Before scoring risks, establish what is being assessed, why it matters and where its boundaries lie. A demand's context combines explanatory text with links to business goals, security drivers, policies, systems, third parties and related risks.
Use these guides to make the scope explicit and keep assessment assumptions traceable to the records they concern.