Risk Management
Making risk explicit, weighing it and placing it.
What it studies
Risk management studies how uncertainty about future events is made explicit, weighed and placed: probability times consequence, risk appetite, and the choice between avoiding, reducing, transferring or accepting. It is the generic framework within which specific disciplines — security, compliance, continuity — locate their own risks.
Why Facility Management needs it
FM continuously makes decisions under uncertainty — deferring maintenance, choosing a supplier, accepting a single point of failure — without those decisions always being recognised as risk decisions. Risk management gives FM the language to make such decisions explicit and transferable, rather than leaving them implicit in someone's head.
Questions it answers
- Was this risk explicitly accepted by someone with the mandate to do so, or has it simply been left unaddressed?
- What is the organisation's risk appetite, and has it ever been stated out loud?
- Is risk being transferred (insurance, contract) or merely shifted to a party unable to carry it?
Evidence sources
- ISO 31000:2018 — risk management guidelines.
- COSO Enterprise Risk Management framework.
Operating and management implications
- A risk register without an owner per risk is a list, not a management instrument.
- Risk acceptance should sit at the right organisational level; FM may accept operational risk, not strategic risk.
Related services
- Contract management and sourcing (risk allocation in contracts)
Related capabilities
- Risk register management
- Scenario and sensitivity analysis
Related operating models
- Demand organisation
The client role should set risk appetite; delivery manages risk within that boundary.
Related standards
- ISO 31000:2018.
The standards section arrives in Part 7.
Common misuse
- A risk matrix filled in as a formality after the decision, rather than as input before it.
Current research frontier
Quantitative risk models for building-related and chain risk remain underdeveloped compared with financial risk models; most FM risk registers stay qualitative and therefore sensitive to subjective judgement.
Further reading
- ISO 31000:2018, risk management — guidelines.
- COSO ERM Framework, 2017 update.