Operational Excellence

Where Do Your Near-Certainties Go?

Once an item passes the likelihood threshold it is reclassified out of the risk process entirely, which leaves the enterprise funding the improbable and absorbing the certain.

EraNorth Insights · 30 Aug 2026 · 14 min read

The risk process is defined so that it expels its most probable items: anything near-certain is reclassified as an issue, and issues receive no contingency, no forward plan and no place in the reserve calculation.

Late in a risk review, someone makes an observation the room accepts immediately. The item under discussion — the one the engineering lead has been describing in the flat voice of a person who has seen it happen four times — is not really a risk. It is going to happen. Somebody says so: that is not a risk, it is a certainty; it does not belong on this register.

The item comes off. The decision takes seconds, it is correct under the enterprise's own definitions, and nobody who agreed has done anything wrong.

Follow what that decision moves. The item leaves the register, so it leaves the reserve calculation, and leaves response planning, so no fallback is designed and no owner is given a date. It leaves the reporting line to the steering committee for one that runs to a different body. It stops consuming attention in the meeting where money is allocated and starts consuming money in the meeting where problems are reported. And it does all of this because the enterprise judged it more likely, not less.

The delivery discipline draws this boundary deliberately: a risk is uncertain, and once something is certain it is no longer a risk but an issue, requiring management action rather than probabilistic assessment. The definition is sound; what follows from it is not, because the process on the far side was built for events that have already happened, and a near-certainty has not happened yet. It has simply been declared too likely to plan for.

The question is short. When an item passes the likelihood threshold and stops being a risk, who funds it?

The Strategic Context

The boundary is not merely conceptual. It is drawn numerically, in the scales the discipline supplies for scoring likelihood, which run in bands from a fraction of a per cent up towards four-fifths — and above that, the top band is not a probability at all. It is an instruction to stop treating the item as a risk. The highest likelihood an item can carry and still be scored sits well below certainty.

That instruction has consequences the scale does not mention. Exposure here is the product of likelihood and impact, and the reserve is built by summing that product across the register, so an item's contribution rises as it becomes more likely — right up to the threshold, at which point it falls to nothing. The funding calculation has a cliff in it, positioned at the point of maximum expected loss.

There is a further tell, and it survives inside a single page of the discipline's own teaching. The scoring matrix carries a row for a likelihood value the accompanying scale says cannot exist as a risk: the matrix computes an exposure for it while the scale beside it directs that such an item be regarded as an issue. A contradiction persisting inside a discipline's own instructional material is not a typographical accident. It is evidence that the boundary was never reconciled with the arithmetic depending on it.

Beyond the boundary sits a competent procedure for events that have occurred: capture, examine, propose options, decide or escalate, implement, close. Every step is triggered by occurrence. Nothing in it holds money in advance, schedules a preventive action, or appears in any forecast before the event arrives.

Three Things the Register Is Read to Say That It Does Not

That it is the enterprise's complete list of what may go wrong. It is the list of things judged uncertain enough to score, which is narrower at both ends. The improbable are filtered out by materiality thresholds, deliberately and visibly. The near-certain are removed by definition, silently, with no record that they were ever considered.

That an item leaving the register has been resolved. Closure and expulsion look identical in most reporting. A risk retired because its response worked and one removed because it became too likely both appear as a reduction in open items — and the headline count improves faster in the second case.

That the reserve is sized against the enterprise's exposure. It is sized against the register, and the register is a truncated population. The calculation is correct on the inputs it is given; the inputs have had their upper tail removed. This is the most dangerous property of the arrangement, because nothing about it looks like an error. Which of the enterprise's two funds should carry a reclassified near-certainty, and who may release it, is a separate governance question belonging to [Related article: Two Funds, Two Authorities].

Reframing the Issue

This is not a definitional quibble but a routing failure. The enterprise runs one process that anticipates and funds and another that reacts and does not, and routes items between them on likelihood — sending the more likely items to the less prepared one.

Consider a commercial bakery introducing a new pack format across an existing line. The illustration is hypothetical; the mechanism is general. The engineering team's honest expectation is that the new sealing head will not hold specification on the first full production run, because it has not done so on any comparable changeover this line has been through. That expectation sits well above any likelihood threshold, so it is not a risk. No contingency is set aside for the re-run, the scrapped film, the discarded ingredient batch, or — the expensive part — the retail delivery window missed, negotiated months in advance and not rescheduled. When the run fails, an issue is raised, examined, and funded from whatever the operating budget can absorb.

Urban bus fleet operations shows the same pattern at portfolio scale. In a hypothetical depot renewal, it is near-certain that some incoming vehicles will arrive requiring rectification, near-certain that driver conversion training will run past its window, and near-certain that an infrastructure connection date will move. Each is confidently expected by the people running the programme, and each is, for that reason, outside the register. The contingency covers the events nobody expects, while the events everybody expects are absorbed by an operating account never sized for them.

The Truncated Distribution and What It Costs

The reserve is sized against a population the process has trimmed

An enterprise funding its reserve from the register is funding against a distribution with its right-hand tail cut off. The error runs one way: the reserve is too small, never too large. The shortfall equals the summed impact of the items thought most likely to occur — the worst possible quantity to omit.

Note what this does to declared risk appetite, which is expressed as a tolerance for exposure and computed from the register. An enterprise can sit well inside its stated appetite on every reported measure while carrying a body of near-certain loss no measure includes.

Expulsion is the cheapest relief available to a risk owner

Consider someone who owns a difficult risk, is asked monthly for evidence that the response is working, and can see that it is not. There are two routes out: fix it, or argue that the likelihood is now so high the item no longer qualifies as a risk.

The second is quicker, requires no engineering, and is defensible under the enterprise's own definitions. It removes the item from the register, the requirement for a response plan and the monthly evidence obligation, and moves it to a log most steering committees read less carefully. A process offering relief in exchange for a higher probability estimate is rewarding the wrong disclosure, and it will get what it rewards. What remains after expulsion is usually a decision waiting to be made rather than work waiting to be done; what that waiting costs, and why a cost-based control system cannot see the work of deciding at all, is developed in [Related article: What Does It Cost You to Wait for a Decision?] rather than here.

The expelled items are the correlated ones

At project level this is a funding gap. At portfolio level it is worse, because near-certainties share causes. A regulatory date, an expiring labour agreement, a struggling supplier, a seasonal constraint, an ageing asset class — each produces near-certain consequences across many delivery units at once, which is precisely why every unit's team is confident about them.

Every affected unit reclassifies its own instance separately, on defensible grounds, and no register carries it. The enterprise thereby removes from view the one category of exposure whose aggregate matters most. Portfolio risk aggregation is usually treated as a problem of adding things up; here the items most worth adding have already been individually deleted.

Decision Framework

The reclassification ledger. Maintain it beside the risk register, with the same version control and standing place on the agenda. It records every item removed from the register, or refused entry, on grounds of likelihood. Seven fields, two tests, one rule.

The fields, per entry: the item and the objective it threatens; the date and name of the person who reclassified it; the likelihood judgement that triggered it, stated as a number rather than a band; the full impact if it occurs, in money and days; the funding source now assumed to cover it — contingency, management reserve, operating budget, or unfunded; the named owner and the date the forward action must be taken; and whether the item exists in more than one delivery unit.

Unfunded must be a permitted entry. A ledger that never records it is not being told the truth.

The sum test. Total the impact column and set it beside the contingency held. If the ledger's total approaches or exceeds the reserve, the reserve is sized against the wrong distribution, and the governing body should be given both numbers together rather than the reserve alone.

The direction test. Over two reporting periods, count the items that left the register on likelihood grounds against those that entered it. Sustained one-way traffic is not evidence of improving estimation. It is evidence that reclassification is functioning as relief, and the remedy is to examine who grants it rather than to adjust the threshold.

The rule. No item leaves the risk register on likelihood grounds without a ledger entry and a named funding source. Where that source is unfunded, the entry goes to the sponsor rather than the delivery manager, because an unfunded near-certainty is a decision about the balance sheet, not about the project.

Which response family an item should be assigned once inside the process — avoidance, transfer, mitigation or acceptance — belongs to ERANORTH's earlier treatment of the response taxonomy and is not re-argued here. This article concerns only the items that never reach a response family at all.

From Strategy to Execution

Immediate. Ask for every item removed from the register in the last two quarters, with the reason. Most enterprises cannot produce it, and the inability is itself the finding. Where reasons exist, separate genuine closures from likelihood reclassifications and total the second group's impact.

Medium term. Put the ledger into the standard reporting pack beside the register, and change the reserve paper so it presents reserve held, register exposure and ledger total on one page. Require every item reclassified on likelihood grounds to carry a forward action with a date: a near-certain event is the easiest kind to prepare for, and the only kind the process currently refuses to prepare for.

Long term. Revisit the threshold itself. An enterprise may reasonably decide that items above a stated likelihood should be planned as work rather than managed as risk — a coherent position, and arguably the right one. What is not coherent is expelling them from the risk process without admitting them to the plan. Either way, the near-certain item must end up somewhere with a budget line and an owner.

Beware the reflex remedy of adding a standing control for every reclassified item. That relieves the immediate exposure and creates a permanent one, because nothing in the discipline retires a control once it exists; that compounding is examined in [Related article: Who Retires a Control?] and is not resolved here.

Signals to Monitor

A falling count of open risks unaccompanied by evidence of successful responses. Items in the issues log that no register ever carried. The same near-certainty recurring across successive projects in one delivery unit, meaning the enterprise pays for it repeatedly and records it nowhere. Contingency drawn against events never scored. Reserve papers quoting exposure without quoting what was removed from the calculation. Risk owners raising likelihood estimates in the period before a response deadline. And the plainest signal available: ask three experienced people what they are certain will go wrong, then see how much of it reaches the board.

Questions for the Leadership Team

  1. How many items left our risk registers on likelihood grounds in the last two quarters, and what is their total impact?
  2. What proportion of the issues we managed last year began as register items removed before they occurred?
  3. Which near-certainties are currently known to more than one delivery unit, and where is that aggregate recorded?
  4. When our contingency was last sized, what was the sum of the items excluded from the calculation because they were judged too likely to be risks?
  5. Who in this enterprise is authorised to remove an item from a risk register, and what evidence must they produce to do it?
  6. For the three largest near-certain events our delivery teams expect, which budget line absorbs the cost, and has its owner been told?

Closing Perspective

The threshold is not the problem. Some boundary between what is planned as uncertain and what is planned as certain is necessary, and the definitions are defensible. The problem is that the enterprise has built a funded, forward-looking, governed process on one side of the line and an unfunded, reactive, lightly governed one on the other, and connected them with a rule that sends items across in the direction of increasing likelihood.

That arrangement guarantees an outcome: the enterprise will be well prepared for what probably will not happen and unprepared for what it is confident will. Nobody chose it. It follows from a definition everyone accepts and a routing rule nobody has examined. The choice now available is whether the near-certainties the organisation's own people can already name go on being discovered by the accounts, or are written down, priced, owned and funded before they arrive.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.