Enterprise GRC Platform: A Two-Stage Risk Scoring Model with AI-Assisted Risk Identification and Audit Workflow Integration

Abstract
In enterprise security, risk scores determine what gets fixed and what gets ignored. Most organisations rely on a 5x5 likelihood-impact matrix, a method shown to generate misleading rankings that treats control effectiveness as little more than a rounding factor. Moving from no controls to best-in-class controls shifts a score by fewer than three points on a 25-point scale, a gap too small to justify any investment decision. This paper presents the Enterprise GRC Risk Intelligence Platform, which separates Inherent Risk from Residual Risk using a two-stage model. Asset criticality is weighted from 0.60 to 1.60 and Control Effectiveness is modelled as a calibrated reduction from 5% to 90%, producing a 22-point residual risk differential compared to two points under the conventional formula. The platform covers 22 asset types and 14 threat categories, combines AI-assisted risk identification with structured analyst input, role-based access control, audit workflow with evidence upload, and alignment across NIST CSF 2.0, NIST RMF, ISO 27001, and Zero Trust. Validation across all 625 scoring combinations confirms strict monotonicity.
© 2026 Saloni Bhosale, Samson Quaye, Maurice Dawson, published by Nicolae Balcescu Land Forces Academy
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.