Risk is not one dimension. It is a structured possibility of loss, harm, failure or undesirable change.
A delayed shipment, cyberattack, examination failure, equipment breakdown, regulatory breach, drought, financial loss and medical complication are all risks, but they differ in source, likelihood, impact, speed, exposure, controllability, dependency and recovery.
Categorising risk well means separating those dimensions instead of compressing everything into one vague label such as “high risk”.
Quick answer: how should risks be categorised?
- Source: where does the risk originate?
- Object exposed: what can be harmed?
- Likelihood: how plausible is occurrence?
- Impact: how severe could consequences be?
- Exposure: how much is currently at stake?
- Velocity: how quickly can the risk materialise?
- Duration: how long can effects persist?
- Controllability: how much influence does the system have?
- Detectability: how early can warning appear?
- Recovery: how reversible or repairable is the damage?
- Uncertainty: how reliable are the estimates?
This article applies the framework from How to Categorise Anything to risk without replacing specialist risk standards used in medicine, engineering, finance, safety or regulation.
1. Define the threatened objective
Risk exists relative to something valued: safety, money, continuity, learning, reputation, compliance, time or capability.
2. Separate hazard from risk
A hazard is a potential source of harm. Risk depends on exposure, likelihood and consequence.
3. Separate risk from issue
A risk may or may not occur. Once the undesirable event has happened, it becomes an issue, incident, loss or state requiring response.
4. Source categories organise origin
Operational, financial, technological, environmental, legal, human and strategic are examples of source dimensions, but local definitions should be explicit.
5. Source is not consequence
A technology failure can create financial, safety and reputational consequences. Keep cause and effect separate.
6. Exposure identifies what is vulnerable
People, assets, data, schedules, ecosystems, learning outcomes and institutional trust can all be exposed objects.
7. Likelihood is one axis
Likelihood may be qualitative, frequency-based, probabilistic or scenario-based depending on evidence.
8. Probability should not be invented
Where data are weak, a qualitative uncertainty range may be more honest than a precise percentage.
9. Impact is another axis
Impact can affect cost, safety, time, quality, rights, environment or continuity.
10. Impact is multidimensional
A risk can have low financial impact and high human impact. One aggregate severity score can hide this difference.
11. Expected loss is not the whole story
Two risks can have similar expected value while one is frequent and small and the other rare and catastrophic.
12. Tail risk deserves distinction
Rare high-impact outcomes may require separate attention even when average likelihood is low.
13. Risk velocity measures speed
Some risks develop slowly; others move from warning to impact in seconds or hours.
14. Detection time matters
A risk may be likely and severe yet manageable if early warning is strong.
15. Duration changes consequence
A one-hour outage and a one-month outage belong to the same broad incident type but carry very different operational significance.
16. Reversibility matters
Temporary delay differs from permanent data loss, irreversible environmental damage or lasting injury.
17. Controllability distinguishes response options
Some risks can be prevented directly; others can only be monitored, transferred, buffered or recovered from.
18. Preventability and recoverability are different
A difficult-to-prevent event may still have excellent recovery options.
19. Inherent and residual risk should be separated
Inherent risk describes exposure before controls; residual risk describes what remains after controls.
20. Control strength is a separate dimension
Preventive, detective, corrective and recovery controls perform different jobs.
21. Control existence is not control effectiveness
A written procedure does not prove the control operates reliably in practice.
22. Risk dependencies matter
One risk can increase the likelihood or impact of another.
23. Common-cause risks create correlated failure
Several systems thought to be independent may fail together because they depend on one supplier, location, network or policy.
24. Cascading risk should be represented as a chain
An initial event can trigger secondary disruptions. Use typed relationships rather than one oversized category.
25. Systemic risk is about network structure
A failure can become systemic when dependencies allow local disruption to propagate widely.
26. Emerging risks need uncertainty states
New technologies or behaviours may have limited historical data. Mark evidence quality and novelty explicitly.
27. Known unknowns deserve classification
A system can know that an uncertainty matters even when probability or impact cannot yet be estimated well.
28. Unknown unknowns cannot be enumerated directly
Resilience, redundancy and anomaly detection help prepare for risks outside the current taxonomy.
29. Risk appetite is not risk level
Risk appetite describes willingness to accept exposure. It should not alter the underlying estimate of likelihood or impact.
30. Risk priority combines evidence and consequence
Priority may consider severity, urgency, controllability and strategic importance, but the formula should be explicit.
31. Risk matrices simplify but compress
Likelihood-impact matrices are useful visual summaries but can hide velocity, uncertainty, control quality and correlated exposure.
32. Thresholds create administrative categories
Low, medium, high and critical require documented boundaries and should not be mistaken for natural divisions.
33. Risk labels need time context
A risk estimate changes as controls, exposure, evidence and external conditions change.
34. Scenario classification helps when probability is weak
Represent plausible pathways and consequences instead of forcing unreliable single-point probabilities.
35. Evidence quality should accompany risk estimates
A high-risk label based on poor evidence should be distinguishable from the same label supported by strong data.
36. AI can assist risk classification
Models can extract incidents, hazards and control signals from text, but consequential risk ratings should remain tied to evidence, rules and review.
37. Risk taxonomies drift
New threats, controls and dependencies appear. Monitor “Other”, emerging-risk and near-miss categories.
38. A practical risk record
- risk ID;
- objective threatened;
- source;
- exposed asset or capability;
- likelihood;
- impact dimensions;
- velocity;
- duration;
- detectability;
- controls;
- residual risk;
- dependencies;
- recovery options;
- evidence quality;
- owner;
- review date.
39. Risk classification should improve action
If categories do not change monitoring, prevention, contingency or recovery decisions, they may be descriptive clutter.
40. The deeper idea
Risk categorisation is an attempt to make uncertain futures comparable without pretending they are certain.
A useful risk category tells us not only what might go wrong, but how, how fast, how badly, how sure we are, and what remains possible afterward.
Final answer
Categorise risks by source, exposure, likelihood, impact, velocity, duration, detectability, controllability, dependencies, uncertainty and recovery. Separate hazard from risk, risk from issue, cause from consequence, and inherent from residual risk. Use multi-dimensional records rather than one opaque severity label.
