The method · Published
Five weeks · Six steps · In public
The method·Published

The rail, in public.

This is the actual normalization method — week by week, artifact by artifact — and the quarterly loop that follows it. We publish it because the method isn’t the moat. The rhythm is.

Methodology 2026.2 · bumps when a box, a gate or a testing standard changes — never for a copy edit · the version on every engagement page points here

Normalization

Five weeks, five artifacts.

Each week produces something you can hold. If a week ends and nothing landed, the rail has slipped — and you’d know.

Week 1 · KickoffArtifact: the intake file
  • 01Document intake against a nine-item checklist: current register (however dead), last risk report to the board, org chart, incident log, audit findings, policy index, KRI/metric inventory, prior assessments, committee calendar
  • 02Access provisioned — portal live, Risk Radar environment stood up
  • 03Cadence set — interview slots, workshop date and readout date fixed in week one, not found later
Week 2 · Owner interviewsArtifact: the interview record
  • 0145 minutes per owner, structured by a twelve-question guide — what could genuinely hurt, what already has, what’s assumed but unverified, what they’d fix with one budget line
  • 02The rule: we interview the people who hold the risk, not the people who write about it
Week 3 · RebuildArtifact: the draft register
  • 01Taxonomy rebuilt — risks stated as consequences, not categories; duplicates merged; orphans retired
  • 02Scored on a defined 5×5 — likelihood and impact scales with written definitions, so a “4” means the same thing in every room
  • 03One name per risk. Committees don’t own risks; people do
Week 4 · Calibration workshopArtifact: the decision log
  • 01Ninety minutes with leadership. The draft is challenged live — scores argued, ownership contested, risks added and killed
  • 02Every change is logged with its reasoning — the decision log is what makes next quarter’s movement explainable
  • 03Partner in the room — this is one of the three moments partner judgment is printed into the box
Week 5 · First pack & readoutArtifact: the pack
  • 01The register goes live in Risk Radar — scored, owned, moving
  • 02The first board pack is issued and walked through in a single readout
  • 03The rhythm begins — the next refresh is already on the calendar
The pack’s exact structure is publicSeven pages

Why publish the rail?

Because any competent team could run these five weeks once — and that was never the product. The product is the loop below running every quarter without drama, at a price printed on the page, with the discipline to name what doesn’t belong in it. Methods are copyable. Rhythms are kept.

The quarterly loop

Six steps. Every quarter. No drama.

The loop, mechanicallyOne price
  • 01Evidence sweep — incidents, KRI movements, audit findings, org changes, external events, pulled from named sources agreed at kickoff
  • 02Owner interviews — the printed number per subscription; same guide, so quarters are comparable
  • 03Register updated in Risk Radar — every score change traceable to evidence or an owner’s call, never to vibes
  • 04Pack built from the live register — movement, heat, movers, watchlist, scope-change log
  • 05Peer review before issue — a second specialist signs the pack, every quarter, no exceptions
  • 06One readout — thirty minutes, leadership in the room, decisions logged
QA gate: peer review · partner at the readoutPrinted, not promised

What we don’t publish.

Two things, and only two. Your calibration parameters — the scale definitions and thresholds tuned to your organization in week three — because they’re yours. And your data, for the reason that needs no sentence.

Everything else about how this works is on this page. If you find a gap, ask it on the call — good gaps end up published.

The next step

Now watch it run on your register.

The method is yours to read. The rhythm is what you subscribe to.

See the risk register box Book a call