Explaining Risk Assessment Versus Risk Management Clarifies The Startup Spirit
Some people treat risk assessment and risk management as if they were the same thing, but their meanings differ.
Let me put it in textbook terms for now.
Risk assessment, as “assess” implies, means recognizing risk itself through past experience and the know-how of seasoned practitioners, then quantifying and cataloguing it as an asset.
Risk management is “managing” that.
In other words, assessment comes first, and management follows.
I skipped over this, but risk generally refers to the trouble, accidents, or other damage that a released product might cause. Here I want you to hear it as a somewhat broader, more abstract concept, since that will bring you closer to what I mean.
If the evaluation in the assessment stage is too lax, management won’t function.
For example, assessment is normally measured as frequency of occurrence multiplied by severity, but if you thought “the probability of occurrence is extremely low, so we’ll be fine” when in fact it could occur at a fairly high frequency, controlling the resulting damage becomes extremely difficult.
Conversely, even if the assessment itself was appropriate, things can still go wrong if the thinking behind management is optimistic. For example, if you assumed too easily that “up to a 5% defect rate can be handled by our existing customer support staff,” but each individual case turned out to take more effort than expected, you might end up unable to keep up with customer responses, causing major confusion in the market.
Everything up to this point has been the sort of trivia you’d find in quality management, but I found it surprisingly apt when applied to running a startup.
Let’s try applying it in a negative light, as an experiment.
A startup is an organization where both assessment and management are sloppy.
Its members are inexperienced, poor at planning, always improvising, and think it’s fine as long as they can respond to things on the fly.
The quality of the product they can offer customers is low to begin with, but they replace that fact with the convenient phrase “an opportunity for growth,” ultimately making the customer put up with it.
That’s why, aside from the rare lucky ones who succeed, most of them end up a mess and disappear from the market.
All of that stems from underestimating risk from the very start.
Something like that. I was impressed at how thoroughly I managed to trash the very world I belong to. lol
Certainly, I won’t deny that there are quite a few startups that, viewed from outside — or even from inside — leave you thinking “well, that criticism is fair enough.”
But I think you can find something like pride, or a kind of philosophy, in that very fact.
A startup is a peculiar kind of organization that looks at the evaluation axis of assessment as if it were on a logarithmic scale, and builds a “growth allowance” into its management.
Let me explain step by step.
First, on logarithmic scales — go ask Wikipedia or Google, I suppose — but put simply, on a logarithmic scale, numbers that look big don’t actually correspond to numbers that are all that large. That’s simply how a log axis works: “the gap between 10 and 100” and “the gap between 100 and 1000” appear to be roughly the same distance.
“You won’t fool us with that.”
That’s the kind of screw-loose thinking characteristic of a startup. In other words, in the end, only “things with conspicuously high risk” get any attention: extremely high frequency of occurrence, extremely high severity, or both. Things with middling frequency and middling severity relatively fail to draw notice.
When you think about how to run a business and its technology within limited assets — time and money — arriving at that conclusion makes a lot of sense once you’re standing in that position.
The CEO of Dropbox reportedly said, “If you want to survive as a startup, you need to be prepared to say no to 93% of things,” and I think that’s describing the same kind of idea.
Next, the “growth allowance”: put in plain words, it means conducting management in a very optimistic way. But rather than letting that optimism operate as “it probably won’t happen anyway” or “if it does happen, we’ll manage somehow,” it operates as optimism for thinking, “we’ll have an adequate setup in place by launch,” or “we’ll strengthen hiring as soon as the next funding round closes” — in short, “we can handle whatever comes in the future.”
This is naturally a sensibility that doesn’t sit well with organizations that think in the ordinary way. In fact, in something like ISO9001, which rigorously and usefully defines quality management processes, “planning” is emphasized, and securing a proper structure along with oversight and record-keeping by a responsible person from the earliest stage is treated as a very important matter. I very much agree with all of that, for what it’s worth.
But in a startup, this kind of risk-taking is considered acceptable, and against the mountain of precarious management matters being juggled at once, a topic like this is nothing more than a minor detail.
So incorporating a “growth allowance” and making “bold choices about what to keep and what to discard” in order to control risk — that’s the startup way of doing things.
Naturally, when the bet doesn’t pay off, that’s the end of it. You’ll be wiped out without mercy.
That’s what it means to take a risk.
And that “pitfall you discovered” becomes a foundation for those who were watching from the sidelines, and for your own future.
The spirit of a startup is to accept yourself as a member of a huge experimental ecosystem and a shared fiction (membership is free), and to devote your personal risk to its advancement.
Originally published in Japanese at https://clazytech.com/2019/10/271/. Translated with LLM assistance and reviewed before publication.