# ApertureRisks Exposure Assessment Methodology

Version: 1.0 — July 2026

## Purpose

This methodology explains how ApertureRisks turns client-provided operating records and source intelligence into an evidence-backed exposure assessment. The assessment is decision support, not an automatic action or a legal, customs, insurance, financial, or certification determination.

## Workflow

1. Confirm the tenant, supplier identities, decision question, assessment period, and accountable owner.
2. Validate structured supplier, relationship, BOM, lane, facility, contract, financial-basis, supplier-performance, and evidence records.
3. Link signals or operating conditions only to client records they can defensibly affect.
4. Assess severity, source confidence, exposure relevance, financial basis, evidence state, and action readiness independently.
5. Deliver prioritized findings, evidence lineage, limitations, recommended next actions, owners, and open evidence requests for human review.

## Data rules

- Missing values remain missing and never become zero risk.
- Client exposure requires a client-scoped relationship or operating record.
- Financial exposure is shown only with a recorded basis.
- Supplier performance uses explicit structured measurements and publishes no score when inputs are insufficient or conflicting.
- External source intelligence without a verified client linkage remains external context.
- Every evidence request remains open until a received response is explicitly validated.

## Output

The assessment output identifies the scope, connected records, source freshness, findings, exposure basis, confidence basis, evidence gaps, recommended actions, accountable owners, and limitations. Recommendations require authorized human review.

## Versioning

Material changes to formulas, required fields, weighting, or decision boundaries require a new methodology version and regression tests. Phase 1 freezes creation of new engines; work is limited to closing and validating the existing registered capabilities.
