Risk Register
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. The ranked record of security and privacy risks, their treatment, and acceptance decisions.
- Supports prioritisation, quarterly posture review, and questionnaire responses on top-risk exposure.
- Each risk traces to the controls that mitigate it and the findings that evidence it.
How to read
- Severity is derived from likelihood and impact.
- Each risk carries a treatment (mitigate, accept, transfer, or avoid), a named owner, and a review date.
- Risk-acceptance rationales are recorded in the Statement of Applicability.
Register
| ID | Risk | Domain | Likelihood | Impact | Severity | Treatment | Owner | Review |
|---|---|---|---|---|---|---|---|---|
| R-01 | Cross-tenant data access | 7 | — | — | — | Mitigate | — | — |
| R-02 | Tenant financial/PII data exposure to external LLM | 2, 5 | — | — | — | Mitigate | — | — |
| R-03 | Erroneous straight-through posting to customer books | 16, 17 | — | — | — | Mitigate | — | — |
Register to be completed; seed from the top findings, the STP/ICFR exposure, and the AI data-egress boundary.
Source of detail
Treatment work is tracked as GitHub issues, consistent with the Findings Register.
Related
- → Control Register — controls that treat these risks
- → Findings Register — observed instances
- → Standards & Methodology — scope, criticality, methodology
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial structure and seed risks. |
Finaisse Internal — Confidential. Not for external distribution.