Every risk scoring instrument in general use has a probability floor well above the range in which enterprise-ending events live, so the class of risk that destroys organisations cannot be recorded on the instrument built to record risk.
An organisation with a mature risk function — several hundred live entries, named owners, weekly review, clean audit findings — has almost certainly not recorded the event that will end it. Not because the function is lazy or the leadership incurious, but because its instrument has a bottom, and the event lives underneath it.
Every probability scale in general circulation is bounded below. The lowest band is not an open category meaning "anything rarer than this"; it has a stated width and a stated floor, and nothing lies beneath it. Where that floor sits varies widely between instruments in current use: some treat anything below five per cent as the bottom, others below ten, others below twenty; one widely taught scheme offers three values and stops at twenty-five per cent; another gives its lowest level a numerical weight with no probability at all. None provides a way to say one in five hundred.
That is precisely where enterprise-ending events live. The failure of a sole-source component across an installed fleet, the loss of a regulatory licence, the counterparty collapse that removes a market, the correlated event that defeats a redundancy design — none has an annual probability of five per cent. If they did, they would have happened already and the organisation would have adapted. Their probabilities are orders of magnitude smaller, their consequences orders of magnitude larger, and the instrument built to record risk has no cell for them.
The result is not that such risks are rated too low. It is subtler: they are either rounded up into a band that overstates their frequency, inviting the reader to discount the entry as alarmist, or never entered at all, because no available rating describes what the analyst means. Either way the register comes back clean, and the cleanliness is a property of the instrument, not the enterprise.
The Strategic Context
The probability floor is a design decision. Someone chose it, usually by adopting a template, and never recorded why. It is not a property of the world, and it carries no warning label.
What makes it consequential is how it interacts with the exposure horizon. A scale whose lowest band is "below five per cent per annum" can express nothing rarer than one occurrence in twenty years. An organisation with forty-year assets, or thirty-year liabilities, is using an instrument whose resolution stops well short of its own horizon. Every hazard in the remaining span is compressed into one cell beside everything merely unlikely.
The discipline's own instruments do not agree about what to do with that cell. Put one class of event — very rare, very severe — through the instruments in common use. One returns a low rating and a green marker. One returns a high rating with an instruction that contingency is required despite the low probability. One returns a middle band meaning monitor but do not plan. One returns a score identical to that of a trivial nuisance expected several times a year. Four instruments, four incompatible verdicts, one event.
The most revealing is the one returning the low rating, because it defends the result. The argument runs that people over-weight vivid catastrophes, and that structured comparison corrects the bias by demoting the catastrophe below the mundane hazard that will actually occur. As a description of a cognitive tendency, sound. As a defence of the instrument, circular: the low rating is offered as evidence the scoring worked, when it is a mechanical consequence of a floor that made any other answer impossible.
What Leaders Commonly Misread About the Bottom of the Scale
The first misreading is that the lowest band is a residual category. Executives read "Rare" or "Very Low" as everything less likely than the band above. It is bounded, and everything below the bound sits outside the instrument.
The second is that a clean register is evidence. A register records what was entered; entry requires a rating; a rating requires a cell. The absence of tail events is a finding about the instrument's range, not the enterprise's exposure, and looks identical in a well-prepared organisation and an unprepared one.
The third is that this is a precision problem, solved with a finer scale. Moving from three bands to five improves discrimination where the instrument already reaches and does nothing at the bottom. Resolution and range are different properties; a new band beneath the lowest simply relocates the floor.
The fourth is that severity compensates. Most instruments allow a catastrophic consequence rating even where the probability cannot be expressed, then combine the two. What that combination assumes about the enterprise is a separate question; this article stops at the lower bound of the input scale and does not take up the operator that consumes it, which is the subject of [Related article: An Expected Value in a Ranking's Clothes].
The two-sided definition of risk — that the framework covers opportunity as well as threat — belongs to Article 1 here, though the floor applies symmetrically: the rare, transformative upside is as unrecordable as the terminal downside.
Reframing the Issue
A risk register is not a map of the enterprise's risk. It is a map of the risks its instrument can express, and those are different documents sharing a title.
Every measuring instrument has a detection limit, and competent practice is to state it alongside the reading; a laboratory result of "not detected" is meaningless without it. Risk instruments carry no such convention. Nobody publishes the floor, so nobody can distinguish "we looked and found nothing" from "we cannot look there".
Consider a hypothetical reinsurance and catastrophe cover business. Its entire economic purpose lies below the floor. The events it underwrites have return periods measured in centuries; the distinction between a one-in-two-hundred-year loss and a one-in-two-thousand-year loss is the difference between a priced risk and insolvency. On a scale whose lowest band is "below five per cent", all of those distinctions collapse into one cell. The firm would still run the scale for operational risks, where it works. The failure is that one document, reviewed by one committee, silently changes meaning depending which class of exposure is being read.
Most enterprises are not reinsurers, but most hold a few exposures of the same shape: low frequency, high correlation, consequences beyond the capacity to absorb them. The question is not whether the instrument is adequate in general, but whether leadership knows which exposures it cannot see.
What Lives Below the Lowest Band
The floor is inherited, not chosen
In practice the floor arrives with the template. A framework is adopted, a matrix comes with it, and the lowest band is whatever its author chose. No board approved it, because it was never presented as a decision — yet it determines, more than any policy statement, which classes of event the enterprise can formally discuss.
That is why the variation matters. Were the floor a considered judgement about exposure, organisations would set it differently for good reasons. Instead the difference between instruments tracks the template's provenance rather than the user's circumstances.
The promotion problem
When an analyst does try to record a tail event, the instrument forces a choice, and both options degrade the record. Promote it into the lowest available band, and the entry asserts a frequency perhaps fifty times higher than the analyst believes. Colleagues who know the domain read it as overstated and discount it — reasonably, since as written it is wrong. Leave it out, and the exposure has no owner, no trigger, no review date, no forum.
The third response looks most like diligence and does the most damage: record an honest severity with an inflated probability, and the combined score lands in a band instructing the reader to monitor rather than act. The organisation now holds a formal record showing it identified the exposure, assessed it, and chose to do nothing — produced by the floor rather than by deliberation.
What the floor does to warning signals
Consider a hypothetical national blood supply and transfusion service. Its severe exposures are specific: a transmissible agent outside the current screening panel, simultaneous cold-chain failure across a network, donor-base collapse after a health scare. None has an annual probability the instrument can express. All would be catastrophic within days, and all announce themselves through weak signals — an anomalous cluster, an unexplained deferral rate, a supplier's quiet change of process.
Weak signals mean something only to an organisation that has already named the event they precede. If the event is on no register, the signal has nothing to attach to and is handled as an operational irregularity. The delay between first signal and decision carries a real cost that cost-based control systems cannot see; that mechanism belongs to [Related article: What Does It Cost You to Wait for a Decision?] and is not developed here. Which failures an enterprise chooses to investigate afterwards is a further governance question, owned by Article 52 in this collection.
There is a related trap in what boards are given. A probability quoted to a board is always the probability of something specific, and rarely of what the board believes. This article concerns events that cannot be assigned a probability at all; what a stated probability is the probability of is examined in [Related article: What Exactly Was the Board Given the Probability Of?].
Decision Framework
The floor disclosure. A short, signed statement accompanying every risk report the board receives. Five elements, refreshed annually.
1. State the floor. Name the lowest probability the instrument can express, in its own terms.
2. Convert it to a return period. Express the floor as a frequency in years, not a percentage. This is the step that changes the conversation: "below five per cent per annum" and "nothing rarer than once in twenty years" say the same thing, and only the second alarms anybody.
| Lowest band as written | Rarest expressible event | What this hides |
|---|---|---|
| Below 20 per cent | About once in five years | Everything on a decade-plus cycle |
| Below 10 per cent | About once in ten years | Most asset-life and licence exposures |
| Below 5 per cent | About once in twenty years | Correlated and systemic failure |
| Fixed lowest value of 0.1 | No rarer value expressible | The entire tail |
3. State the exposure horizon. The longest period over which the enterprise is committed — asset life, liability tail, concession term, decommissioning duty.
4. Compute the gap and populate it. The gap holds every event whose plausible return period is longer than the floor allows but shorter than the horizon. Name at least three. If leadership cannot, that inability is the finding, and should be reported rather than resolved by inventing entries.
5. Give each named event a home outside the scoring instrument. A resilience register, a solvency scenario set, a continuity plan — the vehicle matters less than its willingness to accept an entry with no probability rating. Each needs an owner, a cadence and a trigger.
Two failure conditions. The unsigned floor: if no one will put a name to the statement, the instrument's range has never been examined and the register's coverage is unknown. The empty gap: if the disclosure returns nothing between floor and horizon, either the enterprise has no long-cycle exposures — rare, and worth stating — or the exercise was run by people not permitted to name them.
From Strategy to Execution
Immediate — this quarter. Establish the floor of every scoring instrument in use, including those embedded in subsidiary, joint-venture and supplier frameworks. Convert each to a return period. Expect more than one floor, and expect the difference to be unexplained.
Medium-term — within two review cycles. Run the floor disclosure on the two most consequential portfolios. Designate the register that accepts entries with no probability rating and move the named events into it. Resist extending the scale downwards; a sixth band labelled "Extremely Rare" reintroduces the problem one step lower while appearing to solve it.
Long-term — the next framework revision. Make the floor disclosure a standing element of the risk report, so the board sees the instrument's range whenever it sees its output. Over several cycles this changes what the risk function is for: it stops being the body that rates what it can rate, and becomes the body accountable for what the enterprise cannot express.
Signals to Monitor
A register in which no entry sits in the lowest band, usually a sign that analysts have learned such entries attract challenge. Severe-consequence entries clustered at exactly the floor value. Narratives calling an event remote in prose while the rating says otherwise. Continuity plans covering events that appear nowhere on the register — proof the organisation already knows the instrument is inadequate. Assurance reports treating an absence of tail entries as a positive finding. Long-cycle exposures discussed in strategy papers and absent from risk papers.
Questions for the Leadership Team
- What is the lowest probability our instrument can express, stated as a return period, and who chose it?
- How does that return period compare with the longest obligation this enterprise currently carries?
- Name three events that would end this organisation. Could each have been entered on our register with a rating we would defend?
- Where do exposures live once they are too rare to rate, and when did the board last see that document?
- Has any entry been removed, downgraded or challenged because its probability was judged too low to justify the space it took?
- If a tail exposure were identified tomorrow four levels down, by what route would it reach this table, and how long would it take?
Closing Perspective
The instrument is not broken. It does what it was built to do: sort the frequent and moderate hazards of ordinary operation into a defensible order of attention. The error is one of scope. An instrument built for the middle of the distribution has been handed the whole of it, and its silence at the bottom has been read as reassurance.
Every enterprise therefore carries two registers. One is written down and reviewed. The other is the set of exposures its instrument cannot express, and it exists whether or not anyone has drafted it. Leadership does not choose whether the second register exists — only whether it has been written, by whom, and before or after the event it describes.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
