= Risk =

Risk is the possibility of something bad happening, comprising a level of uncertainty about the effects and implications of an activity, particularly negative and undesirable consequences.

Risk theory, assessment, and management are applied but substantially differ in different practice areas, such as business, economics, environment, finance, information technology, health, insurance, safety, security, and privacy. The international standard for risk management, ISO 31000, provides general guidelines and principles on managing risks faced by organizations.

== Definition ==

The Oxford English Dictionary (OED) cites the earliest use of the word in English (in the spelling of risque from its French original, 'risque') as of 1621, and the spelling as risk from 1655. While including several other definitions, the OED 3rd edition defines risk as "(Exposure to) the possibility of loss, injury, or other adverse or unwelcome circumstance; a chance or situation involving such a possibility". The Cambridge Advanced Learner's Dictionary defines risk as "the possibility of something bad happening". Some have argued that the definition of risk is subjective and context-specific. The International Organization for Standardization (ISO) 31073 defines risk as:effect of uncertainty on objectives
Note 1: An effect is a deviation from the expected. It can be positive, negative or both, and can address, create or result in opportunities and threats.

Note 2: Objectives can have different aspects and categories, and can be applied at different levels.

Note 3: Risk is usually expressed in terms of risk sources, potential events, their consequences and their likelihood.

Other general definitions include:

- "Source of harm"
The earliest use of the word "risk" was as a synonym for the much older word "hazard", meaning a potential source of harm. This definition comes from Blount's "Glossographia" (1661) and was the main definition in the OED 1st (1914) and 2nd (1989) editions. Modern equivalents refer to "unwanted events" or "something bad that might happen".
- "Chance of harm"
This definition comes from Johnson's "Dictionary of the English Language" (1755), and has been widely paraphrased, including "possibility of loss" or "probability of unwanted events".
- "Uncertain events affecting objectives"
This definition was adopted by the Association for Project Management (1997). With slight rewording it became the definition in ISO Guide 73.
- "Uncertainty of outcome"
This definition was adopted by the UK Cabinet Office (2002) to encourage innovation to improve public services. It allowed "risk" to describe either "positive opportunity or negative threat of actions and events".
- "Potential returns from an event ['a thing that happens or takes place'], where the returns are any changes, effects, consequences, and so on, of the event"
This definition from Newsome (2014) expands the neutrality of 'risk' akin to the UK Cabinet Office (2002) and Knight (1921).
- "Human interaction with uncertainty"
This definition comes from Cline (2015) in the context of adventure education.

===Versus uncertainty===
In his seminal 1921 work Risk, Uncertainty, and Profit, Frank Knight established the distinction between risk and uncertainty.

Thus, Knightian uncertainty is immeasurable, not possible to calculate, while in the Knightian sense risk is measurable.

=== By field ===
  - Definitions of risk**

| Field | Definition | Sources | Related concepts |
| Economics | Uncertainty about loss | Willett's "Economic Theory of Risk and Insurance" (1901). | |
| Insurance | Measurable uncertainty | Knight's "Risk, Uncertainty and Profit" (1921). | Knightian uncertainty, mortality risk, longevity risk, interest rate risk |
| Possibility of an event occurring which causes injury or loss | Lloyd's. | | |
| Finance | Volatility of return | Markovitz's "Portfolio Selection" (1952). | Financial risk management, Risk aversion |
| Components: Downside risk, Upside risk, Inherent risk, Benefit risk | | | |
| Business risks: Enterprise risk management, Audit risk, Process risk, Legal risk, Reputational risk, Peren–Clement index | | | |
| Investments: Modern portfolio theory, Value at risk, Hedge | | | |
| Types of financial risks: Market risk, Credit risk, Liquidity risk, Operational risk | | | |
| Decision theory | Statistically expected loss | Wald (1939). Used in planning of Delta Works in 1953. Adopted by the US Nuclear Regulatory Commission in 1975. Remains widely used. | |
| Bayesian analysis | Scenarios, probabilities and consequences: Consequences and associated uncertainty; likelihood and severity of events | Kaplan & Garrick (1981). Found in ISO Guide 73 Note 4. | |
| Occupational health and safety | Combination of the likelihood and consequence(s) of a specified hazardous event occurring | Occupational Health and Safety Assessment Series (OHSAS) standard OHSAS 18001, 1999. | Occupational hazard, High reliability organisation, Probabilistic risk assessment, WASH-1400 |
| Cybersecurity | Asset, threat and vulnerability | Threat Analysis Group (2010). | Information security, IT risk management, IT risk |
| Environment | Chance of harmful effects to human health or to ecological systems | United States Environmental Protection Agency. | Environmental hazards, Environmental issues, Environmental protection |
| Health | Possibility that something will cause harm | Centres for Disease Control and Prevention. | Epidemiology, Risk factors, Health risk assessment, Relative risk, Mortality rate, Loss of life expectancy |
| Project management | An uncertain event or condition that, if it occurs, has a positive or negative effect on a project's objectives | Project Management Institute. | Project risk management |
| Security | Any event that could result in the compromise of organizational assets i.e. the unauthorized use, loss, damage, disclosure or modification of organizational assets for the profit, personal interest or political interests of individuals, groups or other entities | | Security management |

=== Mathematical ===

==== Triplets ====
Risk is often considered to be a set of triplets

$\text{R} = (s_i, p_i, x_i )$ for i = 1,2,....,N

where:
$s_i$ is a scenario describing a possible event
$p_i$ is the probability of the scenario
$x_i$ is the consequence of the scenario
$N$ is the number of scenarios chosen to describe the risk

Risks expressed in this way can be shown in a risk register or a risk matrix. They may be quantitative or qualitative, and can include positive as well as negative consequences.

An updated version recommends the following general description of risk:

$R = ({A, C, U, P, K} )$
where:
$A$ is an event that might occur
$C$ is the consequences of the event
$U$ is an assessment of uncertainties
$P$ is a knowledge-based probability of the event
$K$ is the background knowledge that U and P are based on

==== Probability distributions ====
If all the consequences are expressed in the same units (or can be converted into a consistent loss function), the risk can be expressed as a probability density function describing the uncertainty about outcome:

$R = p(x)$

This can also be expressed as a cumulative distribution function (CDF) (or S curve). One way of highlighting the tail of this distribution is by showing the probability of exceeding given losses, known as a complementary cumulative distribution function, plotted on logarithmic scales. For example, frequency-number diagrams show the annual frequency of exceeding given numbers of fatalities. Another way of summarizing the size of the distribution's tail is the loss with a certain probability of exceedance, that is, the value at risk.

==== Expected values ====
Risk is often measured as the expected value of the loss. This combines the probabilities and consequences into a single value. See also expected utility. The simplest case is a binary possibility of Accident or No accident. The associated formula for calculating risk is then:

$R = (\text{probability of the accident occurring}) \times (\text{expected loss in case of the accident})$

In a situation with several possible accident scenarios, total risk is the sum of the risks for each scenario, provided that the outcomes are comparable:

$R = \sum_{i=1}^N p_i x_i$

In statistical decision theory, the risk function is defined as the expected value of a given loss function as a function of the decision rule used to make decisions in the face of uncertainty.

A disadvantage of defining risk as the product of impact and probability is that it presumes, unrealistically, that decision-makers are risk-neutral. A risk-neutral person's utility is proportional to the expected value of the payoff. For example, a risk-neutral person would consider 20% chance of winning $1 million exactly as desirable as getting a certain $200,000. However, most decision-makers are not actually risk-neutral and would not consider these equivalent choices. Pascal's mugging is a philosophical thought experiment that demonstrates issues in assessing risk solely by the expected value of loss or return.

==== Outcome frequencies ====
Risks of discrete events such as accidents are often measured as outcome frequencies, or expected rates of specific loss events per unit time. When small, frequencies are numerically similar to probabilities, but have dimensions of and can sum to more than 1. Typical outcomes expressed this way include:

- Individual risk - the frequency of a given level of harm to an individual. It often refers to the expected annual probability of death, and is then comparable to the mortality rate.
- Group (or societal risk) – the relationship between the frequency and the number of people suffering harm.
- Frequencies of property damage or total loss.
- Frequencies of environmental damage such as oil spills.

== Financial risk ==
In finance, an elementary measure of risk for financial asset prices is with volatility, the degree of variation of a trading price over time, usually measured by the standard deviation of logarithmic returns.

=== Portfolio theory ===
Modern portfolio theory measures the riskiness of a portfolio using the variance (or standard deviation) of the portfolio. If we denote return by $R(w)$ of a portfolio with weight vector $w = (w_1,\dots,w_n)'$ then the risk, as measured by variance of the portfolio is given by

$\text{Risk}=\mathrm{Var}(R(w)) = \sum_{i=1,j=1}^n w_j w_j\mathrm{Cov}(R_i,R_j)$

where $R_i$ denotes the return of asset $i=1,\dots,n$. Modern portfolio theory tells us an optimal combination of weights creates an optimal portfolio - known as the tangency portfolio - that still has undiversifiable risk. The model implies this 'systematic' source of risk should be the only factor considered, as all other sources of risk can be diversified away. An extension of this is the Capital asset pricing model (CAPM), where this optimal portfolio becomes known as the market portfolio.

The beta coefficient measures the sensitivity of an individual asset to overall market changes, and is defined as the linear projection coefficient of asset $i=1,\dots,n$ returns on the returns of a market portfolio,

$\beta_i = \frac{\mathrm{Cov}(R_i,R_{mkt})}{\mathrm{Var}(R_i)}$

In a CAPM world, $\beta_i$ can be interpreted as the contribution of systemic risk to the risk of asset $i$.

=== Risk-neutral measure ===
In mathematical finance, a risk-neutral measure is a probability measure such that each share price is exactly equal to the discounted expectation of the share price under the measure. This is heavily used in the pricing of financial derivatives due to the fundamental theorem of asset pricing.

Let $S$ be a d-dimensional market representing the price processes of the risky assets, $B$ the risk-free bond and $(\Omega,\mathcal{F},P)$the underlying probability space. Then a measure $Q$ is a risk-neutral measure if

1. $Q\approx P$, i.e., $Q$ is equivalent to $P$,
2. the processes $\left( \frac{S^i_t}{B_t} \right)_t$ are (local) martingales w.r.t. $Q$ $\forall \, i=1,\dots,d$.

=== Mandelbrot's mild and wild theory ===
Benoit Mandelbrot distinguished between "mild" and "wild" risk and argued that risk assessment and analysis must be fundamentally different for the two types of risk. Mild risk follows normal or near-normal probability distributions, is subject to regression to the mean and the law of large numbers, and is therefore relatively predictable. Wild risk follows fat-tailed distributions, e.g., Pareto or power-law distributions, is subject to regression to the tail (infinite mean or variance, rendering the law of large numbers invalid or ineffective), and is therefore difficult or impossible to predict. A common error in risk assessment and analysis is to underestimate the wildness of risk, assuming risk to be mild when in fact it is wild, which must be avoided if risk assessment and analysis are to be valid and reliable, according to Mandelbrot.

=== Estimation ===

- Proxy or analogue data from other contexts, presumed to be similar in some aspects of risk.
- Theoretical models, such as Monte Carlo simulation and Quantitative risk assessment software.
- Logical models, such as Bayesian networks, fault tree analysis and event tree analysis
- Expert judgement, such as absolute probability judgement or the Delphi method.

==Management==
Risk management is the set of actions that organisations take to avoid and mitigate downside risks, taking into account factors such as the possibility of upside risk opportunities, innovation, the environment, safety, scientific evidence, culture, politics, and law. Risk management operates at the strategic, operational, and individual level, and may form part of an overarching governance, risk, and compliance strategy. It comprises the assessment of risk as regards an organisation's objectives and strategies, as well as risk mitigation options, such as risk transformation, risk transfer, risk avoidance, risk reduction, and risk retention.

=== Assessment ===
Risk assessment is a systematic approach to recognising and characterising risks, and evaluating their significance, in order to support decisions about how to manage them. ISO 31000 defines it in terms of its components as "the overall process of risk identification, risk analysis and risk evaluation":

- Risk identification is "the process of finding, recognizing and recording risks". It "involves the identification of risk sources, events, their causes and their potential consequences." ISO 31000 describes it as the first step in a risk assessment process, preceding risk analysis and risk evaluation. In safety contexts, where risk sources are known as hazards, this step is known as "hazard identification".
- The ISO defines risk analysis as "the process to comprehend the nature of risk and to determine the level of risk". In the ISO 31000 risk assessment process, risk analysis follows risk identification and precedes risk evaluation. Risk analysis often uses data on the probabilities and consequences of previous events.
- Risk evaluation involves comparing estimated levels of risk against risk criteria to determine the significance of the risk and make decisions about risk treatment actions. In most activities, risks can be reduced by adding further controls or other treatment options, but typically this increases cost or inconvenience. It is rarely possible to eliminate risks altogether without discontinuing the activity. Sometimes it is desirable to increase risks to secure valued benefits. Risk criteria are intended to guide decisions on these issues.

For example, the tolerability of risk framework, developed by the UK Health and Safety Executive, divides risks into three bands:

- Unacceptable risks – only permitted in exceptional circumstances.
- Tolerable risks – to be kept as low as reasonably practicable (ALARP), taking into account the costs and benefits of further risk reduction.
- Broadly acceptable risks – not normally requiring further reduction.

==== Attitude, appetite and tolerance ====
The terms risk appetite, attitude, and tolerance are often used similarly to describe an organisation's or individual's attitude towards risk-taking. One's attitude may be described as risk-averse, risk-neutral, or risk-seeking.

=== Mitigation ===

- Risk transformation describes the process of not only mitigating risks but also employing risk factors into advantages.
- Risk transfer is the shifting of risks from one party to another, typically an insurer.

==Psychology of risk==
===Risk perception===
Risk perception is the subjective judgement that people make about the characteristics and severity of a risk. At its most basic, the perception of risk is an intuitive form of risk analysis.

Adults have an intuitive understanding of risk, which may not be exclusive to humans. Many ancient societies believed in divinely determined fates, and attempts to influence the gods can be seen as early forms of risk management. Early uses of the word 'risk' coincided with an erosion of belief in divinely ordained fate. Notwithstanding, intuitive perceptions of risk are often inaccurate owing to reliance on psychological heuristics, which are subject to systematic cognitive biases. In particular, the accuracy of risk perception can be adversely affected by the affect heuristic, which relies on emotion to make decisions.

The availability heuristic is the process of judging the probability of an event by the ease with which instances come to mind. In general, rare but dramatic causes of death are over-estimated while common unspectacular causes are under-estimated; an "availability cascade" is a self-reinforcing cycle in which public concern about relatively minor events is amplified by media coverage until the issue becomes politically important. Despite the difficulty of thinking statistically, people are typically subject to the overconfidence effect in their judgements, tending to overestimate their understanding of the world and underestimate the role of chance, with even experts subject to this effect. Other biases that affect the perception of risk include ambiguity aversion.

Paul Slovic's "psychometric paradigm" assumes that risk is subjectively defined by individuals, influenced by factors such as lack of control, catastrophic potential, and severity of consequences, such that risk perception can be psychometrically measured by surveys. Slovic argues that intuitive emotional reactions are the predominant method by which humans evaluate risk, and that a purely statistical approach to disasters lacks emotion and thus fails to convey the true meaning of disasters and fails to motivate proper action to prevent them. This theory has received support from retrospective studies and evolutionary psychology. Hazards with high perceived risk are therefore, in general, seen as less acceptable and more in need of reduction.

Cultural theory of risk views risk perception as a collective phenomenon by which different cultures select some risks for attention and ignore others, with the aim of maintaining their particular way of life. Hence risk perception varies according to the preoccupations of the culture. The theory outlines two categories, the degree of binding to social groups, the degree of social regulation. Cultural theory can be used to explain why it can be difficult for people with different world-views to agree about whether a hazard is acceptable, and why risk assessments may be more persuasive for some people than others. However, there is little quantitative evidence that shows cultural biases are strongly predictive of risk perception.

=== Decision theory ===

In decision theory, regret (and anticipation of regret) can play a significant part in decision-making, distinct from risk aversion. Framing is also a fundamental problem with all forms of risk assessment. In particular, because of bounded rationality, the risk of extreme events is discounted because the probability is too low to evaluate intuitively. As an example, one of the leading causes of death is road accidents caused by drunk driving – partly because any given driver frames the problem by largely or totally ignoring the risk of a serious or fatal accident. The right prefrontal cortex has been shown to take a more global perspective, while greater left prefrontal activity relates to local or focal processing. Reference class forecasting is a forecasting method by which biases associated with risks can be mitigated.

===Risk taking===
Psychologists have run randomised experiments with a treatment and control group to ascertain the effect of different psychological factors that may be associated with risk taking, finding that positive and negative feedback about past risk taking can affect future risk taking. For example, one experiment showed that belief in competence correlated with risk-taking behavior. Risk compensation is a theory that suggests that people typically adjust their behavior in response to the perceived level of risk, becoming more careful where they sense greater risk and less careful if they feel more protected. People also show risk aversion, such that they reject fair risky offers because of the perception of loss. Further, intuitive responses have been found to be less risk-averse than subsequent reflective response.

==Philosophy of risk==
Peter L. Bernstein (2012) showed that people used risk estimates before statistics and probability calculations were developed. Instead of relying on numbers, people used narratives and letters. Captains and merchants shared voyage stories at coffeehouses, comparing notes about hazards on new routes and seasonal patterns. Through a web of correspondents, letters became increasingly important as people could update their beliefs about weather, wars, or piracy over long distances. These qualitative data helped investors and underwriters judge how dicey a proposed voyage felt.

This kind of evidence has led philosophers to think there is more to (objective) risk than the likelihood of an undesirable outcome. Ebert et al. (2020) suggest distinguishing risk monists from risk pluralists: risk monists argue that there is just one correct way to understand risk. Tversky and Kahneman can be considered monists in this sense; probability judgments that diverged from the probability calculus were deemed wrong or biased. By contrast, pluralists claim that there are different, valid notions of risk. On this view, people who lived before statistics were developed may have been doing something legitimate when they estimated risks—even if those estimates conflict with a statistical notion. Without statistics, what else could they have done?

According to the modal account of risk, a situation is risky when nearby possible worlds—differing only slightly from the actual one—contain serious harm. Risk tracks the closeness of such bad outcomes rather than their probability; hence a low-chance disaster may still count as high risk if only a small change would have led to it. On the normic account of risk, a situation is risky when the bad outcome would be normal or unsurprising. Risk is assessed through system functions and norms rather than bare probability. A harm counts as high risk when it would occur in the most normal continuations of the present setup; the less departure from normality needed for the harm, the greater the risk. Especially in domains where we lack predictive power, such approaches allow us to consider risk without relying on unknown probabilities, as illustrated by the normic account of suicide risk.

==Society and culture==
===Risk and autonomy===
The experience of many people who rely on human services for support is that 'risk' is often used as a reason to prevent them from gaining further independence or fully accessing the community, and that these services are often unnecessarily risk averse. "People's autonomy used to be compromised by institution walls, now it's too often our risk management practices", according to John O'Brien. Michael Fischer and Ewan Ferlie (2013) find that contradictions between formal risk controls and the role of subjective factors in human services (such as the role of emotions and ideology) can undermine service values, so producing tensions and even intractable and 'heated' conflict.

===Risk society===

Anthony Giddens and Ulrich Beck argued that whilst humans have always been subjected to a level of risk – such as natural disasters – these have usually been perceived as produced by non-human forces. Modern societies, however, are exposed to risks such as pollution, that are the result of the modernization process itself. Giddens defines these two types of risks as external risks and manufactured risks. The term Risk society was coined in the 1980s and its popularity during the 1990s was both as a consequence of its links to trends in thinking about wider modernity, and also to its links to popular discourse, in particular the growing environmental concerns during the period.

== See also ==

- Ambiguity aversion
- Benefit shortfall
- Civil defence
- Countermeasure
- Early case assessment
- Event chain methodology
- Fuel price risk management
- Identity resolution
- Information assurance
- ISO/PAS 28000
- Life-critical system
- Preventive maintenance
- Reliability engineering
- Peltzman effect

==Bibliography==

===Referred literature===
- James Franklin, 2001: The Science of Conjecture: Evidence and Probability Before Pascal, Baltimore: Johns Hopkins University Press.
- John Handmer. "Trust Us and Be Scared: The Changing Nature of Risk"
- Niklas Luhmann, 1996: Modern Society Shocked by its Risks (= University of Hong Kong, Department of Sociology Occasional Papers 17), Hong Kong, available via HKU Scholars HUB

===Books===
- Historian David A. Moss' book When All Else Fails explains the US government's historical role as risk manager of last resort.
- Bernstein P. L. Against the Gods ISBN 0-471-29563-9. Risk explained and its appreciation by man traced from earliest times through all the major figures of their ages in mathematical circles.
- Rescher, Nicholas. "A Philosophical Introduction to the Theory of Risk Evaluation and Measurement"
- Porteous, Bruce T.. "Economic Capital and Financial Risk Management for Financial Services Firms and Conglomerates"
- Tom Kendrick. "Identifying and Managing Project Risk: Essential Tools for Failure-Proofing Your Project"
- Hillson D.. "Practical Project Risk Management: The Atom Methodology"
- Kim Heldman. "Project Manager's Spotlight on Risk Management"
- Dirk Proske. "Catalogue of risks – Natural, Technical, Social and Health Risks"
- Gardner D. Risk: The Science and Politics of Fear, Random House Inc. (2008) ISBN 0-7710-3299-4.
- Novak S.Y. Extreme value methods with applications to finance. London: CRC. (2011) ISBN 978-1-43983-574-6.
- Hopkin P. Fundamentals of Risk Management. 2nd Edition. Kogan-Page (2012) ISBN 978-0-7494-6539-1

===Articles and papers===
- Cevolini, A. ""Tempo e decisione. Perché Aristotele non-ha un concetto di rischio?" PDF"
- Clark, L.. "The contributions of lesion laterality and lesion volume to decision-making impairment following frontal lobe damage"
- Cokely, E. T.. "Measuring risk literacy: The Berlin Numeracy Test"
- Drake, R. A.. "Decision making and risk taking: Neurological manipulation with a proposed consistency mediation"
- Drake, R. A.. "Lateral asymmetry of risky recommendations"
- Gregory, Kent J.. "A Standard Approach to Measurement Uncertainties for Scientists and Engineers in Medicine"
- Hansson, Sven Ove. (2007). "Risk", The Stanford Encyclopedia of Philosophy (Summer 2007 Edition), Edward N. Zalta (ed.), forthcoming .
- Holton, Glyn A. (2004). "Defining Risk", Financial Analysts Journal, 60 (6), 19–25. A paper exploring the foundations of risk. (PDF file).
- Knight, F. H. (1921) Risk, Uncertainty and Profit, Chicago: Houghton Mifflin Company. (Cited at: , § I.I.26.).
- Kruger, Daniel J., Wang, X.T., & Wilke, Andreas (2007) "Towards the development of an evolutionarily valid domain-specific risk-taking scale" Evolutionary Psychology (PDF file).
- Metzner-Szigeth, Andreas. "Contradictory approaches? On realism and constructivism in the social sciences research on risk, technology and the environment"
- Miller, L. "Cognitive risk taking after frontal or temporal lobectomy I. The synthesis of fragmented visual information"
- Miller, L.. "Cognitive risk taking after frontal or temporal lobectomy II. The synthesis of phonemic and semantic information"
- Neill, M. Allen, J. Woodhead, N. Reid, S. Irwin, L. Sanderson, H. 2008 "A Positive Approach to Risk Requires Person Centred Thinking" London, CSIP Personalisation Network, Department of Health. Available from: https://web.archive.org/web/20090218231745/http://networks.csip.org.uk/Personalisation/Topics/Browse/Risk/ [Accessed 21 July 2008].
- Wildavsky, Aaron. "Risk and Safety"
