Skip to content
Last updated: Sep 25, 2026

Risk Register ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. The ranked record of security and privacy risks, their treatment, and acceptance decisions.

  • Supports prioritisation, quarterly posture review, and questionnaire responses on top-risk exposure.
  • Each risk traces to the controls that mitigate it and the findings that evidence it.

How to read ​

  • Severity is derived from likelihood and impact.
  • Each risk carries a treatment (mitigate, accept, transfer, or avoid), a named owner, and a review date.
  • Risk-acceptance rationales are recorded in the Statement of Applicability.

Register ​

IDRiskDomainLikelihoodImpactSeverityTreatmentOwnerReview
R-01Cross-tenant data access7———Mitigate——
R-02Tenant financial/PII data exposure to external LLM2, 5———Mitigate——
R-03Erroneous straight-through posting to customer books16, 17———Mitigate——

Register to be completed; seed from the top findings, the STP/ICFR exposure, and the AI data-egress boundary.

Source of detail ​

Treatment work is tracked as GitHub issues, consistent with the Findings Register.

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial structure and seed risks.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.