Risk is not a thing sitting on a register waiting for a committee to colour it red, amber, or green. It is uncertainty about the future, and it matters only because someone still has to decide what to do. Most of what passes for risk management replaces that act of judgment with filing, scoring, and ritual. The paperwork grows. The thinking shrinks.

The organisations that take risk management most seriously are not the ones that make the best decisions. They are the ones with the thickest binders. A forty-seven-item register tells you someone has been busy. It does not tell you whether anyone has thought clearly about a single live commitment. The question that cuts through the apparatus is the one the apparatus was built to avoid: on what basis are you proceeding, and is that basis sufficient.

Risk is uncertainty about the future that affects what you are trying to achieve. It is not a category to be managed or scored.

A bureaucratic risk management machine turning live decisions into registers, heat maps, and board papers while the real decision sits ignored at the side
The apparatus records uncertainty while the decision waits elsewhere.
Click to expand

What risk actually is

The first mistake is to talk about risk as if it were a thing. It is not a thing. It is not a box on an org chart, a function in a software suite, or a population of bad outcomes roaming around the business. Risk is uncertainty about the future in relation to what you are trying to achieve. Remove the objective and the word collapses into noise. Remove the uncertainty and it collapses into hindsight.

That is why the common phrase "the risk happened" gives the game away. If something has happened, the uncertainty is over. What happened was an event. The risk was the uncertainty that existed before the event, while the decision was still live. That is not pedantry. It is the difference between learning from a decision and excusing it. Treat risk as a thing that attacks from outside and the Decider disappears. Treat risk as uncertainty tied to a decision and the real question becomes visible.

The field that calls itself risk management has never settled this point. ISO has produced more than forty formal definitions of risk across its standards and still lacks consensus on what the word means. That is not a healthy sign. It is proof that the supposed discipline cannot agree on its own core noun. When a field needs dozens of definitions for its central term, plus notes to explain the definitions, plus committees to reconcile the notes, the field is not clarifying reality. It is generating vocabulary around confusion.

The practical alternative is plain. Start with decision making under uncertainty, because that is the real human activity. People are not "managing risk" in the abstract. They are choosing suppliers, approving investments, launching products, changing staffing, setting prices, or closing plants while the future remains uncertain. The correct response to uncertainty is not management. It is a decision.

The difference between risk and uncertainty is not definitional. It is operational. Risk is the state in which a decision already rests on a testable basis. Uncertainty is the state in which that basis has not yet been named. Most teams treat both words interchangeably and skip the work that separates them. For the distinction that changes what you do next, see risk vs uncertainty: the distinction that changes what you test.

What a risk assessment does and does not do

A risk assessment is a structured attempt to name the uncertainties surrounding a decision and judge how much they matter. In a well-run version, a team identifies what could go wrong, estimates the likelihood and impact of each item, and ranks the results. The output is supposed to be a clearer picture of the terrain before a commitment is made. That is useful work when it stays connected to the decision it serves.

It rarely stays connected. In most organisations, the risk assessment process stops at identification. A team fills a template with hazards, threats, and opportunities, scores them on a grid, and delivers the completed spreadsheet as proof that risk has been "assessed." Nobody asks whether the assumptions behind the live decision are sound. Nobody names who is deciding. Nobody checks whether the items on the list are the ones that would actually change the outcome. The assessment stands beside the decision but never enters it.

That is the gap. A good risk assessment tells you what might go wrong. It does not tell you whether the basis for proceeding is adequate. Naming hazards is a start. Testing the assumptions the decision rests on is the finish. Most risk assessment processes provide the start and call it done. The five-step method in the method puts that testing where it belongs, inside the decision itself, not in a parallel document that nobody reopens after the meeting.

That testing is what a genuine risk assessment process looks like: five steps that interrogate the decision, not a scoring exercise that bypasses it.

Risk registers, risk matrices, and the management apparatus

A risk register is a structured list of identified uncertainties maintained in a spreadsheet or governance platform. Each row names a risk, assigns an owner, records a likelihood score, an impact score, a treatment plan, and a review date. A risk matrix is the visual companion, a grid plotting likelihood against impact and colouring each cell red, amber, or green. Both are standard tools in organisational governance. Both are supposed to help leaders see what matters.

Once the register exists, the organisation starts protecting the register. People argue over wording, categories, owners, and scoring scales. The live decision disappears behind maintenance of the artifact. That is why your risk register does not help you decide. It is adjacent to the decision, not inside it. The same goes for matrices. Colour-coded matrices score colours, not decisions. A red box is not judgment. An amber trend arrow is not a reason. A cluster of green squares is not evidence that anyone has thought clearly.

Enron was receiving fulsome praise for its risk management only months before bankruptcy. That public embarrassment should have killed the apparatus, but instead the apparatus survived and the thinking did not. The same pattern repeats wherever ceremony is mistaken for discernment.

The missing distinction is the one explored in judgment and decision making. Judgment is the hard part. It is where a Decider tests what matters, weighs what is sufficient, and commits. The apparatus cannot do that work. It only crowds the room around it, which is one reason organisations end up producing decision fatigue out of systems that were supposed to create confidence.

How risk management became a belief system

Once you stop treating risk as a thing, the next question is obvious. How did so many organisations end up building a profession around it. The answer is not intellectual rigour. It is institutional drift, backed by incentives. The label "risk management" came from insurance, where "the risk" meant the person, asset, or activity being insured. From there the label escaped its original setting and acquired prestige it had not earned. Four groups drove that expansion: the financial and insurance sector, government and regulatory bodies, academic and standards bodies that codified the language, and consultants who discovered that once a vocabulary sounds technical enough, a fiction of expertise can be sold around it.

The pattern follows the logic of every entrenched creed. "Belief systems inevitably start with the answer rather than with careful and objective definition of the problem." Here the answer was "risk management." The question should have been simpler: how does a person make a sound decision while the future remains uncertain. That question would have produced a method. The answer-first approach produced an edifice. That edifice is still with us in every renamed framework and maturity model, in the apparatus criticised in The Risk Management Millstone, and in structural rearrangements like the IIA Three Lines Model, where lines of defence proliferate while the real decision stays hidden inside them.

The Grenfell Tower fire killed seventy-two people while fire risk assessments sat on file showing compliance. Volkswagen rigged eleven million diesel vehicles while Germany's two-tier board, with supervisory oversight and formally defined decision rights, looked on. These are not obscure edge cases. They are public demonstrations that the apparatus does not fail because it was missing. It fails because it was never aimed at the decision that mattered. The same problem is traced in Unburdened by Risk Management Myths, in Should Internal Audit Perform Risk Assessment?, and in the broader disruption argument set out in Disruption.

What works instead of risk management

If risk management is the answer, what was your question. Most people do not have one. They have inherited a label, a policy, a governance expectation, or a software implementation. They have not defined the problem the machinery is meant to solve. The ordinary person sees the problem faster than the specialist and asks: what are you trying to do, what could go wrong, and what are you going to do about it. Those questions are concrete. They belong to a decision. Risk management cannot answer them because it never asked them.

Risk appetite and risk tolerance are the polished language of the same avoidance. An appetite statement sounds strategic because it is abstract. A tolerance threshold sounds disciplined because it carries numbers. Neither tells the Decider what the present decision rests on. The useful follow-on is the one in enough information to make a decision, not another round of appetite drafting.

The replacement is not chaos, and it is not instinct worship. It is the Universal Decision-Making Method, a five-step discipline built around the thing the apparatus forgot, the decision itself. The method does not ask for less seriousness. It asks for seriousness in the right place.

Purpose. Start by stating what you are trying to achieve and why this decision exists. Most rooms skip this because they assume everyone already knows. Usually they do not. Without purpose, every discussion that follows is badly framed. The team starts debating options before it has agreed what the options are for.

Options. State the real alternatives, not a preferred answer padded with decorative variations. What could actually be done. What would each path require. What secondary elements, such as safeguards or contingencies, belong with each option. A decision cannot be tested if the option itself has not been stated plainly.

Assumptions. Name what each option depends on. This is the point at which the fog starts clearing, because assumptions are where uncertainty actually sits. Some assumptions matter a great deal and deserve hard testing. Others barely matter at all and can be left alone. The job is not to generate a huge inventory. It is to expose the few assumptions that carry the outcome.

Sufficient certainty. Judge whether the basis is sufficient to proceed. Not perfect. Not exhaustive. Sufficient. If not, the response is not to file more categories. It is to improve the option, seek targeted information, or choose differently.

Monitoring. Then decide what must be watched after the decision is made, who will watch it, and what would trigger reconsideration. That produces a live decision with reopen signals, not a dead document with audit trails.

This is not anti-analysis. Models and data are inputs, not substitutes for judgment. The method uses them. It does not worship them. A forecast can sharpen an option. A model can reveal sensitivity. A dashboard can show movement. None of those decides. They inform the Decider, who still has to ask whether the assumptions that matter are sufficiently well founded. The same applies to GRC software. Digitising a register still does not answer who decides, what they are assuming, or why the basis is enough.

If you want the business translation rather than the polemic, start with how to make a difficult business decision, then look at the role of a decision record and the discipline of monitoring. Those three pieces, together with the longer case for risk-based decision making, show how the method replaces the apparatus in ordinary executive work.

The same pattern explains why risk appetite statements stay fuzzy. Boards approve a slogan, consultants refine the wording, and the live decision still sits untouched in the middle of the table.

What this means for your organisation

If you run operations, sit on a board, lead governance, or carry accountability for outcomes, the Monday morning move is not to ask for a better register. It is to pick one live decision and stop the register cycle. Start the assumptions walk. Ask what the decision is for. Ask what options are truly on the table. Ask which assumptions matter enough to change the outcome. Ask what would tell you early that the decision needs reopening.

This is practical, not philosophical. Cancel one routine risk review that exists only to update categories. Replace it with a session on a single live decision. Strip away the heat map. Put the intended outcome at the top of the page. Name the Decider. Write down the assumptions. Rank them by significance. Decide what evidence would improve the weak ones and what monitoring would catch change later. You will learn more in that conversation than in months of register maintenance.

Boards should stop approving appetite prose they will never use. Risk functions should stop measuring diligence by document volume. Internal audit should stop treating parallel risk assessments as proof of rigour. Operations leaders should stop waiting for complete certainty before committing scarce time and capital. The practical version of this shift for real operating decisions is laid out in decision science for operations leaders. The wider discipline is in the method.

You could run a decision through the five steps before your next board meeting.

Stop updating the register. Start with the decision.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.