This page shows a concept lattice built using Formal Concept Analysis (FCA). FCA does one very specific (and very useful) thing: it finds all groups paired with every attribute common to them, and every scenario having those attributes. The scenarios may have different additional attributes; their complete rows need not be identical.
The “causal” part is in how we write the risks: each scenario has a causal chain (“what starts it → what happens → impact”). Control tags describe proposed ways to interrupt the chain. Evidence tags name records such as walkthroughs, logs, audits or tickets. The matrix alone does not show what a record proves, whether a control was implemented, or whether it was effective.
Director‑level questions this view answers quickly: “Which scenarios share a training tag?”, “Which records need a closer look?”, “Which scenarios have evidence tags but no control tags?”, and “Which rows are empty?” These suggest questions, not findings about actual risk.
Each node label shows counts. Example:
Here a row with a control tag is tagged with a control; it is not thereby effectively controlled.
control: attributesevidence:) but still no barrierReal programs often require both barriers and proof. This demo separates “evidence tag present” from “control tag present” so readers can ask whether a tag is missing, an assessment is incomplete, or a corrective action is needed. The table does not infer ownership or effectiveness.