Skip to main content
Category: Enterprise Risk Management

Risk Interdependency

Also known as: Interdependent Risk, Risk Interconnectedness, Interconnected Risk
Simply put

Risk interdependency describes the way individual risks are connected to one another, so that a single event can trigger or worsen others rather than staying isolated. For example, a delay in one project or supplier can set off a chain of related problems elsewhere. Recognizing these links helps an organization see risks as a connected network rather than as separate, standalone items.

Formal definition

Risk interdependency refers to the relationships through which risks influence, propagate to, or amplify one another, such that the aggregate exposure differs from the sum of risks assessed individually. Analytical approaches often model these relationships as a network or graph to capture propagation behavior, cascading effects, and to prioritize risks based on their connectivity rather than in isolation. The concept is applied in domains including project risk management and supply chain risk management; the specific modeling techniques, thresholds, and prioritization criteria depend on the framework and context adopted, and this entry is educational rather than prescriptive of any single method.

Why it matters

Traditional risk registers tend to catalogue risks as discrete line items, each with its own likelihood and impact rating. This approach can understate an organization's true exposure because it treats risks as if they were independent. In reality, risks are frequently connected: a single triggering event can propagate to and amplify others, so that the aggregate exposure differs from the simple sum of risks assessed individually. Recognizing interdependency helps boards, risk committees, and management avoid the blind spot of managing risks in silos while missing the pathways along which a disruption can travel.

The consequences of overlooking these connections are most visible where activities are tightly linked, such as portfolios of interdependent projects or extended supply chains. When projects depend on one another, a delay in one can trigger cascading failures across others, and a single supplier disruption can set off a chain of related problems downstream. Detecting these relationships early and addressing them appropriately is therefore a recurring theme in both project risk management and supply chain risk management, where the timing and connectivity of a risk can matter as much as its standalone severity.

For governance and assurance purposes, understanding interdependency supports more informed prioritization: risks that are highly connected to others may warrant attention disproportionate to their individual rating, because they can act as propagation points. This entry is educational and does not prescribe any single modeling method; the appropriate techniques, thresholds, and prioritization criteria depend on the framework and context an organization adopts, and remain matters for professional judgment.

Who it's relevant to

Chief Risk Officers and Risk Functions
Risk owners and enterprise risk teams are typically responsible for how risks are identified, assessed, and aggregated. Interdependency is directly relevant to how they design their assessment methods, because modelling connections between risks can reveal exposures that a siloed register would miss and can inform which risks warrant priority attention based on their connectivity.
Project and Programme Managers
Where projects depend on one another, a delay or failure in one can cascade across others. Those managing interdependent projects or portfolios generally need to identify these links so that risk planning accounts for propagation across projects rather than treating each project's risks as self-contained.
Supply Chain and Procurement Leaders
Supply chains carry inherent risks that benefit from early detection. Leaders responsible for supplier relationships and continuity generally use interdependency thinking to spot early warning signals and to understand how a single supplier disruption could set off related problems elsewhere in the chain.
Boards and Risk Committees
Boards and their risk committees exercise oversight of the organization's risk profile rather than day-to-day risk operations. An appreciation of interdependency helps them challenge whether management's reporting reflects connected, aggregate exposure or only isolated risks, and whether prioritization gives appropriate weight to highly connected risks.
Internal Audit and Assurance Providers
Assurance functions evaluating the risk management process may assess whether the methods used account for the ways risks influence and amplify one another. This entry is educational and not audit advice; the adequacy of any particular approach depends on the entity's context and the professional's own judgment.

Inside Risk Interdependency

Interconnected Risk Relationships
Risk interdependency refers to the way individual risks influence, trigger, or amplify one another rather than materializing in isolation. A single event may cascade across multiple risk categories, such as an operational disruption that generates financial, reputational, and compliance consequences.
Correlation and Causation
Interdependency can arise from correlation (risks that tend to move together because of a shared driver) or causation (one risk directly precipitating another). Distinguishing the two matters for how risks are modeled and treated, though this often depends on the facts and requires professional judgment.
Concentration and Aggregation
When multiple exposures share a common underlying factor, dependency, or counterparty, seemingly separate risks may aggregate into a larger combined exposure. Aggregating interdependent risks helps management understand exposures that individual risk registers may understate.
Cascade and Contagion Effects
Interdependency describes how the crystallization of one risk can propagate through connected processes, systems, or third parties, producing knock-on effects. This is a conceptual descriptor of dynamics, not a prediction of any specific outcome.
Relationship to Enterprise Risk Management
Under frameworks such as COSO ERM and ISO 31000, considering interdependencies supports a portfolio view of risk. These frameworks are voluntary standards, not universally mandatory law; their treatment of interconnected risks is principles-based and applied according to entity context.
Accountability and Ownership
Management generally owns the identification, assessment, and treatment of interdependent risks as part of the first and second lines. The board and its risk or audit committee typically provide oversight of whether management's approach adequately captures interconnections, without assuming operational responsibility for the analysis itself.

Common questions

Answers to the questions practitioners most commonly ask about Risk Interdependency.

Isn't risk interdependency just the same as looking at risks together in an aggregate view?
No. Aggregation typically refers to summing or combining exposures across a portfolio to understand total magnitude, whereas interdependency concerns the relationships between risks, how the occurrence or movement of one risk influences the likelihood or impact of another. Two risks can be aggregated without any causal or correlated link between them; interdependency specifically addresses those links, including correlation, common drivers, and cascading effects. Treating the two as identical can lead an organization to understand how much risk it holds in total while remaining blind to how those risks may amplify one another. Note that terminology varies across frameworks and organizations, so it is worth confirming how these terms are defined within your own risk methodology.
If two risks are related, does that mean one causes the other?
Not necessarily. Interdependency can arise from several distinct relationships, and correlation is not the same as causation. Risks may move together because they share a common underlying driver, because one genuinely triggers or worsens another (a cascading or contagion effect), or because of coincidental statistical association observed in limited data. Assuming a causal link where only correlation exists can misdirect mitigation efforts and create false confidence that addressing one risk will resolve another. Analyzing the nature of the relationship, rather than only noting that a relationship exists, is generally important, and the conclusion often depends on the facts and the quality of available data, calling for professional judgment.
How can an organization begin to identify interdependencies among its risks?
A common starting point is to use the existing risk register or risk taxonomy as a basis and then examine risks in pairs or clusters rather than in isolation, asking whether a change in one could affect the likelihood or impact of others. Techniques used in practice may include facilitated workshops with risk and business owners, dependency or correlation mapping, scenario analysis, and review of shared drivers such as common suppliers, systems, geographies, or macro factors. Which techniques are appropriate depends on the organization's size, sector, and risk maturity. This is generally a management and first- and second-line activity, with methodology often coordinated by the risk function; the approach should be documented so it can be reviewed and refreshed over time.
Who is accountable for understanding and managing risk interdependencies?
Accountability is typically distributed rather than held by a single party. Management, including risk and business owners in the first and second lines, generally owns the identification, assessment, and management of interdependencies as part of the enterprise risk management process. The risk function often provides methodology, challenge, and consolidation. Internal audit, as an assurance function, may evaluate whether the process for considering interdependencies is designed and operating effectively but does not own the risks themselves. The board and relevant committees generally hold oversight responsibility, satisfying themselves that management has a credible approach, rather than performing the analysis. The precise allocation depends on the organization's governance structure and any applicable framework or regulatory expectations.
How should interdependencies be reflected in scenario analysis and stress testing?
Interdependencies are often incorporated by designing scenarios in which multiple related risks materialize together or in sequence, rather than testing each risk in isolation, so that potential cascading and compounding effects become visible. This may involve identifying common drivers that could trigger several risks simultaneously and considering how the failure of one control or the crystallization of one risk could increase exposure elsewhere. The rigor and quantification appropriate to this work vary widely by sector and entity type, certain financial institutions may operate under specific regulatory stress-testing expectations, while other organizations may take a more qualitative approach. Assumptions about relationships should be documented and revisited, since they can be difficult to estimate and are subject to change.
How does considering interdependency affect the distinction between inherent and residual risk?
Interdependency can influence assessments of both inherent risk (before considering controls) and residual risk (after controls are applied), and it can also affect how much reliance should be placed on controls. For example, a single control weakness or a shared dependency may act on several risks at once, meaning residual exposure could be higher than a risk-by-risk view suggests. Similarly, correlated risks may reduce the diversification benefit an organization assumes it has. These effects are matters of judgment and should be evaluated within the organization's own methodology and risk appetite framework. This entry is educational and does not constitute legal, audit, or compliance advice; specific conclusions depend on the facts and the applicable framework.

Common misconceptions

Assessing each risk individually in a risk register is sufficient to understand the organization's overall exposure.
A risk register that scores risks in isolation may understate exposure because it does not capture how risks trigger or amplify one another. A portfolio view that considers interdependencies is generally needed to reflect aggregate and cascading effects, though the depth of analysis appropriate depends on the entity's context and judgment.
Considering risk interdependencies is a mandatory legal requirement imposed by frameworks like COSO or ISO 31000.
COSO ERM and ISO 31000 are voluntary, principles-based frameworks rather than binding law. They encourage a holistic view of interconnected risks, but whether and how an organization must address interdependencies depends on jurisdiction, sector, entity type, and applicable regulation, not on any single universally mandatory standard.
Correlated risks and causally linked risks are the same thing and can be treated identically.
Correlation means risks tend to move together, often due to a shared driver, while causation means one risk directly triggers another. The distinction affects how risks are modeled and treated, and conflating them can lead to misjudging exposures. Determining which applies typically requires facts and professional analysis.

Best practices

Supplement isolated risk register scoring with a portfolio-level view that explicitly maps how key risks influence, trigger, or amplify one another.
Identify shared drivers, common counterparties, and single points of dependency that could cause otherwise separate exposures to aggregate or cascade.
Distinguish correlation from causation when analyzing linked risks, and document the assumptions and judgments underlying each relationship so they can be challenged.
Clarify ownership by having management perform and maintain the interdependency analysis while the board or relevant committee oversees whether the approach adequately captures interconnections.
Apply relevant voluntary frameworks such as COSO ERM or ISO 31000 in a manner proportionate to the entity's context, rather than treating any single framework as universally mandatory.
Periodically revisit interdependency assumptions as the business, third-party relationships, and external environment change, since interconnections are dynamic rather than static.