Risk
リスク
Risk is the effect of uncertainty on an objective. It can involve downside, upside, or both, and becomes decision-ready only when the objective, uncertain event or condition, likelihood, consequence, owner, response, and remaining exposure are explicit.
What it means
Risk concerns uncertainty that can affect an objective. In practice, teams identify the objective, describe the uncertain event or condition and its causes, assess possible consequences and likelihood, select a response, assign an owner, and monitor residual risk. Some methods focus on downside exposure, while planning may examine both threats and opportunities, so the adopted definition and scale must be explicit. Financial, project, operational, safety, legal, and information security risks do not share one universal scale.
How to calculate it
Risk has no universal formula. A common assessment combines likelihood and consequence under a defined method; expected-value models may multiply probability by financial impact when both inputs are defensible. Qualitative or ordinal scores must not be presented as precise probabilities or money. Likelihood | Estimated chance or frequency of the uncertain event under stated assumptions and controls Consequence | Possible effect on the objective, including magnitude, timing, duration, and affected stakeholders Risk level | Combined likelihood and consequence under a defined method | Reassess residual risk after responses or context changes
| Lens | Formula / treatment | When to use it |
|---|---|---|
| Likelihood | Estimated chance or frequency of the uncertain event under stated assumptions and controls | |
| Consequence | Possible effect on the objective, including magnitude, timing, duration, and affected stakeholders | |
| Risk level | Combined likelihood and consequence under a defined method | Reassess residual risk after responses or context changes |
What counts / what does not
Keep the generic concept distinct from a domain-specific risk model and from an issue that has already occurred. Include | Uncertainty that could affect a stated business, financial, project, operational, safety, legal, or security objective Exclude | Routine work with no material uncertainty and realized issues that require present-tense response rather than future-risk treatment Track explicitly | Objective, scope, causes, event or condition, likelihood, consequences, assumptions, owner, response, indicators, and residual risk
| Item | Treatment |
|---|---|
| Include | Uncertainty that could affect a stated business, financial, project, operational, safety, legal, or security objective |
| Exclude | Routine work with no material uncertainty and realized issues that require present-tense response rather than future-risk treatment |
| Track explicitly | Objective, scope, causes, event or condition, likelihood, consequences, assumptions, owner, response, indicators, and residual risk |
What moves the number
Risk changes when objectives, assumptions, external conditions, dependencies, exposure, controls, or the quality and freshness of evidence change. Market, regulatory, technical, financial, operational, and human changes can alter likelihood or consequences. Dependencies, concentration, weak controls, and limited response capacity can increase exposure. Consequences depend on the objective, affected stakeholders, timing, duration, and reversibility. Responses can change likelihood or consequences, but assumptions, side effects, and control failure can leave residual risk.
- Market, regulatory, technical, financial, operational, and human changes can alter likelihood or consequences.
- Dependencies, concentration, weak controls, and limited response capacity can increase exposure.
- Consequences depend on the objective, affected stakeholders, timing, duration, and reversibility.
- Responses can change likelihood or consequences, but assumptions, side effects, and control failure can leave residual risk.
When it helps
Prioritizes whether to avoid, reduce, share or transfer, accept, or deliberately pursue an opportunity-related risk. Assigns accountability, decision authority, response deadlines, and escalation thresholds before exposure becomes an issue. Makes trade-offs among objective value, response cost, operational constraints, opportunity, and residual risk explicit.
- Prioritizes whether to avoid, reduce, share or transfer, accept, or deliberately pursue an opportunity-related risk.
- Assigns accountability, decision authority, response deadlines, and escalation thresholds before exposure becomes an issue.
- Makes trade-offs among objective value, response cost, operational constraints, opportunity, and residual risk explicit.
How to use it
- Risk must be tied to an objective; a vague concern without a decision context is not yet decision-ready.
- Use a method and scale appropriate to the domain, and record assumptions and evidence.
- A realized event becomes an issue or incident, while related future uncertainty can remain a risk.
- A risk response needs an accountable owner, selected action, acceptance criteria, indicators, and review cadence.
- Monitor changes to context, assumptions, controls, and objectives, then reassess residual risk.
Decision cautions
Do not let a heat map, a single score, or a quiet history create false confidence. Define scales and assessment scope before scoring; do not compare unlike contexts as if their units matched. Record assumptions, uncertainty, and evidence quality; missing data is not evidence of low risk. Move realized events into issue or incident handling without deleting unresolved, secondary, or downstream risk.
- Define scales and assessment scope before scoring; do not compare unlike contexts as if their units matched.
- Record assumptions, uncertainty, and evidence quality; missing data is not evidence of low risk.
- Move realized events into issue or incident handling without deleting unresolved, secondary, or downstream risk.
Read with
Pair the risk register with evidence about exposure, assumptions, response progress, and control performance. Control effectiveness | Whether planned safeguards or responses operate as intended Exposure indicators | Leading signals tied to causes, events, dependencies, or affected objectives Response completion | Whether selected risk responses close on time Issue and residual-risk review | What materialized, which assumptions or controls failed, and what exposure remains
| Metric | Role |
|---|---|
| Control effectiveness | Whether planned safeguards or responses operate as intended |
| Exposure indicators | Leading signals tied to causes, events, dependencies, or affected objectives |
| Response completion | Whether selected risk responses close on time |
| Issue and residual-risk review | What materialized, which assumptions or controls failed, and what exposure remains |
Example
A company plans a product launch to reach a revenue objective. A critical supplier has uncertain delivery capacity, so the team records the delayed-launch scenario, causes, likelihood range, financial and customer consequences, assumptions, and owner. It qualifies a second supplier and sets an escalation date. When the original supplier misses a confirmed milestone, that missed delivery becomes an issue; uncertainty about later deliveries and launch impact remains residual risk.
Compare with
Risk | Effect of uncertainty on an objective | Assess, respond, monitor, and review Issue | A condition or event that already exists and requires present-tense resolution | Resolve and track consequences Assumption | A proposition treated as true for planning | Validate and revisit when evidence changes Control | A measure that modifies risk | Test effectiveness and monitor change Information security risk | Domain-specific risk involving threats, vulnerabilities, assets, likelihood, and adverse impact | Apply a security assessment method
| Metric | Difference | Why read together |
|---|---|---|
| Risk | Effect of uncertainty on an objective | Assess, respond, monitor, and review |
| Issue | A condition or event that already exists and requires present-tense resolution | Resolve and track consequences |
| Assumption | A proposition treated as true for planning | Validate and revisit when evidence changes |
| Control | A measure that modifies risk | Test effectiveness and monitor change |
| Information security risk | Domain-specific risk involving threats, vulnerabilities, assets, likelihood, and adverse impact | Apply a security assessment method |
Common mistakes
- Risk always means a confirmed negative event. Risk addresses uncertainty, and planning may examine opportunities as well as threats.
- A high score proves an event will occur. It expresses an estimate under a defined method, assumptions, and evidence set.
- Controls or a quiet history eliminate risk. Changed conditions, failed assumptions, weak controls, and unobserved exposure can leave residual risk.
Frequently asked questions
What is the shortest useful risk statement?
State the objective, uncertain event or condition, cause, and possible consequence.
When does a risk become an issue?
When the uncertain condition or event has occurred and requires present-tense action. Related future uncertainty can remain as residual risk.
Must every risk be eliminated?
No. An organization can avoid, reduce, share or transfer, accept, or pursue risk according to objectives, obligations, and risk criteria while monitoring what remains.