Skip to content

Explain a Business Risk Through the Decision It Could Change

Business

Explain a Business Risk Through the Decision It Could Change

A risk slide usually fails the same way. It names a category — supply chain, regulatory, key person, platform — and stops. The audience learns that something could go wrong somewhere, and nothing about which of the choices in front of them changes if it does.

More detail will not fix that. A different starting point will. Begin with the commitment the exposure could affect — this launch date, this service promise, this order you are about to accept — and work backwards to the condition that commitment depends on. Trace the consequence only as far as the decision it changes. Describe whatever response actually exists, at the state it actually exists in. Then name the question that still needs an owner.

One risk explained this way is worth more than a page of labels. You are not being asked to certify that a mitigation works, or to produce a risk register. You are being asked to make a dependency understandable to people who have to decide something.

Begin with the commitment the exposure could change

Pick something real: a date, a volume, a service level, an order. Not an aspiration. A commitment is what other people have already started arranging their own work around.

Then ask what has to hold for that commitment to stay credible. Ordinary language is enough. A supplier has to keep delivering a particular component. A licence has to stay available under the current terms. One engineer has to stay long enough to hand over the billing system. Whatever the answer is, that is your condition, and it is the actual subject of the slide.

The label is what you say instead when you have not done this work yet. "Supply-chain risk" tells the room nothing about which promise depends on which supplier, or what anyone would do differently on Monday if that supplier went quiet. It is a category, and categories do not have consequences.

Take a fictional case, so the mechanics stay visible. Ridgeway Equipment makes commercial dishwashers, and it plans to announce a launch date for a new under-counter model. Every unit in that model uses one machined manifold made to Ridgeway's drawing by a single shop, and the tooling for it sits at that shop. Those are the case's facts, and they are not going to change as we go.

So the commitment is the launch date. The condition is that the manifold shop keeps producing on the current schedule. Everything else on the slide has to earn its place against those two sentences.

If you genuinely cannot name a commitment the exposure would touch, that is worth knowing before you build anything. Either the risk is not material to this decision, or you do not yet understand it well enough to present it. Both are findings.

Separate the condition from the scenario

The condition and the interruption are not the same kind of statement, and mixing them is where risk slides start to bluff.

The condition is a requirement that has to keep holding: the manifold shop keeps producing on the current schedule. The interruption is a hypothesis about that requirement failing: the shop's output stops. The consequence — the manifold stops arriving, sub-assembly stalls, the launch date slips — is a chain you are reasoning through, not a thing anyone has watched happen.

What you can observe is the current state underneath both: one shop holds the tooling. That is what makes the requirement fragile, and it is not the condition itself. A reader who mistakes the existing arrangement for the condition ends up describing the situation as it is today as the thing that must hold — the precise confusion this section exists to prevent.

Keep those three registers visibly separate on the slide, and keep the chain short enough to follow:

  • Commitment: announce the launch date in March.
  • Condition: the manifold shop continues producing on the current schedule.
  • If the condition fails: manifolds stop arriving, sub-assembly stops, the date moves.
  • Decision affected: whether to announce in March, or hold the announcement until qualification work is finished.

Three steps is a chain. Ten steps is a forecast, and you probably cannot defend a forecast built this way. The moment you find yourself needing a fourth and fifth link to reach the decision, stop and ask whether the exposure is actually material or whether you are enjoying the story.

This is also where unsupported precision does the most damage. A percentage band, a currency figure, an expected-days-lost estimate — none of those has a defensible basis here, and adding one makes the slide look analytical while making it less honest. Ridgeway does not know the probability of the shop's output stopping. Neither does the person presenting. Say what you know: this is the condition, this is the chain, this is the decision it reaches. If someone in the room asks "how likely is that," the honest answer is that nobody has assessed it — and that absence is not what today's decision turns on. Whether a second source can be qualified is.

Imagined numbers also have a way of becoming remembered numbers. The band you offered as a rough shape gets quoted back in a steering meeting six weeks later, minus its caveats. If you have no basis, the absence of a figure is a form of accuracy.

Describe the response at its actual state

Now separate what exists from what has been discussed. This distinction is small on a slide and enormous in a conversation.

At Ridgeway, a second shop has been discussed. Nothing has been qualified. No sample has been made against the drawing, no tolerance has been held, no qualification run has been scheduled. So the response's actual state is unqualified, and the slide should say that rather than implying a safety net.

The temptation is to write "backup supplier in progress," which reads as a mitigation and functions as a sedative. A proposed response is not a demonstrated one. The audience cannot tell from that phrase whether someone has a plan and a date, or whether the topic came up over coffee once. Write the state instead: a candidate has been discussed; nothing has been tested; the qualification question is open.

It also helps to name the dependency the response itself introduces. Qualifying another shop is work — engineering attention that is currently going somewhere else, tooling that may need to be duplicated, volume that may end up split between two sources. You do not need numbers for any of that. You need to acknowledge that the response is not free and not instant, because a mitigation described as instant is a mitigation nobody has thought about.

Here a bounded comparison helps, and it should be labelled as one. GOV.UK's guidance on managing technical lock-in in the cloud treats technical dependency as a trade-off: a useful capability comes with a real cost of changing providers, and the guidance is careful not to treat an available export or an open standard as an effortless operational move. As a way of thinking about slide language, that is the useful part — the existence of an option is not the ability to exercise it. The page is UK public-sector technology guidance, checked in September 2026 as a wording reference. It is not an assessment of Ridgeway's shop, it is not a US obligation, and it does not establish that any second source would qualify.

That is what using a source as an analogy means. You borrow the shape of the reasoning and you leave the facts where they are.

End at the decision and its responsible owner

The slide should close on two things: what the room can decide today, and what needs someone's assessment first.

Today's decision at Ridgeway is narrow, and narrow is fine. The room can decide whether to announce the March date now or hold the announcement until the qualification question is answered. It can decide to fund a qualification effort. It cannot decide that the exposure is handled, because the fact that would settle that — whether another shop can hold the tolerance, and how long that would take — does not exist yet.

So the unresolved fact becomes the next investigation, with a name attached. Something like: Operations lead to assess whether a second source can be qualified, and what that would take, before the March announcement is made. That sentence does three jobs at once. It states the gap, it keeps the gap in the main explanation rather than tucking it under a reassuring label, and it puts a person behind the answer.

Two cleanups before you finish.

The first is the label you can delete. Any generic risk heading that contributes no consequence and no action should go — not because labels are always wrong, but because on this slide it is occupying a line and implying work that has not been done. If someone needs the formal category for a register somewhere else, it can live there.

The second is the difference between unresolved and managed. These get conflated constantly, usually by accident. A mitigation under discussion is unresolved. A qualification run that has not been scheduled is unresolved. Saying so is not pessimism; it is the only version of the slide that a reader can act on. A risk marked managed that later turns out to be open costs more credibility than a risk marked open would ever have cost.

This is also why the explanation does not need to become a risk register. You are producing one bounded account: this commitment, this condition, this chain, this state of response, this owner, this question. Somebody else can build the register.

The whole thing takes a paragraph. It reads like this: We plan to announce the launch date in March. That depends on one manifold shop producing on schedule, and no second source is qualified today. If that output stops, sub-assembly stops and the date moves. A second shop has been discussed but nothing has been tested. Announce now and accept the exposure, or hold until operations reports on whether a second source can be qualified — that report is the next decision the launch date depends on.

Frequently asked questions

What should replace a generic risk category on a slide?

Begin with the commitment the exposure could affect: a launch date, service promise, volume, or order. Then work backwards to the condition that commitment depends on. A label such as supply-chain risk tells the room nothing about which promise depends on which supplier or what anyone would do differently.

What is the difference between the condition and the interruption?

The condition is a requirement that has to keep holding, such as the manifold shop continuing to produce on schedule. The interruption is a hypothesis that the requirement fails, such as output stopping. The consequence chain is reasoned, not observed; the observable current state, such as one shop holding the tooling, is not the condition itself.

Should I put a probability or money estimate on the slide?

Only if you have a defensible basis. A percentage band, currency figure, or expected-days-lost estimate can make the slide look analytical while making it less honest. Say what you know: this is the condition, this is the chain, this is the decision it reaches. If someone asks how likely it is, the honest answer may be that nobody has assessed it.

How do I describe a mitigation that is not ready?

Describe its actual state: proposed versus demonstrated, qualified versus unqualified. A phrase such as backup supplier in progress reads as a mitigation and functions as a sedative. Name the dependency the response itself introduces, because a mitigation described as instant is one nobody has thought about.

How should the risk slide end?

Close on what the room can decide today and what still needs an owner and assessment first. Put the unresolved fact in the main explanation rather than under a reassuring label, and attach a name to the next investigation. Keep unresolved and managed distinct; a mitigation under discussion is unresolved.

More in Business Browse all articles