There is no information on where the numbers come from. They may be well researched for all I can tell, but they seem almost entirely arbitrary.
You are right that there is still a lot of work to be done. We are constantly adding new information.
You can find first data about Mt.Gox's company and network risk here:
http://imfed.org/ratings/mt-gox-tibanne-co-ltd/ (see how often they had to change their bank, where you could sue them...)
The exact numbers are based on facts but are still just an opinion. It is our goal to encourage people to discuss and share information about the specific risks. A lot has already be done in this forum. Our project will only make sense if the ratings are based on well discussed arguments. We are trying to collect and concentrate these arguments.