Mandelbrot's warning: most risk managers mistake wild risk for mild
Some dangers behave politely, clustering around an average so that big samples make them predictable. Others have fat tails, where one extreme event can dwarf everything before it. The mathematician Benoit Mandelbrot called these mild and wild risk, and argued that the commonest mistake is treating the second kind as if it were the first.
Mild risk follows something close to a normal distribution. Extremes get pulled back towards the average and big samples settle down, so insurers and planners can estimate it with reasonable confidence. Wild risk follows Pareto or power-law patterns, where averages and spreads may be effectively infinite and past data offers little guide. Underestimating that wildness, Mandelbrot said, makes an assessment unreliable.
As a field, risk management appears in writing from the 1920s and became a formal discipline in the 1950s, mostly in finance and insurance at first. Its basic moves have stayed simple: avoid a threat, reduce its likelihood or impact, pass it to someone else, as insurance does, or accept it. Ideally the dangers with the biggest losses and highest odds are tackled first, but real organisations must weigh a likely small loss against an unlikely catastrophic one, and every pound spent on protection is a pound not spent elsewhere.
The idea of upside came surprisingly late. The first draft of the Project Management Body of Knowledge in 1987 did not mention opportunities at all. They crept into the literature in the 1990s and became central in the 2000s, with their own responses: exploit, share, enhance or ignore. Even so, practice still leans heavily towards threats, which can breed target fixation.
Standards bodies now publish guidance, including ISO 31000. One of the ISO principles is blunt: effort spent reducing a risk should cost less than doing nothing. Some standards have been criticised for boosting confidence without measurably reducing risk.
Source: Risk management