Create audit-ready evidence that documents exactly what was modeled, with which parameters, using which data, and producing which outputs
CRML treats risk models as versioned, reviewable artifacts with strict JSON Schema validation. Models capture assumptions, control mappings, threat catalogs, and dependencies explicitly. Combined with Git history and CI validation, this creates a complete, traceable audit trail of how risk was calculated—satisfying compliance and regulatory requirements for reproducibility.
