Risk Assessments

Risks scored on likelihood × impact, prioritised by what actually matters.

ICMS AI runs full risk assessments across every framework in scope, scores each risk on likelihood and impact, and tells you which ones to treat first. The risk register stays live as your posture changes.

risk assessment
likelihood × impact
CatasMajorModMinorInsig
201612842
RareUnlklyPossLikelyCert
Likelihood →
Identified risks
  1. 20R-014Unpatched CVECRITICAL
  2. 16R-007No MFACRITICAL
  3. 12R-022Vendor accessHIGH
  4. 8R-031Backup untestedMEDIUM
  5. 4R-045Weak loggingMEDIUM
  6. 2R-060Phishing overdueLOW
2CRITICAL1HIGH2MEDIUM1LOW

Traditional ICMS is a workflow. ICMS AI is a conversation.

Traditional workflow

You navigate the app.

  • Risk register updated once a year, if at all
  • Scoring driven by whoever shouted loudest in the workshop
  • Treatment plans that nobody tracks
  • No link between a risk and the controls that should mitigate it

ICMS AI · agentic

You just ask.

  • Ask: "Assess information security risks for Site A"
  • The assistant identifies risks, scores L × I, and assigns owners
  • Risks link to the specific clauses and controls that mitigate them
  • The register updates when new NCs, incidents or changes land

How it works.

  1. 01

    Identify risks in context

    The assistant proposes risks based on your industry, size, tech stack, and the frameworks in scope. You confirm, add, or adjust.

  2. 02

    Score likelihood × impact

    Every risk gets a Likelihood (1-5) and Impact (1-5), plotted on a 5×5 matrix. Severity is assigned: Low, Medium, High, Critical.

  3. 03

    Link to controls

    Each risk is linked to the ISO / GDPR / regulatory clauses that mitigate it. Missing controls surface immediately.

  4. 04

    Treat and monitor

    Treatment plans (accept, mitigate, transfer, avoid) route to owners. The register updates as posture changes.

What you get.

Replaces the annual risk workshop with a living register that reflects reality.

  • 5×5 likelihood × impact matrix with severity bands
  • Auto-linking to mitigating controls in your framework
  • Continuous re-scoring as evidence, NCs, and incidents change
  • Prioritised treatment plans routed to owners
  • Sector-specific risk libraries (financial, healthcare, industrial)
  • Chat-first: "Show me the top 3 risks without a control owner"

See it on your standards.

Talk to us about running this on your compliance programme.