Why the Biggest Risk Is Never in the Register
Somebody knew. It was not written down because writing it down would have named someone.
Go back through the post-mortem of almost any program that failed badly and you will find the same thing: the cause was understood by people in the building well before it landed, and it never reached the register. That is usually treated as a culture problem. It is also a measurement problem, and the measurement consequence is sharper than the culture one.
Published
Key Takeaways
- Silence about risk is a collective condition rather than a set of individual failures. The research describes shared beliefs that speaking is futile or costly, and taken-for-granted rules such as not going over a boss and not raising a problem without a solution.
- The quantitative consequence is the part usually missed. A simulation can only widen the distribution around the risks it is given, so a censored register produces a confidence level that is too narrow and too low, and does so with every appearance of rigor.
- Silence and strategic misrepresentation look identical in the register and require opposite remedies. One is fixed by changing the conditions of reporting; the other is only fixed by independent estimation and accountability for forecast accuracy.
Research foundation
The silence mechanism rests on Morrison and Milliken (2000), Milliken, Morrison and Hewlin (2003), Edmondson (1999) on psychological safety, and Detert and Edmondson (2011) on implicit voice theories. The deliberate-understatement case rests on Flyvbjerg, Skamris Holm and Buhl (2002). The elicitation response draws on Dalkey and Helmer (1963). One limit is stated explicitly: no peer-reviewed study located establishes that anonymous elicitation surfaces politically suppressed risks in particular. The Four A's are the executive lens applied on top.
There is a moment in most risk workshops that is easy to miss if you are running the agenda. Somebody starts a sentence, gets three or four words in, and redirects it. The redirect is smooth and nobody comments. What was going to be a statement about a person becomes a statement about a process, and the entry that eventually lands in the register is the sanded-down version.
Multiply that by every workshop over two years and you have a document that describes the program as its participants were prepared to describe it in front of each other. That is a genuinely useful document. It is not the risk profile.
Why do people not report what they can see?
Because the calculation usually comes out against it, and the research on this is unusually consistent.
Morrison and Milliken made the case that silence in organizations is not an aggregation of individually timid people but a collective phenomenon with its own dynamics, sustained by widely shared beliefs that speaking up is futile or dangerous and by structures that make those beliefs self-confirming. Once the belief is shared, the absence of dissent becomes evidence for the belief. Nobody else raised it, so presumably raising it is not done here.
Milliken, Morrison and Hewlin went and asked people. The issues employees most frequently reported withholding were problems with a supervisor and problems with organizational processes, which is precisely the category most likely to matter on a troubled program. And the reason given most often was not fear of formal retaliation. It was fear of being labeled or viewed negatively, and concern about damaging a relationship. Those are much lower-grade fears than the ones organizations imagine they need to eliminate, and they are entirely sufficient to keep a significant risk out of a register.
Detert and Edmondson add the layer that explains why this survives good intentions. People carry implicit voice theories: rules about speaking up that are held without ever being examined. Do not embarrass a superior in public. Do not go over your boss. Do not bring a problem unless you bring a solution. Do not raise something you cannot prove. These are not policies and nobody argues with them, because nobody articulates them. A leader can sincerely invite challenge and receive none, and conclude from the silence that there is nothing to hear.
Edmondson's earlier work on psychological safety supplies the condition under which this changes: a shared belief that the team is safe for interpersonal risk-taking. Worth noting what that construct is and is not. It is not comfort, and it is not the absence of pressure. It is the belief that saying the difficult thing will not be held against you, which is compatible with very high standards and often coexists with them.
What a missing risk does to a quantified model
This is the part that turns a soft problem into a hard one.
A Monte Carlo simulation does exactly one thing: it propagates the uncertainty you gave it through the logic you built. It has no capacity to detect that something is absent. If a risk is not in the register, it is not in the model, and the model does not compensate, hedge or fail safe. It produces a tighter distribution than reality warrants and reports it with the same confidence it would report a complete one.
So the P80 on a censored register is not the eightieth percentile of program outcomes. It is the eightieth percentile of the outcomes generated by the risks people were willing to write down. Those are different populations and only one of them is going to happen.
A simulation cannot widen a distribution around a risk it was never told about. Omission does not make a model conservative. It makes it confidently narrow.
This inverts a common intuition. Executives often assume that a rigorous quantitative process is protection against a weak register, that the mathematics will somehow catch what the workshop missed. The opposite is true. Quantification amplifies whatever the register contains, including its silences, and it dresses the result in a precision that makes challenge harder. An organization with a bad register and no model has an obviously unreliable picture. An organization with a bad register and a good model has an unreliable picture that looks authoritative, and that is a worse position to be in.
It also explains a pattern that recurs on program reviews. The simulation was competently run, the method was sound, the documentation was complete, and the program still landed outside the modelled range. In most of those cases the model was not wrong. The register was, and in a direction nobody could see from inside the arithmetic.
Silence is not the same as misrepresentation
Two things produce an understated register and they need opposite responses, so it is worth being able to tell them apart.
Silence is a risk withheld by someone who would report it if reporting were safe. The information exists in the organization and is blocked on its way up. Every remedy here is about the conditions of reporting: who is in the room, whether the input is attributed, what happens to the last person who raised something inconvenient.
Strategic misrepresentation is different in kind. Flyvbjerg, Skamris Holm and Buhl examined cost underestimation in public works and framed the question directly in their title as error or lie, concluding that the pattern of underestimation across decades and countries was not well explained by innocent forecasting error. Where a party has an interest in a project proceeding, understating its cost and risk is instrumentally rational. That is not a communication failure and no amount of psychological safety addresses it. It is addressed by independent estimation, by reference class methods that bypass the interested party's judgment entirely, and by holding forecasters accountable for accuracy after the fact.
The diagnostic question is uncomfortable but simple: does the person who is not reporting this risk benefit if the program proceeds? If no, you have a silence problem. If yes, you have an incentive problem wearing a silence costume.
How do you get the unnamed risk into the model?
Three mechanisms, in descending order of how well supported they are.
Collect the input before the room forms
The Delphi method exists because Dalkey and Helmer observed that a group of experts in a room converges on the view of whoever is most senior or most confident rather than on the best estimate. Independent written rounds, with controlled feedback between them, remove the audience from the first draft. Applied to risk elicitation this means the first version of a range or a concern is recorded privately, and the workshop discusses a compiled set rather than generating one live. The concern still has to be raised, but it is raised as an entry among entries rather than as an act of dissent.
Ask for a range, not a judgment
This is a framing move and it does real work. Saying that the utility relocation could take twice as long as planned because the coordination has not started is a criticism of a colleague. Providing a duration range whose upper bound is double the planned figure is a technical input. The information content is nearly identical and the social cost is not. Structuring elicitation around ranges on outcomes, rather than around what might go wrong and whose fault it would be, routes the same knowledge through a channel people are willing to use.
Let the tornado chart do the talking
A variance contribution ranking is the most politically useful artifact in quantitative risk work and it is almost never described that way. When a sensitivity chart shows that one activity drives a disproportionate share of the outcome spread, that is a mathematical property of the model, not an accusation. It gets an uncomfortable item onto a governing body's agenda without requiring anyone to be the person who said it. Practitioners use this deliberately. It should be used deliberately more often.
An honest limitation on all three: none of this has been demonstrated in a controlled study to surface politically suppressed risks specifically. The Delphi evidence concerns group judgment quality, and the silence literature establishes the mechanism rather than the cure. These are reasoned responses to a documented problem, and they should be described that way rather than sold as validated technique.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| Silence about problems is a collective organizational condition, not individual timidity | Peer reviewed | Morrison & Milliken (2000), AMR 25(4) |
| Withheld issues most often concern supervisors and processes; the dominant fear is being labeled negatively | Peer reviewed | Milliken, Morrison & Hewlin (2003), JMS 40(6) |
| Unexamined rules about speaking up suppress voice without any hostile act | Peer reviewed | Detert & Edmondson (2011), AMJ 54(3) |
| Psychological safety is a shared belief about interpersonal risk, distinct from comfort | Peer reviewed | Edmondson (1999), ASQ 44(2) |
| Systematic cost underestimation in public works is not well explained by innocent error | Peer reviewed | Flyvbjerg, Skamris Holm & Buhl (2002), JAPA 68(3) |
| Independent written rounds reduce the dominance of the loudest voice in expert groups | Peer reviewed, foundational | Dalkey & Helmer (1963), Management Science 9(3) |
| Anonymous elicitation surfaces politically suppressed risks specifically | Not established | No peer-reviewed study located |
| Quantification amplifies a register's omissions rather than compensating for them | Named field experience | Capital program practice, Mission Intelligence Systems |
What to do with this
Before the next quantitative analysis, ask every person who will supply an input one question in writing and separately: what is the thing you would not say in the workshop. Do not attribute the answers. Compile them and put them in front of the group as a list.
You will get a short list and most of it will already be known to most of the room, which is exactly the finding. An issue that everyone knows and nobody has written down is not a secret. It is an item that has never been given a range, and therefore has never been in a model, and therefore has never been in a number that a board approved.
References
- Morrison, Elizabeth Wolfe, and Frances J. Milliken. “Organizational Silence: A Barrier to Change and Development in a Pluralistic World.” Academy of Management Review, vol. 25, no. 4, 2000, pp. 706–725. doi.org/10.5465/amr.2000.3707697.
- Milliken, Frances J., Elizabeth W. Morrison, and Patricia F. Hewlin. “An Exploratory Study of Employee Silence: Issues that Employees Don't Communicate Upward and Why.” Journal of Management Studies, vol. 40, no. 6, 2003, pp. 1453–1476. doi.org/10.1111/1467-6486.00387.
- Detert, James R., and Amy C. Edmondson. “Implicit Voice Theories: Taken-for-Granted Rules of Self-Censorship at Work.” Academy of Management Journal, vol. 54, no. 3, 2011, pp. 461–488. doi.org/10.5465/amj.2011.61967925.
- Edmondson, Amy. “Psychological Safety and Learning Behavior in Work Teams.” Administrative Science Quarterly, vol. 44, no. 2, 1999, pp. 350–383. doi.org/10.2307/2666999.
- Flyvbjerg, Bent, Mette K. Skamris Holm, and Søren L. Buhl. “Underestimating Costs in Public Works Projects: Error or Lie?” Journal of the American Planning Association, vol. 68, no. 3, 2002, pp. 279–295. doi.org/10.1080/01944360208976273.
- Dalkey, Norman, and Olaf Helmer. “An Experimental Application of the Delphi Method to the Use of Experts.” Management Science, vol. 9, no. 3, 1963, pp. 458–467. doi.org/10.1287/mnsc.9.3.458.
- Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010. doi.org/10.1147/JRD.2010.2042914.
- U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018, clause 4(f) on best available information. iso.org/standard/65694.html.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
