RiskMandate v1.0.0
Risk Acceptance Maturity Model

Maturity you compute, not claim.

RAMM treats risk acceptance not as a free-text exception but as a durable decision node — linked to the risk, the scoring, the owner, the approving authority, the appetite and tolerance, the compensating controls, the evidence, and the review, expiry, and reassessment lifecycle. Because it's a graph, an organisation's maturity can be derived from evidence rather than asserted in a questionnaire.

At a glance

The whole model, on one canvas.

The acceptance node

Acceptance is grounded inward by evidence, outward by governance and appetite.

The acceptance decision is the hub. Its edges are directed: every acceptance has an inward path that grounds it in evidence, and an outward path that ties it to authority and appetite. These are the same directed patterns the corpus already uses, applied to acceptance.

RiskItem assessedBy RiskAssessment RiskAssessment usesMethod FrameworkReference RiskItem treatedBy RiskAcceptanceDecision ownedBy RiskOwner approvedBy DecisionAuthority boundedBy RiskAppetiteStatement withinToleranceOf RiskToleranceThreshold justifiedBy CompensatingControl evidencedBy EvidenceArtifact reviewedAt ReviewEvent expiresAt ExpiryEvent reassessOn ReassessmentTrigger
Five maturity levels

Each level is a Node Type Formula — a path-pattern a query can test.

A level is not a narrative claim; it's a required pattern of typed, directed paths over the acceptance graph. An organisation is at a level when its acceptance nodes satisfy that level's pattern, and not before. Try it: toggle the edges on the sample acceptance node and watch the level recompute.

Level 3 is not a claim that acceptance is "defined." It is the query: do all acceptance nodes have the five required edges, returning true? Change the graph and the level changes with it — computed, not asserted.

The entity model

Five layers, each mapping to something the corpus already has.

Provenance spans all of them — carried as PKI attribution and a commit log recording which standard, tool, or assessment produced each linked artifact.

Risk source · Evaluation
What is at risk, and how bad
  • RiskItem — the risk node, scoped by the union of possible authorization
  • RiskAssessment — scoring, plus confidence band and margin of error
Treatment
The decision itself
  • RiskTreatmentDecision — mitigate, transfer, avoid, or accept (OWASP TAME)
  • RiskAcceptanceDecision — no-deny, accept-in-a-direction, for-an-interval
Governance
Who owns it, and against what
  • RiskOwner · DecisionAuthority — the technical/business split and the underwriting chain
  • RiskAppetiteStatement · RiskToleranceThreshold — the revealed appetite band and Goldilocks zone
  • CompensatingControl — the controls that justify residual exposure
Review
The lifecycle
  • ReviewEvent · ExpiryEvent · ReassessmentTrigger — the interval mechanic and air-gap reassessment
  • EvidenceArtifact — the grounding ladder: evidence, measure, twin, reality
Crosswalk
The bridges out
  • FrameworkReference — the bridge nodes of the ontologies-of-ontologies model
Across all layers
Provenance
  • PKI attribution and a commit log on every linked artifact — which standard, tool, or assessment produced it
Why graph-native

Maturity computed, not asserted.

A questionnaire asks an organisation to rate itself. A graph lets the rating be derived from evidence — which is the whole differentiator.

Evidence-based, not questionnaire-based
A level is assigned by a query over real acceptance nodes, not by self-judgement.
Explicit, testable path-patterns
Each level is a required set of typed, directed edges — verifiable and unambiguous.
Explainable and repeatable
The same query returns the same level, and shows exactly which edges are missing.
Fits ontology-of-ontologies
Types are computable path-patterns already, so RAMM slots into the corpus without new machinery.
Agentic RAMM

An overlay on the base model — because agents bring new risk and new capability.

The agentic variation extends, rather than forks, the base. It adds four entities and tightens each level's criteria for agent acceptances.

Overlay entity
Capability Certificate
The scoped, signed grant — what the agent is actually authorised to do.
Overlay entity
Authorization Closure
The union of everything reachable, not the nominal grant — the real blast radius.
Overlay entity
Moment of Authorization
When the grant was made, against which capability and context.
Overlay entity
Agent Twin
The agent's permissions, capabilities, and track record — the thing reassessment watches.
Defined+ every agent acceptance links a capability certificate Managed+ authorization closure & expected-vs-unexpected delta accepted; trifecta status tracked Optimized+ recurring-acceptance metric instrumented; twin reassesses on capability or track-record change
Interoperability

Bridges, not merges.

RAMM overlays existing standards and links to them at declared points — each framework kept as its own owned ontology. This first pass fixes the bridging approach; the per-control crosswalk is the next, super-detailed pass.

OWASP Risk Ratingscoring substrate
OWASP SAMMgovernance & maturity
ASVScontrol requirements
WSTG · API · Mobilefindings & taxonomies
Threat Dragon · pytmthreat-model evidence
DefectDojo · CycloneDXvuln & supply-chain
RIMS RMMstaged progression
Public-sector modelsauthority & review

Do this in RAMM satisfy a requirement in framework X.

Example maturity queries

Each query is both an assurance check and a maturity probe.

BASEExpired acceptances still above tolerance
BASEAccepted risks with no compensating control
BASEAcceptances justified by an obsolete framework version
BASEAcceptances with no owner-to-board propagation path
AGENTAgent acceptances whose authorization closure exceeds the nominal grant
AGENTAgent acceptances with a full trifecta and no capability certificate

Using RiskMandate raises your RAMM level.

RiskMandate is the graph-native acceptance workflow, so it produces exactly the owned, evidenced, interval-bound, appetite-linked, board-propagated acceptance nodes that the higher levels require. Adopting the product isn't a claim of maturity — it's a mechanism for it. RAMM is the standard the improvement is measured against.

Open questions

A first draft, to be refined into normative statements.

Which graph representation? RDF/OWL, property graph, JSON-LD, or dual publishing — a conceptual ontology alongside an implementable schema.
At what level is maturity scored? Organisation, business unit, application, portfolio, or exception program.
How are crosswalks versioned? Tracking OWASP, RIMS, and other framework versions as they change.
What are the normative level statements? Turning each level's formula into a capability statement with evidence criteria.
Computable · governed · evidence-backed

Turn acceptance from an exception into a graph decision.

RAMM turns risk acceptance from a free-text exception into a computable, governed, evidence-backed graph decision — and RiskMandate is how you get there.