Clay Tech

"clay-works make things real"

translated from clazytech.com

Applying Risk Assessment To Startups Explains Their Mindset

Some people treat risk assessment and risk management as if they were the same thing, but of course they mean different things. Let me start with the textbook definitions.

Risk assessment, as the word “assess” implies, means recognizing risk itself based on past experience and expert know-how, then quantifying it and putting it to use. Risk management is what you do with that.

In other words, assessment comes first, and management follows.

One thing I skipped: risk generally refers to trouble, accidents, or other damage that a released product might cause. Here I’m stretching the concept toward something more abstract, which I think brings it closer to the point I want to make.

If the evaluation at the assessment stage is sloppy, management won’t function. Assessment is normally measured as frequency of occurrence multiplied by severity, but if you assume “the probability of occurrence is extremely low, so it should be fine,” and the actual frequency turns out considerably higher, controlling the resulting damage becomes extremely difficult. Conversely, even when the assessment itself is sound, an overly optimistic approach to management can cause problems. Say you assume “our existing customer support staff can handle defect rates up to 5%,” but each case takes more effort than expected — you fail to keep up with customer support and end up causing major confusion in the market.

Everything up to this point is just textbook-level knowledge about quality control, but I think it becomes quite illuminating once you apply it to running a startup.

Let’s try applying it negatively, as an experiment.

A startup is an organization where both assessment and management are sloppy. Members lack experience, planning is poor, everything is improvised, and as long as they can respond immediately to whatever comes up, they consider that good enough. The quality of the product they offer customers is low to begin with, and they cover for that with the convenient phrase “a growth opportunity,” ultimately making customers put up with it. So except for the rare lucky ones who succeed, most end up a mess and disappear from the market. And all of that stems from underestimating risk from the very start.

Something like that. I was impressed at how thoroughly I managed to trash the very world I belong to. (laughs)

From the outside, it’s understandable if people say that, and even from the inside, I won’t deny that quite a few startups leave you thinking “well, that’s fair enough.” But I also think you can find a kind of pride, or philosophy, in that very fact.

A startup is a peculiar kind of organization: it views its assessment scale as if displayed on a logarithmic axis, and builds a “growth margin” into its management.

Let me explain in order.

On the logarithmic display: go ask Wikipedia or Google, I’d say, but put simply, on a logarithmic scale, numbers that look large don’t actually correspond to values that are all that large in real terms. That’s simply how a logarithmic axis works: “the gap between 10 and 100” and “the gap between 100 and 1000” appear to be equal distances.

“You won’t fool us with that.”

Thinking this way is exactly the kind of screw-loose quality typical of startups. In the end, only “risks that stand out as exceptionally high” get any attention. Either the frequency of occurrence is extremely high, or the severity is extremely high, or both. Things with moderate frequency and moderate severity get relatively little attention. Once you consider how to run a business or build technology within limited assets — time and money — you arrive at that conclusion, and once you’ve stood in that position, you understand it completely. The CEO of Dropbox reportedly said, “If you want to survive as a startup, be prepared to say No to 93% of things,” and I think this points to the same idea.

Next, the “growth margin”: in a word, it means conducting management very optimistically. But rather than letting that optimism work in the form of “it probably won’t happen anyway” or “even if it happens, we’ll manage somehow,” you let it work as optimism about the future: “we’ll have a sufficient structure in place by launch,” or “we’ll strengthen hiring as soon as the next funding round closes” — in other words, “we are capable of responding to what’s coming.” This is naturally a sensibility that doesn’t sit well with an organization operating on ordinary logic. ISO9001, which rigorously and usefully defines quality control processes, emphasizes “planning,” and presents securing a proper structure, along with oversight and record-keeping by a responsible person from the earliest stage, as very important matters. I agree with these points very much. But in a startup, this kind of risk-taking is considered acceptable, and against the pile of precarious management matters already being juggled, a topic like this is nothing more than a minor detail.

So building in a “growth margin” and making “bold selective choices” to control risk — that’s the startup way of doing things.

Naturally, when it misses, that’s the end. It ends in a miserable collapse. That is what it means to take risk. And that “pitfall discovered” becomes a foundation for those watching nearby, and for one’s own future.

The spirit of a startup is to accept that you yourself are part of a massive experimental ecosystem and a shared illusion (membership is free), and to devote your personal risk to its advancement.


Originally published in Japanese at https://clazytech.com/2019/10/271/. Translated with LLM assistance and reviewed before publication.