Unknown Risks: How To Contingency Plan For These Unknown Risks

Contingency planning flowchart drawn by hand

What Is an Unknown Risk?

An unknown risk (or “unknown-unknown”) is an unforeseen vulnerability or threat that standard risk assessments cannot identify because the organisation has no historical precedent or playbook for it.

Risks exist in all organisations; their unknowns are a fundamental property of most risks hidden in operations, and they can evade traditional risk management approaches.

How can an organisation handle these invisible threats to become more resilient and resistant to disruptions in the face of uncertainty?

Risk TypeDefinitionDetection MethodMitigation Strategy
Known RiskIdentified threat with historical precedentRisk Register, AuditsStandard Operating Playbooks
Unknown RiskBlind spot or unexpected disruptive eventHorizon Scanning, Stress TestingFlexible Contingency Planning & Agile Teams
Known Risks vs Unknown Risks

Why Is Contingency Planning Important for Organisations?

Contrary to what some might believe, contingency planning isn’t a tedious administrative task for bureaucrats. It’s a crucial part of good strategic risk management.

Drawing on lessons from exercises and the real world, it becomes the script for how an organisation should run during a crisis. In other words, when the proverbial hits the fan, you’re not frantically searching for ideas—you have a plan. This plan turns potential knockout blows into manageable scenarios and helps you keep calm and carry on.

How Do Organisations Prepare for Unpredictable Events?

Of course, much of this preparation consists merely of writing documents—after all, business continuity planning calls for drafting plans and documents. However, good contingency planning also necessitates achieving a culture of preparedness.

Here, every employee is clear on how they might contribute during duress. This also requires training and flexibility; your ‘plan’ should include general strategies that can change as new information emerges. Suppose you prepare by learning and practising the givens of your operation. In that case, you’re better prepared when the unexpected happens. You’re on your toes because you’re willing to learn what the road ahead might look like tomorrow.

How Do You Identify Potential Unknown Risks?

What Are Unknown Risks?

A risk register or a risk assessment process does not pick up unknown risks. They’re the ‘known unknowns’, the blind spots in an organisation’s operational risk profile. They come from left field – technological change, geopolitical change or a fast-paced change in market conditions. Unlike the known risks, you won’t have a playbook to follow on managing them. You’ll need to do something different.

Common Types of Unexpected Threats

We’re talking about everything from cybersecurity hacking to supply chain disruption, from ‘natural’ disasters like hurricanes and earthquakes to changing regulations. Because threats are diverse, diverse solutions must be found.

Understanding common categories of disruptive events helps you build a broad repertoire of control, mitigation, and counteracting strategies. That’s the only way to stay ahead of the next disruptive event.

Techniques for Uncovering Hidden Vulnerabilities

Identifying these hidden vulnerabilities requires a mix of analysis and creativity. Techniques such as horizon scanning, scenario planning, and stress testing can help identify threats that might otherwise go unseen. At the same time, encouraging open dialogue with stakeholders and building a culture of continuous improvement can surface risks that would otherwise remain hidden, enabling a more effective approach to risk management.

How Do You Evaluate the Impact of Unforeseen Risks?

Assessing the Impact and Probability of Risks

Successful risk assessment involves evaluating the likelihood of risks and their potential outcome.

This dual analysis allows organisations to determine which threats demand immediate attention and resources.

Using qualitative and quantitative techniques, organisations can develop a risk matrix that visually presents the likelihood, severity, or impact of various risks to decision-makers and guides contingency planning.

Prioritising Risks Based on Potential Impact

Not all risks are equally important. Some are existential threats to the organisation, while others cause only minor disruptions.

Prioritising how much each risk harms the bottom line ensures the most critical risks are addressed first.

Examining the risk’s financial, operational, or reputational consequences may be prudent in assessing relative risk. This can help leaders prioritise the vulnerabilities to which they wish to allocate resources.

Tools and Methods for Effective Risk Analysis

Many risk analysis tools, from SWOT analysis to PESTLE analysis to risk registers, provide transparent approaches to analysing risks; they formalise the process, helping identify root causes and take action.

Monte Carlo simulations and fault tree analysis are more advanced risk analysis and modelling tools; they offer analytical routes a risk manager or contingency planner can use to strengthen the contingency plan and make it more nuanced and flexible in assessing risk scenarios.

GetRiskManager logo with sign up now button for risk management solutions.

How Do You Develop a Robust Risk Contingency Plan?

Key Components of a Contingency Plan

A comprehensive contingency plan contains several components: identifying the risk, rating the risk, creating response strategies, formulating communications strategies, and outlining recovery protocols.

Each component of a cohesive contingency plan contributes to its overall functionality, allowing the organisation to anticipate and address diverse potential crises.

Establishing Clear Objectives and Goals

Clear objectives and goals are fundamental. They make the contingency planning effort measurable and actionable. They should be SMART: Specific, Measurable, Achievable, Relevant, and Time-Bound. A SMART goal should specify what should be done, enabling the leadership group to develop a clear ‘to-do’ list. It allows leaders to track and measure progress, reporting status to external constituencies and the organisation’s leadership team. Leaders achieve SMART goals by defining the organisation’s fundamental goals and objectives, mission, and strategic objectives in quantifiable terms; linking the risks faced to those objectives; and following through with the actions.

Creating a Step-by-Step Action Plan

A step-by-step action plan specifies these steps in detail. For example, if a risk has been identified, the organisation should produce an action that maps out how that risk should be approached, for example, by specifying who will do what, the order in which tasks need to be carried out, and what resources need to be brought in to execute the plan. When a crisis is unfolding, this can help to deconstruct the situation into manageable steps and allow organisations to act in a coordinated manner.

How Do You Build an Effective Cross-Functional Response Team?

Identifying Key Stakeholders and Their Roles

Create a cross-functional response team by identifying and bringing in stakeholders from operations, finance, human resources, IT, communications, etc., to articulate roles and define the logistics of the contingency plan. When all these departments are included, the organisation can reach a consensus on its course of action because it draws on each department’s specific competencies when tackling the contingency.

Training and Empowering Your Response Team

It makes sense to train them so they know what to do when the time comes, but it’s also essential to prepare the entire response team to act in a crisis.

Hold regular training sessions and drills with staff, simulating the tasks they would perform in an emergency. You’ll quickly realise that empowered staff tend to take charge. Drills might not have seemed like an obvious priority for a leader whose subsequent burden was to deal with a growing crisis. However, creating a culture of trust in the response team and giving everyone the freedom and ability to make the right decisions, even in challenging situations, will pay dividends.

Importance of Cross-Departmental Collaboration

Cross-departmental cohesion is essential for effective contingency planning. Removing the silos that often emerge within organisations, so people from different departments can communicate more freely, will help ensure everyone in the organisation responds to crises in the same way. This will give people a better understanding of interdependencies across the organisation, which will support risk assessments and response.

How Are Scenario Planning and Simulation Exercises Conducted?

Conducting Scenario Analysis to Anticipate Risks

Scenario analysis is a farsighted approach that models future events that might affect your organisation.

Organisations can prepare for emerging risks by designing and evaluating scenarios and developing reactive strategies to minimise their impact. This approach helps leaders prepare for various outcomes, making the future less unpredictable.

Designing Effective Simulation Exercises

By testing contingency plans against simulation exercises, respondents and other stakeholders can enhance the organisation’s readiness.

In successful simulation exercises, respondents must make tough choices and gauge the reactions of peers, clients, and the media.

For the simulation to be effective, the replica crisis must be realistic, taxing, and ongoing. Doing so prepares and shapes the organisation for when the event does occur.

Lessons Learned from Real-Life Cases

Real-life cases can inform contingency planning. Drawing upon other organisations’ successes and failures when exercising contingency plans provides detailed evidence for organisations to use. Case examples can show best practices, common pitfalls, and new or innovative approaches to contingency planning.

What Are the Best Communication Strategies During a Crisis?

Crafting Clear and Concise Messages

Ensure clear, concise communication to provide critical information to all stakeholders quickly.

Maintaining credibility and trust with stakeholders is crucial to communicating clearly, transparent, and easily understood.

In a crisis, communicators must keep the key messages and information needs in mind to keep internal and external stakeholders informed.

Managing Internal and External Communications

Effective communications inside and outside an organisation are crucial to preserving command and control and instilling confidence when a crisis strikes.

Internal communications can keep employees informed, engaged and aligned with response efforts.

External communications can reassure customers, partners, regulators and the media that your organisation remains in control.

Leveraging Technology for Real-Time Updates

Technology can enable organisations to communicate almost anything, anytime, anywhere. Mass notification systems, social media platforms, and even collaboration software enable crisis teams to communicate in real time with internal and external stakeholders. This ensures that critical information, especially during a crisis, is shared with as many people as possible and as soon as possible. Technology is a powerful tool for speeding up the crisis communication process, thus preventing the buildup of uncertainty and confusion.

How Should Assets and Budgets Be Allocated for Resource Management?

Inventorying Available Resources and Capabilities

Effective resource management starts with taking stock of what you have on hand. This includes personnel, equipment, facilities, technology, and financial assets, providing an overview of the breadth of resources available. Only then do you know what you have and can see what resources are available to apply to a crisis or other task. Those resources can drive and constrain decisions, enabling and limiting what you can do.

Budgeting for Emergency Situations

From a financial perspective, it means earmarking resources for contingency planning and crisis‑response activities. This allows you to purchase training and simulation capabilities, communications stores, and other equipment and supplies. By building flexibility in advance, an organisation can help mitigate the potential disaster response costs on its day‑to‑day operations.

Securing Backup Resources and Partnerships

Having backup resources and partnerships can also boost an organisation’s resilience. Backup resources can include extra suppliers, redundant systems, and contingency staffing arrangements. Partnerships with other organisations, such as mutual aid agreements and industry coalitions, can also assist an organisation in a crisis. Establishing relationships in advance makes these backups available when they are most needed.

How Do You Monitor and Revise a Risk Contingency Plan?

Establishing a Monitoring System for Ongoing Assessment

A robust monitoring system will be crucial for tracking the contingency plan’s effectiveness. Track relevant Key Performance Indicators and Risk Metrics; track simulation learnings and live events as they occur. Regular monitoring will help identify emerging risks, inform plan performance, and enable adjustments as needed to keep the plan fit for purpose.

Regularly Reviewing and Updating the Plan

The plan cannot be static and should be considered a living document. Review contingency plans while they are still in draft form. Moreover, processes should be in place to guarantee that a review of the plan is scheduled at least annually or, to take advantage of the learning opportunities from recent events, have triggers that prompt reviews after organisational or process changes or following an unforeseen event that might have offered essential insights into how the contingency plan could be improved.

Incorporating Feedback and Continuous Improvement

Feedback from all stakeholders, including customers, suppliers and employees, is invaluable in refining the plan. After each round of simulations or actual incidents, hold after-action debriefs and solicit input to identify what worked and where to improve. Improvement means addressing identified weaknesses and incorporating any new practices and technologies that emerge.

How Do You Implement Effective Risk Training and Awareness Programs?

Importance of Regular Training Sessions

Regular training sessions are necessary to ensure all team members know how to execute the contingency plan and understand each person’s role within the team. Practical, hands-on exercises follow presentations to ensure everyone is confident in their role in a crisis. Practising the contingency plan and learning others’ roles will increase employees’ confidence and competence when something happens. This will help avoid mistakes during a crisis and increase the team’s resilience and ability to recover when overall procedures fail.

Creating Awareness Among Employees and Stakeholders

The awareness programme should extend beyond the response team to encompass all employees and other key stakeholders. It should communicate the value of the contingency plan, clarify what’s expected of everyone, and instil vigilance and preparedness in the culture. Building awareness across the organisation ensures contingency planning objectives are understood broadly and that personnel respond when called upon.

Best Practices for Effective Training Programs

These training programmes are effective because they are interactive, diverse and tailored to an organisation’s specific requirements. Several types of training – workshops, e-learning modules or training exercises in the field – can be used depending on the learning preferences and styles. Beyond hiring internal trainers, external experts can enrich the scope of training by adding new perspectives and deeper insight.

What Legal and Regulatory Factors Must Be Considered in Risk Planning?

Understanding Compliance Requirements

Legal and regulatory measures are essential to the planning process. When crafting your plans, clearly separate business-controllable consequences from those outside your company’s control; avoid regulatory and legislative failures; and ensure proper information controls. Employment law, health and safety regulations, and environmental regulations will influence your plans. The crisis team and organisation must know how their actions align with data protection legislation. Changes to these legal and regulatory measures will often affect your organisation’s ability to respond to future incidents.

Addressing Legal Liabilities in Your Plan

Your contingency plans should include this legal risk analysis to avoid potential legal liability if it’s alleged that some decisions made during the crisis led to adverse consequences. For example, if your plan predicts risks or liabilities resulting from contract breaches, accusations of negligence, or regulatory violations, include legal risk analyses and mitigation steps to minimise the organisation’s legal risk if a problem arises.

Navigating Regulatory Challenges

This is especially difficult in highly regulated industries. Good crisis contingency planning recognises these regulatory challenges and crafts the plan accordingly. This might include maintaining contact with regulators in advance, preparing for the inspections and audits that often follow a crisis, and documenting responses in real time so they comply with regulatory expectations.

Final Thoughts

Unknown risks dictate that effective contingency planning is crucial to maintaining resilience and organisational readiness for an uncertain future.

Suppose the nature of unknown risks remains ambiguous. In that case, conducting robust risk assessments and developing well-founded contingency plans becomes central to managing risk.

An effective plan for the unforeseeable includes creating a cross-functional response team, conducting scenario planning and simulation, and setting up an official communication strategy for foreseeable or unforeseeable disruptions.

Organisations that plan proactively and have tested plans and procedures are called resilient organisations because they are not caught flat-footed when times are bad.

Building and sustaining a culture of readiness, continual improvement, and cross-organisational collaboration means the organisation can prepare for a crisis event.

Training and awareness programmes can make contingency plans more effective.

The future of strategic contingency planning is built on innovation and adaptability. We cannot predict new risks in line with new technological opportunities in the business world. We can be sure, however, that organisations must adapt to these emerging risks and new business environments. Collaborating with technology, building a learning culture, and staying proactive will again be crucial for companies facing uncertainty, helping them make the best of the opportunities that difficult times bring.

Frequently Asked Questions

What are unknown risks in project management?

Unknown risks (often called “unknown unknowns”) are unexpected threats or disruptions that cannot be identified during standard risk assessments because there is no past precedent, data, or playbook for them within the organisation.

What is the difference between known risks and unknown risks?

Known risks are anticipated threats that can be listed in a risk register and mitigated using existing procedures. Unknown risks are completely unexpected blind spots, such as sudden geopolitical shifts, new technologies, or unprecedented supply chain failures, that require flexible contingency strategies rather than rigid playbooks.

How do you prepare for an unknown risk?

Organisations prepare for unknown risks by creating adaptable contingency plans, training cross-functional response teams, running realistic simulation exercises, and fostering a culture of rapid communication rather than relying on fixed standard operating procedures.

What are the key steps to contingency planning for unexpected threats?

The core steps include identifying potential vulnerabilities through horizon scanning, building a cross-functional crisis response team, establishing clear SMART recovery objectives, defining emergency communication channels, and continually running simulation drills.

How often should an organisation review its risk contingency plan?

Contingency plans should be reviewed at least annually, and immediately after any major organisational shift, regulatory change, key personnel transition, or simulated crisis drill.

Similar Posts