Mission Intelligence Systems
Risk · Alignment

Should We Mitigate, Transfer, Accept or Avoid?

Four options presented as a flat menu. They are not remotely equivalent.

Every risk framework teaches the same four responses and almost none of them explain that two cost money whether or not the risk occurs, one leaves the event completely untouched, and the one that reads as negligence in most boardrooms is frequently the correct answer. The choice is arithmetic. It is usually made as a reflex.

Published

Key Takeaways

Research foundation

The treatment options are taken from ISO 31000:2018 clause 6.5.2, which lists seven rather than four. The transfer pricing finding is Zaghloul and Hartman (2003) in the International Journal of Project Management. The framing of risk as two-sided draws on Hillson (2002) and Ward and Chapman (2003). Contingency and confidence level practice is anchored in GAO-20-195G. Where a claim is practice rather than published finding it is marked as such. The Four A's are the executive lens applied on top.

The four responses are usually presented as a decision the team makes once, records in a column, and revisits at the next review. In practice the column fills up with the word mitigate for almost every entry, because mitigate is the answer that requires no justification. Avoid sounds defeatist, transfer requires somebody to negotiate something, and accept sounds like nobody did anything.

So the register says mitigate ninety times and the program carries every one of those risks anyway, because a mitigation strategy written in a cell is not a mitigation.

What the four options actually do

Avoidance removes the value with the risk

Avoidance means not doing the thing: not entering the market, not selecting the technology, not building at that site. It is the only response that genuinely eliminates the exposure, and the reason it is rarely chosen is that it eliminates the return at the same time.

It deserves more consideration than it gets in one specific situation, which is a risk that could breach capacity on its own. Where a single exposure could exceed what the organization can absorb, the trade-off is not between value and prudence. It is between a return and the organization's continued ability to operate, and those do not belong on the same scale.

Mitigation is an investment with a probabilistic return

Mitigation reduces likelihood, consequence or both, and it costs money now for a benefit that may never materialize. That structure is the structure of an investment, and mitigations should clear the bar any other investment clears.

They almost never face it. A mitigation is proposed in a workshop, sounds responsible, and enters the plan without anyone computing what it removes. Yet the computation is straightforward once the risk has been quantified: what does the expected loss look like with this in place, what does it look like without, and what does the mitigation cost fully loaded, including the staff time and the schedule it consumes.

A mitigation costing 400,000 dollars that reduces expected loss by 90,000 has destroyed 310,000 dollars. It will still be reported as risk management.

There is one important refinement. Expected loss is the wrong measure on its own, because it collapses the distribution to an average and organizations are not damaged by averages. A mitigation that leaves the mean untouched while cutting off the worst decile is extremely valuable to an organization with limited capacity, and expected-value reasoning will rate it as worthless. Judge mitigations at the confidence level the organization actually funds to, not at the mean.

Transfer moves the invoice, not the event

This is the response most often misunderstood at executive level, and the misunderstanding is expensive.

When a risk is transferred to a contractor, an insurer or a counterparty, what moves is a defined financial obligation, bounded by limits, exclusions, caps and the other party's ability to pay. What does not move is the event. If the systems integration fails, the integration has still failed. The opening date still slips, the service still does not run, the users are still affected, the oversight body still holds a hearing, and the executive still answers for it. Liquidated damages recover a fraction of a cost the organization has already incurred in a currency it does not care about.

And transfer is not free even before the risk occurs. Zaghloul and Hartman studied how contractors respond to risk allocation clauses in construction contracts and found that contractors price the risk they are asked to carry, adding a contingency margin to the bid. The owner pays that margin in the contract sum on every project, including all the ones where the risk never occurs. Transfer through contract is a purchase, and organizations routinely make it without asking the price.

The practical rule that follows is worth stating plainly. Transfer a risk to the party best able to control it, because that party prices it lowest and manages it best. Transferring a risk to a party who can neither control nor absorb it produces the worst available outcome: a high price now and a counterparty failure later, exactly when the risk lands.

Acceptance is a decision, not an omission

Accepting a risk means deciding to carry it, funding it, naming an owner and monitoring it. That is a distinct activity from ignoring a risk, and the fact that both produce the same entry in most registers is a governance problem.

Acceptance is correct more often than governance cultures permit. If the fully loaded cost of the alternatives exceeds the expected cost of the risk and the organization has the capacity to absorb the outcome, acceptance is the value-maximizing choice and every other option is worse. The obstacle is not analytical. It is that acceptance looks like inaction in a document, and nobody wants their name against inaction.

The fix is to make acceptance visible as a decision. An accepted risk carries a funded contingency amount, an owner, a monitoring trigger and a date at which the acceptance is reviewed. An accepted risk that appears in the record with all four is unmistakably a decision. It also, incidentally, produces exactly the evidence a board needs to show that it considered the exposure and chose deliberately.

What the four-item version leaves out

ISO 31000 sets out seven treatment options rather than four, and two of the extras matter.

The first is taking on more risk in order to pursue an opportunity. That option does not exist in the mitigate-transfer-accept-avoid formulation at all, which is why organizations using that formulation systematically treat risk work as a brake. Hillson made this argument two decades ago, that the risk process should handle upside and downside through the same machinery, and Ward and Chapman went further, arguing that the framing should be uncertainty management rather than risk management precisely because the threat-only framing narrows what the process can see.

The second is removing the risk source, which is distinct from avoiding the activity. Retiring the legacy interface is not the same as cancelling the program that depends on it, and the four-item menu has no room for the difference.

How to actually decide

Put the response into the model. A proposed response is a claim about a distribution, and claims about distributions can be tested.

Two things fall out of this that a workshop will never produce. Mitigations that do not move the confidence level are exposed as activity rather than treatment, and there are usually several. And mitigations that cut the tail without changing the average finally get credit, which matters because the tail is what breaches capacity and the average never does.

An honest caveat: this presumes the risk has been quantified well enough for the comparison to mean something, which on a poorly specified register it has not. If the entries are not written specifically enough to model, the response decision cannot be made this way and the prior problem is the register.

Evidence matrix

ClaimEvidence tierSource
Seven treatment options exist, including taking on risk to pursue an opportunityInternational standardISO 31000:2018, clause 6.5.2
Contractors price risk allocation clauses into the bid, so the owner pays for transfer up frontPeer reviewedZaghloul & Hartman (2003), IJPM 21(6)
The risk process should handle upside and downside through the same machineryPeer reviewedHillson (2002), IJPM 20(3)
Threat-only framing narrows what the process can see; uncertainty management is the wider framePeer reviewedWard & Chapman (2003), IJPM 21(2)
Contingency should be established through a risk and uncertainty analysis rather than a percentageGovernment standardGAO-20-195G (2020)
A published threshold exists above which mitigation is uneconomicNot establishedThe comparison is entity-specific; no general rule located
Most registers record mitigation for nearly every entry because it requires no justificationNamed field experienceCapital program practice, Mission Intelligence Systems

What to do with this

Open the register and count how many entries say mitigate. Then take the five largest and ask, for each, what the mitigation costs and how much it moves the number. Most organizations cannot answer either half for any of the five, which means the response column records an intention rather than a decision.

Then find the entries that should say accept and do not. They are recognizable: significant, unmitigatable at reasonable cost, and carrying a mitigation strategy nobody has started. Converting those to funded, owned, monitored acceptances is usually the single largest improvement available to a register, and it costs nothing but the willingness to write the word down.

References

  1. International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, clause 6.5.2 on selection of risk treatment options. iso.org/standard/65694.html.
  2. Zaghloul, Ramy, and Francis Hartman. “Construction Contracts: The Cost of Mistrust.” International Journal of Project Management, vol. 21, no. 6, 2003, pp. 419–424. sciencedirect.com. Contractors price the risk allocation clauses they are asked to accept.
  3. Hillson, David. “Extending the Risk Process to Manage Opportunities.” International Journal of Project Management, vol. 20, no. 3, 2002, pp. 235–240. risk-doctor.com.
  4. Ward, Stephen, and Chris Chapman. “Transforming Project Risk Management into Project Uncertainty Management.” International Journal of Project Management, vol. 21, no. 2, 2003, pp. 97–105. doi.org/10.1016/S0263-7863(01)00080-1.
  5. U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g.
  6. Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance. COSO, 2017. coso.org/guidance-erm.
  7. Cox, Louis Anthony, Jr. “What's Wrong with Risk Matrices?” Risk Analysis, vol. 28, no. 2, 2008, pp. 497–512. doi.org/10.1111/j.1539-6924.2008.01030.x. Why a score is a poor basis for a treatment decision.
  8. Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010, pp. 2:1–2:10. doi.org/10.1147/JRD.2010.2042914.
  9. Flyvbjerg, Bent. “From Nobel Prize to Project Management: Getting Risks Right.” Project Management Journal, vol. 37, no. 3, 2006, pp. 5–15. doi.org/10.1177/875697280603700302.
DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.