Agent Registry·Risk·Risk Register Builder
Riskclaude-opus-4-6Open source · Free to copy

Risk Register Builder

Builds a complete risk register with likelihood, impact, and treatment plans.

Reads your system inventory, threat landscape, and existing controls, then generates a structured risk register with qualitative and quantitative scoring. Each risk gets inherent and residual scores, treatment options, and an owner assignment.

Tools:readgrepglob
Frameworks:ISO 27005NIST RMFSOC 2CMMCISO 31000
Use case 1
First-time risk register for ISO 27001 or SOC 2 and you do not know where to start
Complete register with 20 to 40 risks calibrated to your stack, scored 1–25 inherent and residual, with treatment options and owner mapping
Use case 2
Quarterly risk review and you need to assess delta from last quarter
Side-by-side comparison highlighting new risks, retired risks, score changes, and proposed treatment updates
Use case 3
Board risk committee asks 'what is our top-5 enterprise risk right now?'
Ranked exposure list with dollar impact estimates, treatment ROI, and accept / mitigate / transfer / avoid recommendations

Try a sample prompt:

risk-register-builder · live demo · gemini-flash
◇ Curated sample output (real format)

Risk Register · Acme Fintech · 2026-05-09

Methodology: ISO/IEC 27005 + NIST RMF · Scale: 1–5 likelihood × 1–5 impact → risk score 1–25

Total risks: 28 (4 Extreme, 8 High, 11 Moderate, 5 Low) · Risks > 15 residual requiring treatment: 3


R-001 · Customer PII Exposure via Misconfigured S3

Category: Technical · Data Security

Threat source: External attacker or insider misconfiguration

Threat event: Public-readable S3 bucket containing customer PII

Affected assets: customer-uploads-prod, exports-archive

Inherent Likelihood: 4 (Likely) × Inherent Impact: 5 (Critical) = 20 (Extreme)

Current controls:

- S3 BlockPublicAccess at account level

- KMS encryption at rest

- AWS Config rule s3-bucket-public-read-prohibited

Residual Likelihood: 2 × Residual Impact: 5 = 10 (Moderate)

Treatment: Mitigate (already in progress)

Action: Add VPC endpoint policy for S3, enable AWS Macie for sensitive data discovery, quarterly bucket policy review

Owner: Head of Platform · Target close: 2026-08-31

R-002 · Stripe API Key Compromise

Category: Technical · Third-Party

Threat source: Source code leak, contractor compromise, supply chain

Threat event: Production Stripe restricted key exfiltrated

Inherent: 3 × 5 = 15 (High)

Current controls: Restricted keys (not full), AWS Secrets Manager with rotation, GitHub secret scanning

Residual: 1 × 5 = 5 (Low)

Treatment: Accept residual · monitor

R-007 · Single AWS Region Dependency (Availability)

Category: Operational · Business Continuity

Inherent: 2 × 5 = 10 (Moderate)

Current controls: Multi-AZ within us-east-1, daily RDS snapshots

Residual: 2 × 4 = 8 (Moderate)

Treatment: Mitigate

Action: Multi-region warm standby in us-west-2 by Q3 2026 (capex approved)

R-014 · GenAI Tool Data Leakage (NEW)

Category: Regulatory · AI Governance

Threat event: Engineer pastes customer PII into ChatGPT consumer tier

Inherent: 4 × 4 = 16 (High)

Current controls: Endpoint DLP not deployed, AI policy in draft

Residual: 4 × 4 = 16 (High) — NO MITIGATION YET

Treatment: Mitigate (TOP-3 priority for Q2)

Action:

1. Approve AI Tool Usage Standard (2 weeks)
2. Deploy Microsoft Defender for Cloud Apps with prompt-data classification (4 weeks)
3. Sanctioned enterprise tier (Claude Teams, ChatGPT Enterprise) for permitted use (6 weeks)

Owner: CISO · Escalation: Risk Committee Q2 review


Top-5 Residual Risks Requiring Treatment

RankRiskResidualOwner
1R-014 GenAI Data Leakage16CISO
2R-001 S3 Customer PII10Platform
3R-007 Single-Region Availability8SRE
4R-022 Insider Threat (privileged)8HR + Security
5R-031 Vendor Concentration (Stripe)6CFO

Risk Heat Map Summary

- Extreme (15–25) inherent: 4 risks — mitigation pathways defined for all

- High (10–14) residual: 1 risk (R-014) — currently UNTREATED, executive action required

- Moderate (5–9) residual: 11 risks — managed via routine controls

- Low (1–4) residual: 12 risks — accepted

Top Treatment Investments

1. AI tool governance and DLP rollout (R-014) — ~$45K
2. Multi-region DR (R-007) — ~$120K capex
3. PAM tool with JIT (R-022) — ~$60K/yr

Risks Recommended for Acceptance (with justification)

- R-019 Tornado/seismic event at single colocation (BCM provider has 2 alternate sites under contract)

- R-026 IPv6 exhaustion (5-year horizon; no current architecture dependency)

Cmd+Enter to send