite the past register.
Permissions
| Action | Permission |
|---|---|
| View the register | risk.read |
| Configure scoring methodology, appetite and cadence; run the derivation sweep | risk.methodology_manage |
Requires the risk_management entitlement.
Example
A bank configures:
| Element | Configuration |
|---|---|
| Impact | Insignificant, Minor, Moderate, Major, Severe |
| Likelihood | Rare, Unlikely, Possible, Likely, Almost Certain |
| Matrix | 5 by 5, producing Low, Medium, High, Critical |
| Appetite | Operational risk: residual up to Medium carried in the normal course; High requires a treatment plan; Critical requires CRO acceptance |
| Review cadence | Critical monthly, High quarterly, Medium semi-annually, Low annually |
The appetite configuration is the operative part. It means a risk at High residual with no treatment plan is not merely a data quality issue — it is an unaddressed breach of stated appetite, visible as such, with a named owner.
Troubleshooting
"Ratings did not change after I updated the matrix." Run the derivation sweep to apply the configuration across the register.
"Historical reports show different ratings." Snapshots preserve the ratings in force when taken. That is intentional.
"I cannot access Risk Methodology." Requires risk.methodology_manage, which is an administrative permission.