Analytics and Forecasting, Branding and Reputation, Competitiveness and Innovation, Knowledge Strategy, Metrics and Measurement, Organization and Management, Security and Privacy
I began my career long ago in the insurance business, where risk is (literally) the coin of the realm. Companies buy and trade risk — it’s the currency of our volatile, uncertain, complex, ambiguous (VUCA) world.
In conversation, we often associate risk with something dangerous, to be avoided. And, in a technical sense, risk has a downside, known as threat. But it also has an upside, known as opportunity.
These two sides of the risk coin can offset each other. Opportunity may carry a possibility of threat — if I take that new job, what happens if it turns out I don’t like is well as my current one?
Conversely, threat often carries within it seeds of opportunity. When our downtown New York City apartment was flooded in 2012, we used it as an opportunity to build it back even better.
Risk evaluates the balance and trade-offs between these positive and negative aspects of risk. We can then move forward with making decisions and taking actions based on that evaluation.
We’re all exposed to risks constantly — that’s life. These risk exposures can be intentional (as when I buy a lottery ticket) or not (my car breaks down on the highway.) Prescription drugs, as near-miraculous as their effects may be, are required (here is the US) to list their potential side effects alongside their benefits.
As individuals, we usually conduct any risk evaluation quickly — even instinctively, without thinking about it.
Organizations do risk evaluations too — though these are typically more deliberate and transparent. Larger organizations may even have staff assigned full-time to this enterprise risk management function. At any given time, a given organization can face thousands of risks in different aspects of its operations,
Organizations must continually commit resources — time, effort, attention, and money — anticipating a future that is (by definition) unknown and unknowable. Organizations set budgets, for example, based on a best estimate of what financial results the coming year will bring — well aware that things could change by that time. Businesses typically take months developing and introducing a product, not knowing exactly how it will be received.
All of these investments in an uncertain future involve risk — that’s the definition of risk. So ‘managing risks’ does not mean avoiding them — which is not even possible. Managing risk successfully requires being aware of what the relevant opportunities and threats are, and what their potential impacts and likelihoods are.
Risk is a ‘key success factor’ — I’d argue, the most value-impactful one. Organizations that manage risk well are better performers overall — it’s one of those existential skillsets (like continual learning, to which it’s closely related).
You’ve heard the term ‘calculated risk’ — but that’s redundant, since measurement and evaluation are embedded within our definition of risk. All risk is calculated, whether or not such calculation is formalized.
A related idea we hear about a lot these days is uncertainty. (It’s the single word appearing most often in a recent survey of CEOs conducted by The Conference Board.)
Uncertainty is the stage before risk — where we ‘just don’t know.’ To move from uncertainty to risk, we measure it, as shown in Figure 1.
But where do we start? How do we even know what to measure? Using a technique called risk mapping, we first describe the sources of uncertainty in our business environment. We can usually identify them as being opportunities or threats. But some things could be either one, or have elements of both, so we leave those as unknowns.
Opportunities can often be interpreted as benefits — so we associate those terms one one side of the spectrum. Likewise with threats and costs, on the other. The result is a risk profile, which generically looks like Figure 2.
Note also that these risk do not occur in a vacuum — they are contextual and depend on the specific business case to which they’re being applied.
How does this work in practice? One large and significant risk area that leaders in most organizations are currently facing is AI, particularly generative AI. (And this too is shown in surveys of people at other levels.)
We have developed a generic risk map for genAI. It has two sides, one targeted at buyers of these services, the other at suppliers. These are ‘generic’ in the sense that they apply across a range of organizations, and must be tailored for any given organization in order to become fully operational.
The buyer (demand side) map describes 12 generic risk clusters, as shown in Figure 3. These are assigned as threat, opportunities, or unknowns based on the likelihood of where they fall along that dimension.
Further evaluation could result in their being assigned to a different cluster.
Each cluster is assigned a number only as a label — not to indicate its relative importance.
Here’s an example for each cluster. First, the things that are obviously benefits:
Now some things that could fall either way — unknowns:
Next, some things that usually fall on the cost side of the equation:
Vendor assurances, however persuasive they may appear, are not sufficient. You need assessments that are evidence-based and independent of bias.
An additional nine risk clusters are borne primary by the producers, the sellers of AI. However, in practice they may in effect shift to the buyers of AI.
The provider (supply side) map, shown in Figure 4, is based on the input-throughput-output typology developed by Stanford University’s Human-Centered AI (HAI) lab.
These include upstream factors (model inputs), for example:
From there, the model itself has throughput risks:
And there are downstream risks in how the model is applied:
Note that these last five bullets — and much of the public awareness of these risks — comes from the producers themselves, in product cards and published papers. I also lean heavily on independent industry and academic studies. More recently, the court filings supporting the many lawsuits against, and even criminal probes of, these models have revealed new insights.
Behind each of these 21 risk clusters is set of specific risks for each organization — and for each business case therein. And behind each specific risk is a PI(t) evaluation — Probability and likely Impact of an adverse event within time t. So, yes, it’s complicated — at any given point in time.
And it doesn’t end there. To complicate things even further, the risk ecosystem is in constant motion. New AI risks and exposures arrive fresh nearly every week — and this seems to be a permanent state of affairs, with a likelihood of its accelerating even faster.
As our risk is dynamic, so must our management of that risk be dynamic — beyond static criteria and performative check-boxes. Flexible, adaptive, resilient. As fast as risk evolves, risk measurement and management must adapt and anticipate even faster.
My message is not necessarily to avoid using AI. Nor would I advise you to use a prescription drug before reading the warning label. Rather, it’s to remind us that AI’s promises are offset by its costs and uncertainties — and to ‘look before we leap.’ As with any investment or business decision, we should evaluate these factors before committing significant resources — there’s no ‘AI FDA’ to do it for us. We should ask the usual tough questions (1) What specific benefits does it potentially provide? (2) Are there other, more direct, ways to achieve these same benefits? (3) What are its true total costs — both current and future?
Photo: Hudson Sunset (2012), © TW Powell
Comments RSS Feed