Skip to content

Acting on Quantified Risk

Quantification gives each risk threat a monetary expected loss. This page covers what you do with that number in Modulos: compare it against limits, prioritize across the portfolio, implement mitigations through Controls and Evidence, and re-quantify to measure their effect.

Where in Modulos

  • use Project → Risks to compare quantified exposure against risk and project limits
  • use Organization → Risk Management → Risk Overview for portfolio rollups and top risk drivers
  • implement mitigations as Controls under Project → Controls and attach Evidence to those Controls
  • re-run quantification from Project → Risks → select a risk threat → Quantify after the system or its environment changes

For the end-to-end operating model, see Operating Model.

Permissions

  • Project Owner manages project risks and starts quantification runs.
  • Project Editor creates and updates project risks and threat selections.
  • Project Viewer is read-only for oversight and audit.
  • Organization Risk Manager configures taxonomy, appetite, and limits.

Compare exposure against limits

Risk limits turn appetite into budgets: a total monetary appetite at the organization level, percentage shares per category, and limits per project and per risk. After quantification, each level shows its quantified value against its limit:

  • Project → Risks shows each risk's value against its limit and the project total against the project limit
  • Organization → Risk Management → Risk Overview shows total exposure against organization appetite and per-category utilization

A quantified value approaching or exceeding its limit is the signal to review assumptions, invest in mitigation, or escalate the decision to whoever owns that budget.

Prioritize across the portfolio

The portfolio overview shows which categories are consuming their share of appetite, the highest-value risks per category, and the projects driving the most exposure. Start mitigation work on the highest expected-loss threats.

Implement mitigations as Controls

Modulos does not link risks to Controls directly. Mitigation work lives in the governance workflow, and the risk register measures its effect through re-quantification:

Mitigations usually target the rate (prevention, detection, access control, guardrails) or the damage (containment, human oversight, incident response, rollback). The rate × damage decomposition tells you which lever a mitigation pulls; re-quantification tells you whether it worked.

Quantification also makes mitigation spending a concrete question: “If we spend €X, how much expected loss do we reduce?” Quantify before the investment, re-quantify after, and the difference is the measured impact.

Re-quantify after changes

Each risk threat keeps its full quantification history; only the latest run with status quantified contributes to rollups. Re-run quantification when:

  • mitigation Controls are implemented or retired
  • the system, model, or a vendor changes
  • usage grows or the deployment context shifts
  • an incident or test result challenges your assumptions

The History tab and the Value Over Time views at the risk and threat level show how expected loss develops across runs. See Reviewing past runs and trends.