Skip to content

Risk Methodology

Where to find it: Administration, then Risk Methodology (/settings/risk-methodology).

Risk methodology is tenant configuration: how your organisation scores risk, what it considers within appetite, and how often risks are reviewed.


What is configured

ElementPurpose
Impact scaleThe levels used to describe consequence
Likelihood scaleThe levels used to describe probability
Scoring matrixHow impact and likelihood combine into a rating
Risk appetiteThe thresholds beyond which a risk requires escalation or acceptance
Review cadenceHow often risks of each rating are reviewed

Why methodology is tenant-configured

Risk scales are organisational policy, not platform behaviour. A retail bank, an insurer and a payments processor describe impact in different terms and set appetite at different levels.

OrviQ does not impose a scale. It applies whatever your organisation has agreed, consistently, and records that the configuration was applied.


Risk appetite

Appetite thresholds define the boundary between risks that are carried in the normal course and risks requiring an explicit decision.

Configuring appetite has consequences beyond reporting:

  • A residual rating beyond appetite is a signal that the risk needs treatment or formal acceptance
  • Acceptance requests for risks beyond appetite naturally escalate to a more senior approval stage
  • Appetite breaches are reportable to the board as breaches, not as amber items

Appetite is a decision, not a calculation

Setting appetite at a level where nothing ever breaches makes the concept meaningless. Setting it where everything breaches makes it noise. It should be set where the organisation genuinely wants a conversation.


Review cadence

Review cadence sets how often risks of each rating come back for review. Higher-rated risks are reviewed more frequently.

Scheduled risk review dates project into the GRC Calendar as governance events.


The derivation sweep

The derivation sweep recalculates derived values and takes snapshots across the register according to the configured methodology.

It is a maintenance operation: it applies the methodology consistently and records the resulting state. It does not make judgements, and it does not overwrite human ratings with computed ones.

Requires risk.methodology_manage.


Changing methodology

Changing the scoring matrix or appetite thresholds changes how existing risks are read.

Before changing:

  1. Understand how many risks move band under the new configuration.
  2. Decide whether to communicate the change as a change in exposure or a change in measurement — they are very different messages to a board.
  3. Record the rationale. Someone will ask why the number of Critical risks halved between two quarters.

Historical snapshots preserve the ratings that were in force at the time they were taken, so a methodology change does not retroactively rewrite the past register.


Permissions

ActionPermission
View the registerrisk.read
Configure scoring methodology, appetite and cadence; run the derivation sweeprisk.methodology_manage

Requires the risk_management entitlement.


Example

A bank configures:

ElementConfiguration
ImpactInsignificant, Minor, Moderate, Major, Severe
LikelihoodRare, Unlikely, Possible, Likely, Almost Certain
Matrix5 by 5, producing Low, Medium, High, Critical
AppetiteOperational risk: residual up to Medium carried in the normal course; High requires a treatment plan; Critical requires CRO acceptance
Review cadenceCritical monthly, High quarterly, Medium semi-annually, Low annually

The appetite configuration is the operative part. It means a risk at High residual with no treatment plan is not merely a data quality issue — it is an unaddressed breach of stated appetite, visible as such, with a named owner.


Troubleshooting

"Ratings did not change after I updated the matrix." Run the derivation sweep to apply the configuration across the register.

"Historical reports show different ratings." Snapshots preserve the ratings in force when taken. That is intentional.

"I cannot access Risk Methodology." Requires risk.methodology_manage, which is an administrative permission.


OrviQ Enterprise Governance, Risk & Compliance Platform