1.2 Core Risk Terminology and Definitions

Key Takeaways

  • ISO 31000 / ISO Guide 73 formally defines risk as the 'effect of uncertainty on objectives.'
  • Effects can be positive (opportunities/upside risk), negative (threats/downside risk), or both.
  • Risk appetite represents strategic willingness to pursue risk, whereas risk tolerance defines specific operational variance boundaries.
  • Inherent risk is the raw risk before any controls are applied, whereas residual risk is the remaining exposure after treatment controls are functioning.
Last updated: July 2026

1.2 Core Risk Terminology and Definitions

To manage risk effectively, an organization must establish a unified, unambiguous vocabulary. Misunderstandings regarding basic risk terms lead to flawed risk evaluations, misaligned executive risk reporting, and poor strategic decision-making. ISO 31000 relies upon ISO Guide 73:2009 (Risk Management — Vocabulary) to establish the standardized terminology for risk practitioners worldwide.


The ISO 31000 Definition of Risk

On the ISO 31000 Risk Manager exam, candidates must know the exact formal definition of risk:

Risk=Effect of Uncertainty on Objectives\text{Risk} = \text{Effect of Uncertainty on Objectives}

This simple six-word definition represents a profound conceptual shift from legacy risk frameworks. To understand its full depth, each component must be analyzed:

1. Effect

An effect is a deviation from the expected outcome. An effect can be:

  • Positive (Upside Risk / Opportunity): An outcome that exceeds expected targets, such as unexpected market adoption of a new product line.
  • Negative (Downside Risk / Threat): An outcome that falls short of targets, such as supply chain disruption, financial loss, or reputational damage.
  • Both Positive and Negative: Complex events that present initial negative disruptions followed by long-term strategic advantages.

2. Uncertainty

Uncertainty is the state, even partial, of deficiency of information related to, understanding or knowledge of, an event, its consequence, or its likelihood. Uncertainty stems from data gaps, volatile market conditions, cognitive biases, emerging technology, or ambiguous regulatory environments.

3. Objectives

Risk cannot exist in a vacuum. A potential event is only a risk if it has the potential to impact an objective. Objectives give context to risk and can:

  • Have different aspects: Financial, health and safety, environmental, operational, strategic, reputational, or compliance.
  • Apply at different levels: Organization-wide (enterprise), divisional, project-level, product-level, or individual process level.

Upside Risk vs. Downside Risk

Traditional risk management focused almost exclusively on downside risk—minimizing hazard exposures, securing assets, and purchasing insurance. ISO 31000 mandates a symmetrical view of risk:

  • Downside Risk Management (Loss Prevention): Identifying threats that could hinder objective achievement and implementing controls to reduce their likelihood or impact.
  • Upside Risk Management (Opportunity Exploitation): Identifying positive uncertainties and taking deliberate, controlled risks to achieve breakthrough strategic gains, innovation, and market leadership.

Organizations that manage only downside risk become overly risk-averse and risk missing major market opportunities. Conversely, organizations that pursue upside risk without robust controls expose themselves to catastrophic failure. ISO 31000 aligns both dimensions into a single decision-making framework.


Strategic vs. Operational Risk Lexicon: Appetite, Tolerance, and Criteria

Exam candidates must master the precise differences between three closely related concepts:

TermISO / Executive DefinitionCore Exam DistinctionPractical Example
Risk AppetiteThe broad amount and type of risk that an organization is willing to pursue or retain in pursuit of strategic objectives.High-level strategic stance set by the Board of Directors."We have a high appetite for technology innovation, but zero appetite for regulatory non-compliance."
Risk ToleranceAn organization's or stakeholder's readiness to bear the risk after risk treatment in order to achieve objectives.Specific operational boundaries around a performance metric."System downtime must not exceed 0.01% per quarter, representing +/- 15 minutes of variance."
Risk CriteriaTerms of reference against which the significance of a risk is evaluated.Evaluative benchmark used during risk evaluation to rate severity.A 5x5 matrix scoring financial impact (e.g., Catastrophic = >$10M) and Likelihood.

Inherent Risk, Residual Risk, and Target Risk

Risk levels change as management interventions and controls are deployed across the risk lifecycle:

  1. Inherent Risk (Raw Risk): The level of risk exposure that exists in the complete absence of any management actions, controls, or interventions to alter its likelihood or consequence.
  2. Residual Risk (Net Risk): The risk remaining after existing risk treatment controls have been implemented and evaluated. ISO 31000 requires that residual risk be monitored continuously to ensure it falls within acceptable risk criteria.
  3. Target Risk (Planned Risk): The desired level of risk after planned future risk treatments and controls are fully operational.

Exam Trap: Residual risk is rarely zero. Attempting to reduce residual risk to absolute zero is usually cost-prohibitive and operationally infeasible. If residual risk exceeds acceptable risk tolerance, additional risk treatment is required.


Key Components of the Risk Ontology

ISO Guide 73 defines the causal chain of elements that build a complete risk scenario:

  • Risk Source: An element which alone or in combination has the potential to give rise to risk (e.g., volatile exchange rates, aging legacy software, extreme weather patterns).
  • Event: An occurrence or change of a particular set of circumstances (e.g., cloud server outage, currency devaluation, key executive departure).
  • Consequence: The outcome of an event affecting objectives. Consequences can be certain or uncertain, qualitative or quantitative, direct or indirect.
  • Likelihood: The chance of something happening—whether defined, measured, or determined objectively or subjectively, qualitatively or quantitatively.
  • Risk Owner: The individual or entity with the explicit accountability and authority to manage a specific risk.
  • Control: Any measure, policy, device, procedure, or practice that maintains and/or modifies risk.

Real-World Case Example

FinTech Express, a digital banking firm, evaluates its payment processing system. The risk source is reliance on a third-party payment gateway. The event is a vendor server crash during peak shopping hours. The consequence is $2M in uncollected fees and customer attrition. The inherent risk (without controls) is rated as High.

To manage this, the risk owner (VP of Engineering) deploys automated dual-vendor failover systems (controls). The remaining residual risk drops to Low, which falls comfortably within FinTech Express's risk tolerance.

Loading diagram...
ISO 31000 Risk Causal Ontology
Test Your Knowledge

Under ISO 31000 and ISO Guide 73, how is 'risk' officially defined?

A
B
C
D
Test Your Knowledge

What is the fundamental distinction between 'risk appetite' and 'risk tolerance'?

A
B
C
D
Test Your Knowledge

A control programme is only partly deployed. Management records the exposure it expects once the remaining planned treatments are fully operational. Which risk state has been recorded?

A
B
C
D