Risk, modeled not just tracked

Risk management, built on an ontology, not a spreadsheet.

OntoRisk publishes practitioner-grade analysis across enterprise, cyber, financial, and robotic risk — every article grounded in named standards, written for CROs, risk owners, and the people who have to make the framework actually work.

ISO 31000
Risk management principles & guidelines we build on
COSO ERM
2017 framework mapped to a working operating model
5
Risk pillars covered end-to-end
Weekly
New practitioner-grade articles, no filler
Why OntoRisk

Risk registers describe risk. Ontologies connect it.

Most risk functions run on spreadsheets: a register here, a KRI library there, a controls inventory somewhere else — three copies of the truth, none of them talking to each other. OntoRisk exists to make the case, article by article, for a different foundation: a shared risk taxonomy that the register, the controls, and the obligations all reference.

🧭

Governance that changes decisions

Risk appetite statements, decision rights, and board reporting that actually shape what gets approved.

🕸️

A shared semantic layer

Knowledge graphs and ontologies that let risks, controls, and obligations aggregate instead of duplicate.

🛡️

Named standards, not vague advice

ISO 31000, COSO ERM, NIST CSF 2.0, Basel 3.1, DORA, ISO 10218 — cited by name, applied in practice.

"A risk you can't query, you can't aggregate. A risk you can't aggregate, the board can't see coming."
— OntoRisk Editorial
5
Integrated risk pillars, one taxonomy
900+
Words of substance per article, no padding
3–5
Named standards cited per deep dive
0
Marketing filler tolerated
Coverage

Five pillars, one risk taxonomy

From board-level appetite to the shop floor — we cover every layer where risk actually lives.

Two ways to manage risk

Ontology-driven vs. spreadsheet-driven

Neither is a strawman — most organizations run both today. The difference shows up the moment you need to aggregate.

🕸️ Ontology-Driven

  • One controlled taxonomy referenced by the register, KRI library, controls, and obligations
  • SPARQL queries answer "what is our aggregate exposure to X?" in one pass
  • New risks inherit relationships automatically — no manual re-mapping
  • Machine-readable enough for AI-assisted risk analytics
  • Group-wide aggregation across business units without a re-key project

📋 Spreadsheet-Driven

  • Register, KRI list, and controls inventory live as separate files
  • Aggregation means someone manually reconciling three copies of the truth
  • New risk types require a new tab, a new format, a new mapping exercise
  • Version drift: the "current" register depends on who last emailed it
  • Board reporting is assured once a quarter, not queried on demand
Read the Ontology & Semantic Risk pillar
Blog

Latest articles

New analysis published weekly, rotating across all five pillars.

All articles →

Stop assuring the framework. Start using it.

Follow OntoRisk for weekly, standards-grounded analysis across every risk pillar.