If your risk register can only record threats, your organisation has built an instrument that detects half of reality and calls it prudence.
Here is an observation that most executives find mildly uncomfortable once they sit with it. Imagine a project that finishes substantially early and well under budget. In a great many well-governed enterprises, that outcome will generate more internal scrutiny than one that lands exactly on plan.
Not celebration. Scrutiny. Someone will want to know how the estimate was so wrong. The variance report will show a red or amber flag. The team will spend more effort explaining the favourable outcome than they would have spent explaining a modest overrun.
This is not irrational behaviour by individuals. It is the predictable output of a system that has defined risk as the possibility of things going badly, and therefore treats any departure from plan as a control failure — while possessing no mechanism at all for the thing that actually happened, which is that reality turned out better than the organisation's model of it.
Stanley Portny, writing in 2002 for scientists trying to manage research projects, offered a definition worth reading carefully. Risk, he argued, amounts to more than the prospect of a bad outcome. It covers any departure from what was anticipated — and he was explicit that this includes results which turn out well, but differently from what the plan described.
The distinction sounds academic. It is not. It determines what an entire class of expensive corporate machinery is capable of noticing.
The Strategic Context
Enterprise risk management arrived in most large organisations through the compliance door. Its ancestry is in insurance, audit and regulatory response — disciplines whose legitimate purpose is loss avoidance. That ancestry is visible in the artefacts: registers, heat maps, likelihood-and-consequence matrices, mitigation owners, residual risk ratings.
Every element of that apparatus is oriented towards one question: what could harm us, and how do we reduce it? It is a good question. It is also, at enterprise level, roughly half of the question that matters.
The other half — what could turn out better than we assumed, and would we be positioned to act on it? — has no equivalent machinery in most organisations. There is no opportunity register with the standing of the risk register. There is no monthly forum where favourable deviation is escalated. There is no owner accountable for capturing an upside that was not in the plan.
The result is an asymmetry that few boards have consciously chosen. The organisation invests heavily in the capability to detect and respond to bad surprises, and almost nothing in the capability to detect and respond to good ones. It then describes this as being risk-managed.
What Leaders Commonly Misread
That the downside definition is neutral. It is not. A definition that admits only harm shapes what people look for, what they report, and what they feel able to raise. A team that spots an unexpected opening has no established channel through which to escalate it, no template that fits, and no forum whose agenda accommodates it. So it is raised informally, or not at all — and its fate depends on whether someone senior happens to find it interesting.
That variance-to-plan is a proxy for control. It is a proxy for predictability, which is a different property. An organisation optimised for low variance will systematically prefer estimates it can hit to estimates that are accurate, and will suppress information that would widen the range of possible outcomes in either direction. The forecasting improves. The forecast's usefulness declines.
That upside capture is opportunism rather than discipline. Acting on favourable deviation requires exactly the same organisational properties as responding to threat: early detection, a defined owner, pre-agreed authority to act, and available capacity. Enterprises that treat threat response as a governed process and opportunity response as improvisation are not being prudent. They are resourcing one half of a symmetrical problem.
Reframing the Issue
The reframe: risk is the width of the distribution, not the shape of its left tail.
Once risk is understood as deviation in either direction, several things follow that do not follow from the conventional definition.
The purpose of risk work stops being minimisation and becomes positioning. An organisation does not want the narrowest possible range of outcomes; it wants to be structured so that it survives the unfavourable end of the range and can act on the favourable end. Those are different design goals, and only the first is served by mitigation alone.
It also becomes clear why some genuinely valuable initiatives look bad under conventional risk assessment. Work with a wide outcome distribution scores poorly on a heat map regardless of where the mass of that distribution sits. A proposal with a small chance of failure and a substantial chance of an outcome far better than base case will be rated riskier — and therefore treated more sceptically — than a proposal that is reliably mediocre. The instrument cannot distinguish between the two, because it was not built to.
Where the Asymmetry Costs Real Money
Two industries, one pattern.
In manufacturing — and this illustration is hypothetical — a process improvement program delivers a yield gain materially larger than forecast. The favourable variance is real and repeatable. What happens next depends entirely on whether the organisation has any mechanism for it. In many, the gain is absorbed: the budget is adjusted, the target is reset, and the underlying cause is never investigated with the rigour that a failure of the same magnitude would have attracted. The organisation banks the money and discards the knowledge — which was the more valuable of the two, because the knowledge was transferable to other lines and the money was not.
In resources and energy, the same asymmetry would appear at portfolio scale. Suppose an exploration or development program returns a result better than the sanctioning case. The favourable deviation creates a genuine strategic question — whether to accelerate, expand scope, or bring forward downstream commitments — but that question requires uncommitted capital and available executive attention to answer. An enterprise that has allocated both to the last percentile of planned work has no capacity left with which to say yes. It will decline the opportunity and record no loss, because the accounting system has no line for options not taken.
This is the hidden cost of the downside-only definition: it is invisible in the management accounts by construction. Threats that materialise appear as variances. Opportunities that were never captured appear as nothing at all.
Decision Framework
A diagnostic for whether an organisation's risk function can see in both directions.
| Test | What to examine | Failure signal |
|---|---|---|
| Symmetry | Does any standing forum receive favourable deviation as an agenda item? | Upside travels informally or not at all |
| Ownership | Is anyone accountable for capturing upside on a given initiative? | Named owners exist only for threats |
| Authority | Can a favourable deviation be acted on without a full re-approval cycle? | Acting on good news takes longer than responding to bad news |
| Capacity | Is uncommitted funding and executive attention held deliberately? | Portfolio is fully allocated; no capacity to say yes |
| Language | How does the organisation describe a large favourable variance? | Described as an estimating failure rather than a result |
| Memory | Are favourable outcomes investigated for transferable cause? | Root-cause analysis is applied only to failure |
An organisation failing four or more of these is not risk-managed. It is loss-avoidant, which is a legitimate posture for some enterprises in some conditions — but it should be a deliberate strategic choice made by the board, not an inherited property of a template.
From Strategy to Execution
Immediate. Change what the register records before changing anything else. Add a required field to every material risk entry: if this does not occur, or occurs favourably, what would we do? The field costs nothing and forces the question into a document that executives already read.
Medium term. Hold capacity deliberately. An organisation cannot respond to favourable deviation without uncommitted funding, uncommitted people, and uncommitted executive attention. Most portfolios are planned to full allocation because full allocation looks efficient. It is efficient in the same way that a system with no tolerance is efficient — right up until conditions move. [Related article: What a Stage Gate Is Actually For]
Long term. Change the variance conversation. As long as favourable variance is treated as an estimating error, teams will estimate to be right rather than to be useful, and the organisation will lose the early information that both threat response and opportunity capture depend on. This is a cultural change enacted through a governance mechanism: how leaders respond, on the record, the first few times someone reports that something turned out better than planned.
Signals to Monitor
- Favourable variance triggering more explanation than unfavourable variance of the same size. The clearest single indicator of a downside-only system.
- Risk registers with stable entries. A register whose contents do not change is being maintained rather than used.
- Opportunities surfacing through individuals rather than process. Suggests the formal machinery has no channel for them.
- Zero uncommitted portfolio capacity. An organisation that cannot say yes to anything unplanned has pre-decided to decline every favourable surprise.
- Estimating ranges narrowing over time across dissimilar initiatives. Usually evidence that ranges are being written to be defensible rather than accurate.
Questions for the Leadership Team
- In the last twelve months, what favourable deviation did we detect, and what did we do about it? If the answer is thin, is that because none occurred, or because we cannot see them?
- Who in this organisation is accountable for capturing upside on our three largest initiatives — by name?
- How much uncommitted capital and executive capacity do we deliberately hold, and would it be enough to act on a material opportunity next quarter?
- When a team reports a large favourable variance, what actually happens to that team?
- Are any of our current proposals being penalised for having a wide range of outcomes rather than a poor expected one?
Closing Perspective
The definition of risk an organisation adopts is not a technical preference. It determines the shape of what the enterprise is able to perceive, and no amount of diligence downstream can recover information the instrument was never built to capture.
An enterprise that measures only the left tail will become genuinely good at avoiding loss, and will remain permanently unaware of what it declined to notice. The choice is not between caution and ambition. It is between a system that sees the whole distribution and one that has quietly agreed to look at half of it.
Related article: Uncertainty Is the Case for Planning, Not the Excuse Against It
Related article: Measuring an Outcome You Cannot Predict
Related article: What a Stage Gate Is Actually For
About the author
Kevin Jogin is Founder & Principal Advisor at EraNorth. Meet the Founder.
