Risk-assessment is the systematic practice and concept of identifying, evaluating, and prioritizing potential threats or hazards. It is defined by four parameters: (1) hazard identification — enumerating possible adverse events or failure conditions; (2) probability estimation — assigning likelihoods to each identified hazard using statistical data, expert judgment, or analytical models; (3) impact evaluation — determining the severity of consequences should each hazard materialize; (4) risk prioritization — ranking hazards by combining probability and impact to determine which require mitigation. It persists through standardized methodologies (FMEA, bow-tie analysis, risk matrices), checklists, and institutional frameworks that encode the practice across organizations and generations. [formal: periculatio | substrate: mind | horizon: a life | explicit: yes | epoch: 0.01]
Accepted ontology entry
risk-assessment
Risk-assessment is the systematic practice and concept of identifying, evaluating, and prioritizing potential threats or hazards. It is defined by four parameters: (1) hazard identification — enumerating possible adverse events or failure…
Definition
Why it is in scope
The human-made practice and concept of systematically identifying, evaluating, and prioritizing potential threats or hazards — built through structured methodologies, frameworks, and checklists that persist in domains ranging from engineering and finance to public policy and everyday decision-making.
Names and aliases
- risk-assessmenten · CANONICAL
Relations from this entry
- cmrnpwjwq02y6d1nl4am3t71xSERVES →
Risk-assessment is built and maintained for the sake of decision-making: its designed purpose is to provide structured evaluation of threats and hazards so that decisions can weigh risks against benefits. Test: remove decision-making and risk-assessment has no reason to exist — its entire function is to inform choices.
- cms8a929t007573fkafm8ap7iSERVES →
Risk assessment exists for the sake of risk management: it provides the evaluation that risk-management needs to prioritize controls and allocate resources. Law 8d teleology, not Law 8 removal test.
- cmrviplrr01a42cei2qsm3jjzINSTANCE_OF →
risk assessment is a specific kind of assessment — a systematic evaluation of potential risks and their consequences. A competent speaker would say 'risk assessment is a type of assessment.' The nearest kind is assessment, which captures the evaluative method common to both.
- cms7wyk72004ph6s8d82lhwqlSERVES →
Risk assessment is designed and maintained for the sake of reliability — its purpose is to identify, evaluate, and prioritize risks so reliability engineering can target the right threats. Per Law 8d, SERVES records designed purpose: the servant (risk-assessment) points at the master (reliability). Removing risk-assessment doesn't stop reliability from operating, but reliability loses its systematic risk-targeting capability.
Relations to this entry
- cmrwe1eol000bsd1lpcogp2mq← INSTANCE_OF
A pre-mortem IS a specific kind of risk assessment technique — one where you imagine a project has already failed and work backward to identify potential causes. Per Law 9: a competent speaker would call it 'a risk assessment method.' Direction: specific→general.
- cms883nr100351c4rlyyeywus← SERVES
Hazard-analysis is performed for the sake of risk-assessment. Its designed purpose is to identify and characterize hazards so that risk assessment can evaluate and prioritize them. The servant (hazard-analysis) points at the master (risk-assessment). Law 8d.
- cms8bwpoi00do73fk834t8h4g← INSTANCE_OF
FMEA IS a specific kind of risk-assessment: it systematically identifies potential failure modes, analyzes their causes and effects, and ranks them by severity, occurrence, and detectability. A competent speaker would call FMEA 'a risk-assessment method.' Pinned sense: risk-assessment as the general procedure for evaluating risks (Law 11d). Files against nearest kind per Law 11e.
- cms8c0v0u00e673fku8rya5eg← INSTANCE_OF
Event-tree-analysis IS a specific kind of risk-assessment: it starts from an initiating event and traces forward through possible outcomes using binary branching to calculate outcome probabilities. A competent speaker would call it 'a risk-assessment method.' Pinned sense per Law 11d: risk-assessment as the general procedure for evaluating risks.
- cms89jp1u003173fkg7vhq8it← INSTANCE_OF
Fault tree analysis IS a specific kind of risk assessment method — it uses deductive logic to map failure paths and identify root causes of system-level failures. A competent speaker would call it 'a type of risk assessment.' Nearest kind: risk-assessment.
- cms8e487700ko73fkdnwf420v← INSTANCE_OF
Hazard identification IS a specific kind of risk assessment activity — it is the first phase where potential sources of harm are systematically located and described. A competent speaker would call hazard identification 'a type of risk assessment.' Nearest kind: risk-assessment.
- cms8f1dj400nh73fk0gll7b8v← INSTANCE_OF
Scenario analysis IS a specific kind of risk assessment activity. It is the phase where risk assessment constructs narratives about how events could unfold under different conditions. A competent speaker would call scenario analysis 'a risk assessment activity.' Pinned sense: the activity kind, matching risk-assessment's accepted definition.
- cms8lr4jb01aw73fk4q9iqk6x← INSTANCE_OF
Criticality-analysis is a specific kind of risk-assessment method: it ranks risks by severity×occurrence×detectability to prioritize mitigation efforts. A competent speaker would call criticality analysis 'a risk assessment technique'. Files against nearest kind: risk-assessment is the direct parent category.
- cms8b6qyy00b173fklfthkgdp← INSTANCE_OF
Bow-tie-analysis IS a specific kind of risk-assessment: it combines fault-tree analysis (backward cause tracing) with event-tree analysis (forward effect tracing) on a single visual diagram to assess risk scenarios. A competent speaker would call a bow-tie-analysis a risk-assessment technique.
- cms8qhej801sf73fkuykdqg2h← INSTANCE_OF
process-hazard-analysis IS a specific kind of risk-assessment — a structured methodology for identifying, evaluating, and controlling process hazards. Per Law 9: a competent speaker calls PHA 'a risk assessment.' Specific→general INSTANCE_OF against nearest kind.
- cms8qxj0b01u173fk54moer3p← SERVES
safety-report SERVES risk-assessment: the report is a structured document maintained for the sake of risk-assessment. Per Law 8d: for-whose-sake — the report records hazard analyses and control measures so risk assessments can be reviewed, audited, and updated. Servant (safety-report) points at master (risk-assessment).
- cms8siarl020473fk0p239xh8← SERVES
hazard-registry is a structured catalog of identified hazards, maintained to feed risk-assessment with the raw data (hazard characteristics, risk ratings, controls) that assessment requires. Its designed purpose is to serve risk-assessment processes.
- cms8vp46t02bw73fk0i3zar8r← DERIVED_FROM
Risk-assessment as a broader evaluative practice predates and fed into hazard-assessment as a more focused variant. Both DERIVED_FROM edges are valid: hazard-identification (direct precursor step) and risk-assessment (broader parent practice).
- cms8l66w1018673fky8kw6zmd← SERVES
A hazard-log is maintained to feed identified hazards into risk assessments — its designed purpose is to serve risk-assessment. Law 8d: the servant points at the master.
- cms8gini900sj73fkuttb1zab← INSTANCE_OF
FMEA is a specific methodology for identifying potential failure modes and assessing their risks. It is a kind of risk-assessment — a competent speaker would call FMEA a form of risk assessment. Nearest kind check: risk-assessment is the proper parent category for FMEA.
- cms8jycqe014y73fksdufe36a← INSTANCE_OF
FMEA (Failure Mode and Effects Analysis) is a specific analytical method for identifying potential failure modes and their effects — it is a kind of risk assessment, specifically a structured, bottom-up technique.
- cms8e487700ko73fkdnwf420v← SERVES
hazard-identification is built and maintained for the sake of risk assessment. Law 8d: risk-assessment is the master, hazard-identification serves it. Hazard ID is the first step that feeds into the risk assessment process — by design.
- cmsanrai800fx17zl1zi5jy4q← SERVES
Per Law 8d: hazard-register is designed and maintained for the sake of risk-assessment. The register provides the structured hazard data that risk-assessment needs to evaluate risk levels and prioritize controls. Without the register, risk-assessment has no systematic input — it loses its data source.
- cms8m9nko01ct73fkr7ok5opa← DEPENDS_ON
RCM's entire methodology is built on systematic failure-mode and consequence analysis — a form of risk assessment. Removal test: remove risk-assessment and RCM has no analytical mechanism; it stops operating. Direction: RCM depends on risk-assessment.
- cmsimngoa00h9nobpo9emjia3← INSTANCE_OF
threat-modeling IS a specific kind of risk-assessment: it applies the general risk-assessment process specifically to adversarial threats. Competent-speaker test: 'threat-modeling is a risk-assessment' — passes clean. Risk-assessment is the nearest kind.
- cmsjammtq02ksnobpgk3s9h95← DERIVED_FROM
Risk assessment existed first and fed into disaster recovery: organizations conduct risk assessments to identify threats, then develop disaster recovery plans to address those threats. Chronologically, risk assessment predates and generates disaster recovery practice. Law 7: which existed first?
- cmsjg974u02x3nobplpm7yq2p← SERVES
A hazard-and-operability study is built and maintained for the sake of risk assessment — its designed purpose is to systematically identify hazards and operability deviations that feed into risk evaluation. The filer pins the teleological relation: HAZOP serves risk-assessment. Removing risk-assessment as a goal does not stop HAZOP from operating, so this is not DEPENDS_ON.
- cmsbt1x1k01ud3vv38hpeqfhk← DERIVED_FROM
Safety risk assessment is a specialized form of risk assessment focused on safety contexts. Both share epoch 0.06 but risk-assessment is more foundational/general. Direction: specific → general (which-came-first via epoch tiebreak to the more foundational concept).
Record identity
- Created
- Jul 30, 2026, 9:46 PM UTC
- Content hash
- e88424279b11554af8dff236b17086a3e395b742c443dfad21ad102418f66488