Library/The Failure of Risk Management
The Failure of Risk Management book cover - Leapahead summary
Listen to Key Point 1
0:000:00

The Failure of Risk Management

Douglas W. Hubbard

Duration45 min
Key Points8 Key Points
Rating4.3 Rate

What's inside?

Explore the flaws in current risk management strategies and learn practical solutions to improve and strengthen your approach to handling risk.

You'll learn

Learn1. Common goof-ups in handling risks
Learn2. Spotting and sizing up risks right
Learn3. Why making choices matters in risk handling
Learn4. Using number-crunching in managing risks
Learn5. Steps to ace risk handling
Learn6. Boosting your team's risk handling game.

Key points

01Why Your Safety Net is Actually a Trap

Stepping into the modern corporate boardroom, you will often find executives staring confidently at colorful charts that supposedly predict their greatest threats. Yet, beneath those vibrant reds, yellows, and greens lies a dangerous foundation of mathematical nonsense. We live in an era where businesses spend millions of dollars and thousands of hours trying to predict and mitigate risks, whether they are supply chain disruptions, cybersecurity breaches, or massive project failures. The individuals running these programs are intelligent, dedicated, and highly educated. However, the tools they have been given to do their jobs are entirely inadequate. Douglas Hubbard makes a bold and uncomfortable claim: the vast majority of what we call risk management is essentially a modern form of alchemy. It looks like a rigorous process, it feels like a rigorous process, but it produces absolutely no scientifically valid results. To understand how we arrived at this point, we have to look at the history of how professions develop. Hubbard draws a fascinating parallel between the current state of risk management and the practice of medicine in the medieval era. Centuries ago, if you fell ill, a highly respected doctor might prescribe a treatment like bloodletting. The doctor believed in the treatment, the patient believed in the treatment, and there was a rich, complex methodology behind exactly how and where to draw the blood. It was the industry standard. The only problem was that it did not work, and in many cases, it actively killed the patient faster. But because there was no scientific method, no control groups, and no rigorous data tracking, the medical profession continued this harmful practice for generations. They were victims of the placebo effect. Just doing something—anything—made everyone feel a little bit better, even if the underlying reality was rapidly deteriorating. Today, corporate risk management is suffering from the exact same placebo effect. When a company decides to implement a risk management program, they usually adopt a standardized framework. They gather their department heads into a conference room, hand out some spreadsheets, and ask everyone to brainstorm bad things that could happen. They then write these bad things down on a list, which they grandly call a "risk register." Next, they assign vague, subjective scores to these risks, perhaps rating them as "High," "Medium," or "Low." Finally, they plot these scores onto a brightly colored grid known as a risk matrix or a heat map. When the meeting is over, everyone closes their laptops and walks out feeling incredibly accomplished. They have confronted their fears, organized them into a neat visual format, and presented them to the board of directors. The organization feels secure. The safety net appears to be firmly in place. However, this feeling of security is entirely unwarranted. What has actually been accomplished in that conference room? Did anyone calculate the precise mathematical probability of a specific event occurring? Did anyone determine the exact financial ruin the company might face if three "Medium" risks happened simultaneously? No. They simply engaged in a group exercise of shared intuition, dressed it up in a corporate framework, and called it a day. The danger here is profound. When an organization believes it has managed its risks simply because it has documented them on a colorful chart, it stops looking for real danger. The heat map acts as a blindfold. It gives leadership the confidence to make aggressive business decisions under the false assumption that their downside is protected. Consider the catastrophic failures we see in the business world almost every year. When massive financial institutions collapsed during the 2008 economic crisis, it was not because they lacked risk management departments. In fact, they had massive teams of risk officers, endless compliance checklists, and beautiful executive dashboards. Their failure was not a lack of effort; it was a failure of the methods themselves. They were relying on models and assumptions that fundamentally misunderstood the nature of complex, cascading uncertainties. The same applies to massive IT projects that go hundreds of millions of dollars over budget, or manufacturing companies that are completely paralyzed by a single supplier failure. In almost every case, a post-mortem reveals that the exact risk that destroyed the project was either completely ignored or casually dismissed as a "Low" probability event on a subjective matrix. We must recognize that having a standardized framework is not the same thing as having an effective framework. Just because everyone else in your industry is using qualitative risk matrices does not mean they are scientifically valid. In fact, Hubbard points out that many of the most popular risk management standards heavily promoted by major accounting firms and international standards organizations have absolutely no empirical evidence proving that they actually reduce risk. They have never been subjected to rigorous, scientific testing to see if companies that use them perform better during a crisis than companies that do not. They are adopted simply because they are easy to understand and they create a paper trail that defends management from accusations of negligence. If we want to actually protect our organizations, we have to wake up from this collective illusion. We must demand proof that our risk management methodologies actually work. We need to stop treating uncertainty as a vague, unquantifiable feeling and start treating it as a measurable, mathematical reality. The first step toward genuine safety is admitting that our current safety nets are full of holes. Only when we discard the comfortable, colorful placebos can we begin the hard but incredibly rewarding work of building a risk management system that is anchored in reality, driven by data, and capable of saving our businesses when the unthinkable finally happens.

02The Hidden Mathematical Sabotage in Your Spreadsheets

We often trust numbers simply because they look like math, but slapping a numerical value onto a vague feeling does not magically create a scientific measurement. This is the exact trap that thousands of organizations fall into when they use risk matrices and subjective scoring systems. Let us take a deep dive into the mechanics of these ubiquitous tools and uncover the astonishing logical flaws that are silently sabotaging your company's decision-making process. If you have ever participated in a corporate risk assessment, you have almost certainly encountered the standard 5x5 risk matrix. The process usually goes like this: you are asked to evaluate a potential threat, such as a cybersecurity breach. You are told to rate the likelihood of this event on a scale from 1 to 5, where 1 means "very rare" and 5 means "almost certain." Then, you are asked to rate the financial impact of the event on another scale from 1 to 5, where 1 means "negligible" and 5 means "catastrophic." Finally, you multiply these two numbers together. If you chose a likelihood of 4 and an impact of 3, your total risk score is 12. You write the number 12 in the appropriate box, color it orange, and move on to the next threat. This feels like a rigorous, quantitative exercise. After all, you are using numbers, multiplication, and formulas. But mathematically speaking, you have just committed a profound error. To understand why this is so dangerous, we need to talk about the difference between ordinal numbers and cardinal numbers. Cardinal numbers represent absolute quantities. If you have four apples, you literally have twice as many apples as someone who has two apples. You can add them, subtract them, and multiply them, and the math will always perfectly represent reality. Ordinal numbers, on the other hand, only represent rank or order. Think about a restaurant rating system. A four-star restaurant is better than a two-star restaurant, but is the food exactly twice as delicious? Is the service exactly twice as fast? Of course not. The stars only tell you the order of preference, not the absolute magnitude of difference between them. When you use a 1 to 5 scale in a risk matrix, you are using ordinal numbers. A "Level 4" impact might represent a loss of anywhere from one million to ten million dollars, while a "Level 5" impact might represent a loss of ten million to one billion dollars. The distance between a 1 and a 2 is entirely different from the distance between a 4 and a 5. Therefore, treating these numbers like regular cardinal numbers and multiplying them together produces absolute garbage. It is the mathematical equivalent of multiplying a hotel's star rating by the zip code it is located in. The resulting number might look official, but it has no connection to physical reality. By multiplying ordinal scales, organizations routinely generate risk scores that completely misprioritize their actual threats. This mathematical sabotage is compounded by a phenomenon Hubbard calls "range compression." Because risk matrices force a massive spectrum of possibilities into just five little boxes, they completely obscure the most critical differences between risks. Let us say Risk A has a 10% chance of costing your company $5 million. Risk B has a 90% chance of costing your company $50,000. In a typical matrix, the impact of Risk A might be rated a 4, and its likelihood a 2, resulting in a score of 8. The impact of Risk B might be rated a 2, and its likelihood a 4, also resulting in a score of 8. The matrix tells management that these two risks are perfectly equal and require the same amount of attention. But if we run the actual math, the expected loss of Risk A is $500,000, while the expected loss of Risk B is only $45,000. The matrix has hidden a threat that is ten times more dangerous simply because of where the arbitrary boundaries of the boxes were drawn. But the problems do not stop with bad math; there is also the severe issue of the "illusion of communication." When a team sits down to assign these subjective scores, they are using words like "likely," "rare," "significant," and "severe." These words feel universally understood, but psychological studies have repeatedly shown that they are incredibly vague. If you ask ten different managers what a "likely" risk means in terms of a true percentage, you will get ten wildly different answers. One manager might think "likely" means a 25% chance of happening. Another manager, perhaps someone who is more risk-averse, might think "likely" means anything over a 70% chance. When these two managers sit in a meeting and debate whether a supply chain disruption is "likely," they might eventually nod their heads and agree to assign it a Level 4 score. They leave the room feeling a deep sense of consensus and alignment. They believe they have communicated clearly. But in reality, they have agreed on absolutely nothing. One person is planning for a 25% probability, and the other is planning for a 70% probability. When the crisis actually hits, their responses will be completely uncoordinated because their foundational assumptions were never mathematically defined. The subjective labels simply masked their underlying disagreement. Furthermore, these subjective matrices are highly susceptible to cognitive manipulation and corporate politics. If a project manager desperately wants their project approved, they have a massive incentive to subtly downgrade the risk scores. Because the scale is entirely subjective, no one can definitively prove them wrong. "I just don't feel like a server crash is a Level 5 impact," they might argue. "Let's call it a Level 3." Without hard data or calibrated probabilities, the loudest voice or the highest-ranking person in the room usually dictates the final score. Risk management devolves from an objective search for truth into a subjective negotiation of opinions. We must recognize that spreadsheets filled with subjective, ordinal scores are not just harmless corporate busywork. They are actively dangerous. They scramble our priorities, obscure massive financial exposures, and create a false sense of security while completely failing to facilitate clear communication. If we want to genuinely protect our organizations, we must strip away the illusion of subjective math. We need to stop asking people how they "feel" about a risk on a scale of 1 to 5, and start demanding rigorous, quantifiable ranges. It is time to throw away the colorful heat maps and embrace the actual mathematics of uncertainty.

The Failure of Risk Management book cover - Leapahead summary

Continue reading with LeapAhead app

Full summary is waiting for you in the app

03Why Trusting Your Gut Will Destroy Your Business

04How to Train Your Mind to Predict the Future

05Stop Guessing and Start Simulating Your Reality

06The Secret to Measuring What Actually Matters

07Conclusion

About Douglas W. Hubbard

Douglas W. Hubbard is an American author and decision scientist, known for his expertise in applied information economics and quantitative risk analysis. He is the inventor of the Hubbard Decision Research method and has written several influential books on business decision-making and risk management.