Reference
Glossary
This glossary defines the risk and Monte Carlo terminology used across Monty & Co. Every entry says where its definition comes from, because "ISO 31000 says" without a clause beside it is how wrong attributions survive. Definitions are anchored to ISO 31000:2018 for the core vocabulary, ISO 31073:2022 for the wider risk-management vocabulary that replaced ISO Guide 73:2009, and AS/NZS IEC 31010:2020 for assessment techniques.
◆ 23defined in a standard, quoted with the clause · ◇ 19established practice with no single owning document · ○ 13 a Monty & Co convention. Where this product's usage differs from a standard, the entry says so rather than quietly picking one.
B
- Band (GeoRisk)
- One of GeoRisk's four rating labels: Low, Medium, High or Very High. A band is a quartile of the scored cohort, cut at the 25th, 50th and 75th percentiles, not an absolute threshold: "High" means the second-riskiest quarter of the economies that could be scored, so a band can move between snapshots without the country's own data changing. Category bands rank within each category's own (often smaller) cohort, and a sanctions override can set or floor the overall band regardless of the data.○ Monty & Co convention
- Base estimate
- The deterministic cost of the work as scoped, carrying no allowance for things going wrong. In PRQ it is set on the project header and used to express contingency as a share as well as an amount. PRQ runs without one; the convergence diagnostic then evaluates against the P90 value directly, at a tighter threshold.◇ Common practice · cost-estimating usage
- Bow tie
- A graphical depiction of pathways from the causes of an event to its consequences, showing the controls that modify the likelihood of the event and those that modify the consequences if it occurs. AS/NZS IEC 31010:2020 places it under techniques for analysing controls, which is a claim about what it is for: a bow tie is a way of checking that every pathway has a control, not merely a way of drawing a risk. See What is a bow tie?◆ AS/NZS IEC 31010:2020 B.4.2
C
- Cause
- A pathway through which a risk event could occur. Each cause sits on its own line on the left of a bow tie with its own controls. Phrase it as a precondition, not as the event: "phishing of staff credentials", not "data breach". Maps to what ISO 31000 calls a risk source.◇ Common practice · bow-tie convention; ISO 31000 says risk source
- Cholesky decomposition
- The factorisation of a positive-semi-definite matrix M as L · Lᵀ with L lower triangular. PRQ uses it inside the Iman-Conover step to build correlated normal samples, which are then rank-mapped onto the elicited marginals.◇ Common practice · standard linear-algebra term
- Confidence interval
- An interval computed from a sample by a procedure which, repeated many times, would contain the true value of the estimated parameter in a stated proportion of cases. The distinction is pedantic-sounding and genuinely matters: the probability attaches to the procedure, not to any single interval you are looking at.
PRQ surfaces a 95% interval on the P90 estimate in the convergence badge, describing how much that P90 would move if you ran the simulation again. This is a different thing from a percentile, and neither is "confidence" in the everyday sense.◇ Common practice · standard statistical term - Consequence
- The outcome of an event affecting objectives. A consequence "can be certain or uncertain and can have positive or negative direct or indirect effects", can be expressed qualitatively or quantitatively, and "can escalate through cascading and cumulative effects". This is the standard's word for what Monty & Co's interfaces call impact; the two mean the same thing here.◆ ISO 31000:2018 3.6
- Contingency
- Funds held to cover identified risks that may occur. PRQ reports the contingency at the percentile the project is funded to, and that figure is the amount sitting on top of the base estimate rather than a total including it.
Read the number precisely. Contingency at P80 means 80% of the simulated outcomes fell at or below it. It is not an 80% chance the project comes in on budget: the distribution covers the risks in the register and nothing else, so it excludes scope change, escalation outside your ranges, and estimating error you did not capture. Contingency covers the risks you found; what it cannot cover is the register being incomplete.◇ Common practice · cost-estimating usage; see PMI on reserves - Control
- A measure that maintains and/or modifies risk. The "maintains" half is deliberate 2018 wording, and it matters: a control that holds a risk where it is, rather than reducing it, is still a control. Controls "include, but are not limited to, any process, policy, device, practice, or other conditions and/or actions". The standard also carries a note worth reading before any control-effectiveness workshop: "Controls may not always exert the intended or assumed modifying effect."◆ ISO 31000:2018 3.8
- Convergence
- Whether an estimate has stopped moving as iterations increase. PRQ computes the 95% interval half-width on the P90 estimate; at or below 2% of the base estimate it reports "converged". A converged simulation is a statement about arithmetic stability only. It says nothing about whether the register was right.○ Monty & Co convention
- Correlation matrix
- A K × K matrix of pairwise correlations between K variables. Diagonal pinned at 1.0, symmetric, and positive-semi-definite. PRQ accepts a rank correlation matrix and imposes it on the per-risk impact samples using Iman-Conover. Note what this does and does not do: it correlates impact magnitudes, not whether risks occur together.◇ Common practice · standard statistical term
- Cost-benefit ROI (marginal reduction)
- Event Risk's per-treatment return: the expected-loss reduction attributable to that treatment, divided by its cost. The reduction is marginal, measured by re-running the simulation with just that treatment removed while the others stay in place, so each row answers "does this treatment earn its keep given the rest of the portfolio?" The Total ROI uses the whole portfolio's joint reduction instead, which is why the marginal rows don't sum to it.○ Monty & Co convention
- Coverage (GeoRisk)
- The share of an economy's intended indicator weight that real data actually supplied, shown as a percentage. GeoRisk never imputes missing data; instead coverage drops, and below the floors no computed rating is published: a category needs at least 60% of its designed weight and two indicators, and the overall rating needs at least five of the seven weighted categories plus 70% weighted coverage, else the economy shows "Insufficient data" (unless the sanctions override supplies a band on legal grounds alone). The two floors are independent, so decent coverage with too few scored categories still yields no computed rating.○ Monty & Co convention
E
- Effectiveness
- A judgement about how well a control performs, on the platform's five-level scale: Not, Partially, Moderately, Substantially and Highly Effective (a 1–5 score in the data model, shared with the iOS app). Worth pairing with ISO 31000's note that "controls may not always exert the intended or assumed modifying effect" — an effectiveness rating is an assertion that should be evidenced, not a property of the control's existence.○ Monty & Co convention
- Event (risk event)
- An occurrence or change of a particular set of circumstances. The standard adds three things people routinely miss: an event can have several causes and several consequences; it "can also be something that is expected which does not happen, or something that is not expected which does happen"; and an event can itself be a risk source for something else. In a bow tie it is the single occurrence at the centre, which AS/NZS IEC 31010:2020 calls the event of interest, represented by the central knot.◆ ISO 31000:2018 3.5
- Expected loss
- The mean of the simulated totals: the probability-weighted average cost per period. The basis of Event Risk's cost-benefit table, where a treatment's benefit is the reduction in expected loss it delivers. A mean hides the tail, so pair it with a percentile whenever the tail is the concern.◇ Common practice · standard modelling term
H
- Higham nearest-correlation matrix
- An algorithm for finding the closest valid correlation matrix to one that is not valid, preserving as much of the specified structure as possible. PRQ offers it as "Apply nearest correction" when your matrix fails the PSD check. Higham, 2002.◇ Common practice · Higham (2002), IMA Journal of Numerical Analysis 22(3)
I
- Iman-Conover method
- A rank-reordering algorithm for imposing a target rank correlation on independent samples while leaving each variable's marginal distribution untouched. That last property is why it is used here: the distributions you elicited stay the distributions you get. Iman & Conover, 1982.◇ Common practice · Iman & Conover (1982), Communications in Statistics 11(3)
- Impact
- In Beau-Tie, a consequence pathway following the risk event, each on its own line to the right with its own controls. In PRQ, the monetary value (or distribution of values) incurred when a risk occurs. ISO 31000's word for the first sense is consequence; "impact" is retained in the interface because it is what most registers in the wild say.○ Monty & Co convention · ISO 31000 term is consequence
- Inherent risk
- The rating before any controls are accounted for. Beau-Tie does not plot it. The reasoning: on a live operation the controls already exist, so an inherent rating describes a world that does not exist and cannot be acted on. It remains a common requirement in audit and regulated-sector reporting, so this is a product opinion rather than a settled position. GeoRisk's country ratings carry the same word in a different, legitimate sense: they rate market-entry risk before the controls you would bring, and for an organisation not yet operating in a market that pre-control world is the decision-relevant one, not a fiction. Same definition; what differs is whether anyone's controls exist yet.○ Monty & Co convention · not a standard term; deliberately not plotted
L
- Level of risk
- The magnitude of a risk, or combination of risks, expressed in terms of the combination of consequences and their likelihood. This is the rating itself, and arriving at it is analysis. Drawing it on a grid is presentation. The two get conflated constantly, including by people defending matrices and people attacking them.◆ ISO 31073:2022 3.3.22
- Likelihood
- The chance of something happening. Note carefully what the standard does not say: likelihood is used "whether defined, measured or determined objectively or subjectively, qualitatively or quantitatively", so it is not reserved for word-scale ratings. Monty & Co nonetheless uses "likelihood" for the qualitative band on a matrix and probability for the numeric input to a simulation. That split is a house convention for keeping two different inputs distinct on screen, not a distinction the standard draws.◆ ISO 31000:2018 3.7
M
- Mode
- The value at which a distribution's density peaks: the single most likely outcome. One of the three elicited parameters in PRQ's triangular and PERT distributions (low / mode / high). Not the same as the mean, and on a skewed distribution the difference is the whole point.◇ Common practice · standard statistical term
- Monte Carlo simulation
- A technique for establishing the aggregate variation in a system by sampling its uncertain inputs many times. The standard notes that models "can be developed using spreadsheets and other conventional tools", and that the output is either the whole distribution or key measures from it. It also warns, on aggregation, that "consolidating risks by simply adding them up is not a reliable basis for decision making". See Monte Carlo basics for project risk.◆ AS/NZS IEC 31010:2020 B.5.10
O
- Occurrence rate
- The share of simulated iterations in which the event fired. Event Risk's headline pill. Distinct from severity: an occurrence rate says nothing about what the event costs when it happens, which is what the conditional impact distribution shows.○ Monty & Co convention
- Override (GeoRisk)
- A manual gate applied after scoring, because statistics do not capture sanctions. Comprehensively sanctioned economies are set to Very High regardless of their indicators; targeted Australian sanctions, severe secondary-sanctions exposure, severed correspondent banking or a DFAT "Do not travel" advisory floors the band at High. Overridden pages disclose the computed band alongside, and many overrides are disclosure-only: the economy already scored at or above the floor.○ Monty & Co convention
P
- P50 / P80 / P90
- Percentiles of the simulated distribution. P50 is the median; P80 is the value 80% of iterations landed at or below; P90 the same for 90%. PRQ computes all of them from one run and lets you choose which the project is funded to, defaulting to P80 as a starting point rather than a recommendation. Which level you fund is a risk appetite decision. Australian public infrastructure generally works in P50 and P90. See Monte Carlo basics.◇ Common practice · cost-risk convention
- PERT distribution
- A beta distribution rescaled onto a min/mode/max triple, weighting the mode more heavily than a triangular does. Mean is (min + 4·mode + max) / 6. Named for the Program Evaluation and Review Technique developed for the US Navy's Polaris programme in 1958. Reach for it when the most likely value really is most likely and the bounds are genuinely rare.◇ Common practice · standard statistical term
- Positive-semi-definite (PSD)
- A property of a symmetric matrix: all eigenvalues are non-negative. Required for a correlation matrix to be coherent. It is entirely possible to write down pairwise correlations that cannot all hold at once (A strongly with B, B strongly with C, C strongly against A), and PSD is the check that catches it.◇ Common practice · standard linear-algebra term
- Probability of occurrence
- In PRQ, the chance per iteration that a risk occurs, expressed in [0, 1] (0.30 = 30%). Combined with the impact distribution, it determines the risk's contribution to the total in any one iteration. See the note under likelihood about why this product keeps the two words apart.○ Monty & Co convention
R
- Residual risk
- The risk remaining after risk treatment. Two notes in the standard change how the number should be read. "Residual risk can contain unidentified risk", so it is not a complete account of what is left, only of what was left after treating what you found. And it "can also be known as retained risk", which is the more honest name: somebody is carrying it. In Beau-Tie, plotted as the teal dot on the matrix.◆ ISO 31073:2022 3.3.38
- Risk
- The effect of uncertainty on objectives. Worth sitting with, because it is not what most people mean by the word. Risk is not "a bad thing that might happen": it is an effect, and the standard is explicit that the effect "can be positive, negative or both, and can address, create or result in opportunities and threats". A risk with no objective attached to it is not a risk, it is just an event. If you cannot say what the uncertainty is an effect on, the entry in your register is not finished.◆ ISO 31000:2018 3.1
- Risk analysis
- The process to comprehend the nature of risk and to determine the level of risk. ISO 31000:2018 clause 6.4.3 expands it: analysis considers "uncertainties, risk sources, consequences, likelihood, events, scenarios, controls and their effectiveness", and techniques "can be qualitative, quantitative or a combination of these". Determining a consequence and a likelihood, and combining them into a rating, is analysis whichever of those you use.◆ ISO 31073:2022 3.3.15
- Risk appetite
- The amount and type of risk an organisation is willing to pursue or retain. Both halves count: appetite is not only a quantity, it is also a statement about which kinds of risk are acceptable at all. Appetite is what guides the development of risk criteria, and ISO 31000:2018 clause 5.2 puts establishing "the amount and type of risk that may or may not be taken" with top management. It is therefore not the analyst's to set.
Monty & Co expresses it in more than one place, because appetite genuinely has more than one expression. Beau-Tie plots a per-record appetite rating on the matrix as the "A" marker, the threshold above which the risk would not be tolerated. PRQ carries a funded percentile, which is a quantitative statement of the same thing. Neither is complete on its own.◆ ISO 31073:2022 3.3.27 - Risk assessment
- The overall process of risk identification, risk analysis and risk evaluation. An umbrella term, so worth using precisely: much of what is called "a risk assessment" is only the analysis step.◆ ISO 31073:2022 3.3.8
- Risk criteria
- The terms of reference against which the significance of risk is evaluated. Criteria are "based on organizational objectives, and external and internal context", and "can be derived from standards, laws, policies and other requirements". In practice these are the things you compare a rating against: the band boundaries on a matrix, the threshold that triggers escalation, the percentile a project must be funded to.◆ ISO 31073:2022 3.3.6
- Risk evaluation
- The process of comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable or tolerable. The step that turns a number into a decision, and the step most often skipped: a rating nobody compared against anything has not been evaluated.◆ ISO 31073:2022 3.3.25
- Risk identification
- The process of finding, recognising and describing risks. It "involves the identification of risk sources, events, their causes and their potential consequences" — which is, almost exactly, the anatomy of a bow tie.◆ ISO 31073:2022 3.3.9
- Risk management
- Coordinated activities to direct and control an organisation with regard to risk. The word doing the work is coordinated: a collection of unconnected assessments is not risk management, however many of them there are.◆ ISO 31000:2018 3.2
- Risk matrix (consequence/likelihood matrix)
- A grid displaying risks according to their consequence and likelihood, combining the two to display a rating for the significance of risk. Also called a heat map. The standard files it under techniques for recording and reporting, which is a deliberate placement: the grid presents the result, while determining the consequence and the likelihood is analysis and comparing the rating to bands is evaluation. It also says scales "should always be customized", and that each scale point generally needs to be an order of magnitude greater than the one before. See Risk matrices and the residual / target / appetite triple.◆ AS/NZS IEC 31010:2020 B.10.3
- Risk owner
- A person or entity with the accountability and authority to manage risk. Both are required. Naming an owner who has the accountability but not the authority to act is one of the more common failures in a register, and it is usually visible in the treatment plan rather than in the ownership field.◆ ISO 31073:2022 3.3.14
- Risk source
- An element which alone or in combination has the potential to give rise to risk. This is what the left-hand side of a bow tie holds. AS/NZS IEC 31010:2020 describes the construction as listing "sources of risk (or hazards/threats in a safety context)" to the left of the knot, joined to it by the mechanisms through which they could lead to the event. Beau-Tie labels these causes, which is the more common term in bow-tie practice.◆ ISO 31000:2018 3.4
- Risk tolerance
- An organisation's or interested party's readiness to bear the residual risk in order to achieve its objectives. Distinct from appetite, though the two are used interchangeably in the wild: appetite is what you are willing to take on, tolerance is what you are willing to live with once treatment has done what it can.◆ ISO 31073:2022 3.3.28
- Risk treatment
- The process to modify risk. The standard's options are broader than "reduce it": avoiding the risk by not starting or continuing the activity, taking or increasing risk in order to pursue an opportunity, removing the risk source, changing the likelihood, changing the consequences, sharing the risk, and retaining it by informed decision. An informed decision to retain is a treatment, not an absence of one.◆ ISO 31073:2022 3.3.32
S
- S-curve
- The simulated distribution drawn cumulatively: for each value on the x-axis, the share of simulated outcomes at or below it. A steep curve means tightly clustered outcomes; a long flat right shoulder is tail risk. Reading a percentile off the curve is the graphical form of the percentile strip, and PRQ and Event Risk both render one after every run.◆ AS/NZS IEC 31010:2020 B.10.4
- Sensitivity analysis
- Identifying which inputs drive most of the variation in a model's output. PRQ's tornado ranks risks by contribution: a closed-form variance share when risks are independent, and Spearman ρ² against the totals when a correlation matrix is in play.◇ Common practice · standard modelling term
- Snapshot (GeoRisk)
- The frozen, dated dataset every GeoRisk page and export is computed from. Nothing is fetched live: the pipeline configuration is frozen into each snapshot, source artefacts are recorded with content hashes, and the scoring engine is deterministic, so ratings are reproducible and change only at snapshot boundaries. Always quote a GeoRisk rating as at its snapshot date; because bands are cohort-relative, the same country can rate differently in the next snapshot for reasons outside its borders.○ Monty & Co convention
- Spearman rank correlation
- The Pearson correlation of two variables' ranks rather than their raw values, so it measures monotonic association and is robust to non-linear relationships. PRQ uses Spearman ρ² as the variance-share input for the tornado when a correlation matrix is in play.◇ Common practice · standard statistical term
- Stakeholder
- A person or organisation that can affect, be affected by, or perceive themselves to be affected by a decision or activity. The third clause is the one that catches people out: perception is sufficient, whether or not the effect is real. "Interested party" can be used as an alternative term.◆ ISO 31000:2018 3.3
- Status (control status)
- Whether a control is currently running (existing) or committed but not yet live (planned). Beau-Tie renders existing controls as solid circles and planned controls as dashed circles with the implementation timeline attached. The distinction is what makes the gap between residual and target meaningful.○ Monty & Co convention
T
- Target risk
- Where the residual is intended to land once planned controls are live. Plotted as the confidence-green dot on Beau-Tie's matrix. The distance between residual and target is the treatment plan's ambition, stated as a number.○ Monty & Co convention
- Tornado chart
- A horizontal bar chart of contributors ranked by influence, widest at the top, narrowing downward into the shape it is named for. PRQ renders the top bar in teal as the single "start here" cue.◇ Common practice · standard modelling term
- Triangular distribution
- A distribution defined by three parameters (min / mode / max) with linear falloff either side of the mode. Mean is (min + mode + max) / 3. PRQ's default because it is easy to elicit in a workshop and its hard bounds match how people actually think about a worst case. AS/NZS IEC 31010:2020 notes that triangular and beta distributions "are commonly used" for risk assessment. See probability distributions.◇ Common practice · standard statistical term
- Type (control type)
- The platform's five control types: preventive reduces the likelihood of the event, detective reduces time-to-discovery once an event is in motion, corrective reduces consequence if the event occurs, directive shapes behaviour to support the others, and recovery restores normal operation after the consequences have landed.
The preventive/detective/corrective/directive split is widely used in internal-control and audit practice but has no single owning standard, and we have not found one. A previous version of this page attributed it to ISO 22301, which is a business continuity management system standard and contains no such taxonomy. AS/NZS IEC 31010:2020 makes a simpler cut in its bow-tie clause: controls that modify the likelihood of the event, and reactive controls that modify the consequences after it; corrective and recovery are that reactive side, named more finely. If you know of an authoritative source for the four-way version, we would like to hear about it.◇ Common practice · internal-control and audit usage; no owning standard found
V
- Each risk's contribution to the total variance of the simulated total, as a percentage. The tornado bars are sized by it. Useful for deciding where treatment effort goes, and a different question from which risk has the largest impact: a large risk that rarely occurs may contribute less variation than a moderate one that usually does.◇ Common practice · standard modelling term