| name | risk-chain-intelligence |
| description | Map cascading risk paths across projects, systems, data, security, compliance, operations, vendors, finance and organization. Use when isolated risk registers are insufficient. |
Risk Chain Intelligence
Mission
Expose how one signal can propagate through enterprise dependencies and become a business, board, customer, audit or security event.
Inputs
Accept risk registers, project dependencies, architecture context, security findings, operational metrics, vendor risks, budget notes, compliance findings and incident history.
Workflow
- Start from the truth-layer handoff. Keep facts, assumptions and hypotheses separate.
- Extract risk nodes, affected assets, triggers, dependencies and controls.
- Map propagation paths across project, architecture, security, compliance, finance, vendor, operations and organization domains.
- Identify amplifiers such as weak ownership, missing controls, shared resources, vendor lock-in, scarce skills and technical debt.
- Rank chains by likelihood, impact, velocity, detectability and containment readiness.
- Translate each chain into business exposure: cost, customer trust, audit/control, security, resilience, delivery or reputation.
- Define scenario kill-switches where the chain should trigger pause, escalation, deferral or risk acceptance.
Chain Shape
Use this structure:
Signal -> Dependency -> Amplifier -> Business Impact -> Decision Pressure -> Control / Evidence Gate
Output Format
- Executive Summary
- Risk Chain Map
- Critical Propagation Paths
- Amplifiers
- Trigger Points
- Risk-to-Cash Translation
- Containment Actions
- Escalation Rules
- Scenario Kill-Switch
- Evidence & Assumptions
- Missing Data
Guardrails
Use scenario language when propagation is inferred. Do not present hypothetical chains as confirmed events.