Risk-analysis is the human-made practice of systematically evaluating identified risks to determine their likelihood, impact, and priority for decision-making about risk responses. It is defined by four parameters: (1) the set of identified risks from a risk register or threat-model, (2) likelihood assessment using qualitative or quantitative methods, (3) impact assessment across relevant dimensions (financial, operational, reputational), and (4) prioritization through risk matrices or scoring systems. It persists through documented analysis frameworks, risk registers, and institutional memory of past risk evaluations and their outcomes. [formal: riskus-analyis | substrate: behavior | horizon: hours | explicit: yes | epoch: 0.01]
Accepted ontology entry
risk-analysis
Risk-analysis is the human-made practice of systematically evaluating identified risks to determine their likelihood, impact, and priority for decision-making about risk responses. It is defined by four parameters: (1) the set of identifie…
Definition
Why it is in scope
The human-made practice of systematically evaluating identified risks for likelihood, impact, and priority to inform decision-making about risk responses. Built to persist through documented analysis frameworks and risk registers.
Names and aliases
- risk-analysisen · CANONICAL
Relations from this entry
- cms8320j500ovh6s88qjbtgz4SERVES →
Risk-analysis is conducted for the sake of decision-analysis: its designed purpose is to produce risk information that feeds into broader decision evaluation. The practice exists to inform decisions — without the aim of supporting decisions, risk analysis loses its reason for being.
- cmrvhabuj015f2cei72xywgzfINSTANCE_OF →
Risk-analysis IS a specific kind of analysis — the systematic evaluation of potential risks (likelihood, impact, severity). A competent speaker would say 'risk analysis is a kind of analysis.' Specific→general per Law 9.
Relations to this entry
- cms84gldx00u3h6s8cc35piwj← INSTANCE_OF
threat-model IS a specific kind of risk analysis focused specifically on identifying and analyzing threats. A competent speaker would say 'a threat model is a type of risk analysis.' The note pins this sense: we're classifying threat-model as a subclass of risk-analysis by scope of concern. Specific→general per Law 9.
- cms83xe5u00s0h6s88lc8rrb4← SERVES
The risk register is maintained for the sake of risk analysis — its designed purpose is to centralize risk information so that risk analysis can be systematic and repeatable. Servant (risk-register) points at master (risk-analysis). Per Law 8d.
- cms869e90010sh6s889ng2yh7← INSTANCE_OF
Failure-mode-analysis IS a specific kind of risk-analysis. It systematically identifies potential failures and evaluates their effects — this is risk analysis applied to failure modes. A competent speaker would say 'FMA is a type of risk analysis.' Direction tested: specific (FMA) → general (risk-analysis).
- cms8lchqe018k73fk380ng2hc← INSTANCE_OF
Barrier analysis is a specific kind of risk analysis: it systematically identifies and evaluates safeguards against specific threats. The competent-speaker test passes — one would call barrier analysis 'a risk analysis technique'. Direction: specific(barrier-analysis) → general(risk-analysis).
- cms8nh4s901hf73fkwq492ny1← INSTANCE_OF
risk-matrix IS a specific kind of risk-analysis: it uses a matrix grid to classify and prioritize risks by combining likelihood and impact dimensions. A competent speaker calls a risk matrix a type of risk analysis tool.
- cms8ne39701gz73fkptjtgnic← DERIVED_FROM
risk-acceptance as a formalized practice derived from risk-analysis: the structured concept of formally accepting a risk emerged from the development of systematic risk analysis methods. Historical order test — risk-analysis existed first and fed into the development of risk-acceptance as a formal decision point.
- cms8ntywc01ip73fkn7odfqg6← INSTANCE_OF
consequence-analysis is a specific kind of risk-analysis: both evaluate potential outcomes, but consequence-analysis narrows focus to post-identification assessment of hazard consequences as a rung on the risk-analysis ladder.
- cmsjv12lo03nnnobpnqdomuxx← INSTANCE_OF
FMEA is a specific kind of risk analysis method — a structured, systematic approach to identifying potential failure modes and their effects on system operation. Per Law 9, this is a genuine INSTANCE_OF: an engineer would describe FMEA as 'a risk analysis' technique. The sense is pinned: risk analysis in the broad accepted sense of systematic hazard/failure assessment, not narrow safety-only contexts.
Record identity
- Created
- Jul 30, 2026, 11:10 PM UTC
- Content hash
- 079d6a4554a237c3bfce07d0c8bd722861f1de2d24dcab247856bca424677f03