A treatment either lowers the chance of the event or arranges who absorbs it. Those are different purchases, and most registers record them the same way.
The quarterly risk report arrives with eleven items rated high or extreme. Every one has an owner, a treatment and a review date. Nothing is unattended. The committee works down the page, notes that mitigations are in place, and moves to the next agenda item in under twenty minutes.
The question almost never asked in that room is not whether the risks are managed. It is what the management consists of. For each of those eleven items, has the chance of the event fallen since the last meeting — or has the organisation arranged, at some cost, who pays when it happens?
Both are legitimate. They are not the same purchase. An organisation that has bought the first has less exposure than it had; an organisation that has bought the second has the same exposure and a better claim. Read a page of green treatment lines and you cannot tell which you are looking at, because the instrument was not built to make the distinction — and every quarter that passes, the enterprise's actual risk position drifts further from the one its report appears to describe.
The Strategic Context
Risk treatment is capital allocation conducted in small pieces by people rarely told they are allocating capital. A premium, an indemnity clause, a contingency line, a redesign, a second supplier, a deferred decision — each is funded separately, approved by someone different, and recorded as a register line rather than as an investment with a return.
Aggregate them and they describe a strategy nobody articulated. Some enterprises have reduced the chance of the things they fear. Others have arranged compensation for them. Most have a mixture nobody chose, weighted by whichever treatments were easiest to buy under pressure.
The two families also behave differently when conditions change. Compensation is priced by counterparties who reprice it, withdraw it or dispute it at exactly the moment it is needed. A reduction in likelihood, once built into a design or a process, keeps working without anyone renewing it. A portfolio weighted toward compensation is more fragile than its risk report suggests, and the fragility is invisible while nothing goes wrong.
The teaching material behind this article is unambiguous about the taxonomy — a risk may be avoided, transferred or mitigated, and mitigation is defined as reducing "the probability or impact" [SOURCE DETAILS REQUIRED]. That or carries an enormous amount of weight. Two responses that satisfy the same definition, sit in the same column and pass the same review can leave an organisation in entirely different positions.
What a Register Confirms, and What It Cannot
The habit worth challenging is treating mitigated as a state rather than as a claim. A treatment is an assertion that something has changed. The register records the assertion, the owner and the date; it rarely records what changed, and almost never records the evidence.
One artefact in the supplied material makes the gap concrete. A course-issued risk assessment worksheet asks for likelihood, impact and urgency; then for a mitigation strategy; then it re-rates impact and urgency, and provides no column at all in which a changed likelihood could be written. The eight-step method taught beside it does contemplate one — its later steps reassess severity "in the context of the probability after mitigation" and address planning for the "residual likelihood" [SOURCE DETAILS REQUIRED]. The form and the method disagree, and the form is what gets filled in.
That is one worksheet from one teaching source, and no claim is made here about how common such forms are. The mechanism is what matters: an instrument that cannot record a movement will not prompt anyone to ask for one.
Two boundaries are worth marking. This article is not about whether a risk register should record favourable deviation as well as adverse — that argument, and the definition it rests on, belongs elsewhere [Related article: Risk Is Not the Chance That Things Go Wrong]. Nor is it a claim about which instruments can detect which class of failure in general; it observes that one form omits one variable [Related article: Quality Assurance Cannot Tell You the Specification Was Wrong].
Reframing the Issue
Sort risk treatments by what they actually move and they fall into two families.
Likelihood-reducing treatments change the world in which the event might occur: a different design, a different sequence, a different supplier, a prequalification regime, a redundancy built at source, a decision deferred until the unknown is known, or a scope that no longer includes the hazardous element. The chance of the event genuinely falls.
Consequence-bearing treatments leave the chance where it is and rearrange who absorbs the result: insurance, indemnities, liquidated damages, warranties, a contingency reserve, a clause moving the exposure to a counterparty. Something bad remains equally likely; the organisation has arranged compensation.
The families are not ranked. A rare event with a fully compensable consequence is an excellent candidate for the second. The point is that they are different purchases and the enterprise should know its own proportions.
Two things follow. Transfer belongs to the second family, whatever else is said about it — and who should carry an exposure across a contract boundary, and what remains yours once you have moved it, is a separate argument this one does not re-run [Related article: Risk You Transfer Is Risk You Still Own]. A contingency reserve is likewise consequence-bearing, which is why it is so often the first thing funded and the first thing raided; its own governance sits in two other arguments [Related article: What Does "Critical" Actually Commit You To?] [Related article: From Estimate to Commitment]. And several treatments in this family are contract terms, obtainable only in a window that closes early [Related article: The Terms You Cannot Buy Back].
Why the Second Family Wins Without a Decision
The two families have different politics, and the politics decide the mix.
Reducing likelihood requires somebody to give something up. A different sequence costs time; a different supplier costs a relationship and a rebid; a design change costs rework and, once the schedule is committed, credibility. Each has an identifiable loser who will be in the room.
Consequence-bearing treatments require money and a signature. No design authority concedes anything, no date moves, and the cost sits in a line that reads as prudence. Under schedule pressure — which is to say, always — an organisation buys the second family faster than it can convene the meeting that would consider the first. Both produce a green line and a named owner, so the enterprise chooses its own fragility by default, one small approval at a time.
Where consequence-bearing is right. A rare event with a bounded financial loss and a solvent counterparty is efficiently insured, and the alternative is over-engineering. Where it is not. No premium returns a licence, a patient or a decade of public trust. An enterprise that has insured a regulatory, clinical or reputational exposure has not reduced it at all.
Urgency: the Variable That Decides Whether You Can Wait
The teaching source's qualitative analysis has four steps, and the third is the one most registers drop: identify the likelihood, identify the impact, identify the urgency, then determine the required level of response.
Urgency is not severity, and it is not detection speed — how fast a signal reaches you, and how a deviation indicator should be designed, is a different discipline [Related article: Measuring an Outcome You Cannot Predict]. Urgency is the time available before a response must be committed. Which is to say: the time available to buy information instead of cover.
Read that way, urgency converts a risk item into an investment question. A threat with a long fuse and a large consequence is an argument for a study or a trial — for spending money to move the estimate rather than to arrange the payout. That uncertainty is a reason to plan rather than an excuse not to is argued in full elsewhere, and this article borrows the conclusion [Related article: Uncertainty Is the Case for Planning, Not the Excuse Against It]. One caution travels with it: a trial run by the part of the business that wants the answer will produce that answer [Related article: Volunteers Are Not a Sample].
And every rating is perishable. The same source is blunt about it: risk is relative to the circumstances at the time the assessment was made, and what is low today can be high later. A register whose ratings carry no re-test date is a photograph being read as a live feed.
Two Illustrations
Both are hypothetical.
A dairy processing co-operative is upgrading a plant. The register's largest item is product contamination, rated extreme. Within a fortnight it has funded recall insurance, a supplier indemnity and a contingency line — each sensible, and together changing the probability of contamination by nothing at all. The treatments that would have changed it — revalidating the clean-in-place regime, relaying the line so raw and finished product no longer cross, extending commissioning by three weeks — sit in a paper awaiting a decision that costs the commissioning date. A year later the co-operative has a recall, a valid claim, and a brand problem no policy covers.
A data centre operator is funding resilience. Redundant power paths and additional cooling are consequence-bearing: they do not reduce the chance of a grid failure by one point, they ensure the customer does not experience it. The likelihood-reducing treatments sit elsewhere in the same programme — site selection away from a constrained feeder, components replaced before failure, a change rule forbidding concurrent works on paired systems. Fund only the first family and you have a business that fails less visibly rather than less often.
Decision Framework
Classify the treatments you already fund. Take the top twenty by cost and record four things for each.
| Field | What it captures |
|---|---|
| Family | Likelihood-reducing, or consequence-bearing |
| Claim | What this treatment is asserted to move, in one sentence |
| Evidence | What would show that it moved — a test, a rate, an inspection, a completed change |
| Re-test date | When the rating expires and must be reassessed |
Three tests follow.
The proportion test. What share of treatment spend reduces likelihood — and is that the share you would choose deliberately?
The compensability test. For every consequence-bearing treatment on a high-likelihood item, state what the compensation restores. If the honest answer is "money, and not the thing we care about", the treatment has been misfiled as protection.
The urgency test. How long before a response must be committed? Where the answer runs to quarters rather than weeks, ask what could be learned in that time and what it would cost, then compare it with the cover.
One narrow governance rule follows: an executive committee should be told when a high-likelihood item's only treatments are consequence-bearing. Not escalated, not re-rated — named. Where thresholds sit and what a breach obliges is a separate design question [Related article: Authority With an Expiry Date].
From Strategy to Execution
Immediately. Classify the top twenty treatments — an afternoon's work, no new system — and report the proportions to the risk committee on one slide.
Within two quarters. Change the form: a post-treatment likelihood field and an evidence field, both mandatory. A field that must be filled generates the conversation that fills it. Where a knowledge area is reorganised rather than merely re-formed, more changes than the paperwork [Related article: When a Sub-Process Becomes a Domain].
Over the planning cycle. Build the capability that makes likelihood reduction available at all: design authority that can still change something after approval, supplier development rather than selection alone, and sequencing that keeps decisions open long enough for information to arrive. An organisation that cannot change its own design has only the second family, whatever its register says.
One boundary: this article concerns treating a risk on an initiative already under way, not whether the initiative should proceed — the risk of standing still is its own question [Related article: What Is the Risk of Not Doing It?].
Signals to Monitor
- The proportion itself, tracked over four quarters. Drift toward consequence-bearing treatments is drift toward fragility, and it tracks schedule pressure.
- Empty evidence fields. A treatment whose evidence line stays blank for two cycles has not been tested; it has been asserted.
- Insurance and surety pricing rising faster than the underlying exposure. Counterparties reprice on their own view of your likelihood, and that view is worth reading.
- Recurrence with mitigation in place. The same event twice, both times against a green line, is the clearest evidence available that the treatment moved something other than the probability.
- Counterparty concentration. Several consequence-bearing treatments resting on one insurer or one supplier is a correlation the register records as separate lines.
Questions for the Leadership Team
- Of the treatments we funded this year, what proportion reduced the chance of the event rather than arranging who absorbs it — and did anyone choose that proportion?
- For our three largest exposures, what exactly would the compensation restore, and is that the thing we care about?
- Which of our high-rated risks could still be reduced by a decision that remains open, and how long does that decision stay open?
- What is the oldest rating on our register, and what has changed in the world since it was made?
- Where a treatment has been in place for a year, what evidence do we have that it worked, as distinct from evidence that nothing has happened yet?
Closing Perspective
The register is not the risk position. It is a record of assertions, of two kinds the form treats identically. One kind makes the enterprise less likely to be hurt. The other makes it better compensated when it is.
An organisation is entitled to choose either, and a serious one uses both. What it cannot afford is to accumulate the second family for a decade, report it as risk reduction, and then be surprised when the exposure it believed it had managed arrives intact, at full size, with a valid claim attached.
The distinction costs one column and one question in a meeting that already happens. What it requires is the willingness to hear that some of what has been called mitigation is insurance — an uncomfortable half-hour, and a far better position than learning it at the point of loss.
About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.
