Objectives
Risk
The Risk objective helps organizations understand their trust position, evaluate risks introduced by external companies, and monitor changes that may create new exposure — using structured company understanding instead of fragmented assessments or reactive alerts.
Selecting Risk does not create a separate understanding of a company. It changes what ASUME evaluates and which outputs it produces from the maintained understanding.
What Risk evaluates
How ASUME applies Risk
Maintained understanding → Risk → Risk outputs
ASUME forms a model of the organization's trust posture, dependencies, controls, evidence, and external relationships, then connects that internal understanding to the companies, systems, and market conditions that may affect it.
The purpose is not to claim that risk can be eliminated or reduced to one score. It is to make exposures visible, explain why they matter, show which evidence supports them, and help teams decide where attention is required.
Capabilities
Trust Benchmark
Trust Benchmark evaluates relevant security, governance, privacy, compliance, reliability, and operational indicators. It shows how the organization performs across these dimensions and how that position compares with appropriate peers or market expectations.
The benchmark should not become a superficial league table. Comparisons should remain relevant to the organization's context, and internal inconsistency should remain visible alongside the external position.
Example: A software company has strong encryption, identity controls, and formal policies. Trust Benchmark shows limited evidence for incident response testing and AI governance, and that one business unit relies on exceptions not used elsewhere.
Third-Party Risk
An organization's risk boundary extends beyond the systems it controls directly. Third-Party Risk evaluates an external company in relation to the role it plays for your organization.
Compliance evidence is useful, but it does not fully explain operational dependency. A vendor may hold relevant certifications and still create significant exposure if the organization cannot operate without it.
Example: A company evaluates an AI transcription service with credible security certifications, but the proposed workflow would send confidential customer conversations outside the company's required region.
Exposure Watch
A risk assessment becomes outdated when the organization, a third party, or the surrounding environment changes.
Exposure Watch should not turn every external update into an alert. It should connect each change to the organization's actual dependencies, requirements, and prior assessments.
Example: A vendor updates its terms to permit customer information to be used for model improvement. Exposure Watch identifies that the organization sends confidential documents through the service and flags the affected relationship.
Workflows
Positioning risk
Trust Benchmark establishes the organization's current trust position. Third-Party Risk extends that understanding across external dependencies.
The process can begin with an internal benchmark or with evaluation of a critical vendor.
Continuous risk understanding
Exposure Watch keeps internal and third-party assessments current as conditions change.
New external developments can trigger another benchmark or assessment, and benchmark gaps can define third-party requirements.
Extending Risk
ASUME is expanding the Risk objective across additional workflows and developer interfaces. These extensions are planned.