GovernRisk quantificationx, accounted for
AI risk in money, in a register that fills itself.
A risk register written by your own gaps, audits, scans and proven attacks, quantified with FAIR as an annual loss range.
FAIR · after treatment: an illustrative loss distribution with its range shaded, the likely loss marked and the your appetite as a dashed line; after treatment, the curve moves left.
In short
Risk quantification in ColossalX puts AI risk in money. The risk register fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions, de-duplicated and closed when the source closes. A FAIR analysis on any entry gives an annual loss range with a one-in-twenty-year tail, held against your risk appetite.
A risk register kept by hand misses the attack your own team proved last week.
ColossalX writes that proven attack into the register itself, and FAIR puts a loss range on it.
How it works
From a compliance gap to a loss range in money.
An unmet AI-governance control writes its own register entry. An analyst estimates it, FAIR simulates the loss, and the appetite decides who signs.
01 Entry written
An unmet AI-governance control writes a register entry with its source.
02 Ranges estimated
An analyst enters low, likely and high for frequency and loss.
03 Loss simulated
The analysis returns a range and a one-in-twenty-year tail.
04 Board decides
Accepting it beyond appetite needs a board minute and an end date.
What you see
A range and a tail, not a colour.
The annual loss expectancy for one AI-governance gap, with low, median and high percentiles, the one-in-twenty-year loss and the expected loss beyond it.
- The register fills itselfGaps, audit findings, scans, proven attacks and intel decisions write entries.
- Estimate the rangesEnter minimum, most likely and maximum for frequency and loss size.
- Simulate the lossThe annual loss expectancy, its percentiles and a one-in-twenty-year loss.
- Hold to appetiteAcceptances need a reason and an end date; beyond appetite, the board.
Read the detail, step by step4
- The register fills itself. Entries are de-duplicated by source and close when their source closes: a compliance gap when it is met, a code finding when a rescan shows it fixed, a proven attack when a control stops it or clean re-tests follow. Impact is raised for critical assets, never lowered.
- Estimate the ranges. Run FAIR from any register row. The figures are yours: no workspace is seeded with estimates, and an older analysis without percentiles says so and offers a re-run instead of showing a loss of zero.
- Simulate the loss. The loss is simulated as part of each analysis and reported as annual loss expectancy, with low, median and high percentiles, the loss exceeded one year in twenty, and the average loss in the years beyond it.
- Hold to appetite. A lapsed acceptance goes back to analysis on its own. Treatment plans track what is being done. The register syncs out to GRC, ticketing and SIEM tools, signed and outbound only, so nothing outside can alter it.

3notes
- Expected annual loss
- Range, not a point
- Tail beyond one-in-twenty
How it connectsx, accounted for
Where a quantified risk goes next.
A risk in money is read by the people and tools that act on it.
Your GRC tools
The register syncs out by signed webhook or ticket, outbound only, with each delivery replayable.
The risk pillar of the trust score reads this register and its review discipline.
Acceptances expire within a year and lapse back into open work on their end date.
Vendor inventory
AI vendors in use but never assessed are flagged from the gateway and app catalogue.
Honest by design
What it does, and what it does not.
Risk acceptance · must expire: Risk Tool misuse on research-agent; Reason Required and kept; Review by Within a year; Beyond appetite Board minute required; On expiry Back to analysis. Accepted, not forgotten.
What it does not do
x, not measured
Loss figures are in US dollars, and the analysis form has no currency picker yet.
All 4 limits
- FAIR is only as good as the ranges your analysts enter; nothing is estimated for you.
- The register is outbound only: changes made in your GRC tool do not flow back.
- Vendor questionnaires are not sent from ColossalX; the vendor register is a record.
How we know
- No workspace is seeded with loss estimates; the figures come from your analysts.
- An analysis without percentiles says so and offers a re-run, never a loss of zero.
- Criticality can raise a risk's impact, never lower it, so an unrated asset is not downgraded.
- Archiving a risk needs a reason; it is flagged and kept, never deleted.
Questions
Questions buyers ask
What is AI risk quantification?
AI risk quantification expresses the risk an AI system carries in money rather than colours: how often a loss event might happen and how much it might cost, as a range. ColossalX does it with FAIR on entries in its risk register, giving an annual loss expectancy, a range and a one-in-twenty-year loss a board can plan against.
What is FAIR, and how does it apply to AI risk?
FAIR, Factor Analysis of Information Risk, models risk from loss event frequency and loss magnitude, each estimated as a range. For AI, an event might be a proven tool-misuse path on a production agent. ColossalX simulates the loss from your ranges and reports percentiles, the one-in-twenty-year loss and the expected loss beyond it.
What is an AI risk register?
An AI risk register is the list of risks an organisation carries from its use of AI, each with an owner, a rating, a treatment and a review date. In ColossalX it fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions, and syncs out to the GRC tools you already run.
How does the register fill itself and stay de-duplicated?
Other parts of ColossalX publish what they find, and each finding writes or updates one entry keyed to its source, so a repeat sighting refreshes the entry instead of adding a new one. Entries close when the source closes: a gap when it is met, a finding when a rescan shows it fixed.
What happens to a risk acceptance beyond appetite?
It goes to the board. An acceptance needs a reason and an end date no more than a year away, and one that exceeds your risk appetite waits for a board or audit-committee minute. When an acceptance lapses, the risk returns to analysis on its own and the work reopens.
Related
Where to look next.
-
ColossalX Trust Engine
A trust score that explains itself
-
Compliance and AI governance
Mapped frameworks, policies and evidence
-
Exposure management
Exposures ranked by validated reachability
Next step
Account for your x.
See your own top AI risks as loss ranges, with the tail your board will ask about.
- 01Tell us what you run
- 02See the four verbs on it
- 03Decide where to start