All releases
Governance · Risk Register

Risk Register — signal-driven, three-layer, board-facing

The first shipping GRC risk register that auto-generates customer-environment-specific scenarios from live signals across the platform — not from a pre-built library. Three-layer architecture (board appetite / risk / deficiency) per FAIR discipline. NACD, NIST CSF 2.0, NISTIR 8286A, ISO 31000 grounded.

The Risk Registershipped this week — and it works differently than every other GRC platform’s. Where Vanta, Drata, Hyperproof, and the rest populate the register from a pre-built library or manual entry, vCISO Lite’s auto-generates customer-environment-specific scenarios from real signals across the platform. If a KRI trips, a vendor concentration goes material, a threat-intel feed matches an asset in the dependency graph, or a Refraction alert prices a vendor exposure — a proposed row lands in the register. Customers accept, decline, or adjust; the audit trail records the decision either way.

Three layers, one register

The architecture follows FAIR discipline (Jack Jones / FAIR Institute): risks and control gaps are different things and belong in different registers. Conflating them is what turns a risk register into what Jones calls a “due-diligence dumping ground.”

  • Layer 1 — Board appetite & tolerance. Five rows, one per ERM business-impact category (operational, financial, compliance, reputational, strategic). Each row carries a board-authored appetite statement, a quantitative tolerance trigger (a dollar ceiling, a duration, a named-event predicate), auto-computed current exposure, an in-or-out-of-appetite verdict, and trend. The decisions a board actually makes — accept, tighten, breach-acknowledge, escalate — land here.
  • Layer 2 — Risk Register.Roughly 20–30 scenarios in FAIR shape (“[Threat] impacts [asset] via [method], causing [effect]”), each with a primary ERM category, dollar-exposure via FAIR’s LEF × LM math, driving signals, owner, treatment plan, and audit trail. Scenarios aggregate up into Layer 1 category exposure.
  • Layer 3 — Deficiency Register.Control gaps, scanner findings, audit findings, policy exceptions — each bidirectionally mapped to the scenarios it contributes to. Findings are not risks. They are conditions that contribute to risk. The Deficiency tab is where they live; the Risk Register is where their impact aggregates.

Eight signal sources feed the register

Scenarios materialize from live telemetry, not templates:

  • Reporting-serviceseeds the register from the customer-authored existential-risk exercise at onboarding — customer voice preserved verbatim.
  • Vendor-serviceproposes a “Critical Vendor Outage” scenario when HHI concentration crosses a material threshold.
  • Vendor-incident-servicereprices existing vendor scenarios when a realized loss lands — not a new row, but honest math on an old one.
  • Resilience-service (Keystone)asset-instantiates scenarios with real names from the dependency graph — business functions, systems, key-person single points of failure.
  • Continuous Indicators (KRIE) propose transient scenarios on KRI breach and promote them to persistent if the breach persists. Leading indicators get outsized weight in board projections.
  • Threat-intelligenceproposes a scenario when an active threat matches an asset in the customer’s environment.
  • Findings-serviceamplifies scenario dollars when a KEV-tier CVE lands on an asset that maps to an existing scenario — findings live in Layer 3, but they reprice Layer 2.
  • Compliance-service and policy-servicepropose “audit failure” and “policy exception” scenarios and populate the Deficiency Register with the underlying gaps.

What’s under the standards

The design was validated against the governance sources boards actually cite: NACD/ISA 2026 Director’s Handbook on Cyber-Risk Oversight (5th Edition), NIST CSF 2.0 GV.RM-02, NISTIR 8286A (the NIST integrating-cyber-risk-into-ERM framework), ISO 31000:2018, and the FAIR Institutemethodology — specifically the two-register discipline Jack Jones has been pushing since 2019 and which every shipping GRC platform ignores. The NACD/NIST anchoring matters: COSO ERM 2017 uses four categories; NACD/NIST use five (the ones in Layer 1). The board vocabulary here is board vocabulary.

What it’s for

The Risk Register is where the founder or CISO shows up to a board meeting with the top scenarios, the current exposure, and the recommendation — and where the board records its decisions in a form the auditor and the regulator can defend. “Forward risk vs backward risk: the board report that shows where you’re headed” walks through why the current state of the practice fails at exactly that job.

Related reading: Risk Quantification cluster, Continuous Indicators cluster, Why your KRIs stopped predicting anything.