# Risk Management Policy

**Touch2Sign Ltd**  
**Version:** 1.0  
**Effective date:** 11 July 2026  
**Owner:** Robert — Security Lead  
**Approved by:** Robert — CEO / Managing Director  
**Next review:** 11 July 2027

---

## 1. Purpose

Establish a consistent approach to identifying, assessing, treating, and monitoring information security risks across the Touch2Sign eSignature and eWitness platform. Supports ISO 27001 Clause 6.1 and SOC 2 risk assessment requirements.

## 2. Scope

Covers risks affecting:

- Confidentiality, integrity, and availability of customer data and documents  
- Regulatory compliance (GDPR, eIDAS, ISO 27001, SOC 2)  
- Third-party and sub-processor dependencies  
- Business continuity and reputational impact  

Applies to all Touch2Sign departments; owned operationally by the Security Lead.

## 3. Risk management framework

Touch2Sign follows a continuous cycle:

1. **Identify** — threats and vulnerabilities (risk register, audits, incidents)  
2. **Assess** — likelihood × impact scoring  
3. **Treat** — mitigate, transfer, accept, or avoid  
4. **Monitor** — quarterly review; update after incidents  
5. **Report** — CEO and board summary semi-annually  

## 4. Risk register

Maintained by Security Lead in [GRC tool / spreadsheet — location TBD].

Minimum fields:

| Field | Description |
|-------|-------------|
| Risk ID | RISK-YYYY-NNN |
| Title | Short description |
| Category | Technical / legal / operational / third-party |
| Threat | What could happen |
| Vulnerability | Weakness exploited |
| Asset affected | Documents, IDV, platform, reputation |
| Existing controls | Current mitigations |
| Likelihood | 1–5 (see matrix) |
| Impact | 1–5 (see matrix) |
| Inherent risk | L × I before treatment |
| Treatment | Mitigate / transfer / accept / avoid |
| Action plan | Specific tasks, owner, due date |
| Residual risk | L × I after treatment |
| Risk owner | Named individual |
| Review date | Next review |
| Status | Open / monitoring / closed |

## 5. Likelihood and impact matrix

### 5.1 Likelihood

| Score | Label | Description |
|-------|-------|-------------|
| 1 | Rare | Unlikely in 3+ years |
| 2 | Unlikely | Possible but not expected annually |
| 3 | Possible | May occur once per year |
| 4 | Likely | Expected annually |
| 5 | Almost certain | Multiple times per year or active trend |

### 5.2 Impact

| Score | Label | Description |
|-------|-------|-------------|
| 1 | Negligible | No customer impact; internal only |
| 2 | Minor | Single customer inconvenience; < €10k |
| 3 | Moderate | Multi-customer impact; regulatory inquiry possible |
| 4 | Major | Data breach; ICO/DPC investigation; significant revenue loss |
| 5 | Severe | Mass document leak; platform outage > 24h; existential reputational harm |

### 5.3 Risk score

**Risk score = Likelihood × Impact**

| Score range | Rating | Action |
|-------------|--------|--------|
| 1–4 | **Low** | Monitor; accept with documentation |
| 5–9 | **Medium** | Treat within 90 days; Security Lead owner |
| 10–15 | **High** | Treat within 30 days; CEO informed |
| 16–25 | **Critical** | Immediate treatment; CEO approval for acceptance |

## 6. Risk appetite

Touch2Sign's risk appetite statements:

- **Zero tolerance** for unencrypted customer documents at rest  
- **Zero tolerance** for production access without MFA  
- **Low appetite** for US transfer of document content without SCCs and DPIA (Anthropic)  
- **Low appetite** for PHI processing — default out of scope  
- **Moderate appetite** for single-region AWS dependency — mitigated by DR plan  

Residual risks above **High** require CEO written acceptance with expiry date.

## 7. Risk treatment options

| Option | When to use | Example |
|--------|-------------|---------|
| **Mitigate** | Controls can reduce likelihood or impact | Enable WAF; quarterly access reviews |
| **Transfer** | Insurance or contractual shift | Cyber insurance; Stripe PCI scope |
| **Accept** | Cost of control exceeds risk; documented | Low legacy dependency |
| **Avoid** | Stop the activity | Discontinue Veriff without DPIA |

## 8. Quarterly risk review

Security Lead convenes **quarterly risk review** with Engineering Lead, DPO, and CEO (or delegate):

Agenda:

1. Review open risks and action plan progress  
2. Add risks from incidents, pentests, audits, new features  
3. Re-score changed risks  
4. Close treated risks with evidence  
5. Escalate overdue High/Critical treatments  
6. Update ISO 27001 Statement of Applicability if applicable  

Minutes retained **3 years**.

## 9. Triggered reviews

Risk register updated within **10 business days** of:

- P1 or P2 security incident  
- Notifiable personal data breach  
- New sub-processor integration  
- Material architecture change (new region, AI feature)  
- Failed audit or pentest Critical finding  

## 10. Touch2Sign key risks (starter register)

| Risk | Category | Initial treatment |
|------|----------|-----------------|
| Signing token compromise | Technical | Time-limited tokens; IR playbook §7.1 |
| RDS/S3 misconfiguration | Technical | IAM least privilege; Security Hub |
| IDV sub-processor breach | Third-party | DPA; vendor monitoring |
| Anthropic document exposure | Third-party | DPIA; minimise content; SCCs |
| Single-region AWS dependency | Operational | DR plan; backup restore tests |
| Insider access abuse | Operational | Access reviews; audit logging |
| Customer uploads PHI | Legal | HIPAA Scope Policy; terms prohibition |

Detailed scoring maintained in live risk register.

## 11. Related documents

- Information Security Policy  
- Incident Response Plan  
- Vendor & Sub-processor Management Policy  
- Vulnerability Management Policy  
- Business Continuity & DR Plan  

## 12. Review

This policy reviewed **annually** and when risk methodology changes.

---

**Approval**

| Name | Role | Signature | Date |
|------|------|-----------|------|
| Robert | CEO / Security Lead | Electronic | 11 July 2026 |
