Risk Intelligence (RISKINT): Intelligence Discipline Guide
Risk intelligence is what stops a briefing ending with it depends. It converts what you know, and what you do not, into a judgement someone can defend and act on.
Risk intelligence is what stops a briefing ending with it depends. It converts what you know, and what you do not, into a judgement someone can defend and act on.
What Risk Intelligence is as a discipline
Risk intelligence is the structured assessment of threat, vulnerability, exposure and consequence to produce comparable, decision-ready judgements. It sits downstream of collection, because the discipline is analytic method rather than sourcing. Practitioners define the risk question, decompose it into named drivers, set explicit criteria and scales, weigh evidence using structured analytic techniques, express uncertainty in calibrated probability rather than adjectives, and document assumptions so the assessment can be challenged by others and updated when the underlying indicators move.
Sub-methods include indicator and warning frameworks, scenario development, analysis of competing hypotheses, key assumptions checks, red teaming, and weighted scoring models with sensitivity testing. In the cycle it is the analysis and production stage: it converts multi-discipline reporting into a rating, a scenario set or a watchlist trigger, and then defines the observations that would change the judgement and the cadence at which it is revisited.
Why it matters
Only risk intelligence answers how bad, how likely, compared with what else, and what should be done first. Other disciplines establish facts; this one prioritises them against a specific organisation's exposure, controls and tolerance. It also answers what residual risk is being accepted after existing controls, which is the number a board is actually approving, and it defines the tripwires that turn monitoring into a decision instead of a running commentary.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Named risk drivers with directional indicators, so movement can be observed and reported rather than asserted after the event.
- Base rates for the event class, anchoring probability judgements to history instead of the most recent salient incident.
- Exposure mapping showing which assets, people, suppliers, sites or transactions sit inside the affected set.
- Consequence pathways tracing an initiating event through operational, financial, legal and reputational effects.
- Explicit confidence statements separating the probability of the event from confidence in the underlying evidence.
- Tripwires and thresholds converting an indicator crossing into a defined escalation with a named decision owner.
- Residual risk after existing controls, which is what the decision-maker is actually being asked to accept.
- Documented key assumptions, each paired with the observation that would invalidate it.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- World Bank Worldwide Governance Indicators — Comparable governance, rule-of-law and control-of-corruption measures across countries and years
- Transparency International CPI — Perceived public sector corruption scores, useful as one input rather than a standalone rating
- FATF public statements — Jurisdictions under increased monitoring or countermeasures, with the specific deficiencies identified
- ACLED — Geocoded, dated political violence and protest events supporting base rates and trend analysis
- INFORM Risk Index (EC JRC) — Open composite index of hazard, vulnerability and coping capacity with component scores exposed
- UNODC statistics portal — Crime, homicide and trafficking statistics with methodology notes on cross-country comparability
- National regulator and CERT advisories — Authoritative warnings and enforcement actions that often precede visible incidents
- IMF Article IV reports — Independent macro-financial assessment with candid discussion of fiscal and banking vulnerabilities
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Frame the risk question — State the decision the assessment serves, the timeframe and the specific exposure at stake, so the output is usable rather than general.
- Decompose into drivers — Break the risk into observable drivers and define the scale for each, including what a high and a low score actually mean.
- Gather multi-discipline evidence — Pull findings from the disciplines that own the facts, keeping sourcing intact so the judgement can be audited back to evidence.
- Apply a structured technique — Run competing hypotheses, a key assumptions check or a red team pass to test the judgement against alternative explanations.
- Score with sensitivity testing — Vary weights and inputs to see whether the rating survives reasonable disagreement, and report which drivers it is most sensitive to.
- State judgement and confidence — Give probability and confidence separately, in calibrated language rather than vague adjectives, and say plainly what remains unknown.
- Set tripwires and review — Define the indicators that trigger reassessment, assign owners, and schedule review so the rating does not quietly go stale.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
- Threat Analysis
- Critical Infrastructure
- Emerging Technology & AI Security
- Kidnap, Hostage & Extortion
- Conflict & Humanitarian
- Climate Security
- Water Security
- Food & Agricultural Security
- Maritime Piracy
- Risk Analysis
Operates on these data points
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- Location / Coordinates — A geographic point, place, or region — the basis of GEOINT analysis.
- GPS Coordinates — Precise latitude/longitude coordinates identifying an exact point on Earth — the atomic unit of GEOINT analysi
- Keyword / Narrative — A search term, topic, hashtag, or narrative tracked across media and platforms.
- Satellite Imagery — Overhead imagery of an area of interest, used for change detection and site analysis.
- Facility / Site — A physical installation — plant, base, port, data centre — with a fixed footprint and function.
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Person / Name — A named individual — the subject of identity resolution and profiling.
- CVE / Vulnerability — Common Vulnerabilities and Exposures identifier for a known flaw.
- IP Address — Internet Protocol address identifying a device or server on a network.
Related disciplines
- Open Source Intelligence — Publicly Available Information, Systematically Collected
- Reference Intelligence — Authoritative Reference Data and Standards
Inside the platform: where Risk Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=RISKINT— Discipline hubsource-catalog.php?disc=RISKINT— Source catalogue filtered to this disciplinesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Auto-Collect Feeds
- Enrichment → Local
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Frame the risk question is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Gather multi-discipline evidence turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Set tripwires and review feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Risk Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Risk assessment in defence supports course of action comparison, force protection posture and the commander's decision on acceptable risk. Analysts decompose a threat into capability, intent and opportunity, weigh it against friendly vulnerability and consequence, and express the result in terms the staff can act on rather than a colour. It feeds the intelligence estimate, the running estimate and the indicators and warning matrix that triggers posture change. Constraints matter: risk judgements must be traceable to reporting rather than to staff consensus, must state assumptions that would invalidate them, and must be revisited on a defined cadence because a rating written before a deployment and never revised is a liability rather than a product.
🕵 National intelligence
National assessment bodies use structured risk method to convert multi-discipline reporting into judgements that ministers can act on. The discipline is analytic integrity: explicit criteria, calibrated probability language, separation of what is known from what is assessed, and documented key assumptions that can be challenged. Products carry classification driven by the sourcing rather than the judgement, so a releasable version is usually drafted alongside. Alternative analysis is a formal step rather than a courtesy, with red teaming and analysis of competing hypotheses applied to high-consequence judgements. Dissemination includes stating the observations that would change the assessment, which is what makes a warning product actionable.
👮 Law enforcement
Law enforcement uses risk intelligence for threat and harm assessment, resource prioritisation, and protective decisions about victims and witnesses. The evidential position differs from investigative work: a risk assessment informs action, but the underlying facts must still be evidenced if they later support a charge or an order. Structured, validated tools are preferred over analyst intuition where they exist, because they are defensible and auditable. Where an assessment restricts a person's liberty or entitlements, procedural fairness and the ability to challenge apply, and fully automated decisions with significant effects are restricted under data-protection law in many jurisdictions.
🔍 Private investigation and corporate security
Corporate security and private investigators use risk intelligence for third-party risk, travel and site risk, insider risk and investment due diligence. The value is comparability: ratings that mean the same thing across countries, suppliers and business units, with the evidence retained. The private-sector constraint is consequence. A rating can cost a person a job or a company its banking, so allegations must be characterised as reported and attributed rather than established, evidence must be retained for the life of the decision, and a route to challenge and correct must exist. Fully automated adverse decisions about individuals are restricted in several jurisdictions and should be avoided.
📰 Journalism and OSINT media
Journalists use risk frameworks both as subject matter and as internal discipline. As subject matter, they scrutinise how governments and companies rate risk and whether the ratings drove decisions. As discipline, they assess the risk of a story to sources, to staff and to named individuals before publication. Verification standards apply to any rating reported as fact: obtain the methodology, the inputs and the date, since a score without a method is not a finding. Publication ethics require distinguishing an assessed probability from a prediction, offering right of reply to entities rated adversely, and disclosing the provenance of proprietary scores.
🌍 NGO, humanitarian and human rights
Humanitarian and human rights organisations use risk intelligence for access negotiation, security management, programme criticality and protection analysis. Practice is population-centred as well as staff-centred: the assessment must weigh the risk to the people served by a decision to stay or withdraw, not only the risk to the organisation. Do-no-harm requires assessing the second-order effects of a mitigation, such as the exposure created for local partners by a security measure that protects international staff. Documentation for accountability includes recording the basis of access decisions. Duty of care obliges organisations to act on what their own assessments say rather than filing them.
🎓 University and research
Researchers examine risk methodology itself: calibration, elicitation, aggregation of expert judgement, and whether structured techniques improve accuracy over unaided expertise. Reproducibility requires publishing the scoring model, the weights, the input data and the sensitivity analysis, since a rating cannot be evaluated without them. Ethics approval is engaged where assessments concern identifiable people or vulnerable populations. Forecast evaluation should use proper scoring rules against resolved outcomes rather than post hoc narrative justification. Data sharing is constrained where inputs are proprietary or sensitive, so publish the model and synthetic or aggregated inputs with a documented data management plan.
Playbook: working Risk Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Frame the risk question
Write the question as a specific event, actor, place and time window rather than a topic. Risk to what, from what, over what period, and to what threshold of consequence. Identify the decision the assessment supports and who owns it, because a rating with no decision attached will be interpreted arbitrarily. A good output is a framing note stating the question, the decision, the audience and the review cadence, agreed with the decision owner. Stop when the question is narrow enough that two analysts would collect against the same indicators.
Phase 2 — Decompose into drivers
Break the question into named drivers: threat actor capability, intent and opportunity; vulnerability and exposure; and consequence across the dimensions that matter to the client, typically people, operations, assets, legal position and reputation. Define each driver so it can be observed rather than felt. Avoid drivers that are really outcomes. A good output is a driver tree where each leaf can be evidenced by something collectable. Stop when every driver has at least one observable indicator, and prune drivers that do not.
Phase 3 — Set scales and criteria
Define the scale before you look at the data. State what each level means in observable terms, not in adjectives: what specifically distinguishes a high from a moderate. Define the consequence bands in units the client uses, such as days of disruption, casualties, or financial loss. Publish the criteria with the product. A good output is a rubric that a second analyst could apply to the same evidence and reach the same rating. Stop when the rubric survives a dry run on two contrasting cases without needing interpretation.
Phase 4 — Collect against indicators
Task collection to the indicators rather than to the topic. Pull the multi-discipline reporting that speaks to each driver, record source and date for every input, and note where an indicator cannot be observed at all, since unobservable drivers are a structural weakness in the assessment. Distinguish current observations from historical base rates. A good output is an indicator register with evidence, dates and gaps marked. Stop when the material gaps are documented and the collectable indicators are covered to the depth the deadline allows.
Phase 5 — Establish the base rate
Before weighing the current situation, establish how often this class of event has occurred in comparable settings. Use event datasets, incident histories, regulatory actions or claims data as appropriate. Analysts consistently overweight vivid recent reporting and underweight frequency, and the base rate is the correction. Record the reference class you chose and why, because the choice usually matters more than the arithmetic. A good output is a stated reference class with a frequency. Stop when the reference class is defensible and its limitations are written down.
Phase 6 — Test competing hypotheses
List the plausible explanations or futures, including the benign one, and assess which evidence actually discriminates between them rather than being consistent with all. Evidence consistent with every hypothesis has no diagnostic value however voluminous. Identify the single item that would most change the picture if it were wrong. A good output is a matrix showing evidence against hypotheses with diagnosticity marked. Stop when the surviving hypotheses are ranked by evidence rather than by plausibility, and the discriminating evidence is named.
Phase 7 — Check key assumptions
Surface the assumptions the assessment rests on and test each: is it supported, is it merely conventional, and what would happen to the judgement if it failed. Assumptions about actor rationality, about the continuation of current policy and about data availability are the usual load-bearing ones. Mark any assumption that is both critical and weakly supported as a watch item. A good output is a key assumptions check with a status per assumption. Stop when every critical assumption has been examined by someone who did not write it.
Phase 8 — Score and weight
Apply the rubric to produce driver-level ratings, then aggregate using an explicit, documented rule rather than an unstated mental average. If weights are used, justify them and record who set them. Avoid combining ordinal scales arithmetically as though they were interval measures without acknowledging the distortion. A good output is a scored model where the path from evidence to rating is visible. Stop when the aggregation rule is written down and applied consistently across the population being compared.
Phase 9 — Run sensitivity analysis
Vary the inputs and weights that you are least confident about and see whether the rating moves. If a single subjective weight flips the result, the model is expressing an opinion rather than measuring anything, and that must be disclosed. Identify the two or three inputs that dominate the outcome and prioritise collection against them. A good output is a short sensitivity note naming the dominant inputs and the stability of the rating. Stop when the client can be told what the rating actually depends on.
Phase 10 — Express uncertainty calibrated
Convert the judgement into calibrated probability language tied to defined bands, and use the bands consistently across products. State confidence separately from likelihood: how probable the event is, and how much evidence you have to say so. Avoid adjectives that mean different things to different readers. A good output is a judgement sentence a decision maker can act on without asking what you meant. Stop when the likelihood, the confidence and the time window are all explicit in the same sentence.
Phase 11 — Define triggers and warning
Specify the observations that would change the assessment in either direction, with a named owner for watching each and a threshold for escalation. This is what converts an assessment into a warning capability rather than a snapshot. Set the review cadence and the events that force an off-cycle review. A good output is a short indicator and warning matrix issued with the assessment. Stop when every trigger is genuinely observable by someone with the access to observe it.
Phase 12 — Deliver, review and score yourself
Deliver with the criteria, the assumptions and the triggers attached, and record the decision that followed. Then close the loop: when the time window resolves, compare the judgement to the outcome and record the result. Track calibration across many judgements rather than defending individual ones, since a well-calibrated analyst is wrong at the stated rate by design. A good output is a maintained forecast record. Stop when the review is logged; do not rewrite the original assessment to match the outcome.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| ACLED | Registration | Coded dataset of political violence, protest and strategic developments with date, location, actor and source notes. | Supplies the base rate for political violence risk in a defined geography and time window rather than impressionistic judgement. |
| INFORM Risk Index | Open | Composite index of hazard, vulnerability and coping capacity for humanitarian crisis risk, published with component data. | Provides a transparent, component-level baseline for country risk comparison and a model whose weights can be inspected. |
| World Bank Worldwide Governance Indicators | Open | Aggregate governance measures covering rule of law, control of corruption, regulatory quality and political stability. | Contextualises institutional risk drivers and supports comparison across jurisdictions with published confidence intervals. |
| Transparency International Corruption Perceptions Index | Open | Composite perception-based ranking of public sector corruption by country with source and methodology documentation. | Common comparator for corruption exposure in third-party risk models, used with explicit acknowledgement that it measures perception. |
| Basel AML Index | Registration | Country risk scores for money laundering and terrorist financing built from compliance, governance and transparency indicators. | Inputs jurisdiction risk into financial crime and counterparty risk models with a documented component structure. |
| FATF jurisdiction statements | Open | Lists of jurisdictions under increased monitoring or subject to countermeasures, with mutual evaluation reports. | Authoritative regulatory signal that carries direct control consequences rather than a perception score. |
| UNDRR and disaster loss data | Open | Frameworks, terminology and reporting on disaster risk reduction including national loss and damage reporting. | Standardises hazard and consequence terminology and supplies historical loss baselines for natural hazard risk. |
| EM-DAT international disaster database | Registration | Historical records of disaster events with dates, locations, deaths, affected populations and economic damage. | Establishes the empirical frequency and severity distribution used as the reference class for natural hazard risk. |
| IMF country reports and Article IV consultations | Open | Macroeconomic assessments, fiscal and external position analysis and risk statements for member economies. | Grounds economic and currency risk drivers in an authoritative external assessment with stated assumptions. |
| NIST Special Publication 800-30 risk assessment guidance | Open | Structured method for conducting information security risk assessments including threat, vulnerability and impact taxonomies. | Provides a defensible, widely recognised structure for technology risk components within a broader assessment. |
| ISO 31000 risk management standard | Licensed | International standard setting principles, framework and process for managing risk across an organisation. | Anchors the governance and process expectations that auditors and boards will test the assessment against. |
| Humanitarian Data Exchange | Open | Repository of humanitarian datasets covering displacement, needs, access constraints and administrative boundaries. | Supplies exposure and consequence denominators such as affected population within an administrative area. |
| Freedom House and V-Dem political indicators | Open | Country-level measures of political rights, civil liberties and democratic institutional quality with disaggregated indicators. | Supports political and operating environment drivers with indicator-level data rather than a single headline score. |
| MITRE ATT&CK | Open | Structured knowledge base of adversary tactics, techniques and procedures observed in real intrusions. | Converts cyber threat capability from an adjective into an enumerated, testable set of behaviours for the threat driver. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Risk Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Analysis of competing hypotheses matrix — Structures evidence against alternative explanations and highlights diagnostic items. Limitation: it does not weight evidence quality, so a matrix full of weak sources can look decisive.
- Key assumptions check template — Forces explicit listing and testing of load-bearing assumptions. Limitation: it only works when applied by someone other than the author, otherwise it confirms rather than challenges.
- Weighted scoring model with sensitivity testing — Combines driver scores into a comparable rating and shows which inputs dominate. Limitation: arithmetic on ordinal scales implies precision the underlying judgements do not have.
- Monte Carlo and probabilistic simulation tools — Propagate input uncertainty through a model to produce outcome distributions. Limitation: output confidence is entirely a function of input distributions that are often themselves guesses.
- Bayesian belief network software — Models conditional dependencies between drivers and updates on new evidence. Limitation: structure and prior elicitation are labour intensive and the model can become unauditable to the decision maker.
- Forecast tracking and calibration platforms — Record dated probabilistic judgements and score them against resolved outcomes. Limitation: only useful with enough resolved questions, so calibration takes many months to become meaningful.
- Structured elicitation protocols such as Delphi — Aggregate expert judgement while reducing anchoring and dominance effects. Limitation: slow, and consensus can converge on a confidently wrong view if the panel shares a blind spot.
- Indicator and warning dashboards — Track named triggers against thresholds with owners and escalation routes. Limitation: they decay quickly into unwatched displays unless each indicator has a named human owner and a review cadence.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Auto-Collect Feeds — Pulls the registered feed set server-side on a schedule, recording per-feed status so a silently dead feed is visible.
- Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Set the scale before you see the evidence. Defining what separates high from moderate after reading the reporting guarantees the rubric is fitted to the conclusion you already reached, and the fit will be invisible to reviewers.
- Diagnosticity beats volume. Evidence consistent with every hypothesis carries no information regardless of how much of it you have, and most assessments that feel well supported are supported by non-discriminating material.
- Pick the reference class explicitly and defend it. The choice of what counts as a comparable case usually drives the base rate more than the arithmetic does, and undocumented choices cannot be challenged.
- State likelihood and confidence separately. A high probability judgement on thin evidence and a moderate probability judgement on strong evidence demand different responses, and collapsing them into one word hides that.
- Sensitivity analysis is the honesty check on any scoring model. If a subjective weight flips the rating, the number is an opinion wearing a uniform and the client is entitled to be told so.
- Write the falsifier into the product. An assessment that does not say what observation would change it cannot function as warning, and it quietly becomes permanent because nobody knows when to revisit it.
- Track calibration across many judgements, never defend individual ones. A properly calibrated analyst is wrong exactly as often as their stated probabilities imply, and treating each miss as a failure destroys honest probability use.
- Beware the rating that survives because nobody has time to revisit it. Stale risk ratings are more dangerous than absent ones because they carry unearned authority into decisions long after their evidence expired.
- Distinguish reported allegation from established finding in the wording, every time. In risk products about named people and companies, the phrasing is the legal exposure, and the file supporting the phrasing is the defence.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Risk Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Calibration score across resolved probabilistic judgements, measured with a proper scoring rule over a rolling window rather than by counting individual hits and misses.
- Proportion of assessments issued with explicit falsifying indicators and a named owner for each, and the rate at which those triggers were actually reviewed on schedule.
- Share of high-consequence judgements that received documented alternative analysis, such as analysis of competing hypotheses or red teaming, by an analyst who did not draft them.
- Inter-rater agreement when two analysts independently apply the rubric to the same case, tracked as evidence that the criteria are observable rather than intuitive.
- Median age of ratings in the active portfolio against the stated review cadence, exposing stale assessments still informing decisions.
- Number of decisions where the assessment demonstrably changed the course of action, recorded at the time, as a counterweight to volume of products issued.
- Rate of successful challenges or corrections by subjects of adverse ratings, treated as a quality signal about evidence retention and wording discipline.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Numeric scores that were never calibrated, implying a precision the underlying evidence cannot support.
- Collapsing likelihood and severity into a single number, hiding exactly the distinction the decision needs.
- Assessments with no falsifier, where no observation the analyst can imagine would ever change the stated judgement.
- Recency and availability bias, where one salient incident silently reweights the entire model.
- Adopting the client's risk appetite as an analytic assumption instead of assessing risk and letting them set tolerance.
- Ratings never revisited after the drivers moved, so the file says one thing and reality another.
Legal and ethical considerations
Risk judgements about identifiable people or named companies cause real consequences, including lost banking, contracts and employment. Retain the evidence behind every rating, distinguish allegation from finding in the wording, and avoid fully automated decisions with legal or similarly significant effects where data-protection law restricts them. Provide a route for subjects to challenge and correct. Defamation exposure is genuine, so characterise conduct as reported and attributed rather than as established fact, and keep the file supporting the language you chose.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Risk Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 10 mission domains, 2 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Why not just use a red, amber, green scale?
Because the words carry no shared meaning and no time window. Two analysts will apply amber to materially different situations, and a decision maker cannot tell whether amber means an event is likely this quarter or conceivable this decade. If a traffic light is required by the audience, define each colour in observable terms, attach a probability band and a time window, and publish the definitions alongside the rating. The colour then becomes a presentation layer over a defensible judgement rather than a substitute for one. Never aggregate colours arithmetically.
How do I stop analysts anchoring on the last incident?
Establish the base rate first and record it before current reporting is reviewed. Recency and vividness dominate unaided judgement, and a single recent incident routinely produces ratings an order of magnitude above the historical frequency. Make the reference class an explicit, challengeable step in the method. Have a second analyst who has not read the recent reporting apply the rubric independently and compare. Where the current situation genuinely justifies departing from the base rate, require the analyst to state which specific change in capability, intent or exposure warrants it.
Can risk scores be automated?
Components can be, judgements should not be end to end. Automating data ingestion, indicator computation and consistency checks is valuable and improves comparability. Automating an adverse decision about an identifiable person, such as denial of a service or employment, is restricted under data-protection law in several jurisdictions where the decision has legal or similarly significant effects, and requires meaningful human review, an explanation and a route to challenge. Beyond legality, automated scores drift silently when input data changes upstream, so they need the same monitoring, sampling and periodic revalidation you would apply to any model.
What is the difference between likelihood and confidence?
Likelihood is the probability you assign to the event within the stated time window. Confidence is how much weight you place on that estimate given the quantity, quality and consistency of the evidence behind it. A judgement of high likelihood with low confidence tells a decision maker to act but to invest in collection and to revisit soon. A judgement of moderate likelihood with high confidence tells them the picture is stable. Collapsing the two produces the familiar failure where an assessment based on one thin report is read with the same weight as one built on convergent multi-source evidence.
How should assumptions be handled when they cannot be tested?
Name them, mark them as untested, and state the effect on the judgement if each fails. Untestable assumptions are legitimate; hidden ones are not. Where an assumption is both critical and untestable, it becomes a collection requirement and a watch item, and the assessment should say so explicitly. The practical test is whether a reader can identify, from the product alone, the two or three propositions on which the conclusion rests. If they cannot, the assumptions section is decorative and the assessment will fail silently when the world changes.
How do you rate a company or person without creating defamation exposure?
Separate what is reported from what is established, in the wording and in the file. Attribute allegations to the source and the date, characterise them as reported rather than as fact, and retain the underlying material so the language can be justified later. Avoid conclusory labels that assert criminality without a finding. Distinguish a risk rating, which is a forward-looking judgement about exposure, from an accusation about past conduct. Provide a documented route for the subject to challenge and correct, and record the outcome. The wording is the exposure and the evidence file is the defence.
How often should assessments be refreshed?
On the cadence you published, plus off-cycle whenever a defined trigger fires. Fixed cadence alone produces stale ratings between reviews and wasted effort on stable ones; triggers alone produce drift because nobody notices slow change. Set the cadence from the volatility of the drivers rather than the calendar convenience of the reporting cycle, and record the date of last review on the face of every product. Ratings past their review date should be visibly flagged as stale rather than quietly presented as current, because unearned authority is the main way old assessments cause harm.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ISO 31000, setting principles, framework and process for risk management including establishing context, risk assessment and treatment.
- Intelligence Community Directive 203 analytic standards, governing objectivity, sourcing transparency, expression of uncertainty and distinction between judgement and information.
- NIST Special Publication 800-30, providing a structured method and taxonomies for conducting information security risk assessments.
- Sendai Framework for Disaster Risk Reduction and UNDRR terminology, standardising hazard, exposure, vulnerability and consequence language.
- GDPR Article 22 restrictions on solely automated decision-making producing legal or similarly significant effects, with rights to explanation and human review.
- Structured analytic techniques as codified by intelligence community tradecraft primers, governing analysis of competing hypotheses, key assumptions checks and red teaming.
- Sphere Handbook and humanitarian programme criticality frameworks, governing how risk to staff is weighed against risk to affected populations in access decisions.
- Basel Committee operational risk guidance, framing how financial institutions identify, assess and control non-financial risk in a supervised environment.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- ISO 31000 risk management — International Organization for Standardization. International standard on risk management principles and process
- Guide for Conducting Risk Assessments, SP 800-30 — US National Institute of Standards and Technology. Structured risk assessment methodology widely used for technology risk
- INFORM Risk Index — European Commission Joint Research Centre and IASC. Open composite index of crisis risk with published component data
- ACLED political violence and protest data — Armed Conflict Location and Event Data Project. Event dataset used to establish base rates for political violence
- Worldwide Governance Indicators — World Bank. Aggregate governance measures with published confidence intervals
- Sendai Framework for Disaster Risk Reduction — UN Office for Disaster Risk Reduction. International framework and terminology for disaster risk reduction
- MITRE ATT&CK knowledge base — MITRE. Enumerated adversary techniques used to specify cyber threat capability
- Corruption Perceptions Index — Transparency International. Composite perception index of public sector corruption by country
- V-Dem democracy indicators — V-Dem Institute, University of Gothenburg. Disaggregated indicators of democratic institutions and political rights
- EM-DAT International Disaster Database — Centre for Research on the Epidemiology of Disasters. Historical disaster event records used for hazard frequency baselines
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: structured scoring, tripwire monitoring and evidence-linked risk products your board can interrogate. Explore the platform, or browse the rest of the library by following any tag above.