How to Categorise Risks | Source, Likelihood, Impact, Exposure, Control and Recovery

Risk is not one dimension. It is a structured possibility of loss, harm, failure or undesirable change.

A delayed shipment, cyberattack, examination failure, equipment breakdown, regulatory breach, drought, financial loss and medical complication are all risks, but they differ in source, likelihood, impact, speed, exposure, controllability, dependency and recovery.

Categorising risk well means separating those dimensions instead of compressing everything into one vague label such as “high risk”.

Quick answer: how should risks be categorised?

  • Source: where does the risk originate?
  • Object exposed: what can be harmed?
  • Likelihood: how plausible is occurrence?
  • Impact: how severe could consequences be?
  • Exposure: how much is currently at stake?
  • Velocity: how quickly can the risk materialise?
  • Duration: how long can effects persist?
  • Controllability: how much influence does the system have?
  • Detectability: how early can warning appear?
  • Recovery: how reversible or repairable is the damage?
  • Uncertainty: how reliable are the estimates?

This article applies the framework from How to Categorise Anything to risk without replacing specialist risk standards used in medicine, engineering, finance, safety or regulation.


1. Define the threatened objective

Risk exists relative to something valued: safety, money, continuity, learning, reputation, compliance, time or capability.

2. Separate hazard from risk

A hazard is a potential source of harm. Risk depends on exposure, likelihood and consequence.

3. Separate risk from issue

A risk may or may not occur. Once the undesirable event has happened, it becomes an issue, incident, loss or state requiring response.

4. Source categories organise origin

Operational, financial, technological, environmental, legal, human and strategic are examples of source dimensions, but local definitions should be explicit.

5. Source is not consequence

A technology failure can create financial, safety and reputational consequences. Keep cause and effect separate.

6. Exposure identifies what is vulnerable

People, assets, data, schedules, ecosystems, learning outcomes and institutional trust can all be exposed objects.

7. Likelihood is one axis

Likelihood may be qualitative, frequency-based, probabilistic or scenario-based depending on evidence.

8. Probability should not be invented

Where data are weak, a qualitative uncertainty range may be more honest than a precise percentage.

9. Impact is another axis

Impact can affect cost, safety, time, quality, rights, environment or continuity.

10. Impact is multidimensional

A risk can have low financial impact and high human impact. One aggregate severity score can hide this difference.

11. Expected loss is not the whole story

Two risks can have similar expected value while one is frequent and small and the other rare and catastrophic.

12. Tail risk deserves distinction

Rare high-impact outcomes may require separate attention even when average likelihood is low.

13. Risk velocity measures speed

Some risks develop slowly; others move from warning to impact in seconds or hours.

14. Detection time matters

A risk may be likely and severe yet manageable if early warning is strong.

15. Duration changes consequence

A one-hour outage and a one-month outage belong to the same broad incident type but carry very different operational significance.

16. Reversibility matters

Temporary delay differs from permanent data loss, irreversible environmental damage or lasting injury.

17. Controllability distinguishes response options

Some risks can be prevented directly; others can only be monitored, transferred, buffered or recovered from.

18. Preventability and recoverability are different

A difficult-to-prevent event may still have excellent recovery options.

19. Inherent and residual risk should be separated

Inherent risk describes exposure before controls; residual risk describes what remains after controls.

20. Control strength is a separate dimension

Preventive, detective, corrective and recovery controls perform different jobs.

21. Control existence is not control effectiveness

A written procedure does not prove the control operates reliably in practice.

22. Risk dependencies matter

One risk can increase the likelihood or impact of another.

23. Common-cause risks create correlated failure

Several systems thought to be independent may fail together because they depend on one supplier, location, network or policy.

24. Cascading risk should be represented as a chain

An initial event can trigger secondary disruptions. Use typed relationships rather than one oversized category.

25. Systemic risk is about network structure

A failure can become systemic when dependencies allow local disruption to propagate widely.

26. Emerging risks need uncertainty states

New technologies or behaviours may have limited historical data. Mark evidence quality and novelty explicitly.

27. Known unknowns deserve classification

A system can know that an uncertainty matters even when probability or impact cannot yet be estimated well.

28. Unknown unknowns cannot be enumerated directly

Resilience, redundancy and anomaly detection help prepare for risks outside the current taxonomy.

29. Risk appetite is not risk level

Risk appetite describes willingness to accept exposure. It should not alter the underlying estimate of likelihood or impact.

30. Risk priority combines evidence and consequence

Priority may consider severity, urgency, controllability and strategic importance, but the formula should be explicit.

31. Risk matrices simplify but compress

Likelihood-impact matrices are useful visual summaries but can hide velocity, uncertainty, control quality and correlated exposure.

32. Thresholds create administrative categories

Low, medium, high and critical require documented boundaries and should not be mistaken for natural divisions.

33. Risk labels need time context

A risk estimate changes as controls, exposure, evidence and external conditions change.

34. Scenario classification helps when probability is weak

Represent plausible pathways and consequences instead of forcing unreliable single-point probabilities.

35. Evidence quality should accompany risk estimates

A high-risk label based on poor evidence should be distinguishable from the same label supported by strong data.

36. AI can assist risk classification

Models can extract incidents, hazards and control signals from text, but consequential risk ratings should remain tied to evidence, rules and review.

37. Risk taxonomies drift

New threats, controls and dependencies appear. Monitor “Other”, emerging-risk and near-miss categories.

38. A practical risk record

  • risk ID;
  • objective threatened;
  • source;
  • exposed asset or capability;
  • likelihood;
  • impact dimensions;
  • velocity;
  • duration;
  • detectability;
  • controls;
  • residual risk;
  • dependencies;
  • recovery options;
  • evidence quality;
  • owner;
  • review date.

39. Risk classification should improve action

If categories do not change monitoring, prevention, contingency or recovery decisions, they may be descriptive clutter.

40. The deeper idea

Risk categorisation is an attempt to make uncertain futures comparable without pretending they are certain.

A useful risk category tells us not only what might go wrong, but how, how fast, how badly, how sure we are, and what remains possible afterward.

Final answer

Categorise risks by source, exposure, likelihood, impact, velocity, duration, detectability, controllability, dependencies, uncertainty and recovery. Separate hazard from risk, risk from issue, cause from consequence, and inherent from residual risk. Use multi-dimensional records rather than one opaque severity label.


Continue through the series

Explore the connected learning guides

Choose the question that brought you here. Open one useful guide, try a small task, and stop when you have what you need.

Take one question further

The same learning habit can travel across subjects, while each subject keeps its own methods. These routes help you notice a difficulty, understand one part of it, and return to something you can do.

A word is familiar, but using it is difficult.

Move from recognising a word to retrieving it in a new context. Understand vocabulary plateaus.

Try it without the guide: Choose one word you already know. Close the guide and use it in a new sentence. Explain why it fits; try another context tomorrow.

A piece of writing has ideas, but the reader loses the thread.

Make the order of events and the links between sentences clear. Explore composition writing.

Try it without the guide: Choose one short paragraph. Read the relevant explanation, close it, and revise the paragraph. Ask someone to tell you what happened and why.

The Mathematics seems familiar, but marks still disappear.

Find the first point where the working stops being reliable. Find Secondary 4 A-Math mark leakage.

Try it without the guide: For a Secondary 4 A-Math question you have attempted, locate the first uncertain line. Repair that step, then try a comparable question without the worked answer.

A Science fact is remembered, but the explanation is incomplete.

Connect the evidence to a scientific idea and the resulting change. Follow the Primary Science learning route.

Try it without the guide: Choose a familiar Primary Science example. Explain the evidence, the idea and the result without notes. Then change one condition and explain your prediction.

Two accounts of the world seem to disagree.

Check the question, source, date and evidence before combining claims. Explore the World Knowledge research library.

Try it without the guide: Take one claim. Find the source best placed to support it, note its date, and state what remains uncertain. Return to your original question.

There is plenty of help, but independence is hard to see.

Check what the learner can understand and do after support is removed. Understand how education works.

Try it without the guide: Choose one small task the child has practised. Agree on a calm, brief attempt without prompts. Use what happens to choose one next step, then stop.

For the structure behind these connections, read the eduKateSingapore runtime manifest and the eduKate ecosystem boot contract. The reader map describes public navigation; those manifests preserve the wider ownership and return rules.