The Standards Behind ShadowIQ's Risk Scoring
ShadowIQ's risk model isn't invented from scratch. It's built on three recognised standards — ISO 31030, ICD 203, and the NATO Admiralty system — so security teams find familiar ground.
When a security lead, a school's legal counsel, or a procurement team evaluates a risk platform, a fair question comes up early: is this a sensible methodology, or a black box with a confident-sounding number on the front?
Our answer is that ShadowIQ's risk model isn't invented from scratch. Its bones come from three established standards used across travel risk management, intelligence analysis, and defence. If your team already works in any of those worlds, you'll recognise the framing — and if you don't, these are the references your auditors and insurers will.
Here's what we build on, and why each one matters.
ISO 31030 — the travel risk management standard
What it is: ISO 31030 (Travel Risk Management — Guidance for Organizations) is the international standard for how organisations should manage the risks faced by people who travel on their behalf. It formalises the discipline the same way ISO standards formalise quality or information security.
How ShadowIQ uses it: the core of ISO 31030's risk thinking is likelihood × consequence — how likely harm is, times how bad it would be. That's the spine of our scoring. The important refinement we apply is whose likelihood and consequence: ShadowIQ scores them for the individual traveller on a specific itinerary, not for a whole country. A calm capital city and a volatile border region inside the same country get very different scores, because the risk that matters is the risk to your people, where they actually are.
Why it matters to you: when you show a duty-of-care decision to leadership, an auditor, or a court, "we assessed likelihood and consequence per traveller, consistent with ISO 31030" is a defensible sentence. "The app said medium" is not.
ICD 203 — how the intelligence community reasons
What it is: Intelligence Community Directive 203 (Analytic Standards) is the US intelligence community's rulebook for sound analysis. Two of its principles shape ShadowIQ directly.
Principle 1 — a defined probability vocabulary. ICD 203 rejects vague or falsely-precise likelihood language in favour of a standardised ladder — from "almost no chance," through "roughly even chance," up to "almost certain." ShadowIQ uses exactly this vocabulary for its likelihood axis, so "likely" means the same thing on every alert instead of being one analyst's gut feel.
Principle 2 — never blend likelihood with confidence. This is the one we care about most. ICD 203 insists that probability about the world (how likely is this) and analytic confidence (how sure are we of our information) are separate and must never be merged into one statement. ShadowIQ enforces this rigidly: how likely a hazard is (likelihood) and how much we trust the reporting (confidence) are different axes with different scores. Collapsing them is the single most common way a risk number goes wrong — a confirmed event isn't automatically high-risk, and a shaky report of a dangerous one isn't automatically low-risk.
Why it matters to you: it's why ShadowIQ doesn't cry wolf over confirmed-but-finished events, and doesn't quietly bury a real threat that arrived through a weak source. The discipline is borrowed straight from how national intelligence agencies are required to reason.
The NATO Admiralty system — grading the source
What it is: the Admiralty (or "NATO System") Code is a decades-old, widely-used method for grading intelligence. It scores two things independently:
- Source reliability, A–F — how trustworthy is the source, based on track record. A → completely reliable; F → cannot be assessed.
- Information credibility / corroboration, 1–6 — how well is this specific claim supported. 1 → confirmed by independent sources; 6 → cannot be judged.
How ShadowIQ uses it: every signal is graded on both scales. A government advisory sits near A; an anonymous social post starts low. A claim confirmed across multiple independent outlets scores 1; a lone report can't be graded "confirmed" no matter who posts it. Crucially — as ICD 203 demands — this confidence grade routes the alert rather than inflating its risk: an uncertain-but-serious report is held for a human analyst to verify, not dressed up as a scarier score.
Why it matters to you: it's a transparent, portable way to answer "how much should I trust this?" If your organisation runs its own intelligence function, you can map our A–F / 1–6 grades straight onto your existing process.
Standards are a floor, not a ceiling
None of this means ShadowIQ is only these standards. The value we add is applying them at machine scale, continuously, to open-source signal — and calibrating the automation against human analyst judgement (a subject we cover in our Inside the Risk Model series). But the framework underneath is deliberately conventional, because in duty of care, boring and defensible beats clever and opaque.
When you adopt a risk platform, you're also adopting its judgement about what "risky" means. We think you should be able to check that judgement against something recognised. With ShadowIQ, you can: ISO 31030 for the travel-risk framing, ICD 203 for the analytic discipline, and the Admiralty system for source grading.
Want the model itself in plain language? Start with How We Score Risk, or follow the Inside the Risk Model series — one post per element, published through the week.