What is an emerging risk, and how does it differ from a conventional risk?

An emerging risk is a threat that is developing but not yet well understood, with no reliable history to estimate how likely it is or how hard it will hit. A conventional risk is already known and can be measured against past data. The difference matters because standard risk tools tend to overlook emerging risks until they are already causing damage.

A conventional risk is one your organisation already recognises. There is history behind it, enough past experience or data to estimate a probability and a likely impact, and it usually fits neatly into an existing risk register. Fire, fraud, equipment failure and currency movement all behave this way. You may not welcome them, but you know how to describe them.

An emerging risk is different in kind, not just in size. It is still taking shape, so the evidence is thin and often contradictory, and the usual questions of how likely and how costly cannot be answered with any confidence. Generative AI adoption, climate-driven supply disruption, and rapid shifts in regulation are recent examples. Each began as a faint signal that was easy to dismiss, and each became material faster than traditional risk cycles could react.

The gap between the two creates a specific problem. A standard probability and impact matrix rewards risks that can be quantified, so an emerging risk with unclear numbers scores low and quietly drops off the register, right up until the moment it does not. Boards then ask why nobody flagged it, when the method itself was filtering it out.

ISO/TS 31050 is built around this exact gap. Instead of asking you to quantify a risk you cannot yet measure, it gives you techniques for detecting weak signals, for judging how quickly a risk is moving, and for choosing a proportionate response while the picture is still forming. That shift, from measuring what is known to managing what is uncertain, is the core skill taught in the ISO/TS 31050 Emerging Risks Manager course, and it is what separates emerging risk work from conventional risk management.

Related Information

  • Conventional risk: known, historical, quantifiable
  • Emerging risk: developing, uncertain, little or no historical data
  • Examples: generative AI, climate-driven disruption, fast-moving regulation
  • Standard probability-impact matrices tend to filter emerging risks out
  • ISO/TS 31050 manages uncertainty instead of forcing quantification

The risks that hurt most are the ones that scored too low to make the register. Emerging risk work is about catching them while they still look like noise.

Alexis HIRSCHHORN
Alexis HIRSCHHORN

ISO 22301 Lead Implementer • ISO 27001 Lead Implementer

Browse all Governance, risk & compliance training courses

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.