Risk Management
Risk management is the discipline of naming what could go wrong before it does, rating each threat by likelihood and impact, and deciding in advance whether to avoid it, reduce it, transfer it, or accept it.
Impact climbs up one side, likelihood runs along the bottom, and each risk lands as a dot.
Reach for this when…
- A disruption hit you and you realise you'd never actually rated the odds of it happening.
- You're weighing a big decision and need a shared view of what could derail it.
- A board or investor is asking what your top risks are and you're improvising the answer.
How to run it
- List the risks across categories: operational, financial, market, regulatory, reputational.
- Rate each on likelihood and potential impact.
- Plot them to see which cluster demands attention now.
- Choose a response for each: avoid, mitigate, transfer, or accept.
- Review the list on a fixed schedule, not just after something goes wrong.
A worked example
Situation. Eleni Papadopoulou ran Makedonia Ore Logistics, a mining haulage firm in Thessaloniki, Greece, and had never done more than keep an informal spreadsheet of things that worried her.
Applied. After a border strike stranded a week of shipments, she ran the team through a proper likelihood-and-impact rating of route disruption, currency swings and driver shortage, and put real weight - a pre-negotiated alternate route contract - behind the cluster that scored high on both axes.
Result. When the next strike hit six months later, the alternate route contract was already in place. They lost two days instead of the three weeks the first strike had cost.
The catch
A risk matrix is only as honest as the people scoring it, and teams routinely underrate risks they'd have to admit they created. It also flatters low-likelihood, high-impact risks with a false sense of control - a rating on a chart is not the same as a plan you've actually tested.
A risk sitting in the top-right box with no owner attached is not being managed, it's being observed.