risk-register
Installation
SKILL.md
Risk Register
Disclaimer: risk management is a management responsibility. This skill helps with methodology and documentation; risk appetite, acceptance decisions, and treatment choices require ownership at the management body.
When to use
This skill is methodological, not framework-specific. It is invoked from nearly every other GRC skill — iso27001 (Cl 6.1), soc2 (CC3 Risk Assessment), nis2 (Art 21 first measure), dora (Art 5-14), gdpr-pia (Art 35 via the risk-analysis phase). Also stand-alone applicable for generic business risk management.
Triggers on:
- A question like "how do we do risk scoring", "which methodology for risk assessment", "build a heatmap", "what is risk appetite", "FAIR vs ISO 27005", "when do we accept a risk".
- A handoff from compliance skills when a risk assessment is needed.
- A periodic (quarterly/yearly) risk review.
- A new product/service/project that has a risk assessment as a precondition.
- An incident where the likelihood/impact estimate turned out skewed in hindsight — revision trajectory.