Risk and Uncertainty
Most organizations have a risk process.
Fewer make sound decisions under uncertainty.
The capability at stake is risk judgment: the ability to recognize weak signals, quantify uncertainty honestly, and act while the decision is still open. It is distinct from risk compliance: an organization can maintain a complete register, hold every scheduled review and report faithfully to governance while its judgment stays poor, because none of those activities requires anyone to state a probability they can later be held to. These articles examine the difference between documenting risk and managing it, from the words a register uses to describe a likelihood through to the confidence level a program is actually funded at.
What risk judgment governs
Risk judgment determines whether the organization sees what is coming and acts on it, or files paperwork about it afterwards. It is distinct from risk compliance, and it is the thing that is actually scarce: process is cheap to install and judgment is not.
When risk judgment is strong
- Risk ownership sits with people who have the experience to recognize what matters.
- Weak signals surface early and change decisions.
- The organization separates likelihood from wishful thinking.
- Risk is discussed before commitments, not after incidents.
When risk judgment is weak
- Risk coordination is handed to whoever has capacity.
- The risk register is complete and no one reads it.
- Likelihood is treated as a feeling, not a probability.
- Risk is a compliance ritual disconnected from real decisions.
Diagnose the conditions behind risk
Working tools
Three spreadsheets that do the arithmetic
A forecast calibration scorer, a contingency drawdown tracker, and a risk register to model conversion worksheet. Live formulas, a worked example row in each, and no sign up.
Articles · Risk
The Risk Register Nobody Reads
Most organizations have a risk register. Most risk registers are read once: during the review that required them. This is an attention problem, not a documentation problem.
Read article →
Why 'Likely' Is Not a Probability
When two members of a risk review assign different numerical meanings to the same word, the risk register is not a shared instrument: it is a collection of individual opinions formatted to look like one.
Read article →
Risk Appetite Is Not Alignment
Publishing a risk appetite statement is not the same as building an organization that operates within it. The gap between declaration and behavior is where governance fails.
Read article →
Risk Ownership Without Authority
Naming a risk owner without empowering one creates the illusion of accountability, and leaves every significant risk actually unmanaged.
Read article →
When the Least Experienced Person Owns Risk
A direct address to the leader who made the staffing decision: what you gave up when you assigned risk coordination to whoever had capacity, and what you can do about it now.
Read article →
The Risk Experience Deficit
Organizations routinely assign risk coordination to whoever has capacity - often the newest team member. When the role rotates with team changes, risk identification separates from the experience required to recognize the risks that actually matter.
Read article →
The Organizational Pre-Mortem
The most productive risk tool most organizations never use is not a model or a matrix. It is a question: imagine this has already failed. What happened?
Read article →
Shadow AI
One in five data breaches now involves shadow AI, at 670,000 dollars more per incident. The ungoverned adoption already inside your organization is an authority vacuum before it is a security failure.
Read article →
What P80 Means, and What It Does Not Promise
A P80 is the value a program has an 80 percent modeled chance of not exceeding. It is an output of a simulation rather than a number anyone selects, and it inherits every judgment that went into the model.
Read article →
Are Risk Matrices Valid? What Cox Actually Proved
The published mathematical critique of the risk matrix is narrower and more useful than the slogans built on it. What it establishes, when a matrix genuinely misleads, and what to do when the format cannot be abandoned.
Read article →
How to Present a Probabilistic Cost Range to a Council
A range is not an admission of ignorance, it is a more honest claim than a single number. What a governing body actually has to decide, and the four questions you will always be asked.
Read article →
How Often Should You Re-Run a Risk Analysis?
Practitioners split between weekly, monthly, quarterly and annually, and no research supports any of them. The cadence is the wrong question: what the evidence supports is re-analysis triggered by conditions rather than by the calendar.
Read article →
Ordering Work by Risk-Adjusted Value
Most teams sequence work by stakeholder value, which defers the expensive unknowns until capital is committed. A better rule is to do first whatever most changes the decisions still ahead of you.
Read article →
Releasing Contingency as Risks Retire
Contingency covers uncertainty, so as uncertainty resolves the required amount falls. The binding constraint on releasing it is rarely the arithmetic: it is who is allowed to decide.
Read article →
What FTA Oversight Procedure 40 Actually Requires
FTA has funded cost contingency at the 65th percentile since July 2018, and schedule follows a different larger-of rule that most summaries get wrong. What a sponsor must actually produce, and at what confidence level.
Read article →
Who Controls Contingency, the Owner or the Contractor?
Contingency and management reserve are defined inversely by different federal agencies, so the argument usually starts from incompatible definitions. Where no release authority is named, the default is not neutrality, it is holding.
Read article →
Is This Schedule Good Enough to Run a Risk Analysis On?
A simulation does not repair a schedule, it inherits it and reports the inherited defects with more decimal places. What has to be true before a Monte Carlo result is worth showing anyone.
Read article →
Why the Simulation Disagrees With Your Critical Path Date
A simulated date later than the deterministic critical path is merge bias and mathematically expected. A simulated date that lands earlier is a symptom. Two opposite diagnoses that look identical on the report.
Read article →
From Risk Register to Quantified Model
Fifty entries in a register and someone wants a P80. The gap is larger than it looks and most of it is not arithmetic. What has to change about how each risk is written before it can be modelled at all.
Read article →
The Premortem and the Reference Class
Two corrections for the same bias working from opposite ends. One asks your team to imagine the failure, the other ignores your team entirely. Each is weak exactly where the other is strong.
Read article →
The Shadow AI Problem: When Ungoverned Adoption Becomes an Authority Crisis
One in five data breaches now involves shadow AI. An authority vacuum created the adoption; making governance faster and clearer solves it.
Read article →
What the Duty of Oversight Actually Requires
Boards ask whether they are exposed if a program fails. The standard is not a good outcome, it is a board-level system that produced information and a record that the board used it.
Read article →
Who Owns Risk Under the Three Lines Model
Three groups will each tell you one of the others has it. The model settles accountability for the risk and says nothing about who owns the judgment inside the number.
Read article →
Why the Biggest Risk Is Never in the Register
Somebody knew. It was not written down because writing it down would have named someone. A confidence level built on a censored register is precise and narrow in a specific direction.
Read article →
Risk Appetite, Tolerance and Capacity Are Not Synonyms
Two of the three are chosen and one is arithmetic. On anything quantified, the confidence level is the appetite statement, and it is the only version that can actually be violated.
Read article →
What Is Our Top Risk?
The most common executive question about risk assumes risks form a single ordered list. Three replacement questions that can be answered, and why they disagree with each other.
Read article →
AI Governance Without the Graveyard: Moving from Committees to Conditions
Most AI governance programs create bureaucratic overhead. Effective governance enables work and moves fast, rather than creating gates that drive shadow adoption.
Read article →
Should We Mitigate, Transfer, Accept or Avoid?
Four options presented as a flat menu. Transfer moves the invoice rather than the event, mitigation is an investment that rarely faces the bar, and acceptance is a decision rather than an omission.
Read article →
Is This a Risk or an Issue?
It sounds like taxonomy and it decides which pot of money pays. Misclassification corrupts a quantified forecast in both directions, and assumptions are the category that does the real damage.
Read article →
What Should Risk Reporting to the Board Contain?
Four pages of risk and nothing the board can act on. Most reporting shows position when the only useful content is movement, and uses one format for three kinds of risk that need three.
Read article →
Can You Put a Number on a Risk That Never Happened?
The objection that there is no data is why the largest exposures stay qualitative forever. Quantification needs a calibrated statement of uncertainty, not a frequency history.
Read article →
How Do We Know Our Risk Management Is Working?
Activity metrics cannot fail and the absence of disasters proves nothing. Every bid that arrives is a test of a range the organization already stated, and those tests are all being discarded.
Read article →
More from the Library
