---
name: risk3y-expert-operator
description: Expert guide for operating Risk3y end-to-end with MCP-enabled AI. Use when creating or improving registers, risks, threats, controls, roles, groups, tags, reviews, audits, insights, and verification workflows. Includes HSE prosecutions grounding and a Plan-Do-Check-Change operating cycle.
user-invocable: true
---

# Risk3y expert operator

This Skill is the primary operating guide for new users and experts using Risk3y.

Use this Skill when you need to:

- Build or rebuild a company risk management foundation
- Stand up registers, roles, controls, and governance quickly
- Ground AI assistance in trusted operational knowledge
- Run repeatable review, audit, insight, and verification cycles
- Prove that your risk register is alive, effective, and improving

_Last updated: 2026-06-16_

## Core principles

- Use Risk as the canonical term in user-facing outputs
- Keep tenant data isolated and role access enforced server-side
- Treat AI outputs as proposals that require human judgment
- Prefer evidence-backed updates over opinion-based updates
- Keep a full audit trail for decisions, reviews, and changes
- Use synthetic examples for templates, demos, and onboarding exercises

## How to use this Skill

1. Capture operating context:
   - Industry, locations, workforce profile, contractor footprint, regulators
   - Current maturity level (startup, reactive, stable, proactive)
   - Existing controls and pain points (incidents, near misses, repeat findings)
2. Select operating mode:
   - Simple mode for fast onboarding and broad participation
   - Advanced mode for deeper analysis, linked controls, and formal assurance
3. Execute the Plan-Do-Check-Change cycle in this guide
4. Use MCP-connected AI for analysis, drafting, and gap finding
5. Verify outcomes in Risk3y through reviews, audits, and control evidence

### MCP tooling alignment note

- Use the live MCP tool registry as source of truth for tool names and arguments.
- For risk posture drill-down via AI, prefer `risk_search` with filters such as:
  - open risks: `status=open`
  - high risks: `min_score=15`
  - overdue reviews: `overdue_only=true`
- Keep customer-facing guidance synchronized with the MCP server implementation in:
  - `apps/mcp-server/src/index.ts`
  - `apps/mcp-server/src/hse-read-tools.ts`
  - `apps/mcp-server/src/hse-write-tools.ts`

## Capability map

### Registers

Goal: Define clear boundaries for where risks are owned and managed.

Best practice:

- Create registers by operational domain, legal entity, site, or function
- Assign an accountable owner and backup owner for every register
- Define review cadence and escalation threshold per register
- Keep scope statements explicit so risks are not orphaned

Minimum quality bar:

- Scope statement present
- Owner assigned
- Review cadence set
- Initial risk population complete

### Risks and threats

Goal: Capture what can go wrong, why it can happen, and what harm can result.

Best practice:

- Write concise risk statements with context, cause, event, and consequence
- Model threats (initiators) separately from consequences when useful
- Link each risk to affected people, process, equipment, environment, or compliance duty
- Distinguish inherent and residual risk where available

Minimum quality bar:

- Clear title and description
- Threat or cause documented
- Consequence documented
- Current status and owner assigned

### Controls

Goal: Demonstrate how risks are prevented, reduced, detected, or recovered.

Best practice:

- Classify controls by type (preventive, detective, corrective, recovery)
- Define control owner, operating frequency, and verification method
- Require evidence references for high-criticality controls
- Track control effectiveness and overdue verification tasks

Minimum quality bar:

- Control has owner
- Verification method is defined
- Last reviewed date exists
- Effectiveness state is recorded

### Roles, groups, and permissions

Goal: Align accountability and access with real operating responsibilities.

Best practice:

- Map platform roles to real job functions
- Use groups for team-level collaboration and targeted visibility
- Keep least privilege by default and elevate deliberately
- Verify that reviewers and auditors can access required evidence without over-broad permissions

Minimum quality bar:

- Every critical register has at least one accountable role
- Review and audit roles are assigned
- Group access matches operating boundaries

### Tags and classification

Goal: Make filtering, analysis, and reporting reliable.

Best practice:

- Standardize tags for site, process, asset class, duty holder, and regulator domain
- Use a controlled vocabulary to avoid duplicate tag variants
- Keep tag definitions documented and versioned

Minimum quality bar:

- Mandatory tags present on material risks
- Tag dictionary maintained
- Duplicates merged or retired

### Reviews

Goal: Keep register content current and actionable.

Best practice:

- Use calendar-based and event-triggered reviews
- Include evidence, decisions, and action assignments in every review
- Treat unchanged high-risk entries as requiring explicit justification

Minimum quality bar:

- Review completed on schedule
- Findings captured
- Follow-up actions assigned with due dates

### Audits

Goal: Test whether controls and governance actually operate as designed.

Best practice:

- Build audit samples from high-risk areas first
- Test design adequacy and operating effectiveness separately
- Record pass, fail, and partial outcomes with root-cause notes

Minimum quality bar:

- Audit objective and scope defined
- Sample method stated
- Findings linked to risks or controls
- Corrective actions tracked

### Insights

Goal: Turn register data into management decisions.

Best practice:

- Monitor trend lines: open risk age, overdue reviews, weak controls, repeat findings
- Compare residual-risk movement after control changes
- Prioritize action by potential harm and confidence of evidence

Minimum quality bar:

- Insight outputs have clear decisions or action recommendations
- Trend period and data scope are explicit

### Verification

Goal: Prove the register is working in real operations.

Best practice:

- Verify that critical controls operate at required frequency
- Verify review actions close on time and reduce exposure
- Verify incident and near-miss learnings update register content
- Verify management uses insights in planning and resourcing decisions

Minimum quality bar:

- Verification schedule exists
- Evidence is attached or referenced
- Failed verifications trigger corrective actions

## Grounding AI with HSE prosecutions and internal knowledge

Use this approach to anchor AI assistance in real-world safety lessons plus your own operating context.

### HSE Prosecutions Database operations

Use the prosecutions database as a pattern library, not a direct legal advice source.

Operating steps:

1. Collect:
   - Maintain structured records for available jurisdictions (for example New Zealand and Australia, and United Kingdom as coverage grows)
   - Keep source URL, decision date, sector, regulator, and case summary fields
2. Normalize:
   - Standardize failure mode labels, control failure types, and outcome severity
   - Apply consistent tags so trends are queryable
3. Link:
   - Connect prosecution patterns to Risk3y tags, threats, and control categories
   - Highlight repeated duty failures that match your operating profile
4. Govern:
   - Review database quality monthly
   - Retire duplicate records and keep taxonomy current
5. Apply:
   - Use database patterns in planning, control design, review agendas, and audit sampling

### Source hierarchy

1. Company operating knowledge:
   - Your current register entries, controls, incidents, audits, procedures
2. Sector and regulator intelligence:
   - Public HSE prosecution summaries and judgments relevant to your work
3. Expert interpretation:
   - Site leaders, engineers, supervisors, and worker representatives

### Grounding workflow

1. Ingest and curate external enforcement cases:
   - Keep only relevant jurisdictions and industry patterns
   - Tag cases by failure mode, control breakdown, and legal duty themes
2. Map external lessons to internal risks:
   - For each material risk, attach related prosecution patterns
   - Add or strengthen controls where failure patterns repeat
3. Ground AI prompts with approved context:
   - Register data, control library, and curated prosecution signals
   - Explicitly request evidence-linked recommendations
4. Require explainability:
   - AI should cite which internal evidence and case themes drove each recommendation
5. Human-approve all changes:
   - Use proposal-and-approval workflow for any write action

### Example grounding prompts

- Review our top 20 residual risks and identify where prosecution patterns indicate missing preventive controls.
- For risks tagged contractor-management, propose control verification checks based on repeat enforcement themes.
- Compare our current review findings to prosecution-derived failure modes and rank the top five assurance gaps.

## Plan-Do-Check-Change operating cycle

Use this cycle as the default governance loop.

### Plan

Objective: Design a risk and control strategy for the next cycle.

Checklist:

- Confirm register boundaries, owners, and roles
- Define risk criteria and prioritization method
- Set review and audit cadences
- Set measurable verification objectives
- Select data inputs for insight dashboards

Outputs:

- Cycle plan
- Prioritized risk backlog
- Assurance calendar

### Do

Objective: Execute risk treatment and control operation.

Checklist:

- Add or update risks and threats
- Implement or adjust controls
- Assign and track actions
- Capture evidence continuously
- Use AI for draft analysis and proposal generation

Outputs:

- Updated risk and control records
- Action status updates
- New evidence attachments and notes

### Check

Objective: Measure effectiveness and detect drift.

Checklist:

- Run scheduled reviews
- Perform control effectiveness checks
- Execute targeted audits
- Evaluate trend insights and outliers
- Validate whether residual risk is moving in the right direction

Outputs:

- Review logs
- Audit findings
- Insight summaries
- Verification outcomes

### Change

Objective: Improve design and operation based on evidence.

Checklist:

- Resolve root causes for failed controls
- Retire ineffective controls and replace with stronger design
- Tighten ownership, role mapping, or group access where needed
- Update tags and taxonomy if analysis quality is weak
- Re-baseline cycle targets for next period

Outputs:

- Approved change proposals
- Updated control design
- Revised governance settings

## Quick-start playbooks

### New customer onboarding playbook (first 30 days)

- Week 1:
  - Create core registers
  - Assign owners, roles, and groups
  - Set tag dictionary and minimum fields
- Week 2:
  - Populate top operational risks and threats
  - Add initial control set and verification methods
- Week 3:
  - Run first review cycle and create first insight pack
  - Ground analysis with relevant prosecution themes
- Week 4:
  - Run verification checks on critical controls
  - Execute first Change actions and lock next cycle plan

### Expert uplift playbook (mature teams)

- Rationalize duplicated risks and controls
- Introduce advanced threat-to-control mapping
- Tune dashboards for leading indicators
- Increase audit depth in high-consequence zones
- Automate periodic MCP read-analysis proposals with human approval gates

## MCP usage pattern for expert operation

Use MCP as a role-aware analyst and drafting assistant.

Read-first sequence:

1. List registers and select target scope
2. Pull open risks and control coverage
3. Identify missing or stale verification evidence
4. Search knowledge and enforcement themes for parallels
5. Produce ranked proposals for human review

Write sequence (proposal-driven):

1. Draft proposed risk/control updates
2. Attach rationale and evidence references
3. Route for approval by authorized role
4. Apply approved changes and log audit metadata

## Quality scorecard (operating health)

Score each register monthly on:

- Coverage: critical operations represented by current risks
- Control quality: owner, frequency, verification, evidence completeness
- Timeliness: review and action completion rates
- Assurance: audit closure and recurrence reduction
- Learning: incident and prosecution learnings reflected in updates
- Improvement: measurable shift in residual risk profile

Use a 0-5 scale per dimension and trend month-over-month.

## Common failure patterns and remedies

- Register is static:
  - Remedy: enforce event-triggered reviews and close-loop actions
- Controls exist but are unverified:
  - Remedy: require evidence and failed-check escalation
- Too many low-value tags:
  - Remedy: controlled vocabulary and periodic cleanup
- AI outputs are generic:
  - Remedy: improve grounding context and require cited evidence links
- Audits find repeats:
  - Remedy: root-cause corrective actions, not superficial edits

## HSE NZ/AU Skills — companion skill collection

The [`scottmss/hse-nz-au-skills`](https://github.com/scottmss/hse-nz-au-skills) repository is an open-source collection of 31 Claude Agent Skills that extend AI-assisted HSE capability for NZ and Australian practitioners. These skills are explicitly designed to pair with a structured risk register — Risk3y is that register.

> The skills are the reasoning and drafting layer. Risk3y is where output is recorded, maintained, and governed.

### Key skills for Risk3y operators

| Skill                   | Risk3y integration point                                                                                                                  |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| `hse-advisor`           | Orchestrator — routes to the right specialist; start here                                                                                 |
| `critical-risk-manager` | Bow-tie drafts → save threats, top event, and controls in Risk3y Advanced mode                                                            |
| `prosecution-analyst`   | Grounds analysis in real enforcement data; can query Risk3y's prosecution database via `prosecution_search` / `prosecution_get` MCP tools |
| `incident-investigator` | Five Whys → corrective actions recorded as risk updates or new controls in Risk3y                                                         |
| `task-analysis-author`  | JSA output → risks and controls imported or typed into Risk3y                                                                             |
| `sop-author`            | SOP drafts → linked as knowledge or evidence in Risk3y risk records                                                                       |
| Hazard SME skills       | Specialist control sets → reviewed, approved, and stored as Risk3y controls                                                               |

### Operating pattern

1. Use the appropriate skill to draft bow-ties, task analyses, control sets, or investigation reports.
2. Use `prosecution-analyst` with MCP to ground the analysis in jurisdiction-relevant enforcement patterns.
3. Validate with a competent practitioner.
4. Record approved output in Risk3y — risks, controls, knowledge, evidence.
5. Use Risk3y reviews, verification rounds (CRV), and sharing to govern the register.

### Installing

**Claude Code:**

```
/plugin marketplace add scottmss/hse-nz-au-skills
```

**Single skill:**

```bash
git clone https://github.com/scottmss/hse-nz-au-skills.git
cp -r hse-nz-au-skills/skills/<skill-name> ~/.claude/skills/
```

**Claude.ai / API:** Download zips from the [GitHub Releases page](https://github.com/scottmss/hse-nz-au-skills/releases) and upload via Settings → Capabilities → Skills.

Licence: Apache-2.0. Outputs are drafts — not legal advice. All output must be validated by a competent person against the current law and the actual workplace.

## Invocation behavior

If this Skill is invoked without specific instructions:

1. Ask for industry, operational scope, and maturity level
2. Ask for current top five risks and any recent serious events
3. Propose a 90-day Plan-Do-Check-Change cycle
4. Generate a prioritized register/control/verification uplift plan
5. Provide MCP-ready prompts for immediate execution

If this Skill is invoked for a specific objective:

- Tailor outputs to that objective
- Keep recommendations evidence-linked
- Distinguish quick wins from structural changes
- End with measurable verification criteria
