Skip to content

feat(risk): Key Risk Indicators with thresholds tied to risk appetite — a breach drafts a risk signal #812

Description

@alex-dembele

Problem

A risk manager, especially in banking (COBAC, BCEAO) or under DORA, watches indicators: the share of critical patches older than 30 days, the number of privileged accounts without MFA, the availability of critical services. When an indicator crosses the appetite set by the board, they escalate. On 2026-09-25 OpenRisk has no KRI entity (search: grep -rn 'KRI\|KeyRiskIndicator' backend returns nothing). Risk appetite (#319) is not modelled either. The risk register therefore reacts only to manual entries and scanner findings, never to a drifting metric.

Proposed scope (to refine)

Acceptance criteria (draft)

  1. CRUD on KRIs and on their values, filtered by tenant_id, with the three CLAUDE.md rule 4 tests.
  2. Crossing a threshold emits exactly one signal per state change, not one per value, and the signal carries its provenance (feat(provenance): every field answers "where did this come from?" #546).
  3. The dashboard shows the status of the KRIs and their trend over the last 12 values.
  4. A KRI fed by the API is proven by an integration test.

Definition of Done

A KRI crossing its red threshold produces a draft risk in the validation queue without any manual step.

Depends on: #319 (appetite) · #544 (signal inlet) · #547 (auto-draft). That is why it sits in Release 1.3 — Risk Auto-Draft, after the January launch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions