Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
The 7A Risk Management Framework, Decision Centric Risk | Resilience Guard
The proprietary operating model for risk leadership

The 7A Risk Management Framework®

A decision centric operating model that measures not only how exposed you are, but how much confidence your leadership can justifiably place in that assessment. Developed by Resilience Guard in Switzerland, applied to any risk, built for the board.

The framework

What is the 7A Risk Management Framework?

The 7A Risk Management Framework® is a decision centric risk operating model developed by Resilience Guard GmbH. Unlike traditional enterprise risk management, which collapses a risk into a single probability and impact score, the 7A model measures every risk on two independent dimensions: its exposure under stress, and the confidence leadership can justifiably hold in its ability to understand and control it.

By separating those two questions, the framework exposes the confidence gap that conventional heatmaps hide, and turns risk reporting into board level decision making. It defines risk as the conditional potential for unacceptable impact on organisational objectives, under stress, given uncertainty in system behaviour and control reliability, a definition that anchors risk to objectives, evaluates it under realistic adverse conditions, and treats uncertainty as a structural feature to be governed rather than an error to be hidden.

Three assumptions of conventional risk management rarely survive contact with a real crisis: that probabilities can be estimated reliably, that controls on paper equal controls in practice, and that aggregation equals clarity. The 7A model replaces all three, and it is most valuable exactly where they are weakest: emerging risks such as AI adoption under the EU AI Act, post quantum cryptography and the migration to the NIST FIPS 203, 204 and 205 standards, and operational technology cyber risk in critical infrastructure.

Origin
Developed by Resilience Guard
Model
Exposure and confidence, two axes
Loop
Seven capabilities
Applies to
Any risk category
THE 7A MATRIX: TWO QUESTIONS, NOT ONE SCOREUNACCEPTABLEHigh exposure, low confidence: act nowGOVERNEDHigh exposure, justified confidenceCOMPLACENTLow exposure claimed, weak assuranceEFFICIENTLow exposure, proportionate controlDecision confidence, low to highExposure under stressAnticipateAssessAnalyseActAdviseAuditAssuranceSeven capabilities in a closed governance loop, feeding both axes of the matrix.
The 7A matrix: exposure under stress against decision confidence, with the unacceptable quadrant a conventional heatmap suppresses, fed by the seven capability loop.
The seven capabilities

A closed loop centred on decision confidence

Anticipate. Detect weak signals and emerging threats before they crystallise into crises.
Assess. Score objective based exposure and control reliability under stress.
Analyse. Decompose systemic complexity to expose root causes and interdependencies.
Act. Execute deliberate response and tested preparedness, calibrated to the velocity of the risk.
Advise. Translate exposure and confidence into decision centred narratives for the board.
Audit. Independently challenge framing, scoring and the evidence behind confidence.
Assurance. Synthesise the whole into justified confidence and the second axis of the matrix.
With your standards

An overlay, not a replacement

The 7A Framework does not replace the standards you already operate; it is a decision confidence overlay that strengthens them. To ISO 31000 it adds a defined exposure and confidence measurement and a clear decision response. To COSO ERM it replaces probability times impact scoring with a decision confidence model. To ISO 22301 it assesses and reports confidence in continuity arrangements under stress. And to NIS2 and DORA, which make management bodies accountable for resilience, it gives directors a defensible signal of where that accountability is actually at risk.

Questions

Frequently asked questions

How is the 7A Framework different from a risk heatmap?+

A heatmap compresses each risk into one probability and impact score, which hides the question boards most need answered: how much can we trust our own assessment? The 7A model plots exposure under stress against decision confidence as independent axes, exposing the unacceptable quadrant, high exposure with low confidence, that a heatmap suppresses.

What are the seven As?+

Anticipate, Assess, Analyse, Act, Advise, Audit and Assurance: seven integrated capabilities operating as a continuous governance loop centred on decision confidence.

Which risks does the framework apply to?+

Any category: financial, operational, strategic, legal and regulatory, safety, environmental and climate, reputational, geopolitical, supply chain and third party concentration. It is most valuable for emerging risks whose probabilities are genuinely unknowable, such as AI adoption, post quantum cryptography and OT cyber risk.

Does 7A replace ISO 31000 or COSO ERM?+

No. It is an overlay that strengthens them: ISO 31000 keeps its principles and process, COSO keeps its strategy linkage, and 7A supplies the exposure and confidence measurement and the decision response both lack.

Can our team be certified on the framework?+

Yes. A three level pathway runs from Foundation through Professional to the governed Lead and Assessor scheme; see 7A training and certification.

Explore further

Related services

Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Supply Chain Security

The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Next step

See your risks on two axes for the first time.

Ask us to run a 7A assessment on your current register; the unacceptable quadrant is usually a revelation.

Book a consultation
All consultations are treated with strict confidentiality.