P05 / Technology risk / Independent work sample
Executive risk.
Risk registers need to support decisions, not just record concerns.
The decision
behind the work.
Convert traceable assurance signals into appetite breaches, KRI trends, treatment decisions, and board-ready accountability.
Methodology and scope are defined in the project manifest. Listed capabilities describe the module design; source files show the implemented subset.
Assessment approach
- Risk aggregation
- Appetite and tolerance tests
- KRI trend and velocity
- Scenario analysis
- Decision and acceptance log
- Drill-down to evidence
Evidence
to request.
Start with source records, owner confirmation, scope and observation dates. A completed template alone does not establish operating effectiveness.
Defined output contract
- board-risk-pack.json
- kri-series.json
- appetite-breaches.json
- decision-log.json
The manifest defines these expected artifacts; confirm their existence and completion in source before relying on an output.
Read the full manifest ↗Review & decision boundaries
- No fake precision in risk scoring
- Every metric links to a source and definition
- Board decisions remain human-owned
Remediation sequence
Record each finding with its evidence reference, risk rationale, accountable owner, target date and closure test. Escalate missing evidence rather than treating it as a pass.
Present management with the supported conclusion, remaining uncertainty and a specific decision request.