Product overview

What Riskonami does — an IRAM 2.0-based operational risk assessment — and how it relates to ISO 27001/27002, corporate controls, and NIST CSF 2.0.

Riskonami is a structured operational risk assessment system built on IRAM 2.0 (Information Risk Assessment Methodology 2.0). It is not a chatbot. The server owns the workflow: which phase you are in, what questions and worksheets appear, and when a phase is complete. You supply answers and evidence. AI enrichment is optional — you can complete an assessment using guided steps and manual entry only.

Assessment approaches and AI

Every run follows the same IRAM spine. You choose how you travel it — phased (guided, optional AI) or once-through (bulk upload, forced AI). Red boxes on the outline are AI enrichment steps: optional on the phased path (except Phase 6, which is calculated), and report AI in Phase 10. Product outline: phased vs once-through assessment with AI enrichment steps per phase Legend: green = phased steps · blue = once-through · red = AI · yellow = report. Continue with Choose your approach, the product workflow spine diagrams, or the risk assessment walkthrough.

Why organisations buy this assessment

Boards, CISOs, and auditors do not only want a list of controls. They need a defensible IRAM 2.0-style answer to: What can go wrong for this system, how likely is it, how bad would it be, what are we doing about it, and what residual risk remains? Riskonami produces that answer as a traceable assessment: system context → architecture → controls → threats → likelihood and impact → inherent risk → treatment → residual risk → issued report. That is the artefact people commission when they need to prioritise remediation, support ISMS / risk treatment records, or show due diligence to customers and regulators.

IRAM 2.0 — the base of this assessment

IRAM 2.0 is the foundation. The ten phases, worksheets, likelihood and impact model, inherent/residual risk steps, and report methodology are an IRAM 2.0-based operational risk assessment — not a generic checklist and not a NIST-first product with IRAM bolted on. IRAM 2.0 gives the assessment its spine:
  • threat-oriented analysis (who/what can cause harm)
  • confidentiality, integrity, and availability impact
  • layered likelihood (including control effectiveness)
  • inherent risk before treatment and residual risk after
  • a documented treatment / remediation path into the final report
ISO catalogues, your corporate controls, and CSF language plug into that IRAM 2.0 chain. They do not replace it.

How other frameworks relate

ISO/IEC 27001 — why the assessment matters for an ISMS

ISO/IEC 27001 expects organisations to run an information security management system (ISMS) that includes risk assessment and risk treatment — not only to “have controls”. Riskonami’s IRAM 2.0-based assessment is the engine that helps you produce a consistent, auditable risk picture for a named system, which you can feed into ISMS records, Statement of Applicability discussions, and management review. Riskonami does not claim to certify you to ISO 27001. It helps you do the risk work 27001-style programmes require.

ISO/IEC 27002 — the control catalogue inside the assessment

ISO/IEC 27002 is the detailed control set many organisations use when they talk about “Annex A / ISO controls”. Riskonami loads an ISO/IEC 27002:2022 catalogue for control scoping, matching, enrichment, and treatment planning within the IRAM 2.0 flow (alongside your own additions — see below). So in buying terms:
  • IRAM 2.0 = how the risk assessment is structured and reasoned
  • 27001 = the management-system reason you need that assessment
  • 27002 = a standard control vocabulary used inside the assessment

Custom corporate controls and best practice

Real programmes are never “ISO-only”. Riskonami treats organisation-specific and best-practice controls as first-class alongside the catalogue, still inside the same IRAM 2.0 assessment path. You assess the system you actually run — not only a generic Annex A list.

NIST CSF 2.0 — complementary stakeholder language

NIST Cybersecurity Framework (CSF) 2.0 is how many organisations describe cyber outcomes (Govern, Identify, Protect, Detect, Respond, Recover). Riskonami produces risk evidence those programmes can use. It is not a NIST CSF 2.0 assessment product; the method remains IRAM 2.0, with ISO 27002 and corporate controls feeding the control and treatment steps.

Short buyer summary

FrameworkRole in Riskonami
IRAM 2.0Base of the assessment — methodology for threats, likelihood, impact, inherent/residual risk, treatment, report
ISO 27001ISMS / governance reason to run a defensible risk assessment and treatment
ISO 27002Standard control catalogue used inside the IRAM 2.0 assessment
Corporate / best-practice controlsYour organisation’s controls, in the same IRAM 2.0 workflow
NIST CSF 2.0Optional stakeholder language; outputs can support CSF-style programmes

What the product does (in the product)

Riskonami walks you through a ten-phase assessment of a system or process: profile the system, model architecture, assess controls and threats, estimate risk, plan remediation, and produce a final report. Throughout, the product:
  • keeps one active assessment session per run
  • shows a conversation / action dock and inline worksheets driven by the server
  • saves phase artifacts (structured JSON, and diagrams where applicable)
  • lets you preview work before you accept a phase as done

What you produce (deliverables)

DeliverableWhat it is
Phase artifactsCanonical structured outputs for each completed phase
Architecture diagramsWhere the phase produces DOT / visual models
Final reportIssued PDF (and HTML/DOCX downloads) with a label you choose — IRAM 2.0 methodology narrative plus your system findings
Report variantsAdditional issued reports for other audiences after conclude
Session archiveAuditable snapshot after you end the assessment

How phases work (server-orchestrated)

For every phase the server:
  1. loads prior artifacts and decides the current step
  2. presents instructions, questions, quick picks, or worksheets
  3. validates structured answers
  4. commits the phase artifact when the phase is complete
  5. advances you to the next phase
You do not invent the phase sequence. The model does not choose the orchestration path. Optional AI enrichment is a separate, opt-in action inside a phase (or Phase 10 AI Fill) — never a replacement for the guided flow. See the product workflow for the shared spine, then choose your approach for approach-specific diagrams and steps.

AI enrichment — optional

You can use Riskonami without AI enrichment. Choose Skip / manual paths, enter data yourself, and build the report without AI Fill. When you affirm an enrichment action, the product may call AI to suggest or fill content (organisation context, diagram import, control/threat suggestions, report narratives, and similar). You still review and accept results.

Free vs billable (high level)

Golden line: the guided assessment process is designed to be free. You pay for optional AI enrichment and optional expert validation — not for working through the phases manually. Download your data. Server copies are subject to retention; export reports and sessions you need to keep.
FreeBillable
Guided phases, questions, worksheetsYes
Manual / Skip instead of AIYes
Deterministic report Start / Restart / Issue (no AI Fill)Yes
Affirmed AI enrichment (per gate)1 AI token per affirmed gate
Phase 10 AI Fill1 AI token per Fill request
Expert validation of an issued reportExpert validation token(s)
Details: How billing works. Next: Product workflow · Choose your approach · Getting started