Risk Analysis
Compliance tells you whether your controls are in place. Risk analysis tells you which ones matter most. Governy brings the two together: a risk register built on EBIOS-RM, the reference method published by the French national cybersecurity agency (ANSSI), that lives inside the audit and connects directly to the requirements you are already assessing — with no double entry.
Where to find it
Every audit has a Risk assessment entry in its sidebar, alongside Assessment, Evidences, Tasks and the other sections. The audit Overview also shows a Risk exposure card next to the compliance chart, so the state of the risk study is visible from the moment you open the audit.
The register belongs to the workspace, not to a single audit: the same assets, feared events and scenarios are shared by every audit in that workspace, because a client’s risks are the same whether they are being audited against ISO 27001 or NIS2. What differs from one audit to the next is the set of requirements you link those risks to.
The method in brief
EBIOS-RM structures a risk study around a few simple building blocks, and Governy follows the same vocabulary:
| Building block | What it captures | Rated on |
|---|---|---|
| Asset | What you are protecting — a system, a dataset, a process | — |
| Feared event | What you are afraid could happen to that asset | Severity G1 → G4 |
| Risk source | Who or what could cause it | — |
| Risk scenario | How it would unfold, from source to feared event | Likelihood V1 → V4 |
A scenario’s risk level is read from the EBIOS-RM matrix by combining its likelihood with the severity of the feared event it leads to:
| V1 · Unlikely | V2 · Possible | V3 · Likely | V4 · Almost certain | |
|---|---|---|---|---|
| G1 · Minor | Low | Low | Moderate | Moderate |
| G2 · Significant | Low | Moderate | Moderate | High |
| G3 · Serious | Moderate | Moderate | High | Critical |
| G4 · Critical | Moderate | High | Critical | Critical |
Severity dominates: a critical feared event is never Low, however improbable the path to it. Scenarios rated High or Critical are the priority risks — they are what the platform pushes to the top of every list.
Guided setup
The first time you open the risk assessment of an audit, Governy offers a guided setup that walks through the EBIOS-RM workshops one step at a time. Everything you enter is saved immediately, and you can leave and come back whenever you like — the overview shows a Finish your guided setup prompt until it is complete.
- Workshop 1 — Scope & feared events What outcomes are you afraid of, and to what? Add feared events one at a time, attach each to an asset, and rate how severe it would be if it happened.
- Workshops 2–4 — Build the risk scenarios For each feared event, who or what could cause it, and how would it unfold? Pick a risk source from the catalogue (or add a new one), describe the scenario and rate its likelihood. A live preview shows the resulting risk level as you type.
- Workshop 5 — Treatment Scenarios are listed worst-first. Link each one to the requirements of the audit that mitigate it, starting with those rated High or Critical.
- Summary A recap of the feared events, scenarios and priority risks treated, with a shortcut to the full risk register.
The guided setup deliberately keeps things simple: workshops 2 to 4 are collapsed into a single scenario record, and the finer-grained source/objective pairing of the full method is not modelled.
The risk workspace
Once the register exists, the risk assessment page is organised in four tabs. Each is linkable, so a colleague can be sent straight to the view you are looking at.
| Tab | What it shows |
|---|---|
| Overview | Key figures, the risk matrix, the distribution of scenarios by level, the risk exposure verdict and the status of the link with the self-assessment |
| Register | Every scenario, as a list or a table, with search, filters and a detail panel for editing |
| Impact | A flow diagram reading left to right: which requirements treat which scenarios, what they would cause, and which assets that harms |
| Treatment | The queue of scenarios that still need requirements linked, worst risk first |
Overview
The overview answers one question at a glance: how exposed are we, and what should we do first?
- Priority risks treated — how many High and Critical scenarios already have at least one requirement linked
- Risk matrix — every scenario placed on the severity × likelihood grid; click a cell to filter the register to just those scenarios
- Scenarios by risk level — the distribution across Low, Moderate, High and Critical; when residual risk is enabled, inherent and residual are shown side by side
- Risk exposure — a plain-language verdict (Contained, Needs attention, Significant exposure) based on how many priority risks are not adequately covered
- Needs your attention — the untreated scenarios, worst first, with a link to the treatment queue
Register
The register is the working view. Scenarios can be browsed as cards or as a sortable table, searched by name, asset or source, and filtered by level or by treatment status. Selecting a scenario opens a docked detail panel where you can edit it, link or unlink requirements and — when residual risk is enabled — read a step-by-step explanation of how the linked controls change its level.
Impact
The From control to impact diagram lays the whole study out as a flow in four columns: requirements → scenarios → feared events → assets. It is deliberately not a tree: a single requirement often protects several scenarios, and the diagram shows that. A side panel lists these load-bearing controls — the requirements several risks depend on at once — which are usually the most valuable ones to get right.
Click any box to trace just its chain, upstream and downstream. Dashed edges mark scenarios with no control linked on one side, and a toggle switches the diagram between inherent and residual view.
Treatment
The treatment queue lists every scenario that still has no requirement linked, ordered by inherent risk so the most serious gap is always at the top. From here, linking a requirement is a single action. Each link can optionally record a contribution — how much of the scenario’s protection rests on that particular requirement — for the cases where one control is load-bearing and another is incidental.
Linking risk and compliance
This is what sets the module apart: risk and compliance are not two separate registers that happen to live in the same tool. Once scenarios are linked to requirements, each side can inform the other — in two independent, opt-in directions.
Both are configured in the audit Settings, under Link with the self-assessment, and both are off by default. Turning either one on changes nothing until at least one scenario is linked to a requirement, and both apply across all the audits of the workspace.
Risk → Assessment: let risk weight the compliance rate
A requirement that keeps a High or Critical risk under control counts for more than a purely administrative one. When this direction is enabled, Governy computes a risk-weighted compliance rate in which each requirement is weighted by the worst risk it treats. A requirement no scenario relies on keeps a weight of 1 — so without a risk study, the weighted rate and the plain rate are identical.
Two weighting curves are available:
| Curve | Weight of a requirement |
|---|---|
| Linear (default) | Equal to the worst risk level it treats — a control backing a Critical scenario counts four times a control backing a Low one |
| Priority only | 2 when it backs a High or Critical scenario, 1 otherwise — a gentler curve for teams that find linear too aggressive |
The overview includes a score explainer that decomposes the difference between the assessment page’s figure and the weighted one step by step, so the number is never a surprise.
Assessment → Risk: let assessment results lower risk
Read the other way, the same links let your compliance results reduce your risks. When this direction is enabled, every scenario with linked requirements shows a residual risk level beside its inherent one.
The rule is deliberately conservative:
- Governy looks at how well the linked requirements are doing on average — one perfect control does not cancel out three missing ones.
- When that average reaches 50 %, the scenario’s likelihood drops by one level. It never drops by more: a critical risk can never be reported as negligible just because every box has been ticked.
- Controls change how likely a feared event is, never how bad it would be — severity stays untouched.
Because adjacent cells of the matrix often carry the same value, a likelihood that genuinely dropped one level will sometimes leave the displayed risk level unchanged. Governy shows both numbers so the effect of the treatment is visible either way.
Rather than a percentage that suggests more precision than a handful of verdicts can carry, the effectiveness of the linked controls is shown as a word — No effect, Low, Moderate, High or Very high — with High meaning precisely “this treatment moved the risk”.
A worked example
Take one scenario — an attacker guesses a weak password and reads customer data — rated G3 (Serious) and V3 (Likely): High risk. It is linked to two requirements: enforce password strength (non-compliant) and access-control policy (compliant). The audit has two more requirements, both linked to nothing, one compliant and one partially compliant.
| Before linking | After linking | |
|---|---|---|
| Compliance rate | 62.5 % | 56.25 % — the one failing requirement guards a High risk, so it now counts three times |
| This risk | High | Moderate — the linked controls average 50 %, enough to lower the likelihood one level |
Both figures moved from the same two links, computed independently. Fix the password control and the weighted compliance rate jumps to 93.75 % — but the risk stays Moderate, because one level is the most a treatment can buy.
Who can do what
The risk module follows the audit’s roles exactly. Anyone who can read the audit can read its risk study; building the register, linking requirements and changing the coupling settings require write access, as described on the Security page. Every derived figure — risk levels, residual levels, weights — is computed live from the current assessment, so the risk study can never disagree with the audit it sits in.