# AI risk in money, in a register that fills itself.

> Risk quantification in ColossalX puts AI risk in money. The risk register fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions, de-duplicated and closed when the source closes. A FAIR analysis on any entry gives an annual loss range with a one-in-twenty-year tail, held against your risk appetite.

A risk register written by your own gaps, audits, scans and proven attacks, quantified with FAIR as an annual loss range.

Canonical page: https://colossalx.tech/platform/risk-quantification · Last reviewed: 6 Oct 2026

*Illustration:* FAIR · after treatment: an illustrative loss distribution with its range shaded, the likely loss marked and the your appetite as a dashed line; after treatment, the curve moves left.

## The threat and the control

- **The threat:** A risk register kept by hand misses the attack your own team proved last week.
- **The control:** ColossalX writes that proven attack into the register itself, and FAIR puts a loss range on it.

## How it works: From a compliance gap to a loss range in money.

An unmet AI-governance control writes its own register entry. An analyst estimates it, FAIR simulates the loss, and the appetite decides who signs.

### Workflow: a governance gap, quantified (illustrative)

1. **Entry written.** An unmet AI-governance control writes a register entry with its source.
   Source: AI-governance gap · drift detection; Owner: AI governance; Status: open, de-duplicated
2. **Ranges estimated.** An analyst enters low, likely and high for frequency and loss.
   Frequency: 1 to 4 a year; Loss size: $1K to $20K a time
3. **Loss simulated.** The analysis returns a range and a one-in-twenty-year tail.
   Likely: $12K a year; 1 in 20 years: $29K; Beyond that: $34K on average | Above appetite
4. **Board decides.** Accepting it beyond appetite needs a board minute and an end date.
   Audit committee: Accepted, minute recorded, review in a year | Lapses back to analysis | x, accounted for

## What you see: A range and a tail, not a colour.

The annual loss expectancy for one AI-governance gap, with low, median and high percentiles, the one-in-twenty-year loss and the expected loss beyond it.

1. **The register fills itself.** Gaps, audit findings, scans, proven attacks and intel decisions write entries. Entries are de-duplicated by source and close when their source closes: a compliance gap when it is met, a code finding when a rescan shows it fixed, a proven attack when a control stops it or clean re-tests follow. Impact is raised for critical assets, never lowered.
2. **Estimate the ranges.** Enter minimum, most likely and maximum for frequency and loss size. Run FAIR from any register row. The figures are yours: no workspace is seeded with estimates, and an older analysis without percentiles says so and offers a re-run instead of showing a loss of zero.
3. **Simulate the loss.** The annual loss expectancy, its percentiles and a one-in-twenty-year loss. The loss is simulated as part of each analysis and reported as annual loss expectancy, with low, median and high percentiles, the loss exceeded one year in twenty, and the average loss in the years beyond it.
4. **Hold to appetite.** Acceptances need a reason and an end date; beyond appetite, the board. A lapsed acceptance goes back to analysis on its own. Treatment plans track what is being done. The register syncs out to GRC, ticketing and SIEM tools, signed and outbound only, so nothing outside can alter it.

*Screen, from a demo workspace:* A FAIR analysis in a demo workspace for one AI-governance gap: the annualised loss expectancy, low, median and high percentiles, the one-in-twenty-year loss and the expected loss beyond it. Callouts: 1. Expected annual loss 2. Range, not a point 3. Tail beyond one-in-twenty

## How we know

- No workspace is seeded with loss estimates; the figures come from your analysts.
- An analysis without percentiles says so and offers a re-run, never a loss of zero.
- Criticality can raise a risk's impact, never lower it, so an unrated asset is not downgraded.
- Archiving a risk needs a reason; it is flagged and kept, never deleted.

## Where a quantified risk goes next.

A risk in money is read by the people and tools that act on it.

- **Your GRC tools.** The register syncs out by signed webhook or ticket, outbound only, with each delivery replayable.
- **The trust score.** The risk pillar of the trust score reads this register and its review discipline.
- **Risk acceptances.** Acceptances expire within a year and lapse back into open work on their end date.
- **Vendor inventory.** AI vendors in use but never assessed are flagged from the gateway and app catalogue.

Where an x ends up: x, accounted for.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to NIST AI RMF: AI risks measured and tracked to treatment.

## What it does not do

- Loss figures are in US dollars, and the analysis form has no currency picker yet.
- FAIR is only as good as the ranges your analysts enter; nothing is estimated for you.
- The register is outbound only: changes made in your GRC tool do not flow back.
- Vendor questionnaires are not sent from ColossalX; the vendor register is a record.

*Illustration:* Risk acceptance · must expire: Risk Tool misuse on research-agent; Reason Required and kept; Review by Within a year; Beyond appetite Board minute required; On expiry Back to analysis. Accepted, not forgotten.

## Questions

### What is AI risk quantification?

AI risk quantification expresses the risk an AI system carries in money rather than colours: how often a loss event might happen and how much it might cost, as a range. ColossalX does it with FAIR on entries in its risk register, giving an annual loss expectancy, a range and a one-in-twenty-year loss a board can plan against.

### What is FAIR, and how does it apply to AI risk?

FAIR, Factor Analysis of Information Risk, models risk from loss event frequency and loss magnitude, each estimated as a range. For AI, an event might be a proven tool-misuse path on a production agent. ColossalX simulates the loss from your ranges and reports percentiles, the one-in-twenty-year loss and the expected loss beyond it.

### What is an AI risk register?

An AI risk register is the list of risks an organisation carries from its use of AI, each with an owner, a rating, a treatment and a review date. In ColossalX it fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions, and syncs out to the GRC tools you already run.

### How does the register fill itself and stay de-duplicated?

Other parts of ColossalX publish what they find, and each finding writes or updates one entry keyed to its source, so a repeat sighting refreshes the entry instead of adding a new one. Entries close when the source closes: a gap when it is met, a finding when a rescan shows it fixed.

### What happens to a risk acceptance beyond appetite?

It goes to the board. An acceptance needs a reason and an end date no more than a year away, and one that exceeds your risk appetite waits for a board or audit-committee minute. When an acceptance lapses, the risk returns to analysis on its own and the work reopens.

## Related

- [ColossalX Trust Engine](https://colossalx.tech/platform/trust-engine)
- [Compliance and AI governance](https://colossalx.tech/platform/compliance)
- [Exposure management](https://colossalx.tech/platform/exposure-management)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
