Business: Compliance · Lesson N.comp.3

Choreography: the risk map that updates itself

The traditional risk map is a PowerPoint born once a year that's already stale the next day. With AI reading new signal all the time, it becomes a living matrix: it flags what changed, you decide whether the score really changes.

Examples for

The company's risk map was updated in January, in a one-day workshop, and turned into a twenty-slide PowerPoint nobody opens again until the following January. In March, a new industry regulation changes the yardstick for a risk marked as low. In June, an incident at a similarly-sized competitor shows that an "unlikely" risk happens more often than the map assumes. None of that reaches the PowerPoint, because the PowerPoint only gets revisited once a year. You set AI up to read regulatory news, internal audit findings, and market incidents every day, and ask it to flag when one of these signals should change a risk's score on the map. It doesn't decide the new score, it just flags "risk X might need to go up, look at this signal." You check and decide.

Let me ask you something: when was the last time anyone opened the risk map PowerPoint outside of annual workshop season? Whoa, in most companies the answer is never. The map is born once, everyone signs off on it, and the world keeps changing all year without a single line of that document moving. A new regulation comes out, a competitor gets fined, a supplier ends up on a watch list, and none of it finds its way back into the document until the next workshop. The risk map turns into an old photograph of the day it was taken.

The core idea of this lesson. The living risk map is a four-beat choreography, running all the time instead of once a year. First, AI monitors continuous signal: regulatory news, audit findings, market incidents, regulatory changes. Second, it cross-references that signal with the map and flags which risk might need to change. Third, you validate with the risk matrix in hand: is this change real or is it noise. Fourth, you decide the new score, with a recorded justification. AI never decides a risk's score on its own; it flags when the world has changed enough for you to look again.

01The sweep is its job, the score is yours

The temptation is to ask AI to "update the risk map on its own." Wrong. That's asking it to decide the score, and risk scoring is business judgment, your part. The right request is more modest: "monitor these signal sources and flag when something suggests a risk on the map changed in probability or impact." You're not asking for a conclusion, you're asking for continuous sweeping.

AI is good at this because it reads news, regulatory publications, and incident reports without getting tired, and cross-references them with hundreds of mapped risks at once. It flags: "this new regulation touches risk number 14," "this incident at a competitor is similar to risk number 22, which is marked as rare." That's sweeping gold. But deciding whether risk 14 goes from moderate to high, or whether 22 stays rare even with the competitor's incident, is reading business context. It's yours.

You're the one who gives it the context to flag correctly: what your map's categories are, what counts as relevant signal for your sector, what the company's risk appetite is. Without that context, it sweeps generically; with it, it flags what's relevant to your specific map.

02The matrix is your hand on the update

AI can flag dozens of signals a week. Without a filter, you drown. The filter is your risk matrix: the categories, the probability and impact criteria that already exist on your map. That prioritizes what AI flagged (which signals actually touch a category you map) and, more importantly, reveals the absence: when a signal points to a type of risk the matrix doesn't even list.

Where this fools you: it's easy to confuse "AI didn't flag anything this week" with "nothing changed." That's not the same thing. It flags what crossed with what's mapped; a new risk, from a category nobody thought to include, can slip right by until someone asks "does this category exist in our map?" The matrix is the instrument that turns silence into a question.

03The choreography, from signal to update

Put it all together and it becomes a continuous flow. Signal comes in every day, AI cross-references it with the map and flags what might have changed, you validate with the matrix in hand, and decide the new score with a justification.

new signal every day AI cross-references flags the risk that might have changed you validate matrix in hand real or noise you decide new score, justified AI flags, you decide the score the map changes when the world changes, not once a year

Notice where the boundary sits. The two middle boxes, sweeping and validation, are where AI accelerates and your matrix filters. The last box, the decision, is yours alone. AI might even suggest "this type of signal usually indicates higher risk," but deciding the final score and owning the justification is business reading, not data reading. That's the point that never gets outsourced.

04Every score change goes through audit

This module's rule applies here in full: AI flags, it doesn't conclude, and the entire history of changes to the map needs to stay traceable. It said "this signal suggests risk 14 went up"? You record the date, the signal, and the decision you made, with your justification. It said "risk 22 stays rare despite the competitor's incident"? You record why you decided to keep the score, not just accept AI's silence as confirmation.

Why record it, if AI usually gets the sweep right? Because a risk map that changes without an auditable trail doesn't hold up before the committee or the regulator; it needs to show when each risk changed score and why. The living map isn't just faster than the annual PowerPoint, it's more auditable, because every change has a date, a signal, and a justification, instead of a one-day workshop nobody remembers arriving at that number from.

Do it now

Do it yourself

Take your real task: a risk on your map you suspect has been stale since the last cycle. Run the choreography end to end:

  1. Define the signal. What kind of source (regulatory news, audit finding, market incident, regulatory change) would change this specific risk's score? List 2 to 3.
  2. Ask for the sweep, not the conclusion. Ask AI: "monitor [the sources] and flag when something suggests this risk changed in probability or impact. Don't conclude the new score, just flag the signal and the reason."
  3. Validate with the matrix. Cross-reference what it flagged with the probability and impact criteria your matrix already uses. Does the signal cross an existing category, or reveal a category missing from your map?
  4. Decide and record. Write the new score (or the decision to keep it) with date, signal, and justification.

Compare: how long had this risk's score gone unchanged before this choreography?

Practice

1. What is the right request for AI to continuously monitor risk signal?

2. What is the risk matrix's purpose in the living map choreography, beyond prioritizing the signals AI flagged?

3. Why does a risk map that changes continuously with AI need to keep an auditable trail of every score change?

For the board

On the right requestask for continuous scanning, not a verdict. The AI raises the flag, the scoring stays yours.
On silencethe AI flagged nothing is not the same as nothing changed. The matrix turns silence into a question.
On the trailevery scoring change goes through audit, or the living map becomes rumour with a chart.
What did you think of this page?
Would you recommend this page to someone on your team?