Skip to main content
Category: Enterprise Risk Management

Emerging Risk

Also known as: Emerging Critical Risk, New and Future Risk
Simply put

An emerging risk is a new, evolving, or not-yet-fully-understood threat that does not currently have a significant impact on an organization but could develop into one over time. Because there is limited information about how such a risk might unfold, its potential for harm and its timing are difficult to assess. These risks are ones that should be on an organization's radar even though their consequences are not yet clear.

Formal definition

An emerging risk is generally characterized as a new, unforeseen, or evolving risk whose hazard potential and implications are not yet reliably known and are difficult to assess, and which typically does not yet have a significant impact on the organization. Such risks are commonly described by high uncertainty, rapid change or evolution, and limited available knowledge or information, meaning traditional risk quantification of likelihood and impact may be constrained. Some emerging risks, particularly those that are transboundary, highly uncertain, and systemic, may pose critical challenges at a broader societal or governmental level. Within an enterprise risk management context, emerging risks are typically monitored through horizon-scanning and radar processes distinct from the assessment of established, well-understood risks; this entry is educational and the treatment of any specific emerging risk depends on the organization's facts, sector, and risk management framework.

Why it matters

Emerging risks matter precisely because they sit outside the organization's established risk inventory at a point when there is still time to prepare. By definition, they do not yet have a significant impact, but they are characterized by high uncertainty, rapid change or evolution, and limited available knowledge. This combination makes them difficult to assess using traditional likelihood-and-impact quantification, and it creates a real danger that they remain unmonitored until they crystallize into material threats. For boards and management, the challenge is to keep such risks on the organization's radar even when their consequences and timing are not yet clear.

The stakes are amplified for a particular subset of emerging risks. According to the OECD, emerging critical risks, those that are transboundary, highly uncertain, and systemic, pose significant challenges at a broader societal or governmental level, not only to individual entities. Because these risks can cut across borders and sectors, an organization may face exposures that its own controls cannot fully address, reinforcing the value of early awareness over reactive response.

Without a deliberate process to surface and track emerging risks, an organization risks being caught unprepared by threats that were, in principle, foreseeable but simply not yet contemplated. The value of treating emerging risk as a distinct discipline lies in creating the organizational habit of looking beyond the well-understood risks already being assessed. This entry is educational and not legal, audit, or compliance advice; how any specific emerging risk should be treated depends on the organization's facts, sector, and risk management framework.

Who it's relevant to

Board and Risk Committees
The board and any dedicated risk committee generally hold oversight responsibility for whether management maintains an adequate process to identify and monitor risks that are not yet significant but could become so. Their interest is in confirming that emerging risks are being surfaced and kept on the organization's radar, not in performing the operational monitoring themselves.
Chief Risk Officers and Risk Management Functions
Risk management functions typically own the horizon-scanning and radar processes used to detect emerging risks and to distinguish them from established, well-understood risks. They are responsible for the design of these processes and for escalating risks as understanding matures, while recognizing that traditional likelihood-and-impact quantification may be limited for highly uncertain threats.
Management and Business Owners
Operational management contributes front-line knowledge of new and evolving developments within their areas and helps assess how an emerging risk might affect specific processes, products, or markets. As a risk becomes better understood and more significant, business owners are generally involved in bringing it into the organization's established risk treatment activities.
Internal Audit and Assurance
Assurance functions may evaluate whether the organization's processes for identifying and monitoring emerging risks are designed appropriately and operating as intended, providing independent perspective on gaps in horizon-scanning without themselves owning the risk decisions.
Government and Policy Bodies
For emerging critical risks that are transboundary, highly uncertain, and systemic, the OECD notes these pose significant challenges at a governmental level. Policy bodies and regulators are therefore relevant stakeholders where such risks extend beyond the reach of any single organization's controls.

Inside Emerging Risk

Novelty or evolving nature
An emerging risk is typically one that is newly developing, poorly understood, or changing in character, so that its likelihood, impact, or velocity cannot yet be reliably estimated using established data or experience.
High uncertainty
Emerging risks generally involve significant uncertainty about whether they will materialize, how they will manifest, and how they interact with existing risks, which distinguishes them from well-characterized risks in the current risk register.
Potentially significant or systemic impact
These risks often carry the potential for material or cross-cutting consequences to the organization, its strategy, or its stakeholders, even where the probability remains difficult to quantify.
Horizon scanning and identification processes
Emerging risk management typically relies on forward-looking activities, such as environmental scanning, scenario analysis, and monitoring of external trends, rather than solely on historical loss data.
Relationship to the enterprise risk management framework
Under frameworks such as COSO ERM or ISO 31000, emerging risks are generally addressed as part of ongoing risk identification and assessment, feeding into risk appetite and tolerance discussions, though neither framework is universally mandatory and adoption varies by entity and jurisdiction.
Governance and ownership
Management typically owns the identification, assessment, and response to emerging risks as part of day-to-day and strategic risk activities, while the board or a designated committee generally provides oversight of whether the process is adequate, an accountability distinction that should not be blurred.

Common questions

Answers to the questions practitioners most commonly ask about Emerging Risk.

Is an emerging risk just a new risk that has not yet appeared on the risk register?
Not exactly. An emerging risk is generally understood as a risk that is developing or evolving, often characterized by high uncertainty about its likelihood, impact, timing, or even its precise nature. It is distinct from a simply unregistered known risk, which may be well understood but not yet captured administratively. The defining feature of an emerging risk is typically the limited information available to assess it using conventional methods, rather than its mere absence from a register. The distinction matters because emerging risks often require monitoring, scenario analysis, and judgment rather than the standard likelihood-and-impact scoring applied to established risks. Treatment varies by organization and by the risk framework in use.
Does identifying an emerging risk mean the board must take immediate action to mitigate it?
Not necessarily. Identifying an emerging risk does not automatically create an obligation to deploy controls, and premature mitigation of a poorly understood risk can itself be inefficient or counterproductive. A common response is enhanced monitoring, information-gathering, or scenario planning until the risk becomes better defined and its relationship to the organization's risk appetite is clearer. The appropriate response depends on the potential severity, the degree of uncertainty, the organization's risk appetite, and management's judgment. It is worth distinguishing roles here: management typically owns the assessment and operational response, while the board or a relevant committee generally exercises oversight of whether the process for identifying and responding to emerging risks is functioning. This is a matter of judgment and process, not a fixed rule.
Where should responsibility for identifying and monitoring emerging risks sit within an organization?
Responsibility is generally distributed rather than held by a single function, and specific allocations vary by organization. In many enterprise risk management arrangements, operational management (often described as the first line) identifies risks arising within its activities, a risk function (often the second line) may coordinate horizon-scanning and consolidate emerging risk information, and internal audit (often the third line) may provide independent assurance over the process. The board or a designated committee typically holds oversight responsibility for the adequacy of the overall approach rather than performing identification itself. Because emerging risks often cross functional and business-unit boundaries, organizations frequently establish a defined process or forum to aggregate signals. The precise structure depends on the entity's size, sector, and chosen framework.
How can emerging risks be assessed when conventional likelihood-and-impact scoring may not fit?
Because emerging risks are characterized by high uncertainty, many organizations supplement or replace standard scoring with techniques suited to incomplete information. These can include scenario analysis, stress testing, key risk indicators or early-warning signals, expert elicitation, and structured horizon-scanning. The aim is generally to understand plausible trajectories and potential exposure rather than to produce a precise numerical estimate that the available data cannot support. Some frameworks that address enterprise risk management contemplate such forward-looking techniques, though the specific methods an organization adopts are a matter of choice and judgment. As understanding matures, an emerging risk may be transitioned into conventional assessment processes. These entries are educational and not a substitute for professional risk advice.
How often should emerging risks be reviewed and reported?
There is no single required frequency, and practice varies by organization, sector, and the volatility of the risk landscape. Some organizations integrate emerging risk discussion into periodic risk committee or board meetings, while others maintain more continuous horizon-scanning with escalation triggers when signals cross defined thresholds. A common approach is to calibrate frequency to the pace at which a given risk is developing, reviewing fast-moving areas more often than stable ones. What matters is generally that the cadence is documented, that escalation routes are clear, and that reporting reaches the level with appropriate oversight responsibility. The right frequency is ultimately a judgment shaped by the organization's circumstances and any applicable regulatory expectations, which differ across jurisdictions.
How does an emerging risk relate to an organization's risk appetite and tolerance?
The relationship is often difficult to establish precisely because emerging risks are, by nature, not yet fully understood, which can make it hard to determine whether exposure falls within or outside stated risk appetite. As a practical matter, organizations may treat the appetite question provisionally, monitoring the risk while acknowledging that the assessment against appetite will sharpen as information improves. It is useful to keep the underlying terms distinct: risk appetite generally refers to the amount and type of risk an organization is willing to pursue, risk tolerance to acceptable variation around specific objectives, and risk capacity to the maximum risk it can bear. Applying these to an emerging risk typically involves periodic reassessment rather than a one-time determination, and remains a matter of management judgment and board oversight.

Common misconceptions

An emerging risk is simply any new risk added to the risk register.
A newly identified risk that can be readily characterized with existing data is generally not the same as an emerging risk. The defining feature is typically high uncertainty about likelihood, impact, or behavior, not merely recent addition to the register.
The board is responsible for actively identifying and managing emerging risks.
In most governance models, management owns the identification, assessment, and response to emerging risks as an operational and strategic activity, while the board or a committee exercises oversight of the adequacy of that process. Attributing the operational task to the board mischaracterizes the roles.
A recognized framework such as COSO ERM or ISO 31000 dictates a required method for handling emerging risks.
These are voluntary frameworks or guidance, not universally binding law. They offer principles and processes that many organizations choose to adopt, but their applicability and the specific approach depend on the entity, sector, jurisdiction, and management judgment.

Best practices

Establish a structured horizon-scanning process, for example scenario analysis and monitoring of external trends, so emerging risks are identified before they can be fully quantified with historical data.
Clarify ownership by assigning management responsibility for identifying and assessing emerging risks while defining the board or committee role as oversight of the adequacy of that process.
Assess emerging risks using qualitative and forward-looking methods where historical data is limited, and avoid forcing premature likelihood-and-impact scoring that implies false precision.
Link emerging risk discussions to risk appetite and tolerance conversations so the organization considers how such risks fit within its stated boundaries as understanding evolves.
Review and re-evaluate emerging risks on a regular cadence, moving them into the standard risk register with defined controls as they become better characterized.
Document the basis for judgments about emerging risks, recognizing that these assessments depend on facts and professional judgment and should be revisited as new information arises.