OntoRisk publishes practitioner-grade analysis across enterprise, cyber, financial, and robotic risk — every article grounded in named standards, written for CROs, risk owners, and the people who have to make the framework actually work.
Most risk functions run on spreadsheets: a register here, a KRI library there, a controls inventory somewhere else — three copies of the truth, none of them talking to each other. OntoRisk exists to make the case, article by article, for a different foundation: a shared risk taxonomy that the register, the controls, and the obligations all reference.
Risk appetite statements, decision rights, and board reporting that actually shape what gets approved.
Knowledge graphs and ontologies that let risks, controls, and obligations aggregate instead of duplicate.
ISO 31000, COSO ERM, NIST CSF 2.0, Basel 3.1, DORA, ISO 10218 — cited by name, applied in practice.
"A risk you can't query, you can't aggregate. A risk you can't aggregate, the board can't see coming."— OntoRisk Editorial
From board-level appetite to the shop floor — we cover every layer where risk actually lives.
COSO ERM, ISO 31000, risk appetite, KRIs, and the three lines model — turned into an operating model.
Read articlesNIST CSF 2.0, FAIR quantification, DORA, and third-party cyber risk after Log4j and SolarWinds.
Read articlesOWL, SKOS, and SPARQL applied to risk taxonomies, controls, and obligations — from spreadsheets to knowledge graphs.
Read articlesFRTB, IFRS 9, Basel 3.1, IRRBB, and model risk management under SR 11-7 and SS1/23.
Read articlesISO 10218, ISO/TS 15066, functional safety, and the EU Machinery Regulation for robot integrators.
Read articlesEvery pillar, newest first — the full archive of practitioner-grade risk analysis.
Go to blogNeither is a strawman — most organizations run both today. The difference shows up the moment you need to aggregate.
New analysis published weekly, rotating across all five pillars.
Overview: The revised NIST Cybersecurity Framework (CSF) version 2.0 introduces significant updates to the Govern function, affecting CROs, risk managers, internal auditors, and co…
Risk management, traditionally anchored on spreadsheet models and siloed data, is evolving towards a more integrated, interconnected, and intelligent approach through Ontology & Se…
In the ever-evolving landscape of financial risk management, the FRTB (Finalized Basel 3.1) is a significant development aimed at strengthening banks' capital requirements for mark…
Follow OntoRisk for weekly, standards-grounded analysis across every risk pillar.