Risk Experts / Assessing

Risk management is a decision record, not a prediction system

The value is not in forecasting what will happen. It is in being able to show, afterwards, that the decision was reasonable on what was known at the time.

Risk management is widely understood as an attempt to anticipate what might go wrong and prevent it. That framing sets an impossible standard, because the events that actually cause serious damage are frequently ones that were not on any register, and a discipline judged on whether it predicted them will be judged a failure after every significant incident. It also produces the familiar cynicism about registers: if the last three crises were not in it, what is it for.

A more defensible account is that the discipline produces a record of deliberate decisions under uncertainty. It establishes that somebody identified a hazard, assessed it with the information available, decided what to do, and that the decision was made by a person with the authority to make it. That record is worth having whether or not the event occurs, because the alternative is an organisation where consequential exposures are accepted implicitly, by nobody in particular, without anybody having considered them.

This changes what good looks like. A register full of accurate predictions is not achievable. A register in which every entry has a named owner, a decision, and a date is achievable, and it is what allows an organisation to distinguish between a risk it consciously accepted and one it never noticed. Those are very different positions after an incident, both practically and in how they are judged by anybody assessing conduct afterwards.

It also clarifies why the most common failure is not analytical. Organisations are generally capable of identifying their major exposures; ask any group of experienced staff and they will produce a list within an hour, and it will be broadly correct. What fails is the step after identification: somebody has to own the item, somebody has to decide, and the decision has to be visible enough that it can be revisited. Registers fail at ownership far more often than at identification.

The second common failure is treating assessment as measurement. A likelihood and a consequence rating are compressed judgements, useful for structuring a conversation and for sorting a list, and they are routinely treated as though they carried the precision of the arithmetic performed on them. Multiplying two subjective ratings produces a number with two significant figures and no more information than the judgements that went into it, and the number then travels into reports where the reasoning does not follow.

The third is that registers become archives. Entries accumulate, are never closed, and are reviewed by confirming they still exist. After a few years the document lists everything that has ever concerned anybody, which is unusable for prioritisation and is therefore not used, which means the organisation is once again making its real decisions somewhere else.

So the work that actually matters in this discipline is unglamorous: keeping the list short enough to be held in mind, insisting on named owners rather than departments, requiring that reviews produce a decision, and recording the reasoning rather than only the rating. None of that is sophisticated and all of it is what separates a register that informs decisions from one that is produced when asked for.

A final observation about what the discipline is for, since it explains why it is so often resented. A functioning risk process makes explicit the trade-offs an organisation has been making implicitly, and some of those are uncomfortable to see written down: that a known exposure is being carried because treating it costs more than the organisation is willing to spend. That sentence is accurate, it is a legitimate business decision, and it is one nobody wants to sign. Much of the vagueness in risk documentation exists to avoid producing that sentence.