Risk Chain Intelligence
Mission
Expose how one signal can propagate through enterprise dependencies and become a business, board, customer, audit or security event.
Inputs
Accept risk registers, project dependencies, architecture context, security findings, operational metrics, vendor risks, budget notes, compliance findings and incident history.
Workflow
- Start from the truth-layer handoff. Keep facts, assumptions and hypotheses separate.
- Extract risk nodes, affected assets, triggers, dependencies and controls.
- Map propagation paths across project, architecture, security, compliance, finance, vendor, operations and organization domains.
- Identify amplifiers such as weak ownership, missing controls, shared resources, vendor lock-in, scarce skills and technical debt.
- Rank chains by likelihood, impact, velocity, detectability and containment readiness.
- Translate each chain into business exposure: cost, customer trust, audit/control, security, resilience, delivery or reputation.
- Define scenario kill-switches where the chain should trigger pause, escalation, deferral or risk acceptance.
Chain Shape
Use this structure:
Signal -> Dependency -> Amplifier -> Business Impact -> Decision Pressure -> Control / Evidence Gate
Output Format
- Executive Summary
- Risk Chain Map
- Critical Propagation Paths
- Amplifiers
- Trigger Points
- Risk-to-Cash Translation
- Containment Actions
- Escalation Rules
- Scenario Kill-Switch
- Evidence & Assumptions
- Missing Data
Guardrails
Use scenario language when propagation is inferred. Do not present hypothetical chains as confirmed events.
1---2name: risk-chain-intelligence3description: Map cascading risk paths across projects, systems, data, security, compliance, operations, vendors, finance and organization. Use when isolated risk registers are insufficient.4---56# Risk Chain Intelligence78## Mission910Expose how one signal can propagate through enterprise dependencies and become a business, board, customer, audit or security event.1112## Inputs1314Accept risk registers, project dependencies, architecture context, security findings, operational metrics, vendor risks, budget notes, compliance findings and incident history.1516## Workflow17181. Start from the truth-layer handoff. Keep facts, assumptions and hypotheses separate.192. Extract risk nodes, affected assets, triggers, dependencies and controls.203. Map propagation paths across project, architecture, security, compliance, finance, vendor, operations and organization domains.214. Identify amplifiers such as weak ownership, missing controls, shared resources, vendor lock-in, scarce skills and technical debt.225. Rank chains by likelihood, impact, velocity, detectability and containment readiness.236. Translate each chain into business exposure: cost, customer trust, audit/control, security, resilience, delivery or reputation.247. Define scenario kill-switches where the chain should trigger pause, escalation, deferral or risk acceptance.2526## Chain Shape2728Use this structure:2930`Signal -> Dependency -> Amplifier -> Business Impact -> Decision Pressure -> Control / Evidence Gate`3132## Output Format3334- Executive Summary35- Risk Chain Map36- Critical Propagation Paths37- Amplifiers38- Trigger Points39- Risk-to-Cash Translation40- Containment Actions41- Escalation Rules42- Scenario Kill-Switch43- Evidence & Assumptions44- Missing Data4546## Guardrails4748Use scenario language when propagation is inferred. Do not present hypothetical chains as confirmed events.