From colours to money
Expected exposure is the standard way to make risks comparable: impact multiplied by probability. A €2,000,000 impact with a 10% probability is an expected exposure of €200,000, the same as a €400,000 impact at 50%. Once every risk on the register carries a money figure, mitigation spend can be judged against what it actually buys, and the loudest risk stops automatically being treated as the largest.
The trap in the average
Expected value is honest across a portfolio and misleading on a single event. If the integration fails, you do not experience 10% of a €2,000,000 loss; you experience the full €2,000,000 or nothing. For one-off decisions the question expected value cannot answer is the one that matters most: can the organisation absorb the impact if the risk lands in full? A tolerable expected exposure attached to an intolerable impact is not a tolerable risk.
What the figure hides
- Single-point probabilities on events that have never happened before. Nobody knows whether the ERP cutover risk is 10% or 25%, and the exposure figure doubles between those guesses.
- Impact estimates that stop at the direct cost, the write-off, and miss the slower losses: customers, regulator attention, the leadership year consumed by recovery.
- Correlation. Three risks scored independently can share one cause (the same delivery partner, the same data migration), and land together.
- Tail severity. Two risks with identical expected exposure can differ enormously in worst case, and the register treats them as twins.
Where this helps in practice
The best use of the figure is comparative and repeated: score the register the same way each quarter and watch what moves. It also disciplines mitigation proposals: spending €150,000 to mitigate a €200,000 expected exposure needs a better justification than the colour changing from red to amber.
Limitations
Two inputs cannot describe a distribution. The calculator has no view on correlation, timing or velocity, and it inherits every bias in the impact and probability estimates. Treat the output as a comparison device and a challenge prompt, never as the risk's true size.