Almost every kind of business spending has a document that states its price before money moves. A capital purchase has a business case. A purchase has an order. A new hire has a budget line. A system change has a cost estimate that someone signs. Risk treatment is different. It is usually recorded in a risk register, and a typical register lists the risk, its rating, the planned response, the owner and the date. It rarely has a column for money.
That gap has consequences. A control is approved because the risk it addresses looks large, not because its benefit exceeds its cost. Once approved, its costs scatter across maintenance, labour, subscriptions, testing fees and insurance, where nobody adds them up under the heading of the risk they were bought to reduce. After a few years, the register reads like a list of improvements achieved at no cost, while the business carries a growing set of controls whose value nobody has checked.
This article explains how to treat risk controls as purchases with a price: how to cost them, how to judge them on net benefit rather than the size of the threat, how to record the new risks that controls sometimes create, and how a small business can add a simple cost line to its own risk list without turning risk management into an accounting exercise.
Key terms
- A risk register is a list of the risks a business has identified, usually with a rating, a response and an owner for each.
- A risk treatment or control is an action taken to reduce the likelihood or consequence of a risk, such as a standby machine, a testing regime, a backup service, an inspection, a procedure or insurance.
- Inherent risk is the level of risk before a control is applied. Residual risk is the level that remains after it.
- Expected loss is a simple way of expressing risk in money: the estimated cost of an event multiplied by its likelihood over a period, such as a year.
Where the price disappears
In many businesses, the cost of a control is considered once, when options are being compared, and then dropped. The chosen control moves into the register as a response with an owner and a date. Every later review reads the register, sees no price and is never prompted to ask whether the control is still worth paying for.
Meanwhile, the costs land in different budgets. A standby machine sits in capital and maintenance. External testing sits in laboratory fees. A two-person rule for certain jobs sits in labour hours. A software backup service sits in IT subscriptions. Each is recorded correctly by the accounts, but nothing brings them together and compares them with the risks they address.
The bias towards the biggest number
When cost is invisible, the only thing left to justify a control is the size of the threat. That biases decisions towards the worst case, often without considering how likely it is. A common shortcut divides a worst-case loss by the cost of a control and presents the result as a return, ignoring both the probability of the event and the risk that remains after the control is in place. Sometimes an annual cost, such as an insurance premium or a subscription, is added to a one-off cost as if they were the same kind of number.
The result is that the loudest risk attracts the most spending, whether or not its control buys much protection.
Controls are assets with costs and side effects
A useful way to think about a control is as an asset the business has bought. Like any asset, it has:
- An acquisition cost: buying, installing and setting it up.
- A carrying cost: maintenance, consumables, testing, licences, staff time and any output given up because of it.
- A service life: after which it needs replacement or review.
- Side effects: new risks or burdens it creates.
Nothing about a control is unusual except that many businesses have quietly agreed not to write its price down.
Judge controls on net benefit
The basic test is net: expected loss avoided minus the cost of avoiding it, over the same period. Expected loss avoided is the expected loss before the control minus the expected loss after it. If a control costs $3,000 a year to own and reduces expected loss by $4,200 a year, it has a net benefit of $1,200 a year on these estimates. If it costs $7,800 a year and reduces expected loss by $600, it costs far more than it saves.
The estimates will be uncertain. Likelihoods are often guesses, and consequences can be hard to value. That is not a reason to skip the calculation. It is a reason to state the assumptions, test how sensitive the answer is to them and be explicit when a judgement is being made beyond the numbers.
Two important qualifications apply:
- Some controls are required. Work health and safety laws, food safety rules, environmental conditions, licences and contracts may require specific controls regardless of a cost calculation. For health and safety risks, Australian law requires risks to be eliminated or minimised so far as is reasonably practicable, which is not a simple cost-benefit test. Check guidance from Safe Work Australia and your state regulator. Record the cost of required controls anyway, so you know what compliance costs and can look for more efficient ways to meet the same obligation.
- Some risks could end the business. For rare but catastrophic events, an expected-loss calculation can understate what matters, because a business cannot average its way through a loss it does not survive. For these, judge controls partly on survival, not only on expected value.
A treatment cost line
Add four pieces of information to each significant control in the register:
- One-off cost to establish the control, including staff time, and which budget it comes from.
- Annual carrying cost: consumables, testing, licences, maintenance, a share of someone’s time, and any lost output.
- Review date and budget holder: who pays for the control, which is often not the person who owns the risk.
- Risks created: references to any new risks the control introduces. A blank should mean “none identified after checking”, not “not considered”.
A few rules make the cost line useful:
- Approve controls on net benefit, or state clearly why net benefit could not be calculated and what judgement was made instead.
- Compare like with like: express one-off and recurring costs over the same period, for example by spreading a one-off cost over its expected life.
- Add up the carrying costs each year and report the total as the business’s annual spending on risk controls.
- Send large controls to the right approval level, the same level that would approve capital spending of that size.
Controls can create risks
Controls sometimes introduce new risks. A standby boiler adds a confined-space hazard during maintenance. A two-person rule for site visits halves the number of visits a team can make, which may create a service risk. A stricter approval process slows urgent work. A new security system adds a dependency on its monitoring provider. These secondary risks should be identified, assessed and recorded in their own right, linked to the control that created them. Otherwise, a business cannot see how much of its risk profile it has manufactured itself.
Controls accumulate
Controls are easy to add after an incident and hard to remove later, because removing one feels like inviting the incident back. Over time, a business can carry controls that address risks that have changed, duplicate other controls or cost more than they save. A cost line makes these visible. At least once a year, review the most expensive controls and ask whether each is still needed, still effective and still the cheapest way to manage its risk.
Record insurance properly
Insurance is a control, and it is often recorded only by type: “public liability”, “business interruption”. Record the premium, the excess, the main exclusions and the limits. That shows what the insurance actually costs and what it would pay, and it helps decide whether to insure, self-insure or reduce the risk another way. Discuss cover with a licensed insurance broker or adviser.
A worked example
This is an illustration. A small manufacturer reviews four controls in its risk register. All figures are illustrative estimates.
Standby air compressor. Without it, a compressor failure is estimated to happen about once every four years and to stop production for about three days, losing about $6,000 of contribution a day. Expected loss is 25% of $18,000, or $4,500 a year. With the standby unit, an outage is expected to cost about $300 a year. Expected loss avoided is about $4,200 a year. The standby unit cost $18,000 and is expected to last ten years ($1,800 a year), plus $1,200 a year in maintenance: about $3,000 a year. Net benefit: about $1,200 a year. Keep.
External microbiological testing. Required under customer contracts and the business’s food safety program, at about $9,600 a year. Not optional, but the business now knows its cost and agrees with customers on a testing frequency based on results, which may reduce it over time.
Data backup service. A ransomware attack or major data loss is estimated at a 5% chance a year. Without good backups, the loss is estimated at $120,000. With the service, about $15,000. Expected loss avoided is 5% of $105,000, about $5,250 a year, against a cost of $2,400 a year. Net benefit: about $2,850. Even if the likelihood were only 2%, expected loss avoided would be about $2,100 a year, close to the cost, and the business would keep the service because a loss of that size could threaten its survival.
Security patrol. After a break-in that cost about $6,000 in tools, the business added a nightly patrol at $7,800 a year. The owner estimates the chance of another break-in at 20% a year without the patrol and 10% with it, so expected loss avoided is about $600 a year. The patrol costs $7,200 a year more than it saves. A cheaper alternative, better locks and lighting for about $2,500 (about $500 a year over five years) plus a monitored alarm at $600 a year, is estimated to reduce the likelihood to 8%, avoiding about $720 a year at a cost of about $1,100 a year. Still slightly negative on expected value, but far cheaper, and the owner values the reduced disruption. The patrol is replaced, saving about $6,700 a year.
Before the review, these four controls cost about $22,800 a year and nobody had added them up. After it, the business spends less, protects itself at least as well, and knows what its risk controls cost.
How this applies to a small Australian business
Many small businesses keep a simple risk list, or none at all. Adding a cost line need not be complicated:
- List your main controls, including insurance, backups, standby equipment, testing, inspections, security and procedures that take staff time.
- Estimate each control’s one-off and annual cost.
- Estimate the expected loss avoided, using rough likelihoods and consequences, and record your assumptions.
- Separate required controls from discretionary ones, and confirm obligations with the relevant regulator or adviser.
- Look for secondary risks that controls create.
- Review the most expensive controls each year.
- Talk to your accountant and insurance broker about costs, cover and alternatives.
The articles on business continuity planning and cost-benefit analysis for business decisions cover related methods.
Signals worth watching
- Controls approved with no named budget or cost.
- Residual risk ratings improving year after year with no visible change in spending.
- Insurance recorded by type without premium, excess or limits.
- Controls whose budget holder cannot be named.
- A register that has never recorded a risk created by a control.
- Controls added after incidents and never reviewed.
Common mistakes
- Approving controls on the size of the threat alone.
- Ignoring likelihood in calculations.
- Mixing annual and one-off costs without a common period.
- Treating required controls as optional, or optional ones as required.
- Forgetting the risks controls create.
- Never retiring controls.
- Relying only on expected value for risks that could end the business.
Frequently asked questions
Is this too complicated for a small business? It need not be. A spreadsheet with a few columns for cost, expected loss avoided and assumptions is enough. The aim is to make costs visible, not to achieve precision.
What if we cannot estimate likelihood? Use ranges, such as once every two to five years, and see whether the decision changes across the range. If it does, make the judgement explicitly and note it.
Does cost-benefit thinking apply to safety? Safety obligations are set by law and are not a simple cost-benefit calculation. Recording costs still helps you find efficient ways to meet those obligations, but take advice on what the law requires.
How often should we review controls? At least annually, and after any incident, significant change in operations or change in insurance terms.
Questions to ask
- What did we spend last year, in total, on the controls in our risk register?
- For our three most expensive controls, what expected loss does each avoid, and who estimated it?
- Which controls were approved on cost compared with benefit, and which on the size of the threat alone?
- Which budget pays for each major control, and does that budget holder know why?
- Which risks exist because an earlier control created them?
- Which controls would we not add today if we were starting fresh?
Bringing it together
A risk register without prices is a shopping list with the amounts removed. Treat each control as an asset with a one-off cost, a carrying cost, a service life and side effects. Judge discretionary controls on expected loss avoided minus cost, over the same period, while respecting legal obligations and the special weight of risks that could end the business. Add up what controls cost each year, record the risks they create and retire those that no longer earn their place. Seeing the price of protection is the first step to buying the right amount of it.
Source: KEVOS notes. Examples and figures in this article are illustrations, not actuarial estimates. This article is general information, not legal, insurance or safety advice.