Skip to main content

ICS risks

Internal Control System (ICS) risks are a special risk data type for organizations that run a formal ICS — common under regulatory frameworks that follow a materiality concept. An ICS risk links directly to designated risk-relevant objects, records financial, regulatory, and reputational impact per object, and is automatically classified as material or not.

Requires the ICS Style Risks Early Access feature, enabled by an administrator under Admin → Server Settings → Early Access.

Overview

A risk becomes an ICS risk through its Data Type setting: choose Internal Control System on the risk's Settings tab. The rest of the risk object stays the same — what changes is how its data works:

  • Instead of one impact × likelihood series, the risk's Data tab links to risk-relevant objects and holds a data series per object. Which objects qualify is decided by your repository administrator, who designates resource objects — typically legal entities or organizational units — as risk relevant in the repository configuration.
  • Each data point records the Financial Impact, Likelihood, Regulatory Impact, and Reputational Impact, each at up to three levels: Initial (before controls), Residual (after controls), and an optional Target. Regulatory and reputational impact use the scale Not Applicable, Low, Medium, High.
  • An ICS risk has exactly one risk category, and its financial unit is fixed repository-wide by the ICS Risk Currency setting rather than per risk.

The Settings tab of an ICS risk: a single risk category, and the Financial Impact Unit read-only, configured under Repository, Risks, ICS Risks.

Materiality

Materiality is calculated per data point, against the materiality threshold of the linked risk-relevant object. A data point is material when any of the following is true:

  • the initial Regulatory Impact is Medium or High,
  • the initial Reputational Impact is Medium or High, or
  • initial Financial Impact × (initial Likelihood ÷ 100) is at or above the materiality threshold.

If the risk's category has its own threshold override in the repository configuration, that override is used instead of the object's threshold. If no threshold applies at all, materiality stays empty rather than true or false.

Materiality isn't recomputed on every keystroke: changes queue up, and once nothing has changed for 15 seconds the platform updates the materiality of all affected objects. Adding, editing, or deleting data points, changing thresholds or category overrides, changing a risk's category, and removing a risk-relevant object all trigger this update.

Key concepts

  • Risk-relevant object — a resource object designated in the repository configuration as something ICS risks can be measured against. Each carries a Materiality Threshold and an Impact Class Definition.
  • Materiality threshold — the numeric value at which a risk's weighted financial impact makes it material for that object.
  • Impact class definition — value ranges (by default Low, Medium, High, each with a color) that classify a data point's risk values on the object.

When to use

Use ICS risks when you run a structured risk and control system whose assessments always capture the same three dimensions: a quantitative financial estimate plus qualitative regulatory and reputational estimates. Those dimensions must always bear on your processes, too. If your assessments don't always include all three, or you want a more flexible, relative model (Risk A is higher than Risk B), use the Standard or Value data types instead — see Risks and controls.

It isn't either-or: the data type is set per risk, so different business areas of the same repository can use ICS risks and standard risks side by side.

One difference to plan for: ICS risks have no automatic control-based calculation. You relate Controls and Control Instances to an ICS risk exactly as you would to a standard risk, but their ratings don't reduce anything — you evaluate the controls' effect yourself and enter the residual values by hand. Standard risks, by contrast, derive their residual value from the related controls' ratings — see Residual risk calculation.