Product overview
What Riskonami does — an IRAM 2.0-based operational risk assessment — and how it relates to ISO 27001/27002, corporate controls, and NIST CSF 2.0.
Riskonami is a structured operational risk assessment system built on
IRAM 2.0 (Information Risk Assessment Methodology 2.0). It is not a
chatbot. The server owns the workflow: which phase you are in, what
questions and worksheets appear, and when a phase is complete. You supply
answers and evidence. AI enrichment is optional — you can complete an
assessment using guided steps and manual entry only.
Legend: green = phased steps · blue = once-through · red = AI · yellow = report.
Continue with Choose your approach, the
product workflow spine diagrams, or the
risk assessment walkthrough.
Details: How billing works.
Next: Product workflow · Choose your approach · Getting started
Assessment approaches and AI
Every run follows the same IRAM spine. You choose how you travel it — phased (guided, optional AI) or once-through (bulk upload, forced AI). Red boxes on the outline are AI enrichment steps: optional on the phased path (except Phase 6, which is calculated), and report AI in Phase 10.
Legend: green = phased steps · blue = once-through · red = AI · yellow = report.
Continue with Choose your approach, the
product workflow spine diagrams, or the
risk assessment walkthrough.
Why organisations buy this assessment
Boards, CISOs, and auditors do not only want a list of controls. They need a defensible IRAM 2.0-style answer to: What can go wrong for this system, how likely is it, how bad would it be, what are we doing about it, and what residual risk remains? Riskonami produces that answer as a traceable assessment: system context → architecture → controls → threats → likelihood and impact → inherent risk → treatment → residual risk → issued report. That is the artefact people commission when they need to prioritise remediation, support ISMS / risk treatment records, or show due diligence to customers and regulators.IRAM 2.0 — the base of this assessment
IRAM 2.0 is the foundation. The ten phases, worksheets, likelihood and impact model, inherent/residual risk steps, and report methodology are an IRAM 2.0-based operational risk assessment — not a generic checklist and not a NIST-first product with IRAM bolted on. IRAM 2.0 gives the assessment its spine:- threat-oriented analysis (who/what can cause harm)
- confidentiality, integrity, and availability impact
- layered likelihood (including control effectiveness)
- inherent risk before treatment and residual risk after
- a documented treatment / remediation path into the final report
How other frameworks relate
ISO/IEC 27001 — why the assessment matters for an ISMS
ISO/IEC 27001 expects organisations to run an information security management system (ISMS) that includes risk assessment and risk treatment — not only to “have controls”. Riskonami’s IRAM 2.0-based assessment is the engine that helps you produce a consistent, auditable risk picture for a named system, which you can feed into ISMS records, Statement of Applicability discussions, and management review. Riskonami does not claim to certify you to ISO 27001. It helps you do the risk work 27001-style programmes require.ISO/IEC 27002 — the control catalogue inside the assessment
ISO/IEC 27002 is the detailed control set many organisations use when they talk about “Annex A / ISO controls”. Riskonami loads an ISO/IEC 27002:2022 catalogue for control scoping, matching, enrichment, and treatment planning within the IRAM 2.0 flow (alongside your own additions — see below). So in buying terms:- IRAM 2.0 = how the risk assessment is structured and reasoned
- 27001 = the management-system reason you need that assessment
- 27002 = a standard control vocabulary used inside the assessment
Custom corporate controls and best practice
Real programmes are never “ISO-only”. Riskonami treats organisation-specific and best-practice controls as first-class alongside the catalogue, still inside the same IRAM 2.0 assessment path. You assess the system you actually run — not only a generic Annex A list.NIST CSF 2.0 — complementary stakeholder language
NIST Cybersecurity Framework (CSF) 2.0 is how many organisations describe cyber outcomes (Govern, Identify, Protect, Detect, Respond, Recover). Riskonami produces risk evidence those programmes can use. It is not a NIST CSF 2.0 assessment product; the method remains IRAM 2.0, with ISO 27002 and corporate controls feeding the control and treatment steps.Short buyer summary
| Framework | Role in Riskonami |
|---|---|
| IRAM 2.0 | Base of the assessment — methodology for threats, likelihood, impact, inherent/residual risk, treatment, report |
| ISO 27001 | ISMS / governance reason to run a defensible risk assessment and treatment |
| ISO 27002 | Standard control catalogue used inside the IRAM 2.0 assessment |
| Corporate / best-practice controls | Your organisation’s controls, in the same IRAM 2.0 workflow |
| NIST CSF 2.0 | Optional stakeholder language; outputs can support CSF-style programmes |
What the product does (in the product)
Riskonami walks you through a ten-phase assessment of a system or process: profile the system, model architecture, assess controls and threats, estimate risk, plan remediation, and produce a final report. Throughout, the product:- keeps one active assessment session per run
- shows a conversation / action dock and inline worksheets driven by the server
- saves phase artifacts (structured JSON, and diagrams where applicable)
- lets you preview work before you accept a phase as done
What you produce (deliverables)
| Deliverable | What it is |
|---|---|
| Phase artifacts | Canonical structured outputs for each completed phase |
| Architecture diagrams | Where the phase produces DOT / visual models |
| Final report | Issued PDF (and HTML/DOCX downloads) with a label you choose — IRAM 2.0 methodology narrative plus your system findings |
| Report variants | Additional issued reports for other audiences after conclude |
| Session archive | Auditable snapshot after you end the assessment |
How phases work (server-orchestrated)
For every phase the server:- loads prior artifacts and decides the current step
- presents instructions, questions, quick picks, or worksheets
- validates structured answers
- commits the phase artifact when the phase is complete
- advances you to the next phase
AI enrichment — optional
You can use Riskonami without AI enrichment. Choose Skip / manual paths, enter data yourself, and build the report without AI Fill. When you affirm an enrichment action, the product may call AI to suggest or fill content (organisation context, diagram import, control/threat suggestions, report narratives, and similar). You still review and accept results.Free vs billable (high level)
Golden line: the guided assessment process is designed to be free. You pay for optional AI enrichment and optional expert validation — not for working through the phases manually. Download your data. Server copies are subject to retention; export reports and sessions you need to keep.| Free | Billable | |
|---|---|---|
| Guided phases, questions, worksheets | Yes | — |
| Manual / Skip instead of AI | Yes | — |
| Deterministic report Start / Restart / Issue (no AI Fill) | Yes | — |
| Affirmed AI enrichment (per gate) | — | 1 AI token per affirmed gate |
| Phase 10 AI Fill | — | 1 AI token per Fill request |
| Expert validation of an issued report | — | Expert validation token(s) |