Risk Scorecard guide

TerraTrue’s Risk Scorecard automatically analyzes linked launch documentation to generate instant risk assessments, eliminating manual triage so reviewers can focus directly on decision-making. It scans attached Google Docs, Notion pages, Jira tickets, contracts, and uploaded attachments to evaluate risk across three distinct dimensions.

Prerequisites & Permissions 

The Risk Scorecard is disabled by default and requires an administrator to turn it on alongside the Enable TerraTrue AI setting. Users must hold the Risk Scorecard Viewer permission to view scorecards and their historical timelines. This permission is automatically assigned to all existing review teams upon feature launch. Administrators can expand access across the organization or restrict it to specific teams via the Identity and Access Management page.

How Risk Scorecard Works 

The Risk Scorecard continuously evaluates linked documents against your organization’s custom TerraTrue taxonomy across three core categories. First, the Data Profile & Lifecycle category extracts data types, data uses, and data subjects, while specifically flagging children's data and noting any missing retention or deletion details. Second, the Governance & Regulatory category identifies triggered assessments (such as DPIAs, LIAs, or PIAs), flags cross-border data transfers, and checks alignment with existing playbooks. Finally, the Innovation & Context category evaluates whether the work is novel, such as brand-new architectural components, or iterative, such as styling revamps or performance tweaks.

Core Capabilities & Scoring Logic 

The scorecard employs a high-water mark logic, meaning a category inherits the risk rating of its highest-risk signal. High-risk findings, such as detected children's data or a required DPIA, will escalate a category to High Risk immediately. To ensure clarity, each rating displays explicit Primary Driver labels to explain the exact reasoning behind the score. If attached documents lack sufficient detail to infer data types or uses, the scorecard displays an Inconclusive status instead of defaulting to a false Low Risk. When no documents are attached, it displays a neutral prompt to link one. Additionally, the scorecard features a living version history; when linked specs or documents are updated, the scorecard automatically re-scores itself and records a detailed timeline of all revisions and triggers.

Frequently Asked Questions

Does Risk Scorecard auto-close low-risk reviews? 

No. The Risk Scorecard informs reviewer decisions, but it does not auto-close reviews or automatically route launches on its own.

Does it support the EU AI Act? 

Not currently. While automated EU AI Act tiering and custom scoring playbooks are planned for future releases, the initial version focuses on privacy risk.

Can I customize the risk scorecard?

The risk scorecard is largely dependent on the risk profile of all of your organization's taxonomies (such as data types, data uses, regions, etc.), meaning the output is inherently unique to your specific environment. Having said that, we encourage our customers to reach out to their customer success representative should they have any further ideas for customization. This feature is designed to evolve over time to meet expanding organizational needs.

Was this article helpful?
0 out of 0 found this helpful