Maman Ibrahim is a cyber and digital risk executive, helping boards, CRO, CIO, and CISO turn risk work into decisions, delivery, and proof.gettyThe first time I watched a risk metric fail in an executive meeting, the problem wasn't the model. The analysis was sound, the assumptions were documented and the calculations were defensible. The problem was that two teams had measured different things while using the same label. One had quantified the financial impact of a single supplier failing. The other had measured the business's dependence on a small group of suppliers. Both called it "supplier risk," but they were answering different questions.The discussion quickly shifted away from the numbers and toward a more fundamental issue: Which definition was correct? Until that question was resolved, no one could confidently use either result to make a decision.This is how many risk quantification initiatives break down. The mathematics is often the easy part. The harder challenge is ensuring everyone measures the same concepts in the same way. When business functions define risks differently, even sophisticated models produce results that cannot be compared or trusted.Organizations often respond by refining the model or collecting more data. More often than not, the real problem is much simpler: they never established a common taxonomy in the first place.The Filing Cabinet ProblemA taxonomy is more than a list of risks. A list simply identifies what an organization worries about. A taxonomy defines each risk, explains how different risks relate to one another and establishes where one category ends and another begins.That distinction matters in practice. A cyber team may classify an outage caused by a vendor as third-party risk. Procurement may record it as supplier performance. Operations may log it as service disruption, while legal focuses on contractual exposure. Each team is describing the same incident from its own perspective, creating multiple records of one event instead of one consistent view of enterprise risk.Without a shared taxonomy, every function develops its own language. That makes it difficult to compare risks across business units, aggregate exposure or explain enterprise-wide results to executives and boards. A well-designed taxonomy provides consistent definitions, establishes hierarchy, distinguishes causes from events, links impacts to business outcomes and assigns ownership for maintaining each category.Classification Before CalculationEvery quantification model depends on one assumption: the data being analyzed represent comparable things.A model can estimate event frequency only if similar incidents are classified consistently. It can estimate financial impact only if loss categories are defined the same way across the organization. It can aggregate exposure only if the underlying risks were categorized using the same rules. Without that consistency, the model still produces numbers, but those numbers combine fundamentally different types of events. The sequence is straightforward: classify risks, measure them consistently, quantify exposure and then support decisions. Weak classification undermines every step that follows.The Five Elements Of A Useful TaxonomyA taxonomy that supports quantification should accomplish five things:1. Define each risk clearly. Every category should have a definition that multiple business functions interpret the same way. If teams routinely debate where an event belongs, the taxonomy needs refinement.2. Separate causes from risk events. Weak vendor oversight may contribute to supplier disruption, but it is not the disruption itself. Mixing causes, events and consequences makes historical analysis less reliable and increases the likelihood of double counting.3. Standardize impact categories. Financial loss, operational disruption, customer impact, regulatory action, safety and reputational damage should be measured separately before being combined. Broad categories such as "high impact" provide little analytical value.4. Capture relationships between risks. A ransomware attack can affect operations, customers, contracts, revenue and regulatory compliance simultaneously. The taxonomy should preserve those relationships so analysts understand how one event creates multiple business impacts.5. Assign ownership. Someone must own the definition, assumptions, updates and uncertainty. How Taxonomy Improves QuantificationA common taxonomy can help strengthen every stage of the quantification process.During data collection, it reduces inconsistent reporting by giving teams one set of definitions. During scenario analysis, it helps analysts avoid modeling the same risk multiple times under different names. Historical analysis becomes more meaningful because similar events are grouped consistently.Impact estimation also becomes easier. When downtime, customer losses, regulatory penalties and remediation costs are classified consistently, finance, risk and business leaders spend less time debating definitions and more time evaluating the results.The same principle applies to portfolio reporting. Executives want to understand how risk compares across business units, suppliers, technologies and regions. Those comparisons are only meaningful if every part of the organization is using the same classification framework. Otherwise, the organization is combining numbers that were never intended to be compared.Finally, taxonomy improves governance. Boards rarely need to understand every modeling assumption. They do need confidence that the reported risk reflects a consistent definition, that the assumptions are documented, that ownership is clear and that the results support a specific business decision.From Risk Taxonomy To Decision TaxonomyQuantifying risk is not the objective. Making better decisions is. Once exposure has been quantified, leaders still need to decide whether to accept the risk, invest to reduce it, transfer it, monitor it or change the business activity altogether. Those decisions depend not only on the estimated loss but also on risk appetite, available resources and competing priorities.A mature risk program connects these activities into one process: classify risks consistently, quantify exposure, evaluate response options, invest where appropriate, monitor outcomes and use new information to improve future decisions.Ultimately, boards should spend as much time challenging the structure behind the number as the number itself: Are risks being classified consistently? Which assumptions matter most? Who owns the definitions? Can results be compared across the business? What decision does this analysis enable?The Power Of Shared MeaningEvery quantified risk begins with a classification decision. If that decision varies across business functions, the resulting analysis will always be difficult to compare, aggregate and defend.Organizations that consistently produce useful risk metrics succeed because they established a common language before they began measuring anything. Once everyone is classifying risks the same way, quantification becomes more reliable, comparisons become more meaningful and leaders can use the results to make better-informed decisions.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
How Risk Taxonomy Can Drive Effective Risk Quantification
Organizations that consistently produce useful risk metrics succeed because they established a common language before they began measuring anything.








