Changing the odds or changing who pays: choosing risk responses that actually reduce exposure

Some risk responses make an event less likely; others only decide who pays when it happens. How to tell them apart, why design beats procedures, and how to choose the mix deliberately.

A risk report lists eleven serious risks. Every one has an owner, a response and a review date. The meeting works through the page, notes that responses are in place, and moves on in twenty minutes. The question almost never asked is what those responses actually consist of. For each risk, has the chance of the event fallen since the last meeting, or has the business arranged, at some cost, who pays when it happens?

Both are legitimate. They are not the same purchase. A business that has bought the first has less exposure than before. A business that has bought the second has the same exposure and a better claim. Read a page of green response lines and you usually cannot tell which you are looking at, because most registers record both in the same column. Over time, the business’s real risk position drifts away from what its report appears to say.

This article explains the difference between responses that change the odds and those that change who pays, why the second kind tends to win by default, why changing the design usually beats adding procedures, and how a small business can choose its mix of responses deliberately. It is general information. Work health and safety, food safety and other laws may require particular controls whatever the cost; your regulator and adviser can help with those obligations.

Two families of response

Sort risk responses by what they actually move and they fall into two groups.

Responses that change the odds alter the situation in which the event might happen: a different design, a different sequence of work, a different supplier, a prequalification check, a backup built in at the source, a decision delayed until the unknown is known, or a scope that no longer includes the hazardous step. The chance of the event really falls.

Responses that change who pays leave the chance where it is and rearrange who absorbs the result: insurance, indemnities, warranties, liquidated damages, a contingency fund, a clause that moves the cost to someone else. The event is just as likely; the business has arranged compensation.

Neither family is better in general. A rare event with a loss that money can fully repair is an excellent candidate for insurance, and the alternative might be expensive over-engineering. The point is that they are different purchases, and a business should know how much of each it has bought.

Changes the oddsChanges who pays
ExamplesRedesign, substitution, second supplier, testing before commitment, better sequencingInsurance, indemnities, warranties, contingency funds, contract clauses
What it changesLikelihood, and sometimes consequenceWho carries the financial result
Keeps working without renewal?Usually, once built inNo: it is repriced, renewed or disputed
Restores what you care about?Avoids the lossRestores money, not necessarily reputation, customers or time
Typical costTime, rework, a relationship, a design changeA premium, a price, a signature

Why “who pays” wins without a decision

The two families have different politics, and the politics usually decide the mix.

Changing the odds requires someone to give something up. A different sequence costs time. A different supplier costs a relationship and a new quote. A design change costs rework and, once the schedule is set, credibility. Each has an identifiable person who loses, and that person is usually in the room.

Changing who pays mostly requires money and a signature. Nobody concedes anything, no date moves, and the cost reads as prudence. Under pressure, which is most of the time, a business buys insurance, indemnities and contingency faster than it can hold the meeting that would consider a redesign. Both produce a green line and a named owner. So a business can drift into fragility one sensible approval at a time.

The two families also behave differently when conditions change. Compensation is provided by others, who can reprice it, withdraw it or dispute it at exactly the moment it is needed. A reduction in likelihood built into a design or process keeps working without anyone renewing it.

Where paying is the right answer: a rare event, a loss that is bounded and financial, and a counterparty able to pay. Where it is not: no insurance policy returns a lost customer, an injured worker, a cancelled licence or years of reputation. Insuring those exposures does not reduce them at all.

Mitigated is a claim, not a state

The habit worth challenging is treating a risk as “mitigated” as though that were a settled fact. A response is an assertion that something has changed. The register records the assertion, the owner and the date; it rarely records what changed and almost never the evidence.

Many risk worksheets make this worse. Some re-rate only the consequence after a response, with no space to show whether the likelihood moved. A form that cannot record a change will not prompt anyone to ask for one. Two simple additions help: a field for likelihood after the response, and a field for the evidence that shows it moved, such as a test result, a defect rate, an inspection or a completed change.

Design it out before you manage it

Some risks should never reach day-to-day operations in their original form. If a different layout, technology, process, location or sequence would substantially reduce an exposure, the risk discussion belongs in design, not in a procedure written afterwards.

Australian work health and safety regulations describe a hierarchy of control measures that is widely used beyond safety:

  1. Elimination: remove the hazard, activity or interface altogether.
  2. Substitution, isolation and engineering: use a safer material, method or location, separate people from the hazard, or design equipment to prevent or contain the event.
  3. Administrative controls: procedures, training, signage, supervision.
  4. Personal protective equipment: the last line, relying entirely on individual behaviour.

The higher controls do not depend on people remembering to do the right thing every day. The lower ones do. That is the difference between designed resilience and managed vigilance. Both are sometimes necessary, but they are not equivalent.

One published environmental assessment of a mining project shows the idea well: the initial design involved mining beneath watercourses, and the preferred design simply avoided doing so. The treatment was not another inspection or procedure; the activity creating the exposure was removed. The same thinking applies at any scale. A workshop can manage solvent spills with procedures and spill kits, or reduce the quantity stored, bund it and keep it away from drains. An office can rely on staff not to open sensitive files, or set permissions so they cannot.

Every control is a future obligation

Controls are often compared only on what they cost to introduce. A procedure is cheap to write but can be expensive to sustain, because it needs training, supervision, checking and repeated compliance for as long as the risk exists. The pricing your risk controls article covers how to put a lifetime price on a control. Before choosing, ask:

  • Does the control work without anyone having to act?
  • How often must it be inspected, tested or renewed?
  • What happens when experienced staff leave or work is outsourced?
  • Does it still work in abnormal conditions, such as a power cut, a rush or a holiday period?
  • Does it create new interfaces or ways to fail?
  • Could the exposure be removed instead?

Several weak controls do not automatically add up to one strong one. If they all rely on the same person, the same maintenance routine or the same system, they can fail together. The making a risk register change decisions article covers how to check whether barriers are genuinely independent.

The hierarchy guides judgement; it does not replace it. Eliminating one exposure can reduce capacity, raise costs, create a different hazard or move the problem elsewhere. Compare the whole-of-life consequences, and be honest when a lower-order control is chosen for commercial reasons rather than because nothing better was possible.

Urgency: how long you have to buy information

When assessing a risk, many methods ask for likelihood and consequence. A useful third question is urgency: how long before a response must be committed?

Urgency turns a risk into an investment question. A serious threat with a long lead time is an argument for spending money to learn, such as a trial, a test or an inspection, rather than buying cover straight away. Where the answer is months rather than days, ask what could be learned in that time and what it would cost, and compare it with the cost of insurance or contingency. One caution: a test run by the people who want a particular answer tends to produce that answer, so have someone independent check it.

Ratings also expire. A risk assessed as low today may be high in six months because circumstances changed. Give important ratings a re-test date.

Who owns the design decision

When a risk remains after design, it is often unclear who owns it. The person managing the job coordinates, specialists advise, operators inherit and the owner approves. Each may believe another person accepted the risk. For any significant remaining risk, be clear about:

  • who can change the design;
  • who accepts the remaining risk;
  • who operates the controls;
  • who pays for checking and maintaining them;
  • who can stop the work if the risk becomes unacceptable.

A worked example

This is an illustration. A wholesale bakery supplies bread and rolls to cafés and grocers. Its most serious risk is undeclared allergen cross-contact: sesame from its seeded products reaching products labelled sesame-free. Within a few weeks of the risk being raised, the business takes out product recall insurance and asks its seed supplier for an indemnity. Both are sensible. Neither changes the chance of cross-contact at all.

The owner then compares responses that would change the odds, over five years:

  • Procedures only (administrative). A thorough changeover clean between seeded and sesame-free runs takes about 40 minutes a day. Over 250 production days that is about 167 hours, or $7,500 a year at $45 an hour, plus about $1,500 a year for allergen swab tests: $9,000 a year, $45,000 over five years. It relies on the clean being done properly every day, including on the busiest mornings.
  • A separate seeded-products area (isolation and engineering). A small partitioned area with its own mixer and utensils costs about $22,000 to fit out. Some cleaning and testing is still needed, at about $2,600 a year: $35,000 over five years, with far less reliance on daily behaviour.
  • Removing sesame altogether (elimination). Seeded products bring in about $18,000 a year in sales. But the owner checks with customers and finds that the two cafés buying most of them also buy about $60,000 a year of other products and would likely move their whole order. The real exposure is about $78,000 a year of sales.

The owner chooses the separate area, keeps a shorter changeover procedure for the mixer that remains shared, and keeps the recall insurance, recorded honestly as protection for the cash cost of a recall, not for customer trust. The register now shows two lines for this risk: likelihood after the response, with the evidence being monthly swab results, and the insurance, shown as a “who pays” response with its limits and excess.

How this applies to a small Australian business

Small businesses are often sold “who pays” responses, because insurers, finance providers and contract templates make them easy to buy. Practical steps:

  • Label each response on your risk list as changing the odds or changing who pays.
  • Check the proportion. If almost everything is insurance, indemnities and contingency, ask whether that was a choice.
  • For each “who pays” response, state what it restores. If the honest answer is money but not the thing you care about, it is not protection for that risk.
  • Apply the hierarchy of controls when designing new layouts, products, processes and jobs, not only after incidents.
  • Count the lifetime cost of procedures and checks, not just the cost of writing them.
  • Ask how long you have before you must commit, and whether a test or trial would be worth buying first.
  • Record evidence that a likelihood has actually fallen.
  • Check legal obligations separately. Safety, food, environmental and product laws may require particular controls. Your regulator and an adviser can help.

Signals worth watching

  • High-likelihood risks whose only responses are insurance or contract clauses.
  • Responses described as “procedures” for hazards that could be designed out.
  • Several controls relying on the same person or system.
  • Risks rated “mitigated” with no evidence of any change.
  • Insurance renewals with rising premiums, new exclusions or lower limits.
  • Design reviews that never mention risk.

Common mistakes

  • Treating insurance as risk reduction. It changes who pays, not what happens.
  • Choosing controls on introduction cost rather than lifetime cost.
  • Defaulting to procedures when a design change is available.
  • Counting barriers without checking that they are independent.
  • Leaving the remaining risk unowned after design decisions.
  • Never re-testing ratings after circumstances change.

Frequently asked questions

Is insurance a waste of money? No. It is the right tool for many risks, especially rare events with bounded financial losses. The point is to be clear about what it does and does not do.

What if we cannot afford a design change? Then choose the best practical control, record why the stronger option was not chosen, and revisit the decision when circumstances change, such as at the next refit, equipment replacement or lease renewal.

Do contract clauses reduce risk? Usually they move the financial consequence. Some clauses, such as requiring a supplier to meet tested specifications, can also change the odds. Look at what each clause actually changes.

Where do contingency funds fit? A contingency fund pays for consequences; it does not make the event less likely. It is still worth having for risks you choose to accept.

How do we know a control works? Look for evidence: test results, defect rates, inspection records, incident trends. A control nobody checks is an assumption.

Questions to ask

  • For each of our top risks, did our response change the odds or only who pays?
  • What does each insurance policy or indemnity actually restore?
  • Which risks could we design out rather than manage with procedures?
  • What will our procedures cost to sustain over the next five years?
  • How long do we have before we must commit, and what could we learn in that time?
  • Who accepted the risk that remains, and do they know it?

Bringing it together

Risk responses come in two families: those that make an event less likely and those that decide who pays when it happens. Both have a place, but they are different purchases, and the second tends to win by default because it is easier to buy. Label your responses, check the balance, and ask what each “who pays” response really restores. Where you can, design exposures out before you manage them with procedures, because designed protection keeps working while vigilance depends on people every day. Count controls as long-term obligations, use lead time to buy information, and make sure someone knowingly owns the risk that remains.


Source: KEVOS notes, drawing on teaching material on risk response strategies, the hierarchy of control measures used in Australian work health and safety regulation and environmental risk assessment practice. Examples and figures in this article are illustrations. This article is general information, not legal, safety or insurance advice.

Need practical engineering, manufacturing or process support? KEVOS can help move the work forward.