Skip to main content
Have a personal or library account? Click to login
Enterprise GRC Platform: A Two-Stage Risk Scoring Model with AI-Assisted Risk Identification and Audit Workflow Integration Cover

Enterprise GRC Platform: A Two-Stage Risk Scoring Model with AI-Assisted Risk Identification and Audit Workflow Integration

Open Access
|Jul 2026

Abstract

In enterprise security, risk scores determine what gets fixed and what gets ignored. Most organisations rely on a 5x5 likelihood-impact matrix, a method shown to generate misleading rankings that treats control effectiveness as little more than a rounding factor. Moving from no controls to best-in-class controls shifts a score by fewer than three points on a 25-point scale, a gap too small to justify any investment decision. This paper presents the Enterprise GRC Risk Intelligence Platform, which separates Inherent Risk from Residual Risk using a two-stage model. Asset criticality is weighted from 0.60 to 1.60 and Control Effectiveness is modelled as a calibrated reduction from 5% to 90%, producing a 22-point residual risk differential compared to two points under the conventional formula. The platform covers 22 asset types and 14 threat categories, combines AI-assisted risk identification with structured analyst input, role-based access control, audit workflow with evidence upload, and alignment across NIST CSF 2.0, NIST RMF, ISO 27001, and Zero Trust. Validation across all 625 scoring combinations confirms strict monotonicity.

DOI: https://doi.org/10.2478/kbo-2026-0001 | Journal eISSN: 2451-3113 (formerly 1843-6722) | Journal ISSN: 1843-6722
Language: English
Page range: 1 - 8
Published on: Jul 5, 2026
Published by: Nicolae Balcescu Land Forces Academy
In partnership with: Paradigm Publishing Services
Publication frequency: 3 issues per year

© 2026 Saloni Bhosale, Samson Quaye, Maurice Dawson, published by Nicolae Balcescu Land Forces Academy
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.