Risk: Definitions, Measures, and Applications
- Risk is a multi-faceted concept defined by the product of hazard probability and impact, with applications in machine protection, finance, and reinforcement learning.
- Various formulations such as risk matrices, adjusted Expected Shortfall, and non-additive risk fields enable precise measurement and mitigation across domains.
- Practical implementations include safety lifecycles in high-energy physics, robot motion planning in constrained environments, and systemic evaluations in financial risk management.
Risk denotes different but structurally related concepts across engineering, finance, planning, and governance. In high-energy physics machine protection, risk is defined as the product of the probability of a hazardous chain of events and the consequence or impact if those events lead to damage, (Todd et al., 2016). In project risk management, risk is defined as uncertainty in which one or many causes, composed of probability of occurrence, can generate an impact or consequence, either as threat or opportunity (Antunes et al., 2018). In finance and reinforcement learning, risk is formalized through functionals on random variables or trajectory returns, including adjusted risk measures, distortion-based measures, entropic risk, expectiles, shortfall risk, and optimized certainty equivalents (Alexander et al., 2024, Dhaene et al., 2019, Baier et al., 2023, Gupte et al., 10 Feb 2026). Across these literatures, risk is used to rank adverse possibilities, shape decisions under uncertainty, and determine how much protection, capital, or control effort is required; several of the cited works also stress that risk is often non-additive, tail-sensitive, history-dependent, or dependent on evidential standing rather than on object-level hazard alone (Xiao et al., 2019, Almen et al., 6 Sep 2025, Assa, 11 May 2026).
1. Core definitions and mathematical forms
A recurring engineering definition is the expectation-style decomposition of risk into likelihood and consequence. Todd and Kwiatkowski define risk in machine protection as , visualize risks as points on a risk matrix, and derive a “Risk Reduction Level” (RRL) as the factor by which unmitigated risk must be reduced to reach the ALARP region; protection functions are then assigned “Protection Integrity Levels” (PILs) matching the required RRL (Todd et al., 2016). In robot path planning, risk is defined as the probability of not finishing a path, with the path-risk
which explicitly rejects additive state-cost surrogates (Xiao et al., 2019).
Financial and actuarial work generalizes this perspective from event chains to functionals on random losses. “Risk measures based on target risk profiles” defines the adjusted risk measure
where is a target risk profile and is a family of monetary risk functionals; adjusted Expected Shortfall is recovered by taking (Alexander et al., 2024). “Systemic Risk: Conditional Distortion Risk Measures” defines
thereby measuring systemic stress transmission from to 0 (Dhaene et al., 2019). “Entropic Risk for Turn-Based Stochastic Games” defines, for 1 and base 2,
3
with 4 as 5, and a Taylor expansion
6
which makes variance and higher moments explicit (Baier et al., 2023).
Reinforcement-learning work further enlarges the class of admissible risk functionals. “Risk-sensitive reinforcement learning using expectiles, shortfall risk and optimized certainty equivalent risk” treats risk-sensitive objectives through expectiles, utility-based shortfall risk, and optimized certainty equivalent risk (Gupte et al., 10 Feb 2026). “Reinforcement Learning with Markov Risk Measures and Multipattern Risk Approximation” formalizes coherent static and dynamic risk measures, including translation invariance, convexity, monotonicity, and positive homogeneity, and embeds them through Markov transition-risk mappings in finite-horizon MDPs (Ruszczynski et al., 1 May 2026). A plausible implication is that “risk” in current technical usage is not a single scalar doctrine but a family of mathematically distinct operators, each chosen to preserve particular structural properties such as coherence, tail sensitivity, time consistency, or planner compatibility.
2. Representation, decomposition, and ordering
Risk assessment often begins by identifying the structure of hazardous evolution rather than by assigning a number immediately. In machine protection, the first steps are to identify “hazard chains” linking component failures to damage through intermediate non-nominal energy releases, build a failure-catalogue, and record two characteristic times: 7, the time from initial failure to first non-nominal energy deposition, and 8, the time from non-nominal deposition to actual damage (Todd et al., 2016). In the DEVS/STDEVS framework for unified safety and security assessment, risk is defined over simulation paths 9 as
0
with accidental failures modeled by local transition probabilities and intentional failures aggregated through game-theoretic attacker/defender choices (Draeger et al., 2017).
A more explicitly compositional treatment appears in “Risk Structures: Towards Engineering Risk-aware Autonomous Systems,” where the primitive object is a risk factor
1
with phases 2, a transition relation, a partial order, and a severity interval (Gleirscher, 2019). For a set of factors 3, a risk state is a total injective function selecting one phase per factor, and the risk space 4 admits a parallel composition operator 5. The same paper develops mitigation orders 6, 7, and 8, showing that the strong mitigation order yields a complete lattice on equivalence classes of risk states (Gleirscher, 2019). This framework is qualitative rather than probabilistic, but it supplies an algebra over risky configurations.
Ordering results also play a central role in finance. The conditional-distortion framework derives sufficient conditions under conventional stochastic dominance, increasing convex/concave, dispersive, and excess wealth orders of marginals, together with dependence notions encoded by copulas, so that two bivariate risk systems can be ranked by 9 and 0 measures (Dhaene et al., 2019). “Risk measures based on target risk profiles” gives a sharp criterion for when 1 is positively homogeneous or subadditive: under the paper’s assumptions, this occurs if and only if 2 at at most one point 3 (Alexander et al., 2024). Taken together, these results show that risk comparison is rarely a matter of single-number magnitude alone; it depends on ordering relations over trajectories, states, distributions, and dependence structures.
3. Engineering, safety, and infrastructure protection
High-energy physics offers a particularly explicit risk-engineering lifecycle. Todd and Kwiatkowski adapt the IEC 61508 functional-safety lifecycle into six phases: machine and operations understanding; hazard identification and analysis; risk classification; risk reduction determination; protection-function specification; and protection integrity level specification, realization, verification, and validation (Todd et al., 2016). The same methodology is used both prospectively for new systems and “in reverse” for existing systems, where observed failures and near-misses are fed back into the hazard catalogue, risk matrix, protection-function design, and PIL allocation (Todd et al., 2016).
The contrast between stored beam energy and stored magnetic energy illustrates how a common risk formalism can apply across different time scales. Beam energy of up to 4 demands sub-millisecond detection and dump, with beam losses on the order of a few 5, whereas stored magnetic energy of about 6 is handled through magnet quench detection, energy extraction, and interlocks on millisecond timescales (Todd et al., 2016). The case study of a seven-magnet superconducting circuit re-analyzes four protection functions—interlock neighboring circuits, switch off converter, propagate quench, extract energy—and reassigns PIL requirements after evaluating each function’s failure probability against the number of magnets damaged; the paper also notes that a major uncontrolled magnet discharge in 2008 led to more than one year of downtime and motivated additional energy-extraction redundancy (Todd et al., 2016).
Critical-infrastructure security assessment extends the engineering lifecycle by adding explicit offensive-tool characterization. “Offensive tool determination strategy R.I.D.D.L.E.+(C)” inserts an “Offensive-Tool Analysis” phase immediately after threat identification and before vulnerability analysis (Errico, 16 Nov 2025). The seven variables are resistance, intrusion timing, damage, disruption timing, latency, efficiency, and cost, each scored on an ordinal 7–8 scale, with the composite score
9
mapped to minor threat for 0, medium threat for 1, and severe threat for 2 (Errico, 16 Nov 2025). In the worked SCADA example, “HydraRAT” receives 3 and “Valve-Buster” 4, which guides the decision to allocate more cyber-monitoring and layered EDR for the former while preferring scheduled physical inspections over full hardening for the latter (Errico, 16 Nov 2025).
A persistent theme in these engineering papers is that risk is inseparable from mitigation design. RRL and PIL in machine protection, attacker-tool scoring in critical infrastructure, and STDEVS path aggregation in safety/security all treat risk not merely as description but as a design variable used to allocate redundancy, instrumentation, intervention speed, and organizational procedures.
4. Planning, control, and reinforcement learning
In planning and robotics, risk is often attached to trajectories, action sequences, or spatial fields rather than to isolated states. “Risk Awareness in HTN Planning” augments HTN planning by assigning each operator a probability distribution over execution costs and defining the expected utility of a primitive plan 5 as a sum over all combinations of operator-cost realizations (Alnazer et al., 2022). A risk-aware HTN planning problem is then 6, and its solution is a primitive plan that maximizes expected utility under a specified utility function encoding risk-neutral, risk-averse, risk-seeking, or dynamic attitudes (Alnazer et al., 2022). The paper argues that existing state-based and plan-based HTN planners can be adapted by redefining costs through expected utility and by modifying admissible heuristics accordingly (Alnazer et al., 2022).
Robot motion planning in confined environments provides a distinct correction to common assumptions. “Robot Risk-Awareness by Formal Risk Reasoning and Planning” partitions risk elements into locale-dependent, action-dependent, and traverse-dependent categories and defines path risk through conditional failure probabilities over the full history of the path (Xiao et al., 2019). The paper argues that the common approximation 7 is incorrect because risk is not additive, and it develops an augmented Dijkstra-style search over directional components to handle two-step and history-dependent effects (Xiao et al., 2019). In hardware experiments with a tethered quadrotor in a cluttered staircase, the red path had computed risk 8 and observed failure rate 9, while the green path had computed risk 0 and observed failure rate 1, a match presented as substantially better than ad hoc additive state-cost planning (Xiao et al., 2019).
Reinforcement-learning work treats risk as an optimization criterion over return distributions. “One Risk to Rule Them All” proposes a model-based offline RL approach in which a coherent risk measure is applied over a Bayesian MDP posterior, so that risk aversion simultaneously addresses aleatoric uncertainty and epistemic uncertainty from distributional shift (Rigter et al., 2022). “Entropic Risk for Turn-Based Stochastic Games” shows that zero-sum stochastic games with entropic risk total-reward objectives are determined and admit pure memoryless optimal strategies for both players, in contrast to other risk measures in MDPs that typically require randomization and/or memory (Baier et al., 2023). “Reinforcement Learning with Markov Risk Measures and Multipattern Risk Approximation” introduces mini-batch transition-risk mappings and a feature-based 2-learning method with multipattern 3-factor approximation, together with a high-probability regret bound of 4 (Ruszczynski et al., 1 May 2026). “Risk-sensitive reinforcement learning using expectiles, shortfall risk and optimized certainty equivalent risk” derives policy-gradient theorems, proposes gradient estimators with 5 mean-squared error bounds, and establishes stationary convergence bounds for a risk-sensitive policy-gradient algorithm (Gupte et al., 10 Feb 2026).
Spatial risk fields provide yet another operationalization. “MC-Risk: Multi-Component Risk Fields for Risk Identification and Motion Planning” defines a bird’s-eye-view scalar risk density
6
where 7 is a motorized-agent field, 8 a VRU risk field, and 9 a road-penalty field (Link et al., 20 May 2026). The field is calibrated on RiskBench to align risk peaks with empirical collision probabilities, maximize OT-F1, and minimize PIC, and it attains OT-F1 0 versus 1 for the best baseline “Range,” with PIC 2 versus 3 (Link et al., 20 May 2026). The same field is then inserted directly as an MPC cost density, so that no additional learning is needed for risk-aware trajectory generation (Link et al., 20 May 2026).
5. Financial, systemic, and model risk
Financial risk theory in these papers is driven by dissatisfaction with average-based summaries that can miss tail behavior. “Risk measures based on target risk profiles” states explicitly that classical risk measures may not detect tail risk adequately and gives adjusted risk measures as a generalization of adjusted Expected Shortfall (Alexander et al., 2024). The empirical case study on daily log-returns of the S&P 500 index and selected stocks uses 60-day rolling windows for 4, 5, 6, and 7, comparing SCRM, CRM, FCRM, AERM, and 8 under fixed and adaptive benchmark profiles (Alexander et al., 2024). One reported conclusion is that fixed conservative target profiles flag systemic tail events better than adaptive profiles, because rolling recalculation of 9 tends to rise in tandem with the index and under-estimate crisis peaks (Alexander et al., 2024).
Systemic risk enters when risk is defined on vectors rather than single positions. “Systemic Risk: Conditional Distortion Risk Measures” introduces CoD and 0CoD classes that include conditional Value-at-Risk, conditional Expected Shortfall, and related contribution measures as special cases, with representation theorems in terms of marginals, copulas, and distorted conditional distributions (Dhaene et al., 2019). “Fair Risk Optimization of Distributed Systems” defines systemic coherent risk measures 1 on 2, including both “aggregation then univariate-risk” and “individual-risks then aggregation” constructions (Almen et al., 6 Sep 2025). A particularly მნიშვნელოვანი feature is the use of mean-upper-semideviation as system aggregator,
3
which penalizes individual risks exceeding the weighted average and thereby produces a notion of fair allocation across agents (Almen et al., 6 Sep 2025). In the disaster-management application with five facilities, this non-linear aggregation narrows the spread of individual risks at a slight increase in total risk (Almen et al., 6 Sep 2025).
Model risk is treated as uncertainty over the admissible model class itself. “Model Risk in Credit Risk” considers all finite sequences of exchangeable Bernoulli default indicators consistent with given marginal default probability 4, and optionally pairwise correlation 5, and studies how 6 and 7 vary across that class (Fontana et al., 2019). The class 8 is described as the intersection of the simplex with the hyperplane 9, and its extremal points have support on at most two default counts; with correlation constraints, the extremal rays have support on at most three points (Fontana et al., 2019). For a homogeneous portfolio with 0 and 1, the paper reports pure-model-risk 2 defaults; with 3, the range becomes 4, while a Beta-mixing model gives 5 (Fontana et al., 2019). This suggests that model specification itself can dominate portfolio-capital uncertainty even when marginal default inputs are fixed.
6. Epistemic, reporting, and behavioral dimensions
Several recent works distinguish the presence of risk from the institution’s stance toward that risk. “The Epistemic Risk of Risk” introduces modal operators 6 for assurance-grade endorsement and 7 for working commitment, together with crisp and fuzzy semantics for necessity, possibility, non-exclusion, hesitation, and epistemic inconsistency (Assa, 11 May 2026). Its central diagnostics are
8
which identify cases in which a risk is present but lacks the relevant stance (Assa, 11 May 2026). The paper formulates a Risk Management Principle, according to which 9 is itself risk-relevant when 0 is a risk, and a Risk Reach Principle requiring real and decision-relevant risks to be reachable by the appropriate stance; it then argues that unrestricted combination creates Moorean and Fitch-style collapse pressure, motivating a typed architecture in which object-level risk claims are separated from meta-level epistemic diagnostics handled by an audit layer (Assa, 11 May 2026). A plausible implication is that quantitative risk management must govern validation gaps, model risk, and escalation failures as first-class objects, not just adverse states of the world.
Risk communication and documentation form a practical counterpart to that epistemic layer. “RiskRAG” reports that only 1 of model cards mention risks and that 2 of those copy content from a small set of cards (Rao et al., 11 Apr 2025). Its retrieval-augmented generation pipeline draws from 450K model cards and 600 real-world incidents, with source corpora including 2,672 unique risk-related model cards and 649 AI Incident Database entries, to generate model-specific risks, contextualize them with example uses, and prioritize them by
3
where 4 is the number of example uses affected and 5 indicates appearance in real-world incident reports (Rao et al., 11 Apr 2025). In a preliminary study with 50 developers, 6 preferred RiskRAG, with statistically significant gains in coverage, mitigation clarity, reliable information, concise presentation, and risk prioritization; in a larger study with 38 developers, 40 designers, and 37 media professionals, RiskRAG improved explanation quality for developers and designers, decreased confidence after review for developers and media professionals, and increased choice reversals, which the paper interprets as more careful and deliberative selection of AI models (Rao et al., 11 Apr 2025).
Behavioral work gives yet another sense in which risk is not reducible to expected value. “Risk as Challenge: A Dual System Stochastic Model for Binary Choice Behavior” defines a Challenge Index,
7
with outcome transformations 8 and probability weighting functions of Gonzalez–Wu type, and proposes the general challenge hypothesis that larger CI implies lower popularity of the bold prospect (Shye et al., 2019). In data from 126 respondents over 44 binary choice problems, the reported correlations between CI and bold-choice popularity are 9 for gains and 00 for losses (Shye et al., 2019). The paper presents certainty effect, reflection effect, overweighting of very low probabilities, and loss aversion as consequences of a single-index, processual account rather than a weighted-sum utility calculus (Shye et al., 2019).
7. Cross-domain themes and recurrent controversies
Across the cited literatures, several recurrent claims appear. First, risk is repeatedly distinguished from simple expectation or from additive state-cost heuristics: entropic risk penalizes low outcomes exponentially; adjusted risk measures and distortion measures target tails and dependence; robot path risk is explicitly non-additive; and distributed-system risk is treated through systemic rather than separable aggregation (Baier et al., 2023, Alexander et al., 2024, Xiao et al., 2019, Almen et al., 6 Sep 2025). Second, risk modeling is frequently tied to temporal structure. Machine protection uses 01 and 02 to determine intervention speed, dynamic risk measures rely on nested time consistency, STDEVS aggregates losses over evolution paths, and mini-batch Markov risk measures compound over finite horizons (Todd et al., 2016, Ruszczynski et al., 1 May 2026, Draeger et al., 2017).
Third, the object of risk varies by domain but the workflow is often homologous: identify hazards or candidate tools, construct a representation of possible evolutions, assign a measure or ordering, and use the result to allocate protection, capital, or control. This pattern appears in hazard-chain machine protection, R.I.D.D.L.E.+(C) offensive-tool analysis, DEVS/STDEVS safety-security assessment, HTN planning under utility, systemic financial aggregation, and RiskRAG reporting workflows (Todd et al., 2016, Errico, 16 Nov 2025, Draeger et al., 2017, Alnazer et al., 2022, Rao et al., 11 Apr 2025). Fourth, many papers make explicit that “risk” includes the risk of the model, the risk of the dependence assumption, or the risk that the organization lacks sufficient assurance or commitment. Model risk in credit portfolios, epistemic diagnostics such as 03, and reporting systems that surface incident-linked harms all push risk analysis beyond outcome distributions alone (Fontana et al., 2019, Assa, 11 May 2026, Rao et al., 11 Apr 2025).
The most consistent misconception challenged by this body of work is that risk is a single, universally additive scalar. The papers instead present risk as a family of mathematically disciplined but domain-specific constructs: a product 04, a path-failure probability, a coherent or distortion-based functional, a utility-transformed return criterion, a calibrated spatial field, a systemic aggregation over agents, or a meta-level diagnostic about whether a risk claim is institutionally supportable. This suggests that rigorous risk analysis depends less on choosing one canonical formula than on matching the formalism to the structure of hazards, dependencies, time scales, and governance requirements that define the domain.