Hero image for "The Last Disaster Is Running Your Risk Model"

The Last Disaster Is Running Your Risk Model


Somewhere in a boardroom after the 2008 financial crisis, a risk committee added "mortgage-backed securities" to their list of things to worry about. Which would have been useful advice — in 2005.

That's the availability heuristic at work in its most expensive form: we don't assess risk based on probability, we assess it based on how easily a scary example comes to mind. And what comes to mind most easily is whatever just happened.

Tversky and Kahneman identified this pattern in 1973, but the core mechanism is worth restating because it's so easy to miss in yourself. Your brain has a question — how likely is this? — and instead of calculating, it substitutes a faster question: how easily can I think of an example? Availability (ease of recall) gets mistaken for probability (actual frequency). A plane crash dominates your memory because it was dramatic and widely covered; statistically, you're far more likely to be hurt driving to the airport. The vividness creates an illusion of frequency.

This would be a manageable quirk if we only used it to decide whether to take the highway. The problem is that we use it to run companies.

Vivid Events Crowd Out Base Rates

Here's what this looks like in practice. A research summary on behavioral biases in financial markets notes that availability heuristics distort risk assessments as investors overweight recent or emotionally salient events. That's the academic framing. The street-level version: after a market crash, investors flee to cash and stay there too long. After a long bull run, they pile into equities at the worst possible moment. The most recent vivid event becomes the de facto probability estimate.

This isn't limited to finance. Risk Management Magazine's analysis of cognitive biases in enterprise risk management points out that biases can show up at any stage of the ERM process — from risk identification through monitoring and reporting. The availability heuristic tends to hit hardest at the identification stage: teams catalog the risks they can easily imagine, which skews heavily toward whatever went wrong recently, either in their own organization or in a competitor's headline.

The result is a risk register that functions more like a post-mortem than a forward-looking assessment. You've documented the last war in detail. The next one is underrepresented.

The Framework Doesn't Fix the Bias

There's a tempting belief that if you just install a rigorous enough process — COSO ERM, ISO 31000, a proper risk matrix — the human bias problem goes away. It doesn't. As Risk Management Magazine notes, "regardless of the framework or the level of structure it may provide, there is one component that cannot be removed from the risk management process: human bias."

Frameworks are populated by humans who still decide which risks to include, how to score them, and which ones to escalate. If the person filling out the risk register just read three articles about supply chain disruptions, supply chain risk gets a 9. If cyberattacks haven't hit anyone they know personally this quarter, cyber gets a 6. The structure is sound; the inputs are availability-contaminated.

This is also where AI tools can make things worse rather than better. A Harvard Business Review analysis by Grace Chang and Heidi Grant argues that cognitive bias in AI systems isn't just baked into training data — it's shaped by the humans using the tools. When people interact with AI-assisted risk or decision systems, they tend to anchor on the AI's outputs in ways that can amplify whatever biases shaped those outputs in the first place. A model trained on recent incident data will reflect recent incident data. Ask it what to worry about and it will tell you what just happened.

What Actually Helps

The availability heuristic is hard to eliminate, but it's possible to design around it in a few specific ways.

The most direct intervention is forcing base-rate exposure before the discussion starts. Before a team assesses a risk, show them the historical frequency data for that category — not the memorable cases, the actual distribution. This doesn't override the heuristic entirely, but it gives the brain something concrete to anchor to besides the last vivid story.

The second intervention is deliberately searching for risks that aren't in the news. If your team can easily name five examples of a risk, that's a signal it may be overweighted. The harder question is: what categories of failure are we finding it difficult to imagine? Those are the ones that deserve more structured attention, precisely because they're not coming to mind easily.

The third is scheduling risk reviews on a calendar cadence rather than in response to events. Event-triggered reviews almost guarantee availability bias — you're reviewing risk precisely when a vivid example has just made certain risks feel enormous. A quarterly review with no triggering incident forces you to assess probability rather than recency.

I covered a related version of this in the issue on how your brain treats "recent" as "likely" — the availability heuristic is the underlying mechanism there too. But the risk management context makes the stakes concrete in a way that's worth sitting with. The risks most likely to hurt your organization are probably the ones that feel hardest to imagine right now. That difficulty isn't evidence they're unlikely. It's evidence your brain hasn't been recently reminded of them.

That's the gap worth closing.