You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A risk manager, especially in banking (COBAC, BCEAO) or under DORA, watches indicators: the share of critical patches older than 30 days, the number of privileged accounts without MFA, the availability of critical services. When an indicator crosses the appetite set by the board, they escalate. On 2026-09-25 OpenRisk has no KRI entity (search: grep -rn 'KRI\|KeyRiskIndicator' backend returns nothing). Risk appetite (#319) is not modelled either. The risk register therefore reacts only to manual entries and scanner findings, never to a drifting metric.
Proposed scope (to refine)
A KRI entity (tenant-scoped): name, owner, unit, collection source (manual, API, connector), frequency, thresholds (green, amber, red), and a link to a risk category or to specific risks.
Values are recorded over time. Nothing is overwritten; the history is kept.
Problem
A risk manager, especially in banking (COBAC, BCEAO) or under DORA, watches indicators: the share of critical patches older than 30 days, the number of privileged accounts without MFA, the availability of critical services. When an indicator crosses the appetite set by the board, they escalate. On 2026-09-25 OpenRisk has no KRI entity (search:
grep -rn 'KRI\|KeyRiskIndicator' backendreturns nothing). Risk appetite (#319) is not modelled either. The risk register therefore reacts only to manual entries and scanner findings, never to a drifting metric.Proposed scope (to refine)
Acceptance criteria (draft)
tenant_id, with the three CLAUDE.md rule 4 tests.Definition of Done
A KRI crossing its red threshold produces a draft risk in the validation queue without any manual step.
Depends on: #319 (appetite) · #544 (signal inlet) · #547 (auto-draft). That is why it sits in Release 1.3 — Risk Auto-Draft, after the January launch.