Appearance
Acting on Quantified Risk
Quantification gives each risk threat a monetary expected loss. This page covers what you do with that number in Modulos: compare it against limits, prioritize across the portfolio, implement mitigations through Controls and Evidence, and re-quantify to measure their effect.
Baseline expected loss
€ 2.4M
Quantified before mitigation work
Updated expected loss€ 900K
Re-quantified after Controls are in place
Where in Modulos
- use
Project → Risksto compare quantified exposure against risk and project limits - use
Organization → Risk Management → Risk Overviewfor portfolio rollups and top risk drivers - implement mitigations as Controls under
Project → Controlsand attach Evidence to those Controls - re-run quantification from
Project → Risks → select a risk threat → Quantifyafter the system or its environment changes
For the end-to-end operating model, see Operating Model.
Permissions
- Project Owner manages project risks and starts quantification runs.
- Project Editor creates and updates project risks and threat selections.
- Project Viewer is read-only for oversight and audit.
- Organization Risk Manager configures taxonomy, appetite, and limits.
Compare exposure against limits
Risk limits turn appetite into budgets: a total monetary appetite at the organization level, percentage shares per category, and limits per project and per risk. After quantification, each level shows its quantified value against its limit:
Project → Risksshows each risk's value against its limit and the project total against the project limitOrganization → Risk Management → Risk Overviewshows total exposure against organization appetite and per-category utilization
A quantified value approaching or exceeding its limit is the signal to review assumptions, invest in mitigation, or escalate the decision to whoever owns that budget.
Prioritize across the portfolio
The portfolio overview shows which categories are consuming their share of appetite, the highest-value risks per category, and the projects driving the most exposure. Start mitigation work on the highest expected-loss threats.
Implement mitigations as Controls
Modulos does not link risks to Controls directly. Mitigation work lives in the governance workflow, and the risk register measures its effect through re-quantification:
1
Quantify the baseline
Produce a monetary value with explicit assumptions
2
Implement mitigations as Controls
Capture the work under Project → Controls and attach Evidence
3
Re-quantify
Re-run quantification on the affected risk threats
4
Compare against limits
Check the new value against risk and project limits
Mitigations usually target the rate (prevention, detection, access control, guardrails) or the damage (containment, human oversight, incident response, rollback). The rate × damage decomposition tells you which lever a mitigation pulls; re-quantification tells you whether it worked.
Quantification also makes mitigation spending a concrete question: “If we spend €X, how much expected loss do we reduce?” Quantify before the investment, re-quantify after, and the difference is the measured impact.
Re-quantify after changes
Each risk threat keeps its full quantification history; only the latest run with status quantified contributes to rollups. Re-run quantification when:
- mitigation Controls are implemented or retired
- the system, model, or a vendor changes
- usage grows or the deployment context shifts
- an incident or test result challenges your assumptions
The History tab and the Value Over Time views at the risk and threat level show how expected loss develops across runs. See Reviewing past runs and trends.