Risk is the effect of uncertainty on the achievement of objectives. Note both phrases: “uncertainty”, because it has not happened yet, and “objectives”, because anything that touches no objective does not deserve to be called a risk.
1 Risk and problem: a difference that changes everything
| Risk | Problem | |
|---|---|---|
| Timing | Has not happened yet | Has already happened |
| Probability | Somewhere between zero and one | Its probability is settled: it is now fact |
| Approach | Managed in advance | Its consequences are dealt with |
| Cost | Far lower | Higher, and may include fines and reputational damage |
The idea in one line
Whoever manages risk buys time and options. Whoever waits for it to materialise is left with the fewest options and the most expensive ones.
2 The three elements of a risk
Cause
What might set the risk off?
Event
What might happen?
Effect
What harm to the objective?
A sound risk statement names all three: because of… there is a chance that… leading to…
Weak: “Inventory risks.” That is a heading, not a risk: no cause, no event, no effect.
Sound: “Because of weak periodic stocktaking controls, inventory quantities may be recorded that do not match reality, leading to incorrect financial statements and mistaken purchasing decisions.”
The difference is that the second tells you where to intervene (the controls), what to monitor (the reconciliation), and why it matters (the accuracy of the statements).
3 Types of risk in an organisation
| Type | Examples |
|---|---|
| Strategic | A strong competitor entering, changing customer behaviour, dependence on a single client |
| Financial | Liquidity shortage, collection failures, exchange rate volatility, rising cost of funding |
| Operational | A production line breaking down, human error, a key supplier cutting off |
| Compliance | A legal breach, a late tax return, a new regulatory requirement |
| Technology and cyber | A data breach, loss of backups, a system outage |
| Reputation | A social media crisis, a public complaint, a customer service failure |
4 Why is risk managed?
- To protect the objectives: a plan is not delivered by intent, but by clearing what stands in its way.
- To set priorities: resources are limited, so they go to what has the greatest impact rather than to whatever shouts loudest.
- To make a conscious decision: the difference between accepting a risk knowingly and accepting it unawares.
- To meet a regulatory requirement: many regulators require a risk management framework.
- For the confidence of lenders: whoever sees an organisation that knows its risks trusts its decisions.
A common misconception
“Risk management means reducing risk to zero.” Not so: zero risk means zero activity. What is required is risk that is understood, accepted and managed, not risk that is absent.
Lesson summary
- Risk is the effect of uncertainty on the achievement of objectives, and it has not happened yet.
- Risk is managed in advance; a problem is dealt with after the fact, at higher cost.
- Every risk has three elements — cause, event and effect — and they belong in the statement.
- Risks come in types: strategic, financial, operational, compliance, technology and reputation.
- The aim is not to eliminate risk but to manage it consciously.
5 Test your understanding
Three quick questions
Pick the answer you believe is correct and you will see the result immediately.
1. “The server went down yesterday and work stopped for two hours.” This is:
What has happened is no longer a risk. But it is an excellent source for updating the risk register and preventing a recurrence.
2. Which of the following statements is soundest?
A complete statement names the cause, the event and the effect, and so points you to both the treatment and the indicator.
3. An organisation depending on one client for 70% of its revenue is classified as which kind of risk?
Customer concentration bears on the business model and the sustainability of revenue — the essence of strategic risk.