Core Thesis: Today's risks—AI systems, climate cascades, supply chain disruptions, cyber threats—do not respect organizational boundaries. They propagate across sectors, jurisdictions, and timescales in ways that traditional risk management cannot address.
NRM solves this by providing shared infrastructure for risk governance: a common language for describing risks (GRIx), standardized evidence containers that any system can verify (AEPs), and clear rules for updating decisions when new information arrives. Organizations keep their existing frameworks—NRM makes them interoperable, auditable, and correctionable.
The result: risk decisions become traceable (every determination has a record), comparable (evidence follows the same structure), and correctionable (updates propagate without breaking the chain of accountability). Governance stays separate from execution—you decide what to do, licensed actors carry it out.
Native synthesis of ISO 31000 · COSO ERM · Basel III/IV · TCFD/ISSB/TNFD · DORA · NIST CSF 2.0 · EU AI Act · NIST AI RMF · Sendai Framework · NIS2
NRM is not a framework, methodology, or software product. It is an operating discipline—a complete specification for how risk governance artifacts are created, validated, corrected, and routed to execution under explicit handling rules.
NRM addresses systemic risk governance across the human-machine-nature nexus—the convergence point where technological systems, human organizations, and natural systems create emergent risks that cannot be managed by domain-specific approaches alone.
Organizations, institutions, governance, policy, regulation
AI/ML, automation, IoT, cyber-physical, digital infrastructure
Climate, ecosystems, biodiversity, natural resources, planetary
Cascading effects, feedback loops, emergent properties, tipping points
Traditional enterprise risk management was designed for stable operating environments with identifiable hazards, linear causality, and organizational boundaries. These assumptions no longer hold in exponential technology environments with complex adaptive systems.
Technology development cycles now operate on months, not decades. AI capabilities double in performance annually. Traditional risk registers with annual review cycles cannot track threat evolution at operational tempo.
Complex adaptive systems exhibit feedback loops, phase transitions, and emergent behaviors that defeat linear risk models. Small perturbations can cascade into systemic failures through network effects.
Organizational, sectoral, and jurisdictional boundaries that traditional ERM assumes are no longer meaningful when risks propagate through global supply chains, digital networks, and shared infrastructure.
NRM is grounded in complexity science—the study of systems with many interacting components that exhibit emergent behavior. This foundation enables NRM to address risks that traditional frameworks cannot model.
Simulate individual actor behaviors and observe emergent system-level outcomes. Identifies cascade pathways invisible to aggregate models.
Map dependency structures, identify critical nodes, and model propagation dynamics. Essential for supply chain and financial contagion risk.
Early warning indicators for approaching tipping points. Critical slowing down, increased autocorrelation, and variance changes.
Correction mechanisms that respond to system state changes. Continuous learning with explicit feedback loops and model updating.
NRM implements a continuous six-phase operating loop that transforms environmental signals into governance-ready artifacts. Each phase has defined inputs, outputs, gates, and correction clocks.
Continuous signal acquisition from UNOSINT intelligence network, regulatory feeds, market data, sensor networks, and participatory reporting. Multi-INT fusion across domains.
Generate Assurance & Evidence Packs (AEPs) with cryptographic provenance, source reliability scoring, and confidence intervals. Structured analytic techniques reduce cognitive bias.
Model alternative futures with explicit assumptions, key drivers, and trigger conditions. Agent-based simulation, network propagation analysis, and Monte Carlo methods.
Produce bounded determinations with explicit handling classification, distribution scope, and correction pathways. Defensible under scrutiny with documented reasoning chains.
Interface with Nexus Rails for execution lane selection. Match determinations to appropriate licensed entities—insurance, capital markets, government programs, bilateral arrangements.
Feedback integration from execution outcomes. Model updating, correction issuance, supersession tracking. Continuous improvement with explicit performance metrics.
GRIx (Global Risks Index) provides the semantic infrastructure that enables NRM to synthesize heterogeneous frameworks, resolve entity ambiguity, and maintain conceptual consistency across jurisdictions and sectors.
RDF/OWL foundation with SPARQL query interface. Graph-native storage optimized for traversal and pattern matching. Federated query across distributed nodes.
Bitemporal modeling tracks both valid time and transaction time. Point-in-time queries enable historical reconstruction and audit trails.
Modular ontology architecture supports sector-specific and jurisdiction-specific extensions without breaking core compatibility.
Assurance & Evidence Packs (AEPs) are the fundamental governance currency in NRM—standardized containers for risk evidence, analytical outputs, and governance determinations with immutable sealing and explicit correction pathways.
Raw observations, measurements, source documentation. Provenance chain, collection metadata, authenticity verification. Immutable once sealed.
Methodology documentation, model specifications, assumptions register. Confidence intervals, uncertainty bounds, sensitivity analysis results.
Conclusions, recommendations, routing instructions. Handling classification, distribution scope, validity period. Reasoning chain documentation.
Amendment records, supersession pointers, correction rationale. Effective dates, distribution requirements, impact assessment.
Standardized confidence taxonomy enabling consumers to appropriately weight analytical outputs. Aligned with ICD 203 estimative language and academic evidentiary standards.
Unverified single source
Corroborated reporting
Multiple independent
Analytically validated
Peer reviewed
Ground truth
NRM provides semantic mapping and operational integration for established risk frameworks—enabling organizations to maintain compliance while operating within a unified system that eliminates redundant assessments and inconsistent taxonomies.
Risk management principles, framework, process
Enterprise risk management integrated framework
Business continuity management systems
Institute of Risk Management standards
Banking capital requirements, liquidity standards
Insurance capital directive (EU)
Digital operational resilience act (EU)
Markets in financial instruments directive
Cybersecurity framework (updated 2024)
Information security management systems
Network & information security (EU)
Industrial automation security
Artificial intelligence regulation (2024)
AI risk management framework
AI management system standard
Ethical system design standard
Climate-related financial disclosures
Nature-related financial disclosures
Global reporting initiative
Sustainability accounting, carbon disclosure
DRR 2015-2030 (UN)
Incident management systems
International health regulations
Emergency management guidelines
NRM is built on a fully open-source technology stack with modular architecture enabling selective deployment, air-gap capability, and enterprise integration. No proprietary dependencies or vendor lock-in.
GRIx ontology hosting, schema management, vocabulary services. Framework mappings, control catalogs, taxonomy versioning.
Operating loop orchestration, workflow management, gate enforcement. AEP lifecycle, correction tracking, audit logging.
UNOSINT integration, signal ingestion, indicator monitoring. Multi-INT collection management, source reliability tracking.
Execution interface layer, counterparty registry, eligibility verification. Protocol adapters for insurance, capital markets, government programs.
User interfaces, analytical workspaces, reporting dashboards. Risk register, control management, scenario modeling tools.
Role management, permission enforcement, handling classification. Audit trails, compliance reporting, stakeholder registry.
Cloud-native orchestration with Helm charts
Single-node deployment for development/test
Offline installation with all dependencies
Multi-node with selective synchronization
NRM operates within the broader Nexus ecosystem—a federated network of platforms, institutions, and services that collectively address systemic risk across the sensing-to-execution chain.
UNOSINT Intelligence Network
Continuous risk signal acquisition through participatory multi-INT collection. Source verification, confidence scoring, and reputation-weighted fusion. Feeds NRM Sense phase.
Observatory Documentation →Host Institution Federation
Distributed network of Host Institutions providing local deployment, regional expertise, and data sovereignty compliance. Federated query with selective sync preserves jurisdictional requirements.
Host Institution Program →Execution Interface Layer
Protocol adapters connecting NRM determinations to licensed execution entities. Insurance, reinsurance, capital markets, government programs, and bilateral arrangements. NRM routes; Rails execute.
Rails Architecture →NRM integrates with specialized Nexus platforms for development finance, regional coordination, and sustainable development applications.
Nexus Financing for Development—national-level risk financing and development finance integration.
Learn more →Regional Nexus Financing—cross-border coordination, regional risk pools, corridor development.
Learn more →Universal Nexus for Sustainable Development—SDG alignment, impact measurement, blended finance.
Learn more →NRM Profiles provide sector-specific configurations with appropriate hazard taxonomies, control catalogs, regulatory mappings, and reporting templates. Profiles are composable—organizations operating across sectors can combine relevant configurations.
Basel III/IV, Solvency II, DORA, MiFID II integration. Operational risk, credit risk, market risk, liquidity risk. Stress testing, capital adequacy, recovery planning.
NERC CIP, NIS2, IEC 62443 alignment. OT/IT convergence, supply chain resilience, interdependency mapping. Grid stability, network resilience.
National risk registers, public service continuity, procurement risk. Citizen data protection, democratic integrity, social infrastructure.
Patient safety, clinical trials, supply chain integrity. Pandemic preparedness, AMR surveillance, medical device security, health data protection.
EU AI Act, NIST AI RMF, ISO 42001 alignment. Model governance, algorithmic transparency, platform liability, content moderation risk.
OT security, supplier risk management, quality systems. Trade compliance, export controls, ESG supply chain, industrial safety.
NFD/RNFD/UNFSD integration. Blended finance structuring, concessional capital deployment, impact measurement, ESG safeguards.
Research integrity, dual-use technology, academic freedom. IP protection, collaboration security, grant compliance, data governance.
NRM follows a structured maturation pathway from validated prototype (TRL-7) to full operational deployment (TRL-10). Strategic partners and Host Institutions participate in validation activities at each level, shaping the discipline through real-world application.
Current Status
TRL-7 — System Prototype ValidatedCore operating loop demonstrated in representative environment. Strategic partner validation in progress across financial services and critical infrastructure sectors.
Full operating loop demonstrated in operational environment. Limited deployment with strategic partners. Performance baseline established.
All subsystems integrated and qualified through testing. Multi-sector deployment across jurisdictions. Regulatory engagement and recognition.
Proven through successful operations in multiple operational environments. Documented track record of governance artifacts influencing decisions.
Sustained operations across all targeted sectors and jurisdictions. Self-sustaining governance structure. Native integration in risk management education and practice.
Early adopters providing operational environments for system testing. Structured feedback mechanisms, documented use cases, performance measurement.
Contributing to capability development through sponsored bounties, research quests, and infrastructure builds. Direct roadmap input.
Regional deployment nodes providing local expertise, data sovereignty compliance, and implementation services. Federation infrastructure.
NRM operates as an R&D ecosystem where practitioners, researchers, and institutions collaborate on capability development, methodology validation, and applied research. Structured contribution pathways ensure quality while enabling distributed innovation.
Scoped analytical challenges with defined deliverables and evaluation criteria. Progressive complexity tiers from foundational to advanced. Completion builds verifiable track record.
Institutional sponsors define specific capability gaps or research requirements. Open participation with documented evaluation rubrics. Funding from partners, grants, and enterprise agreements.
Technical development of collectors, analytical modules, and platform integrations. Accepted contributions merge to core repository with permanent attribution. Code review process maintains quality.
Time-bounded collaborative events addressing emerging threat vectors or identified capability gaps. Cross-functional teams work toward defined deliverables. Outputs feed into roadmap prioritization.
Agent-based simulation, network analysis, phase transition detection. Cascading failure modeling, systemic risk quantification, tipping point identification.
Model risk management, algorithmic transparency, AI safety. EU AI Act compliance tooling, model documentation standards, bias detection.
Physical risk modeling, transition risk assessment, nature-related financial disclosure. TCFD/TNFD operationalization, scenario analysis tooling.
OT/IT convergence, supply chain interdependency, critical infrastructure resilience. 5G/6G security, DePIN monitoring, smart city risk.
National risk register automation, public finance risk, fiscal sustainability. Government digital infrastructure, citizen trust infrastructure.
Ground-truthing methodologies, misinformation resilience, source verification. Intelligence quality assessment, confidence calibration.
NRM operates on a non-profit sustainability model ensuring vendor neutrality, transparent governance, and public-good orientation. Revenue from memberships, partnerships, and services sustains operations without commercial conflicts.
Contribution-based credit economy enabling sustained participation without traditional vendor lock-in or per-seat licensing friction.
Validation credits earned through peer reviews, replications, benchmark contributions. Cannot be purchased—expertise-only.
Participation credits from submissions, quest completion, engagement. Tracks contribution history, unlocks features.
Engagement credits from peer support, mentoring, community building. Boosts profile visibility and matching priority.
Nexus Usage Credits for compute, API access, premium features. Allocated via subscriptions or high vCredit conversion.
Open-source access. Documentation. Community forums. Basic quest participation.
Full library access. Certification eligibility. Bounty participation. API access.
Deployment support. Dedicated liaison. Roadmap input. Priority support SLA.
Custom integration. Dedicated compute. SLA guarantees. Governance participation.
Full stack deployment. Federation node. Revenue share. Council voting.
NRM is 100% open-source with no licensing fees. Typical enterprise deployment costs are 60-80% lower than proprietary GRC platforms. No per-seat licensing, no annual escalation, no vendor lock-in. Costs include implementation services, Academy training, and optional support agreements.
NRM supports multiple deployment configurations accommodating varying security requirements, data sovereignty constraints, and operational contexts. All options use the same open-source core with configuration differences.
NRM enforces data sovereignty at the architecture level. Data remains with deploying institutions; only semantic metadata federates through the network with explicit consent and handling rules.
Jurisdictional requirements enforced by architecture
Federated query without data centralization
GDPR, CCPA, PDPA compliance packs
Immutable access logging and consent records
NRM deploys through a federated network of Host Institutions—qualified organizations providing local deployment, regional expertise, and implementation services. Strategic Partners shape capability development and validation.
Continents with active presence
Host Institution candidates
Strategic partner discussions
TRL-10 target institutions
Sectors represented
Jurisdictions engaged
Apply for Host Institution status → | Explore Strategic Partnership → | Sponsor Development →
The NRM Academy provides structured learning pathways, professional certification, and continuing education for risk management practitioners adopting NRM methodology and technology.
NRM fundamentals, GRIx ontology introduction, AEP creation basics. Prerequisites for all advanced tracks. Self-paced with assessments.
Audience: Risk analysts, compliance officers, GRC practitioners
Advanced AEP development, scenario modeling, operating loop implementation. Sector-specific modules available. Includes practical exercises.
Audience: Senior risk managers, CROs, risk consultants
Deployment, configuration, integration, maintenance. Technical operations for Host Institutions and enterprise deployments.
Audience: IT administrators, platform engineers, DevOps teams
NRM Academy content is designed for integration into existing risk management curricula at universities, business schools, and professional development programs.
Ready-to-integrate course modules with instructor materials, assessments, case studies.
Academic licensing for research use. Data access for method validation studies.
Quest participation, internship pathways, thesis collaboration opportunities.
Research collaboration, publication support, governance participation.
NRM is governed by three non-profit organizations ensuring vendor neutrality, transparent decision-making, and public-good orientation. Documented governance processes with stakeholder input mechanisms.
Global Centre for Risk and Innovation
Technical development leadership. Core repository maintenance. Architecture governance. Standard-setting process coordination. US/Canada registration.
Global Risks Forum
International governance coordination. Policy alignment facilitation. Multi-stakeholder dialogue convening. Knowledge dissemination. Switzerland registration.
Global Risks Alliance
Institutional partnership management. Host Institution network coordination. Deployment support services. Capacity building programs. US registration.
Proposal → Review → Public Comment → Ratification → Publication. All decisions documented with rationale. Version-controlled with correction history.
Public → Restricted → Controlled → Confidential. Access controls enforced by architecture. Distribution scope documented per artifact.
Documented escalation procedures. Independent review mechanisms. Appeal pathways. Competition hygiene enforcement.
No financial interest in specific tool or provider recommendations
Apache 2.0 license ensures core remains freely available
Documented decisions with stakeholder input mechanisms
Mission-driven development serving global risk reduction
NRM is designed for adoption across diverse policy regimes, regulatory environments, and sector contexts. Modular architecture enables incremental deployment without requiring wholesale replacement of existing systems.
NRM does not require "big bang" replacement of existing systems. Organizations can adopt incrementally, starting with specific use cases and expanding based on demonstrated value.
Single use case, limited scope. Validate fit with existing processes.
Additional domains or functions. Integration with existing tools.
Enterprise-wide deployment. Full GRC integration.
Ecosystem participation. Federation with partners.
Different stakeholder types have distinct requirements and entry points into the NRM ecosystem. This section provides guidance for initial engagement based on organizational context.
National risk register development, regulatory framework enhancement, supervisory infrastructure. Sovereign Data Zone deployment ensures jurisdictional control. Regulatory recognition pathways documented.
Explore PartnershipBasel/Solvency/DORA compliance enhancement, operational resilience, climate risk integration. GRIx ontology enables regulatory reporting automation. Nexus Rails for risk transfer execution.
NIS2/NERC CIP compliance, OT/IT convergence security, supply chain resilience. Interdependency mapping across infrastructure networks. Air-gap deployment for sensitive environments.
Curriculum integration, research collaboration, methodology validation. Academic licensing for research use. Fellowship programs for sustained contribution. Grant proposal support.
NRM AcademyNFD/RNFD/UNFSD platform integration. Blended finance structuring, impact measurement, ESG safeguards. Sovereign risk analytics for country programs.
Professional certification, methodology training, credential tracking. Quest participation builds verifiable track record. Community engagement via Forum and peer networking.
Complete technical documentation, API specifications, and integration resources for developers, integrators, and technical teams implementing NRM capabilities.
Architecture specifications, deployment guides, configuration references. API documentation with examples. Security hardening guides.
Documentation Portal →REST and GraphQL APIs for all services. Python, JavaScript, Go SDKs. Webhook support for event-driven integration. OpenAPI specifications.
API Reference →Reference architectures for GRC integration, SIEM/SOAR connectivity, data pipeline patterns. Connector templates for common platforms.
Integration Guides →RDF/OWL schemas, vocabulary definitions, framework mappings. Versioned releases with migration guides.
JSON schemas, validation rules, example packs. Sector-specific templates for common use cases.
Standardized control definitions mapped to frameworks. Effectiveness metrics, implementation guidance.
Domain-specific configurations, hazard taxonomies, regulatory mappings. Composable for multi-sector organizations.
Source code, issues, pull requests, discussions
Community documentation, implementation notes
Technical discussions, Q&A, best practices
Real-time chat, community support, events
NRM represents a paradigm shift in systemic risk governance for the human-machine-nature era. From TRL-7 validation through TRL-10 operational deployment by 2030, strategic partners and Host Institutions shape the discipline through structured real-world application.
Structured engagement pathways for governments, financial institutions, critical infrastructure operators, universities, and risk management practitioners.
Trust Architecture: NRM is governance-only and strictly non-executing. It produces credible, comparable, correctionable evidence and bounded determinations that licensed actors route into execution via Nexus Rails—enforced by architecture, not policy.
Nexus Risk Management (NRM)
Systemic risk operating discipline for the human-machine-nature era | Governance-only architecture
Developed collectively by GCRI (Global Centre for Risk and Innovation), GRF (Global Risks Forum), and GRA (Global Risks Alliance)
Non-profit infrastructure for systemic risk governance | 100% open source | Apache 2.0 license | Enterprise ready | Sovereign data zones
The Global Centre for Risk and Innovation (GCRI)
We firmly believe that the internet should be available and accessible to anyone, and are committed to providing a website that is accessible to the widest possible audience, regardless of circumstance and ability.
To fulfill this, we aim to adhere as strictly as possible to the World Wide Web Consortium’s (W3C) Web Content Accessibility Guidelines 2.1 (WCAG 2.1) at the AA level. These guidelines explain how to make web content accessible to people with a wide array of disabilities. Complying with those guidelines helps us ensure that the website is accessible to all people: blind people, people with motor impairments, visual impairment, cognitive disabilities, and more.
This website utilizes various technologies that are meant to make it as accessible as possible at all times. We utilize an accessibility interface that allows persons with specific disabilities to adjust the website’s UI (user interface) and design it to their personal needs.
Additionally, the website utilizes an AI-based application that runs in the background and optimizes its accessibility level constantly. This application remediates the website’s HTML, adapts Its functionality and behavior for screen-readers used by the blind users, and for keyboard functions used by individuals with motor impairments.
If you’ve found a malfunction or have ideas for improvement, we’ll be happy to hear from you. You can reach out to the website’s operators by using the following email
Our website implements the ARIA attributes (Accessible Rich Internet Applications) technique, alongside various different behavioral changes, to ensure blind users visiting with screen-readers are able to read, comprehend, and enjoy the website’s functions. As soon as a user with a screen-reader enters your site, they immediately receive a prompt to enter the Screen-Reader Profile so they can browse and operate your site effectively. Here’s how our website covers some of the most important screen-reader requirements, alongside console screenshots of code examples:
Screen-reader optimization: we run a background process that learns the website’s components from top to bottom, to ensure ongoing compliance even when updating the website. In this process, we provide screen-readers with meaningful data using the ARIA set of attributes. For example, we provide accurate form labels; descriptions for actionable icons (social media icons, search icons, cart icons, etc.); validation guidance for form inputs; element roles such as buttons, menus, modal dialogues (popups), and others. Additionally, the background process scans all the website’s images and provides an accurate and meaningful image-object-recognition-based description as an ALT (alternate text) tag for images that are not described. It will also extract texts that are embedded within the image, using an OCR (optical character recognition) technology. To turn on screen-reader adjustments at any time, users need only to press the Alt+1 keyboard combination. Screen-reader users also get automatic announcements to turn the Screen-reader mode on as soon as they enter the website.
These adjustments are compatible with all popular screen readers, including JAWS and NVDA.
Keyboard navigation optimization: The background process also adjusts the website’s HTML, and adds various behaviors using JavaScript code to make the website operable by the keyboard. This includes the ability to navigate the website using the Tab and Shift+Tab keys, operate dropdowns with the arrow keys, close them with Esc, trigger buttons and links using the Enter key, navigate between radio and checkbox elements using the arrow keys, and fill them in with the Spacebar or Enter key.Additionally, keyboard users will find quick-navigation and content-skip menus, available at any time by clicking Alt+1, or as the first elements of the site while navigating with the keyboard. The background process also handles triggered popups by moving the keyboard focus towards them as soon as they appear, and not allow the focus drift outside it.
Users can also use shortcuts such as “M” (menus), “H” (headings), “F” (forms), “B” (buttons), and “G” (graphics) to jump to specific elements.
We aim to support the widest array of browsers and assistive technologies as possible, so our users can choose the best fitting tools for them, with as few limitations as possible. Therefore, we have worked very hard to be able to support all major systems that comprise over 95% of the user market share including Google Chrome, Mozilla Firefox, Apple Safari, Opera and Microsoft Edge, JAWS and NVDA (screen readers).
Despite our very best efforts to allow anybody to adjust the website to their needs. There may still be pages or sections that are not fully accessible, are in the process of becoming accessible, or are lacking an adequate technological solution to make them accessible. Still, we are continually improving our accessibility, adding, updating and improving its options and features, and developing and adopting new technologies. All this is meant to reach the optimal level of accessibility, following technological advancements. For any assistance, please reach out to