Risk Register Builder
Builds a complete risk register with likelihood, impact, and treatment plans.
Reads your system inventory, threat landscape, and existing controls, then generates a structured risk register with qualitative and quantitative scoring. Each risk gets inherent and residual scores, treatment options, and an owner assignment.
Try a sample prompt:
Risk Register · Acme Fintech · 2026-05-09
Methodology: ISO/IEC 27005 + NIST RMF · Scale: 1–5 likelihood × 1–5 impact → risk score 1–25
Total risks: 28 (4 Extreme, 8 High, 11 Moderate, 5 Low) · Risks > 15 residual requiring treatment: 3
R-001 · Customer PII Exposure via Misconfigured S3
Category: Technical · Data Security
Threat source: External attacker or insider misconfiguration
Threat event: Public-readable S3 bucket containing customer PII
Affected assets: customer-uploads-prod, exports-archive
Inherent Likelihood: 4 (Likely) × Inherent Impact: 5 (Critical) = 20 (Extreme)
Current controls:
- S3 BlockPublicAccess at account level
- KMS encryption at rest
- AWS Config rule s3-bucket-public-read-prohibited
Residual Likelihood: 2 × Residual Impact: 5 = 10 (Moderate)
Treatment: Mitigate (already in progress)
Action: Add VPC endpoint policy for S3, enable AWS Macie for sensitive data discovery, quarterly bucket policy review
Owner: Head of Platform · Target close: 2026-08-31
R-002 · Stripe API Key Compromise
Category: Technical · Third-Party
Threat source: Source code leak, contractor compromise, supply chain
Threat event: Production Stripe restricted key exfiltrated
Inherent: 3 × 5 = 15 (High)
Current controls: Restricted keys (not full), AWS Secrets Manager with rotation, GitHub secret scanning
Residual: 1 × 5 = 5 (Low)
Treatment: Accept residual · monitor
R-007 · Single AWS Region Dependency (Availability)
Category: Operational · Business Continuity
Inherent: 2 × 5 = 10 (Moderate)
Current controls: Multi-AZ within us-east-1, daily RDS snapshots
Residual: 2 × 4 = 8 (Moderate)
Treatment: Mitigate
Action: Multi-region warm standby in us-west-2 by Q3 2026 (capex approved)
R-014 · GenAI Tool Data Leakage (NEW)
Category: Regulatory · AI Governance
Threat event: Engineer pastes customer PII into ChatGPT consumer tier
Inherent: 4 × 4 = 16 (High)
Current controls: Endpoint DLP not deployed, AI policy in draft
Residual: 4 × 4 = 16 (High) — NO MITIGATION YET
Treatment: Mitigate (TOP-3 priority for Q2)
Action:
Owner: CISO · Escalation: Risk Committee Q2 review
Top-5 Residual Risks Requiring Treatment
| Rank | Risk | Residual | Owner |
| 1 | R-014 GenAI Data Leakage | 16 | CISO |
| 2 | R-001 S3 Customer PII | 10 | Platform |
| 3 | R-007 Single-Region Availability | 8 | SRE |
| 4 | R-022 Insider Threat (privileged) | 8 | HR + Security |
| 5 | R-031 Vendor Concentration (Stripe) | 6 | CFO |
Risk Heat Map Summary
- Extreme (15–25) inherent: 4 risks — mitigation pathways defined for all
- High (10–14) residual: 1 risk (R-014) — currently UNTREATED, executive action required
- Moderate (5–9) residual: 11 risks — managed via routine controls
- Low (1–4) residual: 12 risks — accepted
Top Treatment Investments
Risks Recommended for Acceptance (with justification)
- R-019 Tornado/seismic event at single colocation (BCM provider has 2 alternate sites under contract)
- R-026 IPv6 exhaustion (5-year horizon; no current architecture dependency)