Type: Node / Scoped Outcome-Uncertainty Parameter
Working Definition: Risk is a scoped outcome quantity or distribution — a parameter, under a declared measure, for a specified outcome and unit of analysis, relative to a reference scope, stated conditions, and a time horizon. The parameter's value may hold independent of whether it is known or estimated. A Risk Estimate is a structured representation assigning an estimated value to that parameter, which may be asserted or externalized as a Claim; a Risk Score is a derived model representation of one or more Estimates; institutional use is a further, separate governed act. Whether a Risk parameter's value is treated as an objective propensity, an observed frequency, a model-relative probability, an expected loss, or another construction depends on its declared measure's own semantics — this entry does not settle those interpretations universally. Neither Risk, a Risk Estimate, nor a Risk Score by itself confers institutional standing, establishes a Concern Hypothesis, diagnoses a person, or authorizes action. Institutional use is the separate layer in which classification, Recognition, Decision, prioritization, or intervention may occur — and must derive its force from that layer's own governing basis.
Function in the Grammar: Risk keeps several things separate that ordinary usage, and unsafe institutional practice, routinely collapse into one number. First, the Risk parameter — the scoped outcome quantity or distribution being characterized: outcome, unit, reference scope, conditions, horizon, and declared measure. Second, its value — what that parameter actually is, under the measure's own declared semantics, independent of whether anyone knows or has estimated it, exactly as a Danger relation may hold before anyone has appraised it. Third, a Risk Estimate — a structured representation assigning an estimated value to the parameter, which may be asserted or externalized as a Claim, produced under a disclosed method and evidential basis, and capable of being wrong, uncalibrated, or inapplicable like any other estimate. Fourth, a Risk Score — a derived artifact or model output that compresses, maps, ranks, or categorizes one or more Estimates, which may legitimately produce a model-relative tier such as "high," but confers nothing by doing so. Fifth, institutional use — the separate layer in which classification, Recognition, a Decision, prioritization, or intervention may occur, governed entirely by Decision, Recognition, Accountability, and Enforcement's own existing machinery, not by Risk itself. None of these entails the next: a well-formed Risk parameter does not entail that any particular value has been established, that anyone has estimated it, or that a Score or institutional use will ever follow; the value's holding does not entail that anyone has estimated it; an Estimate can exist, be well-formed, and even be accurate, without any Score or institutional use ever following it; a Score can be produced from a well-supported Estimate and still be wrong or miscalibrated; and institutional use can occur that is not warranted by, or does not match, the Estimate or Score it claims to rest on.
This separation is not a stylistic preference. concern-hypothesis.md already carries a strong, specific, published prohibition directly relevant here: within the Concern Hypothesis grammar, "a numerical likelihood, severity, or person-level ranking used to classify the subject or drive downstream treatment" is forbidden outright, and an implementation that attaches such a number "has built a risk score wearing a concern hypothesis's name." Risk's own admission does not soften that local rule, and does not need to — Risk's job is to supply a universal boundary that Concern Hypothesis's stronger, domain-specific rule sits on top of, not to relitigate or generalize away what Concern Hypothesis already forbids in its own domain. The universal boundary this entry supplies: a Risk Score may assign a model-relative value, tier, or ranking to its unit. That output does not by itself confer institutional standing, establish a Concern Hypothesis, diagnose the person, or authorize action. That boundary holds everywhere Risk is used, including in domains — a single patient's estimated surgical complication rate, a single bridge's estimated failure probability under load — where an individual-level Estimate is structurally well-formed and inspectable, not automatically legitimate, because the boundary is about what an Estimate or Score is and does, not about whether its unit of analysis is one person or a population. Within Concern Hypothesis specifically, disclosure does not cure a violation of the stronger local rule: a numerical likelihood, severity score, or person-level ranking may not substitute for the required bounded interpretation or be used to classify the person or drive downstream treatment, however well-documented its method or however calibrated its uncertainty. Outside that grammar, a Risk Estimate may inform a Decision only under the governing domain's own Authority, Standards, review requirements, and protections — disclosure makes an Estimate well-formed and inspectable, not legitimate; legitimacy still depends further on Evidence quality, calibration, Authority, applicable Standards, consent, purpose, and the institutional use it is put to.
Risk is not merely quantified Danger, and should not be defined as if it were. Risk does not entail a particular Source, Pathway, or set of EnablingConditions, and therefore does not establish any specified Danger relation — a positive Risk of harm may still imply that some prospective pathway exists, even where none has been identified. A Risk Estimate may be well-supported by observed frequency alone, with no known Danger pathway ever identified — an actuary can price a risk from historical loss data without any causal account of mechanism. Conversely, a Danger relation's pathway can be well understood, appraised, and Claimed with too little evidence to support any reliable quantification of it at all. Where a Danger relation's pathway is known, a Risk Estimate may draw on it; where it is not, a Risk Estimate may still be well-formed and evidenced through frequency alone. Neither composition is required of the other.
This entry sits in Division IV, alongside Danger, Attention, Claim, Evidence, and Significance, for the same reason Danger does: a Risk parameter and its value need not depend on any particular Estimate — whether that value is understood as fully agent-independent, model-relative, or evidential depends on the declared measure — but the entry's demonstrated compositional yield, per the admission evidence behind it, is almost entirely in the appraisal layer: how an Estimate gets made, what it must disclose, what it does and does not entail, and how it must be kept distinct from the value it estimates and the institutional use it might inform. Appraisal-independence alone does not settle placement, exactly as it does not for Danger or for Consequence; what is decisive is where the entry's own compositional work actually falls, and here it falls on structuring the Estimate, not on structuring a realized condition the way Harm does.
Formal Pattern
Risk(r, outcome: o, unit: u, reference_scope: rs, conditions: C,
horizon: t, measure: m)
is well-formed iff each argument is supplied and typed as follows:
o is the specified outcome being characterized — need not be Harm
u is a UnitOfAnalysis(u): the individual, system, instance, or
scenario the characterization is per
rs is a ReferenceScope(rs): a population or reference class, a
scenario ensemble, a model domain, a cohort, or another comparison
set u is drawn from or characterized against
C is Conditions(C): the conditions and exclusions under which the
characterization applies
t is a Horizon(t): the interval over which o is characterized
m is a Measure(m): probability, frequency, rate, distribution,
expected loss or burden under a disclosed loss function, or another
domain-defined measure — expected loss must also disclose how
consequence magnitude is valued
A well-formed Risk parameter identifies the scoped outcome quantity or
distribution being characterized; it does not by itself supply or
presuppose a value for that quantity.
RISK_VALUE(r, v) holds iff:
v correctly characterizes o for u relative to rs, under C, over t,
according to the semantics declared by m
v may be a probability, frequency or rate, distribution, expected-loss
value, interval, or other value appropriate to m. Whether v is treated
as an objective propensity, an observed frequency, a model-relative
probability, an expected loss, or another construction depends on m's
own declared semantics — this entry does not settle that
interpretation universally. This truth condition requires neither
Evidence, an Estimate, nor any institutional use to be satisfied — an
unknown RISK_VALUE can hold wherever the domain's declared measure
permits that interpretation, without imposing it universally.
RiskEstimate(re, target: r, estimated_value: v_hat, method: md,
evidential_basis: b, uncertainty: unc, calibration: cal,
version: ver)
is well-formed iff:
r is a well-formed Risk parameter
v_hat is appropriate to the Measure(m) of r
md and b are disclosed
unc is disclosed, or explicitly marked unavailable
cal is disclosed, marked not applicable, or explicitly marked
unavailable
ver identifies the producing method or model
A well-formed Estimate can still be inaccurate or inapplicable. It may
be asserted or externalized as a Claim:
Claim(c, claimant: a, proposition: ESTIMATES(re, risk: r, value: v_hat),
modality: evidential, context: Cx)
ASSERTS(Agent(a), Claim(c))
-- c's own EpistemicProfile, InstitutionalDisposition, and
EvidenceAttachments track how well-supported and how contested it
is; none of them determines whether re's estimated_value matches
r's actual RISK_VALUE
RiskScore(sc, derived_from: RE, mapping: map, score_value: sv,
version: ver)
-- RE is a nonempty set of one or more RiskEstimates; sc compresses,
maps, ranks, or categorizes RE into sv, and may legitimately
produce a model-relative tier such as "high." sc must preserve
traceability to each Estimate in RE, including its reference
scope, method, uncertainty, calibration status, and version.
Derivation does not transfer validity across scopes or purposes.
A well-formed Risk parameter does not entail:
that any particular RISK_VALUE has been established
an Estimate
a Score
institutional use
RISK_VALUE(r, v) holding does not entail:
that anyone has estimated v
a Score
institutional use
A well-formed or well-supported RiskEstimate does not entail:
that its estimated_value matches r's actual RISK_VALUE
that the outcome will or will not occur for u
a RiskScore
institutional use
A RiskScore does not entail:
that its source Estimate or Estimates are accurate
a person-level institutional status
a Concern Hypothesis
an authorized Decision or intervention
Institutional use does not entail:
that the Estimate or Score supporting it was accurate, applicable, or
properly governed
Examples
| Domain | Unit / reference scope | Outcome and measure | Disclosed basis and status |
|---|---|---|---|
| Engineering | A single bridge, within a scenario ensemble of comparable structures under the same load code | Structural failure probability under specified load, over a stated inspection horizon | Model-based estimate from load modeling and inspection data; informs, but does not itself authorize, a maintenance Decision |
| Medicine | A single patient, within a cohort of patients with comparable clinical presentation | Surgical complication rate, over the perioperative horizon | Structurally well-formed and inspectable as an individual-level Risk Estimate: scope, method, evidential basis, and uncertainty are disclosed. Its institutional legitimacy and use remain separately governed |
| Product liability / insurance | A vehicle component model, compared against a reference scope of prior model years | Component failure rate, over the warranty horizon | Aggregate estimate from incident data; composes with Danger's own Product Liability example without requiring its specific pathway to have been appraised first |
| Digital governance | A platform user, scored by a model whose reference scope was never disclosed to the systems applying it | A self-harm or personal-welfare Risk Score, computed from observed behavioral Evidence, over an undisclosed horizon | Failure case: no disclosed reference scope, method, or uncertainty; used to directly flag the user without routing through a Concern Hypothesis's own review path — the pattern concern-hypothesis.md already prohibits |
Distinctions
Risk ≠ Danger. Danger is prospective and qualitative: a source stands in a relation to a subject through a pathway, whether or not that pathway has ever been quantified. Risk does not entail a particular Source, Pathway, or set of EnablingConditions, and therefore does not establish any specified Danger relation — a positive Risk of harm may still imply some prospective pathway exists, even where none has been identified. Danger can be well understood but unquantifiable; Risk may be estimated from frequency alone without ever identifying the Danger pathway that generates it. Risk is not "quantified Danger."
Risk ≠ Harm. Harm is a realized adverse condition a subject already bears. Risk characterizes an outcome's uncertainty, before or independent of any realization. A Risk Estimate may concern an outcome that never occurs, and a realized Harm may occur with no prior Risk Estimate ever having been made.
Risk ≠ Consequence. Consequence connects a source to an effect under a warranted basis of connection; it is Consequence's own text that first names "cost, risk" as an unstructured effect-description it does not itself structure. Risk supplies exactly the structure Consequence's bare mention leaves missing: a reference scope, conditions, horizon, and measure — none of which Consequence's HAS_CONSEQUENCE requires or supplies.
Risk ≠ Risk Estimate ≠ Risk Score. Risk is the scoped parameter or distribution being characterized — outcome, unit, reference scope, conditions, horizon, and measure — distinct from any particular value assigned to it. A Risk Estimate is a structured representation, which may be asserted or externalized as a Claim, assigning an estimated value to that parameter, carrying its own method, evidential basis, uncertainty, and calibration. A Risk Score is a further derived artifact — compressing, mapping, ranking, or categorizing one or more Estimates, often into a single value or tier. A Risk Score must preserve traceability to its source Estimate or Estimates, including their reference scopes, methods, uncertainty, calibration status, and versions; derivation does not transfer validity across scopes or purposes. Two situations can share the same expected value while differing radically in likelihood, severity, distribution, reversibility, affected population, uncertainty, and tail behavior; a Score that compresses those away is a modeling choice, not a fact about the underlying Risk, and must be disclosed as such.
A Risk Score ≠ person-level standing. This is the distinction that needs the most careful handling. A Risk Score may assign a model-relative value, tier, or ranking to its unit. That output does not by itself confer institutional standing, establish a Concern Hypothesis, diagnose the person, or authorize action — this holds universally, whether the unit is a population or a single person. concern-hypothesis.md supplies a further, stronger, domain-specific rule on top of this universal one, and disclosure does not cure it: within that grammar specifically, a numerical likelihood, severity score, or person-level ranking may not substitute for the required bounded interpretation of observed Evidence, or be used to classify the person or drive downstream treatment, however well-documented its method or however calibrated its uncertainty.
Common Failure Modes
| Mode | Description |
|---|---|
| Scored concern | A Risk Score substitutes for a bounded Concern Hypothesis, or is used to classify a person, reproducing the exact pattern concern-hypothesis.md's own "Scored concern" failure mode already names and prohibits — regardless of how well-disclosed or well-calibrated the Score is. Where to look: any numerical likelihood, severity, or ranking attached to a person and used to sort, tier, or drive treatment, rather than a disclosed, bounded Concern Hypothesis feeding a properly governed review path. |
| Scope or model laundering | An Estimate or Score derived for one population, model, horizon, or purpose is reused in another context as though its validity transferred automatically. Where to look: a model calibrated against one reference scope applied to a materially different one with no re-validation, or a Score computed for one decision context cited to justify an unrelated one. |
| Estimate mistaken for truth | A Risk Estimate or Score is treated as though it revealed the true outcome for the particular unit estimated, rather than a model-relative characterization that may be wrong. Where to look: language that reports a Score as what "will happen" to a specific unit, rather than as an estimate with disclosed uncertainty. |
| Scalar collapse presented as complete | A single Risk Score is presented as though it captured the full underlying Risk, with no disclosure of the likelihood, severity, distribution, or uncertainty it compressed away. Where to look: a single number driving a Decision with no accompanying account of what measure it represents, what reference scope it was computed over, or how calibrated it is. |
Minimum Viable Test Case
Case A — A legitimate individual conditional Estimate:
o = specified outcome: post-operative complication
u = Patient_44
rs = ReferenceScope(patients with comparable clinical presentation and
procedure type)
C = Conditions(specified comorbidity and procedure parameters)
t = Horizon(perioperative period through 30-day follow-up)
m = Measure(probability)
r1 = Risk(outcome: o, unit: u, reference_scope: rs, conditions: C,
horizon: t, measure: m)
-- well-formed: identifies what is being characterized, supplies no
value
RISK_VALUE(r1, v_actual)
-- v_actual exists under probability's own semantics for this patient,
these conditions, and this horizon; not known here, and its
holding does not depend on anyone estimating it
re1 = RiskEstimate(
target: r1,
estimated_value: 0.12,
method: validated_clinical_model,
evidential_basis: cohort_data,
uncertainty: confidence_interval,
calibration: validation_results,
version: model_v3
)
-- well-formed: r1 is well-formed, 0.12 is appropriate to probability,
method and basis are disclosed, uncertainty and calibration are
disclosed, version identifies the model
Claim(c1, claimant: attending_clinician,
proposition: ESTIMATES(re1, risk: r1, value: 0.12),
modality: evidential, context: PreoperativeAssessment)
ASSERTS(Agent(attending_clinician), Claim(c1))
Result:
re1 and c1 are disclosed and well-formed: outcome, unit, reference
scope, conditions, horizon, measure, method, evidential basis,
uncertainty, and calibration are all stated. This makes re1
structurally well-formed and inspectable — it does not by itself make
re1 accurate, and does not by itself classify Patient_44, establish
any status, or authorize any intervention. Whether 0.12 matches
v_actual is a separate question Evidence and calibration bear on;
legitimacy of any institutional use depends further on Authority,
applicable Standards, consent, and purpose, and is a separate, later,
governed act that may or may not follow.
Case B — A well-formed Estimate and Score, scope-laundered and misused:
o' = specified outcome: self-harm within 30 days
u' = User_88214
rs' = ReferenceScope(the platform's original clinical-intake population,
used to train the underlying model)
C' = Conditions(as specified by the original training protocol)
t' = Horizon(30 days)
m' = Measure(probability)
r2 = Risk(outcome: o', unit: u', reference_scope: rs', conditions: C',
horizon: t', measure: m')
-- well-formed; RISK_VALUE(r2, v_actual') exists under probability's
own semantics, but is not what this case turns on
re2 = RiskEstimate(
target: r2,
estimated_value: 0.31,
method: the_original_clinical_model,
evidential_basis: User_88214's platform activity — not the model's
original clinical-intake data,
uncertainty: confidence_interval,
calibration: calibrated against rs' — not against platform-activity
data,
version: model_v3
)
-- well-formed as a representation: r2 is well-formed, 0.31 is
appropriate to probability, and method, basis, uncertainty,
calibration, and version are all disclosed. Well-formed does not
mean applicable: its evidential_basis does not match the
population its calibration was validated against — the model was
developed for rs' (clinical intake), applied here to
platform-activity data for a materially different population
sc2 = RiskScore(derived_from: {re2}, mapping: threshold_at_0.3,
score_value: "high", version: model_v3)
-- traceable to re2 alone; that traceability is what exposes the
scope mismatch on inspection
The platform automatically flags User_88214 as high-risk and restricts
their account, based on sc2 alone:
no revalidation of the model against the platform-activity population
was performed before applying it here,
sc2 substitutes directly for a Concern Hypothesis: no possible
interpretations, no observed-Evidence disclosure bounded to this
person, no review path,
User_88214 is classified and treated — account restricted — with no
authorized Decision, no Recognition, and no resolution or challenge
path
Result:
re2, sc2, and their traceable derivation are each individually
well-formed — this is a stronger failure than a malformed score, not
a weaker one. The failure is not in re2's or sc2's own structure, but
in two acts layered on top of them: applying a model calibrated for
one reference scope to a materially different one without
revalidation ("Scope or model laundering"), and letting sc2 substitute
for a bounded Concern Hypothesis and drive treatment directly ("Scored
concern"). Neither Risk(r2) nor RiskEstimate(re2) nor RiskScore(sc2)
ever entails this outcome; the failure is entirely in the
institutional-use layer, exactly where this entry's own non-entailment
chain says accuracy and proper governance are not guaranteed.
Cross-References
- Consequence — Consequence's own vocabulary first names "cost, risk" as an unstructured effect-description; Risk supplies the reference-scope, conditions, horizon, and measure structure Consequence leaves missing
- Danger — Risk is not merely quantified Danger: an Estimate may be evidenced by frequency alone with no known Danger pathway, and a well-understood Danger pathway may exist with too little evidence to quantify reliably
- Harm — Risk characterizes an outcome's uncertainty before or independent of realization; Harm describes the realized condition an Estimate may or may not have anticipated
- Claim — a Risk Estimate may be asserted or externalized as a Claim whose proposition asserts a value for a candidate Risk parameter; it carries its own basis, epistemic profile, and contestability, independent of whether that value is accurate
- Evidence — supports or undermines a Risk Estimate's disclosed evidential basis; uncertainty and calibration belong primarily to the source Estimate or Estimates, and a Risk Score must preserve traceability to them rather than silently acquiring its own
- Standard — may specify acceptable measures, reference scopes, or calibration requirements for Risk Estimates within a given domain
- Concern Hypothesis — supplies a stronger, domain-specific prohibition on top of Risk's universal boundary, which disclosure does not cure: within that grammar specifically, no numerical likelihood, severity, or person-level ranking may substitute for bounded interpretation of Evidence or classify the person
- Decision — institutional use of a Risk Estimate or Score is a Decision's own province; either may inform a Decision without ever entailing one
- Recognition — institutional uptake of a Risk Estimate or Score as warranting some status is a Recognition act, distinct from the Estimate's or Score's own existence or accuracy