Risk Score
Pronunciation: RISK SKAWR
Definition
A risk score is a numeric or categorical value summarizing assessed exposure, priority, or decision conditions under a defined method. Risk Score must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Risk Score to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.
Overview
Risk scores combine selected factors such as likelihood, impact, transaction behavior, control strength, vulnerability, or customer characteristics. They may support triage, limits, authentication, review, pricing, monitoring, or portfolio reporting.
The same score can mean different things across models, versions, populations, and time periods. Compression into one value hides uncertainty, factor interactions, severe low-frequency outcomes, and the reason a case received that result.
Organizations should document scale, interpretation, inputs, thresholds, version, missing-data behavior, calibration, and permitted uses. Decision logs should retain the score context and reason codes, while outcome testing monitors drift, bias, false positives, and manipulation. Users should know whether a score measures current exposure or future probability.
Risk Score is a generic model output whose scale, subject, outcome window, and evidence must be stated before it can support a decision.
A risk score is a numeric or categorical value summarizing assessed exposure, priority, or decision conditions under a defined method. A risk score is a governed summary for a specific purpose, not a universal fact or substitute for underlying evidence and uncertainty.
For Risk Score, the assessment should evaluate a numeric or categorical value summarizing assessed exposure, priority, or decision conditions under a defined method. The assessment record should separate observed evidence supporting a numeric or categorical value summarizing assessed exposure, priority, or decision conditions under a defined method from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in a numeric or categorical value summarizing assessed exposure, priority, or decision conditions under a defined method have changed enough to require a new rating, treatment, or approval.
Key Takeaway
A risk score is a governed summary for a specific purpose, not a universal fact or substitute for underlying evidence and uncertainty.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)