Touch2Sign Policy Library
← All policies

Risk Management Policy

Version 1.0 · Draft · Owner: Security Lead

Download .md →

Risk Management Policy

Touch2Sign Ltd

Version: 1.0

Effective date: 11 July 2026

Owner: Robert — Security Lead

Approved by: Robert — CEO / Managing Director

Next review: 11 July 2027


1. Purpose

Establish a consistent approach to identifying, assessing, treating, and monitoring information security risks across the Touch2Sign eSignature and eWitness platform. Supports ISO 27001 Clause 6.1 and SOC 2 risk assessment requirements.

2. Scope

Covers risks affecting:

  • Confidentiality, integrity, and availability of customer data and documents
  • Regulatory compliance (GDPR, eIDAS, ISO 27001, SOC 2)
  • Third-party and sub-processor dependencies
  • Business continuity and reputational impact

Applies to all Touch2Sign departments; owned operationally by the Security Lead.

3. Risk management framework

Touch2Sign follows a continuous cycle:

  1. Identify — threats and vulnerabilities (risk register, audits, incidents)
  2. Assess — likelihood × impact scoring
  3. Treat — mitigate, transfer, accept, or avoid
  4. Monitor — quarterly review; update after incidents
  5. Report — CEO and board summary semi-annually

4. Risk register

Maintained by Security Lead in [GRC tool / spreadsheet — location TBD].

Minimum fields:

Field Description
Risk ID RISK-YYYY-NNN
Title Short description
Category Technical / legal / operational / third-party
Threat What could happen
Vulnerability Weakness exploited
Asset affected Documents, IDV, platform, reputation
Existing controls Current mitigations
Likelihood 1–5 (see matrix)
Impact 1–5 (see matrix)
Inherent risk L × I before treatment
Treatment Mitigate / transfer / accept / avoid
Action plan Specific tasks, owner, due date
Residual risk L × I after treatment
Risk owner Named individual
Review date Next review
Status Open / monitoring / closed

5. Likelihood and impact matrix

5.1 Likelihood

Score Label Description
1 Rare Unlikely in 3+ years
2 Unlikely Possible but not expected annually
3 Possible May occur once per year
4 Likely Expected annually
5 Almost certain Multiple times per year or active trend

5.2 Impact

Score Label Description
1 Negligible No customer impact; internal only
2 Minor Single customer inconvenience; < €10k
3 Moderate Multi-customer impact; regulatory inquiry possible
4 Major Data breach; ICO/DPC investigation; significant revenue loss
5 Severe Mass document leak; platform outage > 24h; existential reputational harm

5.3 Risk score

Risk score = Likelihood × Impact

Score range Rating Action
1–4 Low Monitor; accept with documentation
5–9 Medium Treat within 90 days; Security Lead owner
10–15 High Treat within 30 days; CEO informed
16–25 Critical Immediate treatment; CEO approval for acceptance

6. Risk appetite

Touch2Sign's risk appetite statements:

  • Zero tolerance for unencrypted customer documents at rest
  • Zero tolerance for production access without MFA
  • Low appetite for US transfer of document content without SCCs and DPIA (Anthropic)
  • Low appetite for PHI processing — default out of scope
  • Moderate appetite for single-region AWS dependency — mitigated by DR plan

Residual risks above High require CEO written acceptance with expiry date.

7. Risk treatment options

Option When to use Example
Mitigate Controls can reduce likelihood or impact Enable WAF; quarterly access reviews
Transfer Insurance or contractual shift Cyber insurance; Stripe PCI scope
Accept Cost of control exceeds risk; documented Low legacy dependency
Avoid Stop the activity Discontinue Veriff without DPIA

8. Quarterly risk review

Security Lead convenes quarterly risk review with Engineering Lead, DPO, and CEO (or delegate):

Agenda:

  1. Review open risks and action plan progress
  2. Add risks from incidents, pentests, audits, new features
  3. Re-score changed risks
  4. Close treated risks with evidence
  5. Escalate overdue High/Critical treatments
  6. Update ISO 27001 Statement of Applicability if applicable

Minutes retained 3 years.

9. Triggered reviews

Risk register updated within 10 business days of:

  • P1 or P2 security incident
  • Notifiable personal data breach
  • New sub-processor integration
  • Material architecture change (new region, AI feature)
  • Failed audit or pentest Critical finding

10. Touch2Sign key risks (starter register)

Risk Category Initial treatment
Signing token compromise Technical Time-limited tokens; IR playbook §7.1
RDS/S3 misconfiguration Technical IAM least privilege; Security Hub
IDV sub-processor breach Third-party DPA; vendor monitoring
Anthropic document exposure Third-party DPIA; minimise content; SCCs
Single-region AWS dependency Operational DR plan; backup restore tests
Insider access abuse Operational Access reviews; audit logging
Customer uploads PHI Legal HIPAA Scope Policy; terms prohibition

Detailed scoring maintained in live risk register.

11. Related documents

  • Information Security Policy
  • Incident Response Plan
  • Vendor & Sub-processor Management Policy
  • Vulnerability Management Policy
  • Business Continuity & DR Plan

12. Review

This policy reviewed annually and when risk methodology changes.


Approval

Name Role Signature Date
Robert CEO / Security Lead Electronic 11 July 2026

Questions: security@touch2sign.com · privacy@touch2sign.com