ASUME

Objectives

Risk

Objective
Risk
Primary use
Exposure
Applies to
Maintained understanding
Status
Planned
Capabilities
Trust Benchmark · Third-Party Risk · Exposure Watch
Workflows
Positioning risk · Continuous risk understanding

The Risk objective helps organizations understand their trust position, evaluate risks introduced by external companies, and monitor changes that may create new exposure — using structured company understanding instead of fragmented assessments or reactive alerts.

Selecting Risk does not create a separate understanding of a company. It changes what ASUME evaluates and which outputs it produces from the maintained understanding.

What Risk evaluates

Trust posture
Examines how the organization's trust posture compares internally and with relevant organizations.
Third-party exposure
Evaluates which risks enter the organization through vendors, partners, and other dependencies.
Change
Considers which changes create new or increased exposure relative to a previous assessment.

How ASUME applies Risk

Maintained understanding → Risk → Risk outputs

ASUME forms a model of the organization's trust posture, dependencies, controls, evidence, and external relationships, then connects that internal understanding to the companies, systems, and market conditions that may affect it.

The purpose is not to claim that risk can be eliminated or reduced to one score. It is to make exposures visible, explain why they matter, show which evidence supports them, and help teams decide where attention is required.

Capabilities

CapabilityWhat it does
Trust BenchmarkEstablishes the organization's internal and external trust position.
Third-Party RiskEvaluates the exposures introduced by vendors, partners, and other dependencies.
Exposure WatchMonitors changes that may alter the organization's risk profile.

Trust Benchmark

Trust Benchmark evaluates relevant security, governance, privacy, compliance, reliability, and operational indicators. It shows how the organization performs across these dimensions and how that position compares with appropriate peers or market expectations.

The benchmark should not become a superficial league table. Comparisons should remain relevant to the organization's context, and internal inconsistency should remain visible alongside the external position.

Example: A software company has strong encryption, identity controls, and formal policies. Trust Benchmark shows limited evidence for incident response testing and AI governance, and that one business unit relies on exceptions not used elsewhere.

Third-Party Risk

An organization's risk boundary extends beyond the systems it controls directly. Third-Party Risk evaluates an external company in relation to the role it plays for your organization.

Compliance evidence is useful, but it does not fully explain operational dependency. A vendor may hold relevant certifications and still create significant exposure if the organization cannot operate without it.

Example: A company evaluates an AI transcription service with credible security certifications, but the proposed workflow would send confidential customer conversations outside the company's required region.

Exposure Watch

A risk assessment becomes outdated when the organization, a third party, or the surrounding environment changes.

Exposure Watch should not turn every external update into an alert. It should connect each change to the organization's actual dependencies, requirements, and prior assessments.

Example: A vendor updates its terms to permit customer information to be used for model improvement. Exposure Watch identifies that the organization sends confidential documents through the service and flags the affected relationship.

Workflows

WorkflowHow Risk is applied
Positioning riskEstablish the current trust position and the exposures that enter through third parties.
Continuous risk understandingKeep both assessments current as the organization, vendors, and environment change.

Positioning risk

Trust Benchmark establishes the organization's current trust position. Third-Party Risk extends that understanding across external dependencies.

The process can begin with an internal benchmark or with evaluation of a critical vendor.

Continuous risk understanding

Exposure Watch keeps internal and third-party assessments current as conditions change.

New external developments can trigger another benchmark or assessment, and benchmark gaps can define third-party requirements.

Extending Risk

ASUME is expanding the Risk objective across additional workflows and developer interfaces. These extensions are planned.

InterfacePurpose
Risk APIAccess Risk capabilities programmatically.
Risk SDKBuild Risk-specific workflows into applications.
Risk MCPMake Risk capabilities available to supported agents.

What Risk does not claim

Risk cannot be reduced to one score
Risk outputs make exposures visible and explain why they matter. They do not claim that risk can be eliminated or reduced to one score.
Not every uncertainty is a threat
ASUME reveals which assumptions need verification and which dependencies deserve closer examination. It does not label every uncertainty as a threat.
Human judgment still matters
ASUME supports risk attention and review but does not replace accountable decisions about mitigation, acceptance, or escalation.
© 2026 ASUME B.V.