DRAFT — REQUIRES REVIEW BY EXTERNAL ISO 27001 CONSULTANT AND SIGN-OFF BY BRITIAI CTO BEFORE USE IN BID OR AUDIT.
ISO/IEC 27001:2022 — Information Security Risk Register
Document ID: ISO04 Version: 0.1 (Draft) Date: 15 June 2026 Owner: BritiAI CISO (interim: CTO) Methodology: ISO/IEC 27005-aligned. Likelihood (L) and Impact (I) scored 1–5. Risk = L × I. Inherent risk is pre-control; residual is post-control. Review cycle: quarterly, or on material change.
Scoring key
- Likelihood: 1 Rare, 2 Unlikely, 3 Possible, 4 Likely, 5 Almost Certain
- Impact: 1 Negligible, 2 Minor, 3 Moderate, 4 Major, 5 Severe
- Rating bands: 1–4 Low, 5–9 Medium, 10–14 High, 15–25 Critical
Risk register
| # | Asset | Threat | Vulnerability | L | I | Inherent | Controls in place | L’ | I’ | Residual | Owner | Review |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| R01 | NHS patient data (future state) | Unauthorised access by Votee/Beever personnel | Weak tenant isolation, identity sprawl | 4 | 5 | 20 Crit | A.5.19, A.8.22, RBAC, no Votee identities in NHS tenants, audit logging | 2 | 5 | 10 High | CISO | Q3 2026 |
| R02 | Production cloud workloads | Account compromise via phished engineer | MFA fatigue, no FIDO2 on all roles | 3 | 5 | 15 Crit | A.8.5, MFA, SSO, EDR | 2 | 4 | 8 Med | HoE | Q3 2026 |
| R03 | Source code & model weights | Theft of IP via insider | Broad repo access, no DLP | 3 | 4 | 12 High | A.8.4, repo perms, NDAs | 2 | 4 | 8 Med | HoE | Q3 2026 |
| R04 | Training datasets | Data poisoning by malicious contributor | No dataset provenance signing | 2 | 4 | 8 Med | Code review; dataset registry planned | 2 | 3 | 6 Med | HoE | Q4 2026 |
| R05 | AI model in production | Prompt injection causing data exfiltration | Insufficient output filtering | 4 | 4 | 16 Crit | Input/output guardrails; allowlisted tools | 3 | 3 | 9 Med | HoE | Q3 2026 |
| R06 | Cloud KMS keys | Key compromise via misconfigured IAM | Default cloud-managed keys, no CMK | 2 | 5 | 10 High | A.8.24, TLS, at-rest encryption | 2 | 4 | 8 Med | HoE | Q4 2026 |
| R07 | Endpoint devices | Lost/stolen laptop | Disk encryption inconsistent on contractor devices | 3 | 3 | 9 Med | MDM, FileVault/BitLocker on staff | 2 | 3 | 6 Med | HoE | Q3 2026 |
| R08 | SaaS tenants (M365/Google) | Account takeover via OAuth grant abuse | No DLP, no third-party app review | 3 | 4 | 12 High | MFA, SSO; DLP planned | 2 | 3 | 6 Med | CISO | Q3 2026 |
| R09 | CI/CD pipeline | Supply-chain compromise via malicious dep | No SBOM, no signing | 3 | 5 | 15 Crit | Renovate/Dependabot; SBOM planned | 2 | 4 | 8 Med | HoE | Q4 2026 |
| R10 | Production logs | Log tampering hiding breach | Logs writable by app role | 2 | 4 | 8 Med | A.8.15, central SIEM, append-only | 1 | 4 | 4 Low | CISO | Q4 2026 |
| R11 | NHS contractual obligations | Breach of DSPT/Data Protection requirements | DSPT not yet completed | 4 | 5 | 20 Crit | UK-only residency; DPO; DSPT roadmap | 3 | 4 | 12 High | DPO | Q3 2026 |
| R12 | Sub-processor (Votee HK) | International data transfer non-compliance | IDTA not executed for all data flows | 4 | 4 | 16 Crit | Inter-company NDA; UK GDPR review underway | 2 | 4 | 8 Med | Legal/DPO | Q3 2026 |
| R13 | Sub-processor (Beever CA) | Personnel access to in-scope data | Job-role boundary unclear | 3 | 4 | 12 High | Contractual prohibition on NHS data; RBAC | 2 | 3 | 6 Med | HoO | Q3 2026 |
| R14 | Backup data | Ransomware deletes backups | Backup IAM shares prod credentials | 2 | 5 | 10 High | A.8.13, immutable backups (planned) | 1 | 4 | 4 Low | HoE | Q4 2026 |
| R15 | Office premises | Physical intrusion | Mixed-tenant building | 2 | 2 | 4 Low | A.7.1–A.7.3, key-card, clear-desk | 1 | 2 | 2 Low | HoO | Q1 2027 |
| R16 | Remote workforce | Insecure home network | No mandatory VPN for SaaS | 3 | 2 | 6 Med | Zero-trust SSO; MDM | 2 | 2 | 4 Low | HoE | Q4 2026 |
| R17 | Vulnerability backlog | Unpatched CVE exploited | No enforced patch SLA | 4 | 4 | 16 Crit | Scanning in place | 2 | 3 | 6 Med | CISO | Q3 2026 |
| R18 | DNS / domain | DNS hijack | Registrar lacks MFA | 2 | 5 | 10 High | Registrar lock; MFA enabling Q3 | 1 | 5 | 5 Med | HoE | Q3 2026 |
| R19 | Third-party AI model APIs | Outage of foundation model provider | Single-vendor dependency | 4 | 3 | 12 High | Multi-model routing planned; SLAs | 3 | 2 | 6 Med | HoE | Q4 2026 |
| R20 | Customer support inbox | Phishing/social engineering | No verified-caller workflow | 3 | 3 | 9 Med | Awareness training | 2 | 3 | 6 Med | HoP | Q4 2026 |
| R21 | Personal data of employees | Unauthorised disclosure | HR system access overly broad | 2 | 4 | 8 Med | RBAC; UK GDPR; DPO oversight | 1 | 4 | 4 Low | HoP/DPO | Q4 2026 |
| R22 | Incident response | Delayed detection of breach | No 24/7 SOC; alert backlog | 3 | 5 | 15 Crit | SIEM in place; on-call rota gaps | 2 | 4 | 8 Med | CISO | Q3 2026 |
| R23 | Disaster recovery | Inability to recover within RTO | No tested DR runbook | 3 | 5 | 15 Crit | Multi-AZ deployment | 2 | 4 | 8 Med | HoE | Q1 2027 |
| R24 | Compliance posture | Loss of ISO 27001 certification path | Resourcing of ISMS underfunded | 3 | 5 | 15 Crit | Roadmap (ISO06); fractional CISO planned | 2 | 4 | 8 Med | CTO | Q3 2026 |
| R25 | AI ethics / safety | Model produces harmful clinical output | Insufficient red-team coverage | 3 | 5 | 15 Crit | Eval harness; human-in-the-loop; out-of-scope clinical decisions | 2 | 4 | 8 Med | HoE | Q3 2026 |
Risk treatment decisions (summary)
- Critical (15–25) inherent risks are treated with active mitigation and tracked monthly until residual is High or below.
- High (10–14) residuals are reviewed quarterly; R01 and R11 are gating risks for the NHS SBS award and have dedicated workstreams in ISO03.
- Risk acceptance is permitted only with written sign-off by the CTO and a documented review date.
- All residual risk owners are accountable to the next Management Review.
Aggregate risk position
- Critical inherent risks: 9 → reduced to 1 residual (R11) after treatment.
- High inherent: 6 → 0 residual High after planned treatments complete.
- The single residual High (R11, NHS DSPT) closes upon DSPT submission and acceptance, targeted Q4 2026.
End of document.
