This is an open working note. Values and definitions here are working values, they are published so the reasoning is inspectable, not because they are settled.
Status: open. Needs a decision rather than a default.
The problem
A residual risk score resting on a verification from two hundred days ago is weaker than the same score resting on one from last week. The environment moved. The population changed. The control may have drifted. Nothing in the record says so, and the two scores render identically.
Today, IO surfaces the age of the verification supporting each residual. Nothing else happens. There is no automatic decay of the score back toward inherent as evidence ages.
Why this has not been implemented
Three arguments against automatic decay, and they are not weak.
Decay is itself an assertion. If a score drifts upward because time passed rather than because anything was measured, the number has moved without evidence which is precisely the behaviour this risk model exists to eliminate. An automatic decay function would be the one place in the system where a number changes because a clock ticked.
The half-life is not knowable in general. How fast evidence about phishing resilience goes stale is not how fast evidence about network segmentation goes stale. A single decay curve applied across a register would be wrong nearly everywhere, and a per-practice curve requires calibration data that does not exist.
It creates a perverse incentive. If residual decays automatically, the cheapest way to keep a register looking good is to re-run verifications frequently on measures that are easy to pass, rather than to measure the things that matter.
The argument for doing it anyway
One argument, and it is strong: without decay, a register can look thoroughly measured while resting entirely on evidence nobody has refreshed in a year. Coverage stays high. Confidence stays high. The register is stale and says nothing about it beyond a date field most readers will not open.
The options on the table
Do nothing further. Age is surfaced; readers are trusted to use it. Simple, honest, and easy to ignore.
Flag rather than decay. Past a per-practice staleness threshold, the residual keeps its value but gains a state, measured, stale, that appears wherever the number appears and is counted in the board rollup. The score never moves without evidence, but the reader cannot miss the age.
Decay to unmeasured, not to inherent. Past a threshold, residual reverts to not yet measured rather than drifting toward inherent. This treats stale evidence as absent evidence, which is at least consistent with the rest of the model, though it may be too blunt.
Full decay curves. Per-practice half-lives, calibrated. Most informative, least defensible without data, and most gameable.
Current inclination
The second option, flag rather than decay, because it adds information without letting any number move on anything other than a measurement. But this is inclination, not decision, and it is recorded here so that it can be argued with before it becomes behaviour.
A stronger state model
Age alone is not enough. A future policy should distinguish:
| State | Meaning | Reporting effect |
|---|---|---|
| Current | Inside the practice-specific review interval; source healthy | Value shown with normal confidence treatment |
| Aging | Approaching the interval; no contrary evidence | Value shown with age warning |
| Stale | Past the interval | Value retained, visibly stale and excluded from claims of current coverage |
| Superseded | A newer valid verification exists | Historical only |
| Source impaired | Freshness cannot be determined because collection failed | Confidence reduced or finding withheld |
The staleness interval must follow the volatility of the condition and the expected control cadence, not the convenience of a universal 90-day default. Material change, new architecture, population, threat condition or control version, may end relevance before the time threshold.
What would settle it
Evidence about how quickly verified outcomes actually revert in practice. That requires repeat verifications of the same measure over long windows, which the platform is now capable of producing but has not yet accumulated.
Industry relationship
Continuous monitoring and management-system review already require evidence to remain relevant. IO's unresolved question is narrower: whether staleness should change only the confidence and coverage state or also the risk value. Until calibrated, the product should not let a clock manufacture numerical movement.