Most Risk Plans Are Made of Reminders

Open your organisation's risk register and read down the mitigation column. Not the risks — the fixes. You will mostly find four things: a policy, a training module, an approval step, and a warning of some kind. Occasionally something was actually built. Usually not.

Every one of those four has the same mechanism. Each depends on a human being remembering something, correctly, at the moment it matters, on their worst day of the quarter. That is not a criticism of the people. It is a description of what you bought.

Somebody already ranked these

Occupational safety worked this out decades ago and wrote it down as the hierarchy of controls. It ranks the kinds of intervention available to you, strongest first, and the instruction is to only move down a rung when the one above is genuinely impossible.

Eliminate — remove the hazard. Don't hold the data, don't build the feature, don't run the route. Substitute — swap the dangerous thing for a safer thing that does the same job. Engineer it out — change the system so the mistake is impossible rather than forbidden. Administrate — policies, procedures, training, checklists, approvals. Protect at the point of harm — warnings, signage, protective equipment, banners.

Notice where the contents of your risk register sit. Almost everything most organisations count as risk management lives on the bottom two rungs — the ones safety engineers treat as a last resort.

The ranking is not about effect size

This is the part people get wrong, and it is worth being precise about. On a good day, a policy everyone follows works fine. Training genuinely raises the odds someone chooses correctly. These are real controls, not theatre, and some of them are legally required.

The hierarchy is not ranking how much a control helps on a good day. It is ranking how much of the control's strength depends on a person choosing correctly, every time, forever. A physical barrier is right once, at installation, and then it is right every day without anyone thinking about it. A right-of-way rule has to be re-earned on every shift, by every new starter, under whatever pressure that day happens to bring.

Which means the hierarchy is really a prediction about bad quarters. And bad quarters are exactly when you need the control to work.

Nothing gets cancelled. It just stops working.

Here is the failure mode nobody puts in a board pack. A deadline arrives, two experienced people leave, and there is a cost freeze. No one convenes a meeting to remove a control. The policy is still on the intranet. The training still happened. The banner is still on the screen.

And yet the training is no longer recent, the checklist is being skimmed by someone covering two roles, the approval is a tired person clicking yes at five o'clock on a Friday, and the banner became furniture about nine days after it shipped. Your exposure went up substantially and every control is still, on paper, in place. That gap between the plan on paper and the plan in operation is the part that was never really there.

Run the same test on an engineered control and mostly nothing happens. The system does not care that it is a bad quarter.

Why the top rung is unpopular

There is an honest reason organisations reach downwards, and it is not stupidity. The bottom of the ladder asks nobody to give anything up. You can write a policy without a trade-off, without a budget line, and without telling anyone their project is being cut. It is always available.

Eliminating a hazard nearly always means surrendering something — a feature, a data set, a convenient integration, a way of working that somebody likes. That is a real cost and a real conversation, usually with a person who will be unhappy. So the top rung requires a decision the bottom rung lets you avoid.

Which is why the most useful question in a de-risking session is not "how do we manage this?" but "what would we have to stop doing for this risk to not exist?" Sometimes the answer is unacceptable and you go down the ladder honestly, knowing what you chose. Often the answer is a feature three people use, and it turns out you were about to spend a year defending it with reminders.

The current example nearly everyone has: staff pasting customer records into public AI chatbots. The instinctive move is a policy and a training module — both rung four. Blocking it on managed devices is rung three and much stronger, though it leaves your most productive people with a job to do and a wall in front of them, so some will do it on a phone. Giving them an approved tool that does the same work without keeping your data is rung two, and it wins because it removes the reason rather than the route.

One more question, and it is the one that gets skipped

Every control is a claim: this stops the bad thing. Most organisations never test the claim, and the ones that do usually run a test the control could not have failed. A fire drill announced a week in advance tests the calendar, not the building. A backup restore the team warmed up for on Wednesday tests a prepared team. Ninety-eight per cent policy attestation measures signature collection.

The rule is short: a test that could not have failed tells you nothing. Before you run the check, write down what result would prove the control is broken. If you cannot name one, you are not testing — you are rehearsing.

See it for yourself

We built a free interactive resource — The De-risking Ladder — that makes this concrete. You take one of three situations, fund controls from a fixed effort budget, and then turn up the pressure: a deadline, some turnover, a cost freeze. Nothing gets removed. You watch which of your controls are still doing anything afterwards, and it tells you what share of your protection is resting on somebody remembering.

The result that lands hardest is this one. Four bottom-rung controls, five points of budget, takes exposure from 100 to 35 — and back up to 62 the moment the quarter gets hard. One top-rung control, the same five points, takes it to 15 and leaves it there.

Open The De-risking Ladder →

Three neighbours worth reading next, because this piece deliberately does not re-teach them: Small Batches on shrinking what a failure can reach, Feature Flags on making a release reversible in seconds, and The Swiss Cheese Model on why stacking more layers still leaks. And if the risk in front of you could end the organisation rather than bruise it, start with The Expected-Value Tree — no ladder saves a bet you cannot survive losing.