Risk leaders face growing pressure to report risks, explain how those risks were assessed, and make a credible case for how they may evolve. Yet most organizations still rely on manual processes, inconsistent methodologies, and point-in-time snapshots that cannot hold up in board meetings, audits, or regulatory reviews. Watch this Solution Showcase to see Risk Assessment Intelligence, Origami Risk’s new AI-powered capability for Enterprise Risk Management (ERM). You’ll see how Modeling and Validation work together to help organizations simulate future risk scenarios, surface inconsistencies across assessments, and build a traceable foundation for more confident decision-making. Origami Risk brings together the tools risk teams need to move beyond static reporting and into more strategic, forward-looking conversations with leadership. What you’ll learn: How AI-powered Modeling simulates how risks may evolve over time, while keeping users in control of every assumption. How Validation surfaces inconsistent assessments across your risk program and creates a transparent, traceable record. Why point-in-time risk assessments fall short in board meetings, audits, and regulatory reviews and what to do instead. How organizations can move from static risk reporting to more strategic, forward-looking conversations with leadership. What a traceable, defensible risk assessment process looks like in practice. Hey. Good morning, and welcome, everyone. Thank you for joining us on today’s solution showcase defensible risk assessment intelligence. Well, I’m excited to have you here and walk through this, new solution, and I’m Raina Hawthorne. I’m gonna be guiding today’s conversation, and I’m joined by Josh Newsum who’s gonna walk us through the product demonstration. Over the next fifteen, twenty minutes or so, we’re gonna focus on the one question that is really becoming increasingly important for our enterprise risk teams. If you are asked why a particular risk has received its score, how confidently could you explain the answer? We’ll start by looking at why that question is getting harder to answer. Then we’ll introduce the origami risk risk assessment intelligence capability and show how the modeling and validation tools work together to create a more forward looking traceable assessment process. Then we’ll spend, or and we will spend most of our time in the product. We’ll finish with the key few key takeaways and questions. Alright. Let’s dive right in. Josh, do you wanna walk us through why this question is getting harder to answer? Yeah. Absolutely. You know, thanks, Raina. So, you know, interestingly, I think most risk leaders, don’t really have a confidence problem on the surface, on their program, the result that they ultimately produce. They know their organizations well. They know their risks in their environment, and likely they’ve got experienced people contributing to that assessment process at the end of the day. The challenge, right, is what sits underneath that final risk score rating? What do they produce coming out of that assessment? Score is high. It’s a five. It it’s it’s urgent. What does all of that actually mean at the end of the day? So I think in many organizations, assessments are still point in time exercises. Right? They’re they’re gathered across spreadsheets, workshops, you know, emails, or even other, different business units. Methodologies ultimately might be really well intended, but assumptions are not always applied consistently across those risks and the assessments. And I think what we see is, like, the rationale behind the score, as you alluded to, can be really difficult to reconstruct later. So that that leads us to three common problems that many of our clients are are seeing today. You know, first, those assessment scores, they vary across teams without any kind of clear or traceable explanation. Right? So two groups might evaluate, you know, similar risks differently, and the risk team is left reconciling, you know, that difference manually. So why are the scores different? Which thought process wins out? What assumptions what went into that risk? You know, the task becomes a heavy burden on deciphering the noise between different opinions on risk and how does that translate into something that gets reported back to leadership boards and committees. Second problem, right, is these are stack assessments. Right? They they go stale between the formal risk cycles. You think about the most common use case, we evaluate a risk, you know, maybe it’s a periodic assessment. It’s the first of the year. We pick it up and do it again that, you know, we do the same exercise again next year. And heat map might show where risk sits today, but it doesn’t necessarily help leadership understand how that risk could change, you know, over the next year, over the next three years, over the next five years. Organizations typically consider things like likelihood. But what does that actually mean? Right? Maybe there’s a certain percent of chance that that risk occurs in a given year or over some sort of time horizon or even at all. Or when an executive or board member says, you know, why is this risk a four, not a three? Right? We’re getting really particular. Usually, you know, the answer is based on some sort of consensus and intuition rather than traceable, you know, evidence. And as we get into this simulation discussion or or intelligence discussion, the simulation really replaces some sort of, like, arbitrary single number with the defensible distribution. Right? It shows the range of potential outcomes instead of some sort of static guess. And then finally, right, you know, that third challenge that we’re seeing is the the pressure on the risk function has changed. Right? You know, boards and audit committees are increasingly expecting more than a list of our top risks. Don’t come to me with a flat list of our risks, what was the score now, and what was it last year. Now they’re asking other questions aside from just what are the strategic and goals linked to those risks. Now they wanna understand the underlying methodology. Right? The assumptions. How is the organization preparing ultimately for what might for what might come next? And so, you know, I think the the end result here, right, is risk team spent a significant amount of time defending the process behind those numbers instead of using those numbers to guide a more strategic, you know, conversation. Or, ultimately, right, those those numbers are meaningless if they don’t drive any particular action with who they’re being reported to. Exactly. And I think you hit on a lot of things that are gonna be familiar to our audience today, which is exactly some of the challenges that the risk assessment intelligence tools are designed to address. They’re built directly into our enterprise risk management solution, and it comes with two key pieces. So first, modeling is gonna help risk teams explore how risk behave over time and how those might look in those different time horizons. You know, if the company is doing five year planning, the risk team can get right in that conversation very easily with the risk, simulation that looks out five years. Right? And it gives users that forward looking view while keeping a human in control of the inputs, recommendations, and final decisions. So this tool does run with AI, but everything is human validated at the end, which brings us to the second piece of the application, which is validation, which applies systematic logic based comparisons to the manual human assessment that happened and the AI assessment that was created during the simulation. And when those surface inconsistencies, it explains why it thinks there’s a difference, and then it creates a record that is traceable that can support you know, be brought in to support a board or audit or regulatory conversation. So really powerful things packed in here, But I’ll stop talking about what it can do, and, Josh, maybe let’s take a look at this thing in action. Thanks, Raina. Let’s go ahead and dive right in. So here we are in Origami’s new risk simulations experience solution. This process begins with a few quick but important configurations. So first, we’ll go ahead and start with the global narrative or more simply an organization overview. This gives the model the organizational context it needs to produce relevant and consistent outputs. It could include information such as the organization’s industry, business model, geographic footprint, major products or services, or frankly any other facts that help ground the analysis at the end of the day. The global narrative is really important because AI outputs are only as useful as the context behind them. The organization can control this information and can update it as the business changes, perhaps under m and a activity, the way that you execute business, types of goods or products or services that you produce or offer up to, the public. Next, we’re gonna move on to the model configuration. And, ultimately, what this configuration is doing is telling us when we perform a simulation, at what time frames are we looking to simulate. It’s often the case that we’re looking to understand what is the effect of that risk over a period of time. So you may choose the model to set it one month, three months, six months, or even multiyear type of duration. And then finally, we can look at how many iterations are ultimately executed as part of the simulation. Effectively, more iterations can produce a smoother probability distribution while fewer iterations, you know, they might be useful for an initial test or walk through as you’re as you’re learning the tool. So let’s go ahead and move on to the actual simulation. And what we’ll do is start by picking a small group of priority enterprise risk so we can focus on the workflow rather than the size of the risk register. So once I selected a risk, Origami’s risk assessment intelligence recommends the ultimate probability distributions. And so what this is telling us is what type of context did you provide, what impact drivers are going into this particular risk, which in this case happens to be a malware infection or a cybersecurity risk to the organization, is looking at other items such as what are the likelihood drivers, and then it’s coming up with a baseline. So it’s saying based off of the narrative that you gave us and these assumptions that we’ve made, we believe the baseline estimates for some sort of event are x amount of impact in range and occurrences over the course of a given year, and then it documents what those assumptions are. Now let’s assume for a moment that we need the tool to take into account other assumptions. And then maybe in this case, it means some sort of mitigation or control that we’ve applied to this risk within the business. So in this case, the organization we’re looking at here, Sonora Peak Software, maybe they’ve implemented a few controls to help with malware infection. So in this case, those controls might be things like vulnerability and patch management tool and some sort of malware detection tools. So I’ll go ahead and feed this information into the intelligence tool, and it will process an updated set of baseline estimates before we run our simulation. So as this quickly processes with Origami’s versus AI, we can go ahead and tell those impact values have changed. As we might expect if we’re implementing solid controls, the impacts and the likelihood and the amount of events ultimately comes down. So we’ll go ahead and apply those suggestions, and then we’ll move on with our with our simulation. Once we confirm these values and we run the simulation, the output from Origami is whatever the results are of those underlying simulations. So across the bottom of the screen here, now we just need to interpret the sim the simulation. And these results show how these risks may behave over the different selected time horizon. So rather than relying on a single static score, the risk team can see a range of potential outcomes and discuss where uncertainty may increase, decrease, or compound over time. So as I take a look, of course, looking at a one month interval, we can see our risk score is x as is our exposure and a certain type of confidence interval. And, obviously, the ten thousand iterations were simulated. As I move up that time horizon, the exposure becomes greater over time. Obviously, as time goes on, we’re more likely to have an event, and the impact of the organization is, you know, compounded. This gives the risk leader a much stronger foundation for some sort of executive conversation. So instead of saying, just this risk is higher, this risk is low, they can explain how that exposure could change, what assumptions are driving that view, and where management attention ultimately might be the most valuable. So after reviewing the model outcomes, we really move into validation. Right? And this is where the connected workflow becomes especially important in Oregon. So validation compares assessment results systemically and looks for inconsistencies across risks, business units, or other prior periods. So here, for example, we can see a a variance. Right? So, ultimately, if we had performed some sort of assessment on our own on this risk in the business, and then we simulated a score using the underlying assumptions, there’s a large disconnect between what we thought the risk was and what the simulation ultimately told us. As a result, we have the ability to have Origami’s intelligence tool tell us not only what the difference is, but what are the drivers? Why why is this change different? What might it know about this particular risk that we haven’t considered? By the end of the workflow, the organization is more than some sort of simulation result. It is a traceable record of the assumptions, the recommendations, overrides comparisons, and explanations that ultimately shape this assessment. Initially, you can reduce the amount of reconstruction required before a board meeting or auto review. Also helps that risk team build a more consistent process over time. I should also mention that just because the AI simulator comes up with a particular score, there still could be underlying context. There may be something unique about this risk or the environment that you’re operating on or even current events that can’t be accounted for through AI. You always have the ability to come into the application and take what the system provides and still create some sort of an override. I think that the impact and the likelihood are lower in alignment with my, you know, impact and likelihood scales because of those underlying conditions. And then I can apply or save those scores or even supply some sort of a comment into the tool, and that lives and breathes against that risk record. So what you’re really seeing here is a shift from a static point in time assessment towards a forward looking and defensible risk narrative. And that is Origami’s risk simulation experience. Awesome. Thank you so much, Josh. So what you all just saw was not just a faster way to run an assessment, but it was a way to build more confidence in the results and the processes behind it. And we’d like to just reiterate the three key takeaways. And as before I get into that, if you do have any questions, feel free to drop them in the q and a box, and we will get to those shortly. But our first of the three key takeaways is that modeling is gonna help teams move beyond a static snapshot when it comes to their risk. It’s gonna give them a way to explore how risk evolve over time and bring that more forward looking perspective into key leadership conversations. Secondly, validation is gonna help make assessments, assessments differences visible and explainable and create a stronger, more traceable foundation for those conversations as well. And thirdly, we think that this is a core kind of tenet of our AI approach, but human judgment should always remain at the center. Users should review the AI’s assumptions, adjust the recommendations if needed, and the system documents over documents overrides automatically, and that nets out to the final decision. Ai is strengthening the process, not replacing the expertise of your teams. Right. Right. And, you know, I just might add. Right? You know? Also, you know, model modeling and validation, they work on an organization’s existing data methodology. So it’s gonna really just be a practical next step for teams that wanna mature their program with starting over. It doesn’t require rewriting your risk register, or or rethinking about the way that you execute your own assessments. It’s a way to scale and use it as a solution that allows, you know, our our our clients to be able to move into the next favor phase of a advanced risk assessments. Yeah. Absolutely. And if any of y’all would like to explore how the risk assessment intelligence could help support your program, you can reach out to the Origami risk team. Anybody would happy be happy to walk you through it, or you can complete the short survey following today’s session and just indicate your interest. We would be more than happy to arrange a deeper conversation tailored specifically for your program. Alright. Let’s take a look and open it up to questions. If you do have any questions, please feel free to drop them in the, q and a box. Otherwise, we will get started with this first one. And they just asked, is risk assessment intelligence, is this tool intended to replace human assessment and, like, human judgment? Josh, you wanna take that one? Yeah. Of course. No. Emphatically, no. Right? You know, human human judgment remains central to to the workflow. Right? AI recommends, you know, assumptions and ranges, but, ultimately, users, you know, dictate or or get to review those recommendations, you know, adjust them where they’re needed and and make a final conclusion. Right? So every override could be documented, which actually strengthens the defensibility of the assessment and and is able to evaluate what assumptions the tool made, what we know about our business, and decide whether the recommended ratings fit our business, or if we need to make some adjustments to those, underlying ratings and assessments. Absolutely. Absolutely. Let’s see. Someone else is asking, how is this different from using just a regular AI, think Claude or ChatGBT, to summarize risk data? Yeah. I I think there’s a key differentiator here. Right? You know, when I think about generative AI, you know, we might be thinking about, you know, where risk ass risk assessment intelligence isn’t you know, it’s not simply producing some sort of narrative summary. Right? Modeling actually uses the data that we know about an organization’s organization or their underlying risk environment, you know, configured context context, the risk, how you’re scoring those assessments in the selected assumptions to how we simulate how the risk might behave over time. And so, you know, validation then compares that assessment outcome systematically and creates a traceable record of inconsistencies and, you know, and explanations. So, really, right, that values and that connected assessment workflow where generative AI might be able to tell you about the risk and what that risk might look like in a in a common type of situation. It doesn’t understand the underlying organization, you know, maybe the vertical that you work in, and all of the nuance that you might need to provide to it through the assumptions. Yeah. Great point. Great point. And I’ll just add that, you know, Origami has built these AI tools with prompts specific to the situation and kind of the task at hand where, you know, you’re gonna have to do a lot of explaining to get a standard AI tool to to get to that point of understanding to give it to what you need. Yeah. Yeah. Raina, one thing I might add there just to kind of wrap up that answer, you know, is the ability you know, you think about scenarios as well. And so as we think about those assumptions, you know, of course, the the the tool is going to simulate the, you know, the the outcomes based off of all of the underlying assumptions. Well, I think what we’re going to find is that our is that our clients are going to ultimately apply different assumptions and look at the different outputs. And not only does that tell you based off of what we have in place today with the outcome might be, but if we apply different, you know, scenarios to those assumptions, we can see what the effect of that risk might be. So, know, we provide a certain level of investment in the control that’s, you know, high or low. What effect does that have on the risk? And I think it tell starts to tell a story that isn’t something that, you know, has has old something that has been missing in this space for a while. Yeah. Yeah. Absolutely. I think we could talk about this all day. But let’s let’s see. Let’s take just a moment and answer. Maybe this one will be a little quick answer before we wrap. Someone asked, can this be used for IT or cybersecurity risks, or is it just broader enterprise risks? Yeah. Really, answer is all risks. Right? So IT and security leaders, they face the same pressure to explain, you know, how risk posture was assessed as any other risk in the business. So as long as those risks are managed, within the supported ERI methodology within Origami, modeling can help them explore how exposure can change over time, how that validation can create a more consistent or traceable assessment record. So, really, it is not specifically tailored toward any risk group within the, you know, within Origami. It can be used across the enterprise. Yep. Absolutely. Great answer there. Awesome. That brings us to the end of our time for today. Thank you all for joining us for this solution showcase. And, again, if you want to explore, any of these tools further, just reach out to our team, and we would be happy to help. Thank you so much. Thank you.