What Is Our Top Risk?
The most common executive question about risk, and the one with no honest answer.
It is a fair question asked in good faith and it presupposes something false: that the organization's risks form a single ordered list with a genuine occupant at position one. They do not. What usually gets presented as the answer is arithmetic performed on scales that will not carry it, and the item at the top is frequently the one whose owner argued best.
Published
Key Takeaways
- Ranking requires a common unit. Most registers rank in scores, and ordinal scores preserve order without preserving distance, so the multiplication used to produce a rank is not an operation the scale supports.
- Rankings evaluate risks one row at a time, which is exactly where compound failures hide. Two correlated moderate risks can dominate one larger independent risk and no individual ranking will reveal it.
- Three replacement questions are answerable: what drives the most variance, what has the shortest time to irreversibility, and what could breach capacity alone. They produce different orders, and the disagreement is the useful part.
Research foundation
The measurement argument rests on Stevens (1946) on scales of measurement, Hubbard and Evans (2010) in the IBM Journal of Research and Development, Cox (2008) in Risk Analysis, and Thomas, Bratvold and Bickel (2014) in SPE Economics & Management. The survey discussion uses the NC State ERM Initiative and Protiviti Executive Perspectives on Top Risks 2026. The replacement questions are practice, marked as such. The Four A's are the executive lens applied on top.
Watch how the answer gets produced. Someone opens the register, sorts by score descending, and reads the first row. Nobody in the room asks where the score came from, because the score is a number and numbers are assumed to have been measured.
They were not measured. They were assigned, in a workshop, by people applying adjectives to a five point scale, and then multiplied together.
Why the ranking is usually invalid
The scale does not support the arithmetic
Stevens set out the distinction that this turns on eighty years ago. An ordinal scale preserves order but not distance: it tells you that four is worse than three without telling you how much worse, and specifically without licensing the assumption that the gap between three and four equals the gap between one and two. Multiplication requires the stronger property. Applying it to ordinal inputs produces a number that looks like a measurement and behaves like a ranking of the labels rather than of the things.
Hubbard and Evans made this argument specifically about risk assessment and it is the cleanest statement of the problem in the literature. Cox demonstrated the consequence formally, showing among other things that matrices can assign a higher qualitative rating to a quantitatively smaller risk, and that in some configurations the ratings are barely better than random with respect to the underlying quantities. Thomas, Bratvold and Bickel took the same critique into petroleum industry practice and found the design choices that determine the ranking, the scale boundaries and the category widths, are typically arbitrary and undocumented.
None of this means the register is worthless. It means the sort order is not evidence. The full treatment of what Cox actually proved covers where a matrix remains defensible, which is narrower than its critics say and much narrower than its users assume.
The units are not commensurable
Set the scale problem aside and a deeper one remains. A ransomware event, an eighteen month permitting delay and the retirement of the only engineer who understands the signalling system are not more or less than one another in any natural sense. They are different kinds of harm.
Ranking them requires converting each to a common measure, and there are only two honest options. Convert everything to a monetary distribution, which is real work and is what quantification actually means. Or accept that you are ranking within a category and say so, which is legitimate and much less impressive on a slide.
What organizations usually do instead is convert everything to a score, which has the appearance of a common measure and none of its properties.
Rankings hide the combinations
This is the failure that costs the most and it is structural rather than technical.
A ranked list assesses each risk on its own row. Real damage rarely arrives that way. A supplier problem that is survivable alone becomes existential when it coincides with the labor shortage that made the alternative supplier unattractive, and the two share a cause nobody wrote down. Assessed individually, both sit in the middle of the register. Assessed together, they are the program.
A register that ranks fifty risks and models none of their dependencies has described the parts and said nothing about the system. Compound failure is the normal shape of serious failure.
This is why correlation is a first-class input in a quantitative model rather than a refinement to be added later if time permits. Ignoring it does not produce a neutral result. It produces a systematically narrow one, because independent risks partially cancel and correlated risks do not.
What the top risks surveys are actually telling you
They are worth reading and they are worth reading correctly.
The NC State ERM Initiative and Protiviti survey for 2026 asked 1,540 board members and C-suite executives what they expect to affect them over the near term. Cyber threats came first, third-party risk second, adoption of emerging technologies with the associated workforce upskilling third, with legacy technology performance gaps and economic conditions close behind. Five of the top ten were operational rather than strategic or macroeconomic.
That is a real measurement of a real thing: the current distribution of executive attention across a large sample. It is genuinely useful for one purpose, which is checking whether your own attention is unusual. If cyber is nowhere in your top ten and it is first for everyone else, that gap deserves an explanation, and the explanation might well be good.
It is not a measurement of your exposure and it cannot be, because it contains nothing about your funding plan, your contracts, your workforce, your asset condition or your schedule. Importing a published ranking into a board pack as though it described the organization is the most common misuse of this research, and it is encouraged by the fact that doing so produces a defensible-looking answer to the unanswerable question.
Three questions that can be answered
What drives the most variance in the outcome?
Within a single quantified objective, this has a real answer. A sensitivity analysis over a Monte Carlo model ranks inputs by their contribution to the spread of the result, and that ranking is on a genuinely common scale because everything has been converted to the same unit. A schedule model produces the same thing through criticality: how often each activity appears on the critical path across iterations.
Two constraints, both important. The ranking is only valid within the modelled objective, so a cost tornado ranks cost drivers and says nothing about reputational exposure. And it ranks by contribution to uncertainty, not by expected loss, which means a large but well-understood cost sits low on the chart. That is correct behavior and it surprises people the first time.
What has the shortest time to irreversibility?
Magnitude is the wrong axis for a decision-making body. What a board can actually affect is the set of choices still open, and those close on their own schedule.
A risk with a large consequence that can be addressed at any point in the next two years is less urgent than a moderate one whose mitigation requires a procurement decision this quarter. Ranking by time to irreversibility produces a list that is often nearly disjoint from the ranking by size, and it is the list that matches what the meeting can actually do.
What could breach capacity on its own?
Not a ranking at all, which is why it works. It is a filter with a yes or no answer.
Take the amount the organization can absorb before it breaches an obligation, and ask which single risks, at a reasonable upper bound, exceed it alone. Usually the answer is one or two items and sometimes it is none. Those items require a different kind of attention from everything else on the register, and identifying them requires no ranking, no scoring and no workshop. It requires one number, which is capacity, and an upper bound on each risk.
When these three questions produce three different lists, and they usually do, that is not a contradiction to be resolved. It is the honest structure of the problem finally becoming visible.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| Ordinal scales preserve order but not distance, and do not support multiplication | Peer reviewed, foundational | Stevens (1946), Science 103(2684) |
| Scoring methods in risk assessment misuse ordinal inputs | Peer reviewed | Hubbard & Evans (2010), IBM J. Res. Dev. 54(3) |
| Matrices can assign higher ratings to quantitatively smaller risks | Peer reviewed | Cox (2008), Risk Analysis 28(2) |
| Scale boundaries that determine the ranking are typically arbitrary in practice | Peer reviewed | Thomas, Bratvold & Bickel (2014), SPE E&M 6(2) |
| Cyber threats rank first among near-term risks for boards and executives in 2026 | Institutional survey | NC State ERM Initiative & Protiviti (2025), n = 1,540 |
| A published top risks ranking indicates a given organization's exposure | Not established | The instrument measures executive concern, not entity exposure |
| Variance, irreversibility and capacity produce three different and equally legitimate orders | Named field experience | Capital program practice, Mission Intelligence Systems |
What to do with this
The next time the question is asked, do not refuse it. Answer it three times.
Give the variance ranking for the objective that has been quantified, the irreversibility ranking for the decisions in front of the board this quarter, and the short list of items that could breach capacity alone. Then say plainly that these are different questions and that the register's sort order is not a fourth answer, it is a filing convention.
The reaction is usually better than expected. Executives are not attached to the ranking. They are attached to knowing where to look, and three defensible lists serve that better than one indefensible one.
References
- Stevens, S. S. “On the Theory of Scales of Measurement.” Science, vol. 103, no. 2684, 1946, pp. 677–680. doi.org/10.1126/science.103.2684.677. The measurement scale taxonomy the scoring critique depends on.
- Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010, pp. 2:1–2:10. doi.org/10.1147/JRD.2010.2042914.
- Cox, Louis Anthony, Jr. “What's Wrong with Risk Matrices?” Risk Analysis, vol. 28, no. 2, 2008, pp. 497–512. doi.org/10.1111/j.1539-6924.2008.01030.x.
- Thomas, Philip, Reidar B. Bratvold, and J. Eric Bickel. “The Risk of Using Risk Matrices.” SPE Economics & Management, vol. 6, no. 2, 2014, pp. 56–66. doi.org/10.2118/166269-PA.
- Ball, David J., and John Watt. “Further Thoughts on the Utility of Risk Matrices.” Risk Analysis, vol. 33, no. 11, 2013, pp. 2068–2078. doi.org/10.1111/risa.12057.
- NC State University Enterprise Risk Management Initiative and Protiviti. Executive Perspectives on Top Risks 2026. 14th annual survey, December 2025, n = 1,540 board members and C-suite executives. erm.ncsu.edu.
- U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g. Sensitivity analysis and risk and uncertainty analysis as distinct steps.
- U.S. Government Accountability Office. Schedule Assessment Guide: Best Practices for Project Schedules. GAO-16-89G, December 2015. gao.gov/products/gao-16-89g. Criticality and schedule risk analysis.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018. iso.org/standard/65694.html.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
