Overview
Risk management is the identification, evaluation, and prioritization of risks, followed by the minimization, monitoring, and control of the impact or probability of those risks occurring. Risks can come from various sources (i.e., threats), including uncertainty in international markets, political instability, dangers of project failures (at any phase in design, development, production, or sustaining of life-cycles), legal liabilities, credit risk, accidents, natural causes and disasters, deliberate attack from an adversary, or events of uncertain or unpredictable root-cause.
Retail traders also apply risk management by using fixed percentage position sizing and risk-to-reward frameworks to avoid large drawdowns and support consistent decision-making under pressure.
Two types of events are analyzed in risk management: risks and opportunities. Negative events can be classified as risks while positive events are classified as opportunities. Risk management standards have been developed by various institutions, including the Project Management Institute, the National Institute of Standards and Technology, actuarial societies, and International Organization for Standardization.
Methods, definitions and goals vary widely according to whether the risk management method is in the context of project management, security, engineering, industrial processes, financial portfolios, actuarial assessments, or public health and safety. Certain risk management standards have been criticized for having no measurable improvement on risk, whereas the confidence in estimates and decisions seems to increase.
Strategies to manage threats (uncertainties with negative consequences) typically include avoiding the threat, reducing the negative effect or probability of the threat, transferring all or part of the threat to another party, and even retaining some or all of the potential or actual consequences of a particular threat. The opposite of these strategies can be used to respond to opportunities (uncertain future states with benefits).
7 sources for this section
- 1Risk management — Wikipedia, revision 1370651792
- 2Cybellium. Risk Management Exam Review: A Comprehensive Guide to Excelling in Risk Management Exams. Cybellium. p. 3. ISBN 978-1-83679-348-9.
- 3Ata, Nabil Abu el; Schmandt, Rudolf (2016-05-17). The Tyranny of Uncertainty: A New Framework to Predict, Remediate and Monitor Risk. Springer. p. 7. ISBN 978-3-662-49104-1.
- 4ISO 31073:2022 — Risk management — Vocabulary. ISO. Feb 2022. Retrieved 17 July 2024.
- 5ISO 31000:2018 — Risk management — Guidelines. ISO. Feb 2018. Retrieved 17 July 2024.
- 6ISO 31000:2018 – Risk management – A Practical Guide (1 ed.). ISO, UNIDO. 2021. ISBN 978-92-67-11233-6. Retrieved 17 December 2021.
- 7Bhandari, Ashok (2021-10-27). 10X Execution: For Extra-ordinary Business Growth & Success. The PrintWorks. p. 310. ISBN 978-81-949109-2-3.
Introduction
Risk is defined as the possibility that an event will occur that adversely affects the achievement of an objective. Uncertainty, therefore, is a key aspect of risk. Risk management appears in scientific and management literature since the 1920s. It became a formal science in the 1950s, when articles and books with "risk management" in the title also appear in library searches. Most of research was initially related to finance and insurance. One popular standard clarifying vocabulary used in risk management is ISO Guide 31073:2022, "Risk management — Vocabulary".
Ideally in risk management, a prioritization process is followed. Whereby the risks with the greatest loss (or impact) and the greatest probability of occurring are handled first. Risks with lower probability of occurrence and lower loss are handled in descending order. In practice the process of assessing overall risk can be tricky, and organisation has to balance resources used to mitigate between risks with a higher probability but lower loss, versus a risk with higher loss but lower probability. Opportunity cost represents a unique challenge for risk managers.
It can be difficult to determine when to put resources toward risk management and when to use those resources elsewhere. Again, ideal risk management optimises resource usage (spending, manpower etc), and also minimizes the negative effects of risks.
9 sources for this section
- 1Risk management — Wikipedia, revision 1370651792
- 8Office of Financial Management, State of Washington (July 1, 2017). ""Risk Assessment"" (PDF). Office of Financial Management. Retrieved June 27, 2025.
- 9Hardy, Karen (2014-11-10). Enterprise Risk Management: A Guide for Government Professionals. John Wiley & Sons. p. 121. ISBN 978-1-118-91102-0.
- 10Yang, Kai (2024-01-04). Quality in the Era of Industry 4.0: Integrating Tradition and Innovation in the Age of Data and AI. John Wiley & Sons. p. 242. ISBN 978-1-119-93244-4.
Risks vs. opportunities
Opportunities first appear in academic research or management books in the 1990s. The first PMBoK Project Management Body of Knowledge draft of 1987 doesn't mention opportunities at all.
Modern project management school recognize the importance of opportunities. Opportunities have been included in project management literature since the 1990s, e.g. in PMBoK, and became a significant part of project risk management in the years 2000s, when articles titled "opportunity management" also begin to appear in library searches. Opportunity management thus became an important part of risk management.
Modern risk management theory deals with all types of external events, both positive and negative. Positive risks are called opportunities. Similar to risks, opportunities have specific mitigation strategies: exploit, share, enhance, or ignore.
2 sources for this section
Mild versus wild risk
Benoit Mandelbrot distinguished between "mild" and "wild" risk and argued that risk assessment and management must be fundamentally different for the two types of risk. Mild risk follows normal or near-normal probability distributions, is subject to regression to the mean and the law of large numbers, and is therefore relatively predictable.
Wild risk follows fat-tailed distributions, e.g., Pareto or power-law distributions, is subject to regression to the tail (infinite mean or variance, rendering the law of large numbers invalid or ineffective), and is therefore difficult or impossible to predict. A common error in risk assessment and management is to underestimate the wildness of risk, assuming risk to be mild when in fact it is wild, which must be avoided if risk assessment and management are to be valid and reliable, according to Mandelbrot.
1 source for this section
Identification
After establishing the context, the next step in the process of managing risk is to identify potential risks. Risks concern events that, when triggered, cause problems or benefits. Therefore, risk identification can begin either with the sources of problems and those of competitors (benefits) or with the consequences of the problems.
Some examples of risk sources are: stakeholders of a project, employees of a company or the weather over an airport.
When either source or problem is known, the events that a source may trigger or the events that can lead to a problem can be investigated. For example: stakeholders withdrawing during a project may endanger funding of the project; confidential information may be stolen by employees even within a closed network; lightning striking an aircraft during takeoff may make all people on board immediate casualties.
1 source for this section
The source notesEvidence & further reading15 sources
- Risk management — Wikipedia, revision 1370651792 Wikipedia contributors · Reference source · accessed 2026-09-22
- Cybellium. Risk Management Exam Review: A Comprehensive Guide to Excelling in Risk Management Exams. Cybellium. p. 3. ISBN 978-1-83679-348-9. books.google.com · Reference source · link imported 2026-09-22
- Ata, Nabil Abu el; Schmandt, Rudolf (2016-05-17). The Tyranny of Uncertainty: A New Framework to Predict, Remediate and Monitor Risk. Springer. p. 7. ISBN 978-3-662-49104-1. books.google.com · Reference source · link imported 2026-09-22
- ISO 31073:2022 — Risk management — Vocabulary. ISO. Feb 2022. Retrieved 17 July 2024. iso.org · Reference source · link imported 2026-09-22
- ISO 31000:2018 — Risk management — Guidelines. ISO. Feb 2018. Retrieved 17 July 2024. iso.org · Reference source · link imported 2026-09-22
- ISO 31000:2018 – Risk management – A Practical Guide (1 ed.). ISO, UNIDO. 2021. ISBN 978-92-67-11233-6. Retrieved 17 December 2021. iso.org · Reference source · link imported 2026-09-22
- Bhandari, Ashok (2021-10-27). 10X Execution: For Extra-ordinary Business Growth & Success. The PrintWorks. p. 310. ISBN 978-81-949109-2-3. books.google.com · Reference source · link imported 2026-09-22
- Office of Financial Management, State of Washington (July 1, 2017). ""Risk Assessment"" (PDF). Office of Financial Management. Retrieved June 27, 2025.