Why not both?
Graph finds the neighbourhood; Jev picks the lucky hit. Can Jev on top of Graph RAG beat either alone — more consistent relevance in long docs — and can we get closer to an “I’m Feeling Lucky” #1? (Yes, we can have both — but “both” is not free lunch.)

Prep Jev cleans the corpus; query Jev reorders Graph’s neighbourhood.
Scoreboard
Gold@1
- Graph 5/6
- Jev-only 3/6
- Hybrid 3/6
Gold in top-3
- Graph 5/6
- Jev-only 6/6
- Hybrid 6/6
Cost
- Hybrid (this run) ~$0.0040
- Jev-only ~$0.0031 (reused)
- Graph $0 (offline)
Latency
- Avg Jev scoring 503 ms
- Avg end-to-end / Q 508 ms
- Concurrency 8 · ~3500 chars
Pipeline
Both vs either alone
Verdict: why not both?
Hybrid fixes Q4
Graph latches onto art-6 (framework wording). Scoring the Graph neighbourhood with Jev promotes art-28 General principles to #1 — same win as keyword→Jev, without needing a wider BM25 pool.
…and wrecks Q2 / Q3 / Q5
Hybrid inherits Jev’s taste: Art 17 over Art 19, Rec 56 over Art 26, Rec 52 over Art 45. Graph alone was already “I’m Feeling Lucky” on those. Gold stays in Hybrid top-3 (6/6) but rank-1 consistency drops to 3/6 — same as Jev-only.
Practical takeaway
Use Graph for default lucky #1 on a clean legal corpus. Reach for Graph→Jev when the question is principle-level / easy to keyword-mismatch (Q4-shaped). Always-on hybrid costs ~$0.0040 here and is not strictly better at rank 1.
What are the ICT risk management framework requirements?
Hybrid cost ~$0.0008 · Jev scoring 758 ms · e2e 766 ms · Keyword→Jev #1: art-6 · gold@1: Graph ✓ · Hybrid ✓ · Jev-only ✓
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-6ICT risk management framework | art-6ICT risk management framework | art-6ICT risk management framework | Hybrid keeps Graph’s lucky #1 (art-6). Keyword→Jev also hits gold at #1. |
| 2 | art-16Simplified ICT risk management framework | art-16Simplified ICT risk management framework | art-5Governance and organisationabsent from Hybrid shortlist | Both keep art-16 at #2. Keyword→Jev #2=art-16. |
| 3 | art-27Requirements for testers for the carrying out of TLPT | art-9Protection and preventionwas Graph #10 | art-15Further harmonisation of ICT risk management tools, methods, processes and policiesabsent from Graph shortlist; absent from Hybrid shortlist | Graph #3=art-27; Hybrid #3=art-9 (jev 2.87). Keyword→Jev #3=art-9. |
| 4 | art-32Structure of the Oversight Framework | art-5Governance and organisationwas Graph #19 | art-7ICT systems, protocols and toolsabsent from Graph shortlist; absent from Hybrid shortlist | Graph #4=art-32; Hybrid #4=art-5 (jev 2.86). Keyword→Jev #4=art-33. |
| 5 | art-24General requirements for the performance of digital operational resilience testing | art-33Tasks of the Lead Overseerwas Graph #6 | art-16Simplified ICT risk management framework (small/micro entities) | Graph #5=art-24; Hybrid #5=art-33 (jev 2.72). Keyword→Jev #5=rec-21. |
When must financial entities report major ICT-related incidents?
Hybrid cost ~$0.0005 · Jev scoring 689 ms · e2e 696 ms · Keyword→Jev #1: art-17 · gold@1: Graph ✓ · Hybrid ✗ · Jev-only ✗
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | art-17ICT-related incident management processwas Graph #4 | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | Hybrid moves gold art-19 off #1 (now art-17) — Graph alone was luckier. Keyword→Jev #1 was art-17. |
| 2 | art-21Centralisation of reporting of major ICT-related incidents | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threatswas Graph #1 | art-17ICT-related incident management process | Graph #2=art-21; Hybrid #2=art-19 (jev 2.15). Keyword→Jev #2=art-19. |
| 3 | art-18Classification of ICT-related incidents and cyber threats | rec-53Recital (53)was Graph #7 | art-18Classification of ICT-related incidents and cyber threats | Graph #3=art-18; Hybrid #3=rec-53 (jev 1.75). Keyword→Jev #3=rec-53. |
| 4 | art-17ICT-related incident management process | rec-51Recital (51)was Graph #12 | art-21Centralisation of reporting of major ICT-related incidents | Graph #4=art-17; Hybrid #4=rec-51 (jev 1.64). Keyword→Jev #4=rec-51. |
| 5 | rec-100Recital (100) | art-18Classification of ICT-related incidents and cyber threatswas Graph #3 | art-20Harmonisation of reporting content and templatesabsent from Graph shortlist; absent from Hybrid shortlist | Graph #5=rec-100; Hybrid #5=art-18 (jev 1.40). Keyword→Jev #5=art-18. |
What is TLPT and who must perform threat-led penetration testing?
Hybrid cost ~$0.0006 · Jev scoring 398 ms · e2e 402 ms · Keyword→Jev #1: rec-56 · gold@1: Graph ✓ · Hybrid ✗ · Jev-only ✗
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-26Advanced testing of ICT tools, systems and processes based on TLPT | rec-56Recital (56)was Graph #5 | art-26Advanced testing of ICT tools, systems and processes based on TLPT | Hybrid moves gold art-26 off #1 (now rec-56) — Graph alone was luckier. Keyword→Jev #1 was rec-56. |
| 2 | rec-18Recital (18) | rec-18Recital (18) | art-27Requirements for testers for the carrying out of TLPT | Both keep rec-18 at #2. Keyword→Jev #2=rec-18. |
| 3 | art-3Definitions | art-26Advanced testing of ICT tools, systems and processes based on TLPTwas Graph #1 | art-24General requirements for the performance of digital operational resilience testingabsent from Graph shortlist; absent from Hybrid shortlist | Graph #3=art-3; Hybrid #3=art-26 (jev 2.11). Keyword→Jev #3=art-26. |
| 4 | art-27Requirements for testers for the carrying out of TLPT | art-27Requirements for testers for the carrying out of TLPT | art-25Testing of ICT tools and systems | Both keep art-27 at #4. Keyword→Jev #4=art-27. |
| 5 | rec-56Recital (56) | rec-44Recital (44)was Graph #7 | rec-56Recital (56) — TLPT rationale | Graph #5=rec-56; Hybrid #5=rec-44 (jev 1.54). Keyword→Jev #5=rec-44. |
How should financial entities manage ICT third-party risk?
Hybrid cost ~$0.0007 · Jev scoring 409 ms · e2e 412 ms · Keyword→Jev #1: art-28 · gold@1: Graph ✗ · Hybrid ✓ · Jev-only ✓
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-6ICT risk management framework | art-28General principleswas Graph #8 | art-28General principles (ICT third-party risk) | Hybrid promotes gold art-28 to #1 (Graph had art-6). Keyword→Jev also hits gold at #1. Q4 fix: Jev on the Graph neighbourhood recovers Art 28. |
| 2 | art-29Preliminary assessment of ICT concentration risk at entity level | rec-71Recital (71)was Graph #12 | art-29Preliminary assessment of ICT concentration risk at entity level | Graph #2=art-29; Hybrid #2=rec-71 (jev 2.96). Keyword→Jev #2=rec-71. |
| 3 | art-31Designation of critical ICT third-party service providers | art-29Preliminary assessment of ICT concentration risk at entity levelwas Graph #2 | art-30Key contractual provisionsabsent from Graph shortlist; absent from Hybrid shortlist | Graph #3=art-31; Hybrid #3=art-29 (jev 2.82). Keyword→Jev #3=art-29. |
| 4 | art-16Simplified ICT risk management framework | art-5Governance and organisationwas Graph #18 | art-31Designation of critical ICT third-party service providers | Graph #4=art-16; Hybrid #4=art-5 (jev 2.74). Keyword→Jev #4=art-26. |
| 5 | rec-92Recital (92) | art-26Advanced testing of ICT tools, systems and processes based on TLPTwas Graph #9 | rec-65Recital (65) — third-party risk contextabsent from Graph shortlist; absent from Hybrid shortlist | Graph #5=rec-92; Hybrid #5=art-26 (jev 2.54). Keyword→Jev #5=rec-18. |
What information must be shared on cyber threats?
Hybrid cost ~$0.0006 · Jev scoring 358 ms · e2e 360 ms · Keyword→Jev #1: rec-52 · gold@1: Graph ✓ · Hybrid ✗ · Jev-only ✗
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-45Information-sharing arrangements on cyber threat information and intelligence | rec-52Recital (52)was Graph #5 | art-45Information-sharing arrangements on cyber threat information and intelligence | Hybrid moves gold art-45 off #1 (now rec-52) — Graph alone was luckier. Keyword→Jev #1 was rec-52. |
| 2 | art-18Classification of ICT-related incidents and cyber threats | art-45Information-sharing arrangements on cyber threat information and intelligencewas Graph #1 | rec-34Recital (34) — encourage cyber threat information sharing | Graph #2=art-18; Hybrid #2=art-45 (jev 2.73). Keyword→Jev #2=art-45. |
| 3 | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | rec-33Recital (33) — limited/fragmented information sharingabsent from Graph shortlist; absent from Hybrid shortlist | Both keep art-19 at #3. Keyword→Jev #3=art-1. |
| 4 | art-37Request for information | art-22Supervisory feedbackwas Graph #20 | art-18Classification of ICT-related incidents and cyber threats | Graph #4=art-37; Hybrid #4=art-22 (jev 2.42). Keyword→Jev #4=art-19. |
| 5 | rec-52Recital (52) | rec-32Recital (32)was Graph #8 | rec-52Recital (52) — threat intelligence context | Graph #5=rec-52; Hybrid #5=rec-32 (jev 2.29). Keyword→Jev #5=art-18. |
Which entities are in scope of DORA?
Hybrid cost ~$0.0008 · Jev scoring 407 ms · e2e 412 ms · Keyword→Jev #1: art-2 · gold@1: Graph ✓ · Hybrid ✓ · Jev-only ✓
| Ranking | Graph-only | Hybrid (Graph→Jev) | Perfect/gold | What this row tells us |
|---|---|---|---|---|
| 1 | art-2Scope | art-2Scope | art-2Scope | Hybrid keeps Graph’s lucky #1 (art-2). Keyword→Jev also hits gold at #1. |
| 2 | art-26Advanced testing of ICT tools, systems and processes based on TLPT | art-26Advanced testing of ICT tools, systems and processes based on TLPT | art-3Definitions | Both keep art-26 at #2. Keyword→Jev #2=rec-42. |
| 3 | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats | art-1Subject matterwas Graph #13 | art-1Subject matterabsent from Hybrid shortlist | Graph #3=art-19; Hybrid #3=art-1 (jev 2.14). Keyword→Jev #3=art-26. |
| 4 | art-38General investigations | art-16Simplified ICT risk management frameworkwas Graph #17 | art-16Simplified ICT risk management framework (proportionality)absent from Hybrid shortlist | Graph #4=art-38; Hybrid #4=art-16 (jev 1.76). Keyword→Jev #4=art-19. |
| 5 | art-3Definitions | art-19Reporting of major ICT-related incidents and voluntary notification of significant cyber threatswas Graph #3 | rec-42Recital (42) — entity coverage contextabsent from Graph shortlist; absent from Hybrid shortlist | Graph #5=art-3; Hybrid #5=art-19 (jev 1.62). Keyword→Jev #5=art-45. |