• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » Business risk

Business risk

Definition

Business risk

Business risk is any threat — internal or external — that can dent sales or squeeze margins. It spans bad strategy, compliance gaps, weak operations, and financial shocks. Risk can never be cut to zero, so the job is to price it and manage it.

Every operating decision carries some downside. A new product can flop. A key supplier can fold. A junior accidentally emails a customer list to the wrong distribution group.

The job of a risk program isn’t to predict each event. It’s to keep the company standing when one lands, and to price the exposure clearly enough that the board can decide what to carry.

That calculus widened once work started moving offsite. When payroll, support, or engineering sits with a provider, you inherit their controls as well as your own, so outsourcing decisions belong in the risk conversation.

Key takeaways

  • Business risk spans five working categories: strategic, compliance, operational, financial, and reputational.
  • Internal sources, including people, process, and technology, cause more outages than external shocks.
  • A 2024 McKinsey survey found 40% of executives said their risk function lagged the pace of business change.
  • Outsourced functions inherit the provider’s risk posture, so vendor due diligence is risk work, not procurement admin.
  • Mature programs price risk in dollars rather than colours on a heat map.

How it works

Business risk management runs on a four-step loop: identify, assess, treat, monitor. You list the threats that could damage revenue, reputation, or compliance, rate each by likelihood and impact, pick a treatment, then watch the indicators as conditions shift.

Most firms anchor the work in a risk register, a single document or platform that tracks every named risk, its owner, its controls, and its residual rating.

The ISO 31000 standard, refreshed in 2018, sets the global baseline for how that register gets built and reviewed. It’s guidance rather than certification, so auditors read it as a reference point, not a pass mark.

Treatment falls into one of five buckets. The pick usually comes down to how cheap the control is against how much loss it prevents.

TreatmentWhat it meansTypical example
AvoidStop the activity that creates the riskExiting a sanctioned market
ReduceAdd controls that lower likelihood or impactMulti-factor authentication on every login
TransferMove the financial loss to a third partyCyber-insurance policy or a currency hedge
AcceptAcknowledge the exposure and budget for itSelf-insuring small petty-cash shortfalls
ShareSplit the exposure with a partnerLiability clauses in a joint-venture contract

Mature programs put a number on each entry. Expected loss equals likelihood times impact — so a 10% chance of a $2 million outage reads as a $200,000 line item you can weigh against the price of the control.

The board owns the appetite, meaning how much risk the company will carry to hit its growth targets. Management owns the controls. Internal audit tests whether those controls actually work.

Shared structures need that discipline twice over. A joint venture or a captive center splits the upside and the liability, so each side has to name its own risk owner.

Examples

Concrete cases land the categories faster than definitions do. The four below map to strategic, compliance, operational, and financial risk, and each shows a control that existed on paper yet failed to change a decision in time.

Strategic risk — Kodak, 2012. The film giant filed for Chapter 11 in January 2012 after misreading how quickly photography went digital. Its bankruptcy filing listed $6.75 billion in debts against $5.1 billion in assets.

Kodak engineers built the first digital camera in 1975. Leadership underweighted the strategic threat for the next two decades.

Compliance risk, Wells Fargo, 2016 to 2022. The bank paid more than $3 billion across settlements and fines after staff opened millions of unauthorised accounts to hit sales quotas.

The Consumer Financial Protection Bureau’s 2022 order alone required $3.7 billion in customer refunds and civil penalties, six years after the first headlines.

Operational risk, CrowdStrike, July 2024. A faulty kernel-level update took down roughly 8.5 million Windows machines on 19 July 2024. Delta Air Lines later said the outage cost it more than $500 million in lost revenue and recovery spend.

Financial risk, Silicon Valley Bank, March 2023. SVB failed within 48 hours after a $1.8 billion loss on its bond portfolio triggered a digital deposit run.

The collapse showed how interest-rate risk, concentration risk, and liquidity risk compound when controls miss the link between them. Each exposure looked survivable alone. Together they weren’t.

For outsourcing buyers the lesson repeats. Risk shows up at the seams between teams, suppliers, and tech stacks, and a working vendor management program is where most of those seams get stitched.

Those seams multiply in offshore outsourcing, where data-protection law, currency swings, and intellectual property terms sit under a different jurisdiction from the buyer’s.

Buyers weighing that trade-off can talk to the Outsource Accelerator team while the shortlist is still open and the contract clauses are still movable.

Related terms

Business risk sits inside a family of terms that split the same problem into owners, controls, and contracts. Mapping them early keeps the register readable, and it tells you which function answers when a threat turns real.

  • Risk Management: the umbrella discipline that identifies, assesses, and controls threats across every category.
  • Operational Risk: exposure from failed internal processes, people, or systems during day-to-day delivery.
  • Compliance: the practice of meeting every legal, regulatory, and contractual requirement that governs the business.
  • Vendor Management: the controls a buyer uses to track third-party performance, security, and continuity.
  • Business Continuity Plan (BCP): the playbook that keeps critical operations running through a disruption.
  • Due Diligence: the fact-finding step that surfaces hidden risks before a deal or partnership closes.
  • Service Level Agreement (SLA): the contract clause that turns vendor risk into measurable, enforceable thresholds.

FAQ

What’s the difference between business risk and financial risk?

Business risk covers anything that could threaten sales, profit, or survival, including strategic, operational, compliance, and reputational threats. Financial risk is the narrower subset tied to capital structure, debt, liquidity, and market moves.

Can business risk be eliminated?

No. Every revenue-generating activity carries some downside. Mature programs cut likelihood and impact through controls, transfer residual loss through insurance, and accept what’s left inside a stated appetite.

How often should a risk register be reviewed?

Most listed companies refresh the full register quarterly and update high-severity items in real time. Smaller firms can run a lighter half-yearly cycle, though anything longer than a year tends to miss material shifts.

Does outsourcing increase or reduce business risk?

Both. A capable provider absorbs operational and talent risk you would otherwise carry alone, while a weak one concentrates supplier risk and adds fresh compliance exposure. The due-diligence and SLA work done before signing decides which way it lands.

Who owns business risk inside a company?

The board sets the appetite, executives own the controls, internal audit tests them, and every employee owns the risks attached to their own role.

If you’re mapping a risk register against vendor SLAs, browse the Outsource Accelerator directory for verified BPO partners matched to your sector.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image