PRISM maps how AI systems produce and propagate signals, links them to risk, and delivers 21 structured outputs across your organisation — continuously, not once a year.
Existing frameworks classify risk, quantify losses, define governance requirements, and specify control obligations. None of them tells a practitioner how to read the observable signal state of a live system. They treat signal interpretation as something the practitioner brings to the framework. PRISM closes that gap.
PRISM is both a formal methodology and a working software system. It is domain-agnostic by architecture and calibrates to any environment where risk can be read through signals. PRISM-C is the cyber and AI risk instantiation. It accepts inputs from your existing environment, applies a structured signal taxonomy and a five-property propagation model, and delivers 21 structured outputs across the organisation — continuously, not once a year.
PRISM sits at the centre of your risk and security ecosystem. It does not replace your cyber defence capability or your risk management function. It gives every function something they currently do not have: a structured, auditable, continuously updated read of the signal environment around them.
Structured outputs from a single assessment, serving every organisational function simultaneously from one underlying signal evaluation.
Formally defined signal categories — including absent signals and strategic signal ambiguity, which no other methodology addresses.
Temporal layers — before, during, and after an event — so PRISM operates across the full lifecycle of a risk signal, not only after something has gone wrong.
A fire inspector cannot predict when or where a spark will occur. But the inspector can measure exactly how flammable the building is: whether fire can travel from room to room, whether the smoke detectors work, whether the fire doors hold, and whether anything inside will accelerate a fire faster than people can respond.
That inspection does not require knowing when the spark arrives. It measures the conditions that determine what happens when it does.
PRISM performs that inspection on any AI or cyber system. It does not predict the exact path an event will take. It measures the flammability of the environment the event would land in — how fast risk can spread, how visible that movement is, and how difficult it will be to stop.
Can fire travel from room to room? Do the alarms work? Will anything accelerate the spread?
How does this AI system propagate signals? How fast can risk spread? Is the environment so opaque that damage would be invisible until it is too late?
21 structured outputs telling every function in your organisation exactly what the signal environment looks like — before the spark arrives.
This is one of the clearest methodological departures from conventional risk practice, which often treats silence, normality, or unresolved ambiguity as administratively neutral unless an event threshold has already been crossed. PRISM formalises all four categories and requires each to be assessed on its merits.
The category conventional monitoring is designed for. Adverse events, anomalies, and deviations from baseline. PRISM captures these and situates them within the full signal picture rather than treating them in isolation from the three categories most monitoring tools miss entirely.
A system generating no alerts is not necessarily functioning correctly. It may have lost the ability to detect and report. A reporting period passing without exceptions, findings disappearing from a risk register without resolution, or a week without any attack attempts — all carry information. Absent signals are frequently the earliest warning available.
A risk environment that appears uniformly clean, consistently exception-free, or lower in variance than the operating context would reasonably suggest. A system generating no alerts while reporting high availability may have had its logging compromised or thresholds adjusted to suppress anomalies. Suspiciously positive environments should trigger verification, not reassurance.
The formally defined fourth category. Signals that exist but are deliberately maintained in a form that resists stable classification. The ambiguity is the intended outcome — which distinguishes this from ordinary uncertainty. In practice it appears as engineered grey zones, unresolved but administratively acceptable states, or conditions maintained precisely to avoid a definitive assessment.
Alongside the signal taxonomy, PRISM derives five system properties — Adaptive System Gradients — that describe the environment through which any event must propagate. Two systems facing the same initial disturbance produce very different outcomes depending on their propagation environment. PRISM measures that environment.
Degree of independent action capability. Higher autonomy accelerates propagation before human intervention is possible.
Monitoring visibility and explainability. Higher opacity means compromise or drift may spread before it is detected.
Density of dependency across connected systems. Higher coupling increases propagation reach and compresses response time.
Trustworthiness of inputs and instructions. Lower integrity increases manipulation and contamination risk at scale.
Strength of technical and operational boundaries. Weak containment produces an expanding or undefined blast radius.
A single PRISM assessment produces 21 structured outputs serving different organisational consumers simultaneously. Security operations, risk quantification, compliance, legal, audit, and executive leadership each receive the signal intelligence relevant to their role. The outputs are designed to be auditable, reproducible, and independent of the systems being assessed.
| # | Output | Primary Consumer |
|---|---|---|
| 01 | Overall Score and Rating | Executive and board reporting |
| 02 | Events Triggered | First-line and second-line risk teams |
| 03 | Chain Analysis | Operational risk and incident response |
| 04 | Kill-Chain Pattern Detection | SOC and threat intelligence |
| 05 | Risk Taxonomy Mapping | Threat intelligence and compliance |
| 06 | Control Failure Analysis | Control owners and internal audit |
| 07 | Regulatory Resilience Assessment | Compliance and regulatory functions |
| 08 | FAIR-Style Risk Indices | Risk quantification functions |
| 09 | Invisibility Score | SOC, monitoring teams, and governance |
| 10 | Toxic Signal Assessment | Risk governance and executive leadership |
| 11 | Strategic Mitigants | CISO, risk owners, business continuity |
| 12 | Environmental Module Summary | Second-line risk and governance |
| 13 | Third-Party Risk Summary | Vendor management and third-party oversight |
| 14 | Intelligence Layer | Board, audit committee, senior management |
| 15 | Evidence Preservation Guidance | Legal, audit, and compliance functions |
| 16 | CIA+A+NR Impact Assessment | Governance, compliance, and control owners |
| 17 | Propagation Velocity and Response Window | Incident response and business continuity |
| 18 | Assessment Confidence Band | All consumers |
| 19 | Designed-State Drift Analysis | Architecture review and governance |
| 20 | Organisational Signal Culture Indicator | Board, audit committee, external auditors |
| 21 | Reassessment Schedule | Risk governance and compliance |
PRISM does not require replacing existing infrastructure. It reads inputs from sources your environment already produces — logs, telemetry, governance documentation, access records, vendor outputs — and processes them through a structured four-layer architecture. The scoring is deterministic: the same input produces the same output every time, making every finding traceable and every conclusion auditable.
Every assessment begins with a structured threat profile characterising the relevant actor type, vector, intent, and capability level. From this, the five Adaptive System Gradients are derived from the system's current operational state — not its intended design. Three signal quality modifiers then calibrate the assessment when the signal environment itself is unstable: the Signal Volatility Index, Vulnerability Dwell Time, and Intermittent Threat Pattern. When the assessed system includes AI, machine learning, or autonomous action capability, the AI Gate activates a structured assessment branch that adjusts derivation logic accordingly.
Classified signals are processed through a four-step transformation: observations become system properties, properties become patterns, patterns become risk meaning, and risk meaning becomes action-oriented outputs. Chain analysis asks whether observed conditions form a propagation sequence. Compound pattern detection asks whether the property profile reveals structural fragility. Where conditions combine in ways that aggregate scoring cannot adequately represent, toxic signal clusters trigger the hard-floor principle — a structural refusal to average categorically severe conditions into a moderate or low-risk interpretation.
Before an event, PRISM functions as a susceptibility and fragility assessment. During an event, it updates as observable conditions change. After an event, it serves as a forensic evidence base that can reconstruct the signal environment at any point in the record. This temporal architecture means PRISM operates across the full risk lifecycle rather than only at defined assessment points. The reassessment schedule output assigns a structured refresh cadence because not all findings age at the same speed.
All signal classifications and scoring outputs are retained in an evidence layer that is structurally independent of the systems being assessed. When an incident occurs, PRISM can reconstruct the signal environment at any point in the record. Signal suppression attempts are captured rather than lost. Post-mortems become evidence-based rather than reconstructed from memory. The evidence preservation layer is designed to support audit use, regulatory review, and legal defensibility from the first assessment onward.
PRISM's domain-agnostic architecture remains structurally stable across distinct signal-bearing environments through domain-specific calibration. Domain transferability has been validated across ICT and cyber risk, financial crime and KYC signal assessment, and relationship dynamics.
The signal intelligence layer for organisations deploying or procuring AI systems in regulated environments. PRISM-C maps how AI systems produce signals, how those signals propagate and move, and how they link to risk taxonomy — making AI system behaviour visible and interpretable by the governance functions responsible for it.
Built for environments where "the model said so" is not a risk management position and regulatory scrutiny is already active.
Signal mapping for financial crime environments — identifying negative, absent, anomalously positive, and ambiguous signals in transaction monitoring and customer due diligence, with reference to FATF typologies.
The signal taxonomy applied to interpersonal and organisational relationship risk, including the formal treatment of hyper-priming — concentrated positive signalling designed to reduce verification and increase misplaced trust.
The core PRISM methodology, calibratable to any environment where risk can be read through signals, system properties, propagation conditions, and structured outputs.
If you are accountable for AI risk, cyber resilience, or regulatory compliance in an environment where AI systems are deployed or procured, PRISM gives you the analytical foundation that model cards, vendor assurances, and annual assessments do not provide. It serves the people who have to sign off, not only the people who built it.
Responsible for the security posture of environments that now include AI systems whose signal behaviour is not visible through conventional monitoring. PRISM-C provides a structured, continuous read of AI-specific signal propagation that existing security tooling does not produce.
Under increasing pressure from regulators who are asking, in specific and enforceable terms, what AI governance looks like in practice. PRISM produces outputs that answer that question in defensible, auditable, and continuously updated terms aligned to DORA, the EU AI Act, and sector-specific obligations.
Evaluating AI vendors requires more than reading their documentation. PRISM provides a structured due diligence framework for assessing the signal environment of third-party AI systems before and after deployment, with outputs your legal and compliance teams can use directly.
PRISM's deterministic outputs and evidence preservation layer are designed for audit use from the ground up. The methodology produces findings that are traceable, reproducible, and structurally independent of the system under review — which is the standard that AI audit actually requires.
Reaction time to risk signals has become a competitive and regulatory variable. AI systems propagate faster than most monitoring assumptions were designed for. The gap between what regulators require and what organisations can demonstrate is widening. Waiting for an annual assessment cycle is no longer a viable approach to AI and cyber risk.
The EU AI Act, DORA, and sector-specific AI guidance from financial and healthcare regulators are active requirements with enforcement timelines. Organisations need to demonstrate structured AI risk governance with continuous evidence, not point-in-time reports.
AI systems do not come with a structured account of how they produce signals, how those signals propagate, or how they link to risk. PRISM is the first methodology to formally map that process, making AI system behaviour visible and interpretable by governance functions.
PRISM's signal taxonomy formally captures anomalously positive signals — environments that look clean immediately before something goes wrong. This is the pattern that precedes most significant incidents and the category that conventional monitoring does not capture at all.
Without a structured signal record, organisations cannot reconstruct what the risk environment looked like before an incident. PRISM's evidence preservation layer creates that record continuously. Building it retrospectively is not possible.
Threat actors do not wait for your annual risk review. A methodology that delivers signal intelligence once a year is not a risk management tool — it is a compliance document. PRISM operates continuously because that is the tempo at which the signal environment actually changes.
PRISM is the first methodology to formally define how AI signals should be read and how they propagate through a system. The 21-output architecture, the four-category signal taxonomy, and the five Adaptive System Gradients do not exist in any other framework.
PRISM is available for advisory engagements, methodology briefings, and implementation projects. If you are evaluating AI risk governance approaches or need a structured assessment of a specific AI or cyber environment, reach out directly.
The full PRISM methodology is available as a peer-referenceable preprint on Zenodo.
An initial conversation will focus on your environment, your current AI risk posture, and where PRISM's signal intelligence outputs would be most immediately useful.
PRISM-C engagements are structured around your existing infrastructure. No proprietary data environment is required and no existing tooling needs to be replaced.
If you are a researcher, standards body, or regulator with interest in the methodology, academic and institutional enquiries are also welcome.
Hannimari Karola Savola
ISO 31000 Certified Risk Manager
ISO 22301 Lead Implementer
MSc Strategy and Management in International Organisations
Independent Researcher, Frankfurt, Germany