Skip to content
Business Term

Risk

リスク

Risk is the effect of uncertainty on an objective. It can involve downside, upside, or both, and becomes decision-ready only when the objective, uncertain event or condition, likelihood, consequence, owner, response, and remaining exposure are explicit.

Formula
Estimated chance or frequency of the uncertain event under stated assumptions and controls
Use when
Prioritizes whether to avoid, reduce, share or transfer, accept, or deliberately pursue an opportunity-related risk.
Watch out
Uncertainty that could affect a stated business, financial, project, operational, safety, legal, or security objective
Updated: 07/17/2026Quality: ReviewedPage tier: Reviewed articleSources: 3

What it means

Risk concerns uncertainty that can affect an objective. In practice, teams identify the objective, describe the uncertain event or condition and its causes, assess possible consequences and likelihood, select a response, assign an owner, and monitor residual risk. Some methods focus on downside exposure, while planning may examine both threats and opportunities, so the adopted definition and scale must be explicit. Financial, project, operational, safety, legal, and information security risks do not share one universal scale.

How to calculate it

Risk has no universal formula. A common assessment combines likelihood and consequence under a defined method; expected-value models may multiply probability by financial impact when both inputs are defensible. Qualitative or ordinal scores must not be presented as precise probabilities or money. Likelihood | Estimated chance or frequency of the uncertain event under stated assumptions and controls Consequence | Possible effect on the objective, including magnitude, timing, duration, and affected stakeholders Risk level | Combined likelihood and consequence under a defined method | Reassess residual risk after responses or context changes

LensFormula / treatmentWhen to use it
LikelihoodEstimated chance or frequency of the uncertain event under stated assumptions and controls
ConsequencePossible effect on the objective, including magnitude, timing, duration, and affected stakeholders
Risk levelCombined likelihood and consequence under a defined methodReassess residual risk after responses or context changes

What counts / what does not

Keep the generic concept distinct from a domain-specific risk model and from an issue that has already occurred. Include | Uncertainty that could affect a stated business, financial, project, operational, safety, legal, or security objective Exclude | Routine work with no material uncertainty and realized issues that require present-tense response rather than future-risk treatment Track explicitly | Objective, scope, causes, event or condition, likelihood, consequences, assumptions, owner, response, indicators, and residual risk

ItemTreatment
IncludeUncertainty that could affect a stated business, financial, project, operational, safety, legal, or security objective
ExcludeRoutine work with no material uncertainty and realized issues that require present-tense response rather than future-risk treatment
Track explicitlyObjective, scope, causes, event or condition, likelihood, consequences, assumptions, owner, response, indicators, and residual risk

What moves the number

Risk changes when objectives, assumptions, external conditions, dependencies, exposure, controls, or the quality and freshness of evidence change. Market, regulatory, technical, financial, operational, and human changes can alter likelihood or consequences. Dependencies, concentration, weak controls, and limited response capacity can increase exposure. Consequences depend on the objective, affected stakeholders, timing, duration, and reversibility. Responses can change likelihood or consequences, but assumptions, side effects, and control failure can leave residual risk.

  • Market, regulatory, technical, financial, operational, and human changes can alter likelihood or consequences.
  • Dependencies, concentration, weak controls, and limited response capacity can increase exposure.
  • Consequences depend on the objective, affected stakeholders, timing, duration, and reversibility.
  • Responses can change likelihood or consequences, but assumptions, side effects, and control failure can leave residual risk.

When it helps

Prioritizes whether to avoid, reduce, share or transfer, accept, or deliberately pursue an opportunity-related risk. Assigns accountability, decision authority, response deadlines, and escalation thresholds before exposure becomes an issue. Makes trade-offs among objective value, response cost, operational constraints, opportunity, and residual risk explicit.

  • Prioritizes whether to avoid, reduce, share or transfer, accept, or deliberately pursue an opportunity-related risk.
  • Assigns accountability, decision authority, response deadlines, and escalation thresholds before exposure becomes an issue.
  • Makes trade-offs among objective value, response cost, operational constraints, opportunity, and residual risk explicit.

How to use it

  • Risk must be tied to an objective; a vague concern without a decision context is not yet decision-ready.
  • Use a method and scale appropriate to the domain, and record assumptions and evidence.
  • A realized event becomes an issue or incident, while related future uncertainty can remain a risk.
  • A risk response needs an accountable owner, selected action, acceptance criteria, indicators, and review cadence.
  • Monitor changes to context, assumptions, controls, and objectives, then reassess residual risk.

Decision cautions

Do not let a heat map, a single score, or a quiet history create false confidence. Define scales and assessment scope before scoring; do not compare unlike contexts as if their units matched. Record assumptions, uncertainty, and evidence quality; missing data is not evidence of low risk. Move realized events into issue or incident handling without deleting unresolved, secondary, or downstream risk.

  • Define scales and assessment scope before scoring; do not compare unlike contexts as if their units matched.
  • Record assumptions, uncertainty, and evidence quality; missing data is not evidence of low risk.
  • Move realized events into issue or incident handling without deleting unresolved, secondary, or downstream risk.

Read with

Pair the risk register with evidence about exposure, assumptions, response progress, and control performance. Control effectiveness | Whether planned safeguards or responses operate as intended Exposure indicators | Leading signals tied to causes, events, dependencies, or affected objectives Response completion | Whether selected risk responses close on time Issue and residual-risk review | What materialized, which assumptions or controls failed, and what exposure remains

MetricRole
Control effectivenessWhether planned safeguards or responses operate as intended
Exposure indicatorsLeading signals tied to causes, events, dependencies, or affected objectives
Response completionWhether selected risk responses close on time
Issue and residual-risk reviewWhat materialized, which assumptions or controls failed, and what exposure remains

Example

A company plans a product launch to reach a revenue objective. A critical supplier has uncertain delivery capacity, so the team records the delayed-launch scenario, causes, likelihood range, financial and customer consequences, assumptions, and owner. It qualifies a second supplier and sets an escalation date. When the original supplier misses a confirmed milestone, that missed delivery becomes an issue; uncertainty about later deliveries and launch impact remains residual risk.

Compare with

Risk | Effect of uncertainty on an objective | Assess, respond, monitor, and review Issue | A condition or event that already exists and requires present-tense resolution | Resolve and track consequences Assumption | A proposition treated as true for planning | Validate and revisit when evidence changes Control | A measure that modifies risk | Test effectiveness and monitor change Information security risk | Domain-specific risk involving threats, vulnerabilities, assets, likelihood, and adverse impact | Apply a security assessment method

MetricDifferenceWhy read together
RiskEffect of uncertainty on an objectiveAssess, respond, monitor, and review
IssueA condition or event that already exists and requires present-tense resolutionResolve and track consequences
AssumptionA proposition treated as true for planningValidate and revisit when evidence changes
ControlA measure that modifies riskTest effectiveness and monitor change
Information security riskDomain-specific risk involving threats, vulnerabilities, assets, likelihood, and adverse impactApply a security assessment method

Common mistakes

  • Risk always means a confirmed negative event. Risk addresses uncertainty, and planning may examine opportunities as well as threats.
  • A high score proves an event will occur. It expresses an estimate under a defined method, assumptions, and evidence set.
  • Controls or a quiet history eliminate risk. Changed conditions, failed assumptions, weak controls, and unobserved exposure can leave residual risk.

Frequently asked questions

What is the shortest useful risk statement?

State the objective, uncertain event or condition, cause, and possible consequence.

When does a risk become an issue?

When the uncertain condition or event has occurred and requires present-tense action. Related future uncertainty can remain as residual risk.

Must every risk be eliminated?

No. An organization can avoid, reduce, share or transfer, accept, or pursue risk according to objectives, obligations, and risk criteria while monitoring what remains.

Sources

SourcesKindLink
ISO 31000: Risk managementtier_sOpen
NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessmentstier_sOpen
NIST SP 800-39: Managing Information Security Risktier_sOpen