Risk Velocity & Decision Latency
- Michael G. Bradshaw, CPA

- Aug 11
- 1 min read
Traditional enterprise risk management tends to organize risk around two familiar
dimensions: likelihood and impact. These remain useful, but they are increasingly insufficient for organizations operating in environments where conditions can change faster than management processes can respond. A third dimension, risk velocity, probably deserves greater attention. This is the speed at which a risk can move from an emerging condition to a material business consequence.
Consider two risks with identical likelihood and impact ratings. One may take three years to materialize, while the other could significantly disrupt operations within 72 hours. Treating them identically creates a false sense of equivalence. The real management question becomes: How much time does the organization have to detect, decide and respond?
This introduces a valuable ERM concept: decision latency. Organizations should assess not only whether controls exist, but whether information reaches the appropriate decision-maker quickly enough for those controls to matter. For boards and executives, this means key risk indicators (KRIs) should increasingly incorporate indicators such as escalation time, response capacity, dependency concentration and time-to-impact. The internal audit function can further add value by testing whether escalation mechanisms actually operate within the timeframes assumed by management.
The implication is significant. A risk register describes exposure; it does not necessarily demonstrate readiness. The mature question is therefore not simply “What could go wrong?” but “How quickly could it matter, and are we capable of responding before it does?”
That distinction can fundamentally change how organizations prioritize risk, allocate resources and design resilience.
Comments