# 1. The idea

## Every risk is already accepted

A risk does not wait for a decision to exist. The moment an agent is given write access to production, or a supplier holds customer data, or a control is switched off for a release, the exposure is there. The organisation is carrying it. What is missing is the answer to two questions: **who has accepted it, and until when?**

In most organisations the honest answer is "nobody in particular" and "until somebody notices". The register has a row. The row has an owner, which is usually a function rather than a person, a rating, and a review date months away. Nothing connects the row to the configuration, the access list or the log that made it true, and nothing happens when the review date passes except another review.

## There is no deny button

A register that lets a risk be rejected lets the organisation pretend it is not carrying it. You cannot vote a fact out of existence. So the choice at every point is between three doors, each with a name against it: **accept it for a stated interval, fund the work that reduces it, or fix it.** Silence is not a fourth door. A risk that nobody accepts is treated as critical and rolls up to the holder's boss on its own.

## The interval is the decision

Accepting a risk for four hours is declaring an incident. Accepting it for two weeks is committing an existing team to a fix. Accepting it for a month is funding the work. Accepting it for six months is saying, with a name on it, that it is not worth doing anything now. The length of the acceptance is what tells the organisation what to do next, and when the interval ends the same decision comes back to the same desk, with the evidence attached.

## Every path ends at the board

Every risk has a holder. Every holder has a boss, and that boss's boss, up to the board. The chain is computed, not reported: a board member sees a risk arrive because the graph says it must, not because somebody chose to write a paragraph about it. No risk is orphaned.

## From the board to the bytes

A risk at the board is a line such as "loss of customer funds". Underneath it are business risks, operational risks and technical risks, each with its own holder, down to the configuration file that makes it true. The same grammar applies at every altitude: established by facts, ended by facts, held by a person, accepted for an interval. That is what graphs.sgit.ai calls a fractal risk register: one register per person who accepts risk, each in their own words, joined by named edges.

## Why this is a company

None of this is primarily software. It is the work of establishing risks on facts, connecting them to the people who hold them, running the clocks, writing the evidence down, and helping executives through a change most of them will resist at first. That is a service, delivered alongside whatever GRC platform the client already has, and it is the business this plan describes.
