The KRI Framework gives every key risk indicator green/amber/red thresholds and trend lines, fed by live telemetry — so a breach can auto-create a risk, escalate to the risk function, and notify owners, all inside an eight-state ERM engine.
Each KRI carries configurable thresholds with a clear status band, so risk posture is legible at a glance rather than buried in a spreadsheet.
KRIs are tracked over time, so you see whether a risk indicator is improving or deteriorating — not just today's value.
A KRI breach can auto-create a risk, escalate to the risk function, and notify owners — the indicator drives action, not just a dashboard colour.
Inherent scores update from LiveThreat's daily intelligence refresh, so KRIs move with reality instead of waiting for a manual reassessment cycle.
Risks move Identified → Assessed → Treated → Accepted / Mitigated / Transferred / Avoided → Closed / Re-Opened, with the full history retained.
A configurable probability × impact matrix captures inherent score at identification and updates residual score as treatment progresses.
A tenant-configurable appetite statement per category means acceptances that exceed appetite require elevated approval — governance built in.
Operational owners, the risk function and internal audit each get scoped permissions, enforcing the model rather than just describing it.
The KRI Framework is part of the RiskOps Hub — where assessment findings, breach alerts, CVE matches, control deficiencies and privacy gaps all converge into one register.