Your risk register is the first thing an auditor, a board member, or a plaintiff's counsel will pull apart. And most registers do not survive the second question.
The first question is "what's your top risk?" Any tool answers that. The second question is "why is it scored a 4, who owns it, and which regulation says you have to treat it?" That is where the spreadsheet goes quiet. The number came from a workshop nine months ago. The owner left in Q1. The regulatory link is a memory, not a citation.
Risk you can defend is risk where every score traces down to the obligation behind it and the verbatim regulation behind that. Not a narrative you reconstruct under pressure. A record that was already built that way.
The three-tier model: inherent, effectiveness, residual
A single risk number hides the two decisions that actually matter. Aigis scores every risk across 40+ cyber and privacy domains in three separate tiers, so you can see where the number comes from.
- Inherent risk is the exposure before you do anything about it. It is a function of the asset, the threat, and the domain, independent of your controls. This is the honest starting point most registers skip straight past.
- Control effectiveness is how much your implemented controls actually reduce that exposure, graded on evidence rather than a self-assigned maturity rating.
- Residual exposure is what remains after controls are applied. This is the number your board should be governing, and the number your risk-acceptance decisions attach to.
Keeping the three separate is not academic. When residual exposure moves, you can tell whether the threat got worse (inherent rose) or a control decayed (effectiveness dropped), and those two failures go on different tickets to different people.
This tiering is not our invention imposed on the law. NIS2 Article 21 requires in-scope entities to take measures "appropriate to the risks posed," with proportionality assessed against the entity's degree of exposure, its size, and the likelihood and severity of incidents. That is an inherent-versus-residual judgment written into the statute. Article 21(2)(f) goes further and names "policies and procedures to assess the effectiveness of cybersecurity risk-management measures" as a required measure in its own right. The control-effectiveness tier is not a nice-to-have. For NIS2 entities it is an obligation.
Every risk binds down to source text
Here is the chain that makes the score defensible, and it runs in one direction only:
→ Each risk binds to one or more obligations → Each obligation binds to the regulations that impose it → Each regulation binding carries a verbatim quote from the source legal text, with article-level citation
So when a risk is scored and treated, you are never more than three clicks from the sentence in the law that put it on your register. Open the supply-chain risk and you land on NIS2 Article 21(2)(d), "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers." Open the MFA-related risk and you land on 21(2)(j). The quote is not paraphrased and it is not generated. It was extracted from the parsed regulation and carried through to the binding.
This matters for one reason above all others. Most compliance AI generates a mapping from a model's memory, and a generated citation is exactly the thing that fails an audit. Aigis is built the other way. The engine is AI-built but deterministic: every obligation and every risk traces to verbatim regulation text, grounded in source law rather than a model's recall. When you tell a regulator why a risk exists, you are reading them the statute, not a paraphrase a chatbot produced last Tuesday.
Continuous re-scoring, not a point-in-time snapshot
An annual risk assessment is a photograph of a moving target. By the time it is reviewed, the org has onboarded three vendors, deprecated a system, and answered a follow-up question that changes the picture.
Aigis re-scores continuously. Risk state is composed at read time from the underlying facts across four independent dimensions: scope (is this risk in scope for you), evaluation (what is its current score), decision (has it been accepted or treated), and lifecycle (is it active or retired). Change any input and the affected risks re-materialize. You are not looking at last quarter's spreadsheet. You are looking at the register as it stands right now.
What breaks with point-in-time scoring: the gap between assessments is exactly where incidents live. A supplier's posture degrades in month two of a twelve-month cycle, and your register still shows the month-one score straight through to the next annual review. Continuous re-scoring closes that window. It also means NIS2 Article 21(4), the requirement to take corrective measures "without undue delay" once you find you are non-compliant, has a live signal to act on rather than a yearly discovery event.
Ownership routes by domain, not into one inbox
A risk with no owner is a risk no one is treating. Aigis routes obligations by domain, not into a single "compliance" mailbox. Access-control risks go to the identity owner. Supply-chain risks go to the vendor-management owner. Continuity risks go to the resilience owner. Every threshold breach and every review action is timestamped against the responsible domain.
This maps directly onto how NIS2 assigns accountability. Article 20 requires management bodies to approve the risk-management measures, oversee their implementation, and it makes them liable for the entity's infringements. You cannot govern what you cannot see attributed. Domain routing gives the board a view where each risk has a name against it, which is the precondition for the oversight the law demands.
Evidence-backed treatment
A treatment with no evidence is a claim, and a claim is what you get marked down for. In Aigis, existing evidence in your stack is referenced where it already satisfies a control. New evidence is requested only where the gap is real. The reviewer's job becomes review-and-confirm, not collect-everything, and every mitigation is evidence-backed with an immutable audit trail.
That is the difference between "we have MFA" as an assertion and "here is the enrollment coverage report attached to the control that satisfies Article 21(2)(j)" as a record. One survives the audit. The other invites the follow-up question you do not want.
Board-ready dashboards built from the data, not alongside it
The reason board dashboards and working risk registers disagree is that they are usually two different artifacts, maintained separately, drifting apart between meetings.
Aigis builds the executive view from the same underlying records that drive the working register. Because the dashboard is a query over the traceable data and not a hand-curated slide, it cannot contradict the register. Drill from a board-level heat tile into the residual-exposure number, into the risk, into the obligation, into the source-law quote, without leaving the same data. That is the risk-management view in one continuous line from headline to statute.
Your agents keep it current. The engine keeps it honest.
Here is where the two moves fit together. The determinism above is what makes the next step safe.
Because every risk sits on a source-cited record, you can point your own agents at the platform over MCP or API to do the tedious labor: discovering assets and what connects to what, gathering the evidence that backs a treatment, updating control status, reporting posture. The agent runs inside your perimeter, under your IAM, your logging, your DLP. We never receive a credential, only attested signal. Bring your own agent, Claude Code or any MCP client.
Contrast that with the model where a vendor's agent gets standing access across your stack. That is the exact third-party-agent exposure a 2026 CISO is being told to shut down. Aigis inverts it: your agents do the work, and everything they submit lands on a defensible, source-cited risk record. Automation without exposure.
The result is a risk posture you can defend in front of a regulator, a board, or a plaintiff, because every line of it traces to the law that put it there.
FAQ
How is "traceable" risk different from a risk register with a regulation column? A regulation column is a label someone typed. Traceable risk means the link is a live binding: risk to obligation to regulation to a verbatim quote from the source text with article-level citation. You can click through to the statute, and the score recomputes when the underlying facts change. A typed label does neither.
Does continuous re-scoring mean my numbers change without explanation? No. Because scoring is split into inherent, control effectiveness, and residual exposure, every movement is attributable. You can see whether inherent risk rose (the threat or asset changed) or effectiveness dropped (a control decayed), and the change is timestamped against the domain owner responsible for it.
Where does the regulatory grounding come from, and can it hallucinate a citation? Citations are extracted from the parsed regulation text through a deterministic pipeline, not generated from a model's memory. Every obligation carries the verbatim source quote it was built from. The engine is AI-built but the output is source-grounded, which is the whole point: a generated citation is what fails an audit, so we do not generate them.
Do I have to give a vendor's AI access to my systems to automate this? No, and that is deliberate. You bring your own agent over MCP or API, and it runs inside your own trust boundary under your controls. The platform receives attested signal, never your credentials. Your agents do the work; the engine keeps the record honest.
See your risks mapped to the law
Inside 60 minutes you can see your exposure scored across 40+ domains and mapped to the obligations that actually apply to you, each one traceable to source text. No call required.
Visit agrc.ai to start.


