The Build Journal
Roll the dieAverage of 0 rolls
Research Supplement

The Build Journal

ForecastUncertainwith a chance of being wrong about the chance.

Risk, Uncertainty and Decision-Making

The same word means different things to a banker, a doctor and an engineer

People talk about risk when they head to an exam in bad weather, choose a medical treatment, board a flight, invest their savings, release software, approve a policy or build a bridge. It is one of the most familiar words in ordinary life, and one of the most argued over in research and practice.

In classical probability, risk usually means measurable chances attached to outcomes. In expected utility theory it is about choosing between uncertain prospects. Bayesians tie it to degrees of belief that change with evidence. Psychologists find it shaped by framing, emotion, trust and memory. Institutions link it to objectives, accountability and action.

This paper compares those frameworks on the same questions, works through the core mathematics in plain language, and concludes that the strongest approach is layered: use different tools for different decisions, and be honest about their limits.

Continued in section 1

1Introduction

Deciding Before the Future Arrives

Something of value is at stake, the future is uncertain, and the decision cannot wait.

Risk is present whenever we have to act before we know how things will turn out. A student travelling to an exam in the rain worries about traffic, a broken-down bus or arriving late. A traveller choosing a flight weighs safety, cost, fatigue, delays and missed connections. A family buying insurance worries about an illness that may never come but could ruin them if it does. An investor asks whether a higher expected return is worth a bigger possible loss. A software team asks whether shipping a feature now will cause failures, security holes or embarrassment. A government weighs whether a policy that reduces one danger might create another.

The scale differs, but the shape is the same. Something of value is at stake, the future is uncertain, and the decision cannot be put off forever.

Because the word is so familiar, its meaning can seem obvious. It is not. In finance, risk can mean volatility, loss, the chance of default, a cash crunch, or assets falling together in a crisis. In public health the language is of risk factors, exposure and the burden of disease. In disaster studies, risk depends not only on the hazard but on who is exposed, how vulnerable they are and how well they can cope. Engineers frame it through scenarios, likelihoods and consequences. The international standard ISO 31000 defines it as “the effect of uncertainty on objectives”.1 Psychologists care about how people perceive, fear, ignore or misread uncertain outcomes. These are not small differences of wording. They decide what gets measured, who is held responsible, which choices look rational and how institutions justify what they do.

This is a comparative study rather than a survey of one field. For each framework it asks the same questions. What does risk mean here? What assumptions hold that meaning up? Where does the framework work well, and where does it break? Does it describe the world, prescribe rational choice, explain behaviour, or support practical management? Asking the same questions everywhere shows that much disagreement about risk comes from different purposes, not just confusion.

The argument has four claims. First, risk is a family of related ideas, not one universal formula. Second, risk must be kept separate from the numbers used to describe it, because no single number captures everything that matters about uncertain harm or opportunity. Third, a sound account of risk needs both numbers and judgement, since probabilities and averages do not cover everything that matters in real decisions. Fourth, the best framework depends on the decision. Probability models are powerful where events repeat and data are plentiful. Expected utility is strong for prescribing choice. Bayesian methods shine when evidence arrives over time. Behavioural approaches explain how people actually read uncertainty. Organisational frameworks turn uncertainty into governance, controls and action.

The paper runs as follows. Section 2 sets out the core ideas and terms. Section 3 reviews the literature and its history. Section 4 compares the main frameworks. Section 5 develops the mathematics, explains every symbol in plain English and proves the central results. Section 6 covers psychology and behaviour, section 7 risk in eight applied fields, and section 8 practical risk management. Section 9 compares the frameworks side by side; sections 10 to 12 give the findings, the limitations and the conclusion.

2Foundations

What Risk Actually Means

Chance attached to consequences that matter to someone.

Risk in everyday life

In everyday speech, risk means the possibility that something important may go badly because the future is not fully under our control. The thing at stake may be health, time, money, status, comfort, opportunity, safety or trust. This plain meaning has an advantage: it starts from what people care about. If nothing of value is at stake, uncertainty may be interesting, but nobody calls it a serious risk. So ordinary language already holds a deep idea. Risk is not just about chance. It is about chance attached to consequences that matter to someone.

A simple example shows the structure. A student has an exam at 8:30 in the morning. The route is usually reliable, but heavy rain is forecast, the buses have a history of delays, and there is little spare time. Is leaving at the usual time risky? That small question already contains a goal, uncertainty, ways things can fail, uneven consequences and a choice between actions. Scroll through the morning and watch how each framework picks out something different.

The morning

Leave at 7:40, walk to the stop, wait for a bus, ride 25 minutes. Rain is forecast. The exam doors close at 8:30.

The probability lens

Run the morning 2,000 times. Each dot is one possible arrival. The share of dots past 8:30 is the chance of being late.

The behavioural lens

The student remembers the last few smooth trips. That memory draws a much tighter, rosier picture than the real spread of outcomes. Overconfidence is a risk in itself.

The vulnerability lens

If the bus breaks down, a student with no backup is badly late. One with money for a taxi loses only a few minutes. Same hazard, different risk.

The management lens

Set a rule: accept at most a 5% chance of being late. The model then says how much earlier to leave. Risk becomes a decision threshold.

Model: walk 8 minutes; wait for a bus 0 to 10 minutes; ride 25 minutes plus a delay (rain adds about 12 minutes on average); a 3% chance the bus breaks down, adding 35 minutes, or 12 with a taxi as backup. Illustrative values.

So risk is not merely a technical label. It is a way of organising practical judgement when we lack full knowledge. People do not first solve a probability problem and then decide whether risk exists. They notice that something they value is uncertain, then look for tools to think about it. Try your own morning.

Plan your own morning

Change the weather, the buses, your departure time and your backup. The chart re-runs 2,000 mornings each time.

Risk, uncertainty, hazard and their relatives

Serious analysis starts by separating words that everyday talk mixes together.

Risk is the broader possibility that uncertain future events will affect something people value. It usually includes both the chance of outcomes and how serious they are. Uncertainty is incomplete knowledge about outcomes, probabilities, causes, timing or how a system works. Following the economist Frank Knight, many writers separate uncertainty that can be measured from deeper uncertainty that does not allow stable probabilities at all.2 The distinction still matters wherever novelty, strategic opponents or poor data make numerical confidence fragile.

A hazard is a potential source of harm: a toxic chemical, a storm surge, a design flaw, a software exploit, a virus. A hazard does not automatically mean high risk. It matters only when people, assets or systems can actually be reached by it. Probability is a number for chance. It answers “how likely is this event?” but says nothing on its own about how big or important the consequences would be. Impact, or consequence, is what happens if the event occurs, whether financial, physical, social, ethical, legal, ecological or reputational.

Exposure is how far people, assets or systems sit in harm's way. A server open to the internet has more cyber exposure than an isolated internal machine; a community on a floodplain more flood exposure than one on a hill. Vulnerability is susceptibility to damage, or limited capacity to withstand, absorb or recover. Two groups can be equally exposed but unequally vulnerable because one has savings, backups, mobility or political support and the other does not.3 A risk factor is a condition or attribute linked to a higher chance or greater severity of a bad outcome: smoking for heart disease, chronic absence for dropping out of school, weak passwords and slow patching for a security breach. A risk factor contributes to risk. It is not the risk itself.

These distinctions stop ideas collapsing into each other. Confuse hazard with risk and you ignore exposure and vulnerability. Confuse probability with risk and you ignore consequences. Treat a risk factor as a cause and you overstate certainty. Mistake uncertainty for randomness and you overlook ignorance, ambiguity and model error. Here is how three of them combine.

Hazard, exposure, vulnerability

Raise the storm, move the house, and give the family some protection. Watch the risk meter.

Note: the meter multiplies the three terms, the teaching relation in equation 41. It is a way of thinking, not a physical law.

Why risk is everywhere

Risk exists almost everywhere because action points towards an open future. Even stable systems vary. Weather changes, machines wear out, viruses mutate, prices move, institutions miscommunicate and people make mistakes. Uncertainty rooted in variability or randomness is called aleatory. Many situations also involve epistemic uncertainty, which comes from limited knowledge: a medical team that does not fully understand a rare drug interaction, a business without reliable data on a new market, a regulator unsure how a technology will behave at scale. Real decisions usually involve both.

Human systems add complexity because they adapt and connect. One disruption can cascade: a software outage becomes a financial, legal and trust problem. A health measure can cut disease while straining schools or the economy. A bank can look stable until many people react to the same signal at once. Strategy makes it harder still. In cybersecurity, defenders face adversaries who watch, adapt and exploit change, so risk cannot be reduced to counting past events.

Risk also persists because people value many things at once. Safety, liberty, efficiency, innovation, fairness and cost do not always move together. A rule that reduces fraud may add delay. A stricter security system may block intruders while frustrating and excluding legitimate users. Trade-offs like these mean risk is not only an enemy to eliminate. It is a condition to be negotiated.

History and philosophy

The modern language of risk grew out of trade, insurance, sea voyages, state administration and probability theory. The correspondence between Blaise Pascal and Pierre de Fermat in 1654, and later work by the Bernoullis, created the first mathematics for reasoning about uncertain gains and losses. Daniel Bernoulli's 1738 analysis of the St Petersburg paradox was a turning point: it showed that expected money alone cannot explain sensible choice, because an enormous average payoff can still be unattractive if each extra unit of wealth matters less than the last.4

Knight's Risk, Uncertainty and Profit of 1921 remains one of the most influential statements in the field. Knight argued that some uncertain events can be measured well enough for probability, while other uncertainty is too open-ended or unique to be measured that way.2 The distinction still shapes debates about innovation, entrepreneurship and change. Later thinkers widened the field. Mary Douglas and Aaron Wildavsky argued that what people see as dangerous is shaped by culture and social organisation, not only technical estimates.5 Ulrich Beck's “risk society” described how modern industry and technology manufacture new risks whose causes are built into institutions.6 Risk, on this view, is social, political and moral, not a neutral technical object.

Four centuries of thinking about chance

Drag the timeline, or press play.

A glossary

TermPlain-English meaning
RiskThe possibility that uncertain future outcomes will affect something people value.
Risk factorA condition or attribute linked to a higher likelihood or greater severity of an unwanted outcome.
UncertaintyIncomplete knowledge about outcomes, probabilities, timing, causes or how a system works.
HazardA potential source of harm.
ProbabilityA number describing how likely a specified event is.
Impact or consequenceThe size and kind of effect if the event occurs.
ExposureHow far people, assets or systems are in the path of possible harm.
VulnerabilitySusceptibility to damage, or limited ability to cope and recover.
Risk appetiteThe amount and type of risk an actor is willing to pursue or keep.
Risk toleranceThe acceptable range of variation around an objective before action is needed.
Decision thresholdA trigger point at which action, escalation, redesign or refusal is required.
ResilienceThe ability to absorb disruption, adapt and keep functioning.

3The literature

How the Field Grew Up

From games of chance to boardrooms, by way of psychology.

From probability to utility

The first technical work on risk came from probability and games of chance. Bernoulli's insight changed it: uncertain prospects have to be judged by their value to the person deciding, not just by their money payoff.4 That gave decision theory its foundation. John von Neumann and Oskar Morgenstern formalised expected utility in 1944 from a set of axioms about preferences,7 and Leonard Savage extended it in 1954 to situations where probabilities are personal judgements rather than objective frequencies.8 Together they built a powerful ideal of rational choice under uncertainty.

Its strength is coherence: it says how a disciplined decision-maker should compare uncertain options if their preferences are consistent. The same literature exposed its limits. Maurice Allais in 1953 and Daniel Ellsberg in 1961 showed that real choices often break the axioms, especially when certainty or ambiguity is involved.9,10 That did not destroy decision theory, but it made clear that being elegant as a rule is not the same as describing what people do. Try Ellsberg's famous choice.

Ellsberg's two urns

Two bets, two urns. Pick the urn you would draw from each time.

The statistical and financial turn

A second stream analysed risk through distributions, variance and portfolios. Harry Markowitz showed in 1952 that the risk of a collection of assets depends not only on each asset but on how they move together.11 It was one of the first systematic demonstrations that risk is relational: diversification helps precisely because outcomes do not all move in step. Later work added beta, downside risk, value at risk, expected shortfall, drawdown, credit risk and liquidity risk. Finance is technically sophisticated because markets produce constant data and explicit prices, yet it shows how unstable the concept is. For some, risk means volatility; for others, permanent loss, insolvency or extreme tail events. Even in the most quantitative field, risk is plural.

The Bayesian turn

Bayesian thinking treats probability as a degree of belief that can be updated when new evidence appears, not only as a long-run frequency. That is especially useful in medicine, reliability analysis, intelligence and forecasting, where evidence arrives step by step and prior knowledge matters. Bayesian methods do not remove uncertainty. They make analysts state their assumptions and revise them consistently. They are strongest when data are sparse, expert judgement matters and learning is ongoing, and they highlight a key modern theme: uncertainty is about what may happen, and also about how much to trust the model of what may happen.

Behaviour and psychology

Behavioural research challenged the idea that people usually decide the way expected utility says they should. Amos Tversky and Daniel Kahneman showed in 1974 that people rely on mental shortcuts such as availability, representativeness and anchoring.12 Their prospect theory of 1979 argued that people judge outcomes against a reference point, feel losses more strongly than equal gains, and weight probabilities unevenly.13 Paul Slovic showed that public responses to hazards depend on dread, control, familiarity, trust and catastrophic imagery as much as on statistics.14 George Loewenstein and colleagues argued that risk is often felt before it is thought about.15 This changed the field: a technically correct estimate can fail to guide behaviour if it clashes with how people perceive uncertainty.

Organisations and institutions

Another stream turned risk into management practice. Stanley Kaplan and John Garrick defined risk in 1981 as a set of triplets: what can happen, how likely it is, and what the consequences would be.16 Health and environmental assessment built step-by-step methods: identify the hazard, assess the dose-response relationship, estimate exposure, characterise the risk. Disaster frameworks stressed hazard, exposure, vulnerability and capacity.3 ISO 31000 and the COSO enterprise risk framework connected risk to objectives, governance, monitoring and treatment,1,17 and the US National Institute of Standards and Technology built detailed frameworks for information security, privacy and artificial intelligence.18,19,20 This work is less philosophically pure, but it is indispensable: it shifts the question from definition to action.

A comparative gap

For all this richness, the field is fragmented. Economists, psychologists, engineers, public-health scholars, disaster researchers and managers use the same word for different structures: some stress choice, some perception, some failure scenarios, some objectives, some social vulnerability.21 A comparison is needed. The useful question is not which field uses the word correctly, but what each framework makes visible and what it leaves out.

4Frameworks

Six Ways to See Risk

Each framework is a lens. Each lens shows some things and hides others.

Before going framework by framework, look at one decision through all six lenses at once.

One release, six lenses

A software team wants to ship a new payments feature on Friday afternoon. Pick a lens to see what it measures and what it would decide.

Classical probability

Here risk is expressed through the likelihood of events and the spread of their possible values. It works best when events repeat, or are similar enough that frequencies and statistical models can be estimated: insurance pricing, quality control, much reliability analysis and epidemiology. Its strength is clarity. It makes analysts define events carefully, assign probabilities openly and compare options on common numerical ground. Its weakness is that real uncertainty is often unstable, sparse or changing. The more unique the event, the less a frequency can be trusted. Strategic contests, new technologies, novel viruses and one-off political shocks do not fit a model built for repeated identical trials. Probability is an essential language of risk, but not the whole language.

Expected utility and decision theory

Expected utility shifts attention from events to choices: how should a rational person rank uncertain prospects whose outcomes they value differently? It explains risk aversion without calling it irrational. Someone may refuse a gamble with a high average if extra wealth matters less and less to them and a bad outcome would really hurt. It is strongest where options are clear and stable and consistency matters, as in insurance, investment, policy analysis and negotiation. Its assumptions are demanding: preferences may be unstable or incomplete, probabilities disputed, and framing can change choices. It is best seen as a benchmark of rational coherence, not a full description of how people decide.

Bayesian approaches

Bayesian frameworks treat uncertainty as belief revised by evidence. An analyst starts with a prior, meets evidence and reaches a posterior. That makes learning explicit, which is valuable when data are incomplete, expert judgement matters or decisions must be updated repeatedly, as in diagnosis, forecasting, fault detection, security monitoring, intelligence and medicine. Its weakness is not incoherence but dependence on assumptions. Priors can be disputed, models can be wrong and data can be biased. Bayesian methods do not remove judgement. They discipline it.

Behavioural and psychological approaches

These ask how people actually perceive and choose under uncertainty, starting from limited attention, framing, emotion and social influence. Prospect theory, affect-based models and risk-perception studies belong here. Their strength is realism. They explain why people fear rare catastrophes yet ignore common chronic harms, why they hold losing investments too long, why trust changes how technical information is heard, and why identical numbers can provoke opposite reactions in different frames. Their weakness is that they offer fewer unified rules for institutions. They are best for explaining behaviour and designing interventions, not as stand-alone systems of governance.

Organisational and managerial frameworks

These link risk to objectives, governance, accountability and treatment. ISO 31000 defines risk as the effect of uncertainty on objectives; COSO ties it to strategy and performance.1,17 Risk here is a management matter of ownership, criteria, escalation, reporting and control. The strength is reach: these frameworks help institutions decide what to watch, how much uncertainty to accept, who owns each risk and what response is needed. The weakness is vagueness. If every uncertain effect on objectives is a risk, the idea can lose precision. They remain indispensable because organisations need workable procedures even when conceptual purity is impossible.

Domain-specific frameworks

Many of the most successful frameworks belong to one field. Health and environmental assessment follows hazard identification, exposure assessment, dose-response and characterisation. Disaster management uses hazard, exposure, vulnerability and capacity. Engineering uses scenarios, likelihoods and consequences. Cybersecurity speaks of threats, vulnerabilities, impact, governance and recovery. They work because they follow the causal structure of their field. Their limit is that they do not travel well: a flood model is not a theory of portfolio choice, and a volatility model is not an account of AI safety.

5Mathematics

The Mathematics of Risk, Explained

Every equation stated, every symbol translated, the central results proved.

Why mathematics matters

Mathematics does not solve the whole problem of risk, but it makes clear what is being assumed, measured and compared. “This option is risky” can hide several different claims: that the bad event is likely, that its impact is large, that the uncertainty is hard to measure, that losses matter more than gains, or that the decision-maker could not recover. Notation forces us to say which. It can also create false confidence if symbols are used without clear meaning. So each equation below comes in layers: the formula, its symbols in plain English, and where it helps, a short proof.

Notation

SymbolMeaning in plain English
S_iScenario or outcome number i, for example S_1 = “arrive on time”, S_2 = “arrive late”.
p_iProbability of scenario S_i, a number between 0 and 1.
L_iLoss if scenario S_i happens, in money, time, injuries or another unit.
XA random variable: a quantity whose value depends on which uncertain outcome occurs.
x_iA possible value of X.
E[X]The expected value of X, its probability-weighted average.
U(x)Utility of outcome x: its value to the decision-maker, not just the raw number.
\muThe mean or expected value, often \mu = E[X].
\sigma^2Variance: the average squared distance of outcomes from the mean.
\sigmaStandard deviation, the square root of the variance.
A, BEvents, for example A = “the traveller misses the flight”, B = “the road is blocked”.
P(A)Probability that event A occurs.
P(A \mid B)Probability of A given that B has happened.
\pi(p)Decision weight in prospect theory for probability p, not the same as the objective probability.
wWealth or resources, in discussions of utility.
rRate of return in finance.
w_1, w_2Portfolio weights on assets 1 and 2, usually adding up to 1.
\sigma_1^2, \sigma_2^2Variances of the returns of assets 1 and 2.
\operatorname{Cov}(X, Y)Covariance of X and Y: whether they move together.
HHazard, the source of harm, in conceptual relations.
E_xExposure, with a subscript to avoid confusion with the expected value E[\cdot].
VVulnerability: susceptibility to damage or weak capacity to cope.

Expected loss

The most basic numerical description of risk is the expected loss:

where EL is the expected loss, p_i the probability of outcome i, L_i the loss if it happens, and n the number of possible outcomes. In words: multiply each possible loss by its chance, then add them up. If a server outage has a 2% chance of costing 100,000, that scenario contributes 2,000 to the expected loss. The result is a long-run average, not a forecast that the next outage will cost exactly that.

A 2.0% chance of losing 100,000 adds 2,000 to the expected loss. Over 30 years you would expect it to strike about 0.6 times, and to escape it entirely 55% of the time.

Drag the red numbers.

Why expected loss is useful, and not enough

Expected loss squeezes uncertain outcomes into one average that helps with budgeting, pricing, insurance and rough comparison. It also hides things. A sure loss of 2,000 and a 2% chance of losing 100,000 have the same expected loss, but they are not equally bearable. One can be absorbed from cash flow; the other may threaten survival. Build a table of your own, then put the two side by side over a lifetime.

The same average, a different fate

Edit the scenarios to compute an expected loss. Then compare a sure loss with a rare large one over 30 years, with the cash reserve you choose.

Simulation: 1,000 thirty-year lives. Each year the reserve earns 2,500 and pays either a sure 2,000 or, with 2% probability, 100,000. A life is ruined if the reserve ever drops below zero. Illustrative values.

Expected loss from the definition of expectation

Let X be a loss that takes the values L_1, L_2, \ldots, L_n with probabilities p_1, p_2, \ldots, p_n. By the standard definition of the expectation of a discrete random variable,

and writing L_i for x_i,

So expected loss is simply the expected value of the loss. No extra theorem is needed; it is the same object in the language of risk.

Linearity of expectation

One of the most useful and reliable facts in risk analysis is that expectation is linear:

where X and Y are uncertain quantities and a and b are fixed numbers. The expected value of a weighted combination equals the same combination of expected values.

Proof. Suppose X and Y take values (x_j, y_k) together with probabilities p_{jk}. Then

The second line is ordinary algebra; the third uses the definition of expectation. Importantly, the result does not need X and Y to be independent. That is why expected values add up so much more easily than variances.

Expected utility

Expected utility replaces the raw payoff with its value to the decision-maker:

where EU is expected utility, x_i the outcome in scenario i and U(x_i) its utility. Uncertain choices should be judged by the average of utility, not necessarily the average of money, because the same amount does not mean the same to everyone. A loss of 1,000 may annoy a large firm and devastate a household with no savings. A common illustration is logarithmic utility,

where w is wealth and \ln the natural logarithm. It captures diminishing marginal utility: when you have little, an extra unit matters a lot; when you have plenty, it matters less. This is exactly how Bernoulli dissolved the St Petersburg paradox. Play the game, then see what a sensible person would pay to enter.

The St Petersburg game

Toss a coin until it lands heads. If that takes k tosses, you win 2k. The average payout is infinite. Would you pay a fortune to play?

Calculation: certainty equivalent CE solves ln(w + CE) = Σ 2−k ln(w + 2k), summed to k = 60, for a player with wealth w who pays nothing up front. This follows Bernoulli (1738).

Why a curve makes you careful

A 50–50 gamble: win or lose the same amount. Widen the gamble and watch the gap between the average outcome and the average happiness.

Expected utility gives a disciplined rule for choice. It is not a law of how people actually behave. People respond to framing, ambiguity, regret and reference points in ways the equation does not capture.

Variance and volatility

The expected value describes the centre of a distribution. The variance describes its spread:

where \mu = E[X]. Subtract the mean from each outcome, square the difference and take the average. Squaring stops positive and negative deviations cancelling, and gives more weight to large ones. The standard deviation is

which is in the same units as X. In finance it is often used as a measure of volatility.

Proof of the variance identity. Starting from the definition,

Since \mu is a constant, E[\mu^2] = \mu^2, and E[X] = \mu. Therefore

The identity is useful because it often makes the variance easier to compute. Check it yourself.

Two roads to the same variance

Drag the six equally likely outcomes up or down. Both formulas are recomputed live, and always agree.

Bayes' theorem

Bayesian reasoning rests on one theorem:

where A is a hypothesis or event of interest, B the observed evidence, P(A) the prior probability of A, and P(A \mid B) its posterior probability after seeing B.

Proof. By the definition of conditional probability,

and likewise

Rearranging the second gives

and substituting into the first,

which is Bayes' theorem. Updated belief depends on three things: how plausible the hypothesis was beforehand, how strongly the evidence would be expected if it were true, and how common the evidence is overall. Ignore the base rate and medical tests or alarms are badly misread.

A practical Bayesian example

Suppose a disease affects 1% of a population. A test is positive 95% of the time when the disease is present, and also positive 5% of the time when it is absent. Let A be “the patient has the disease” and B “the test is positive”. Before you see the answer, guess: if your test comes back positive, how likely is it that you have the disease?

A positive test, a thousand people

Make your guess first. Then see the answer as people, not percentages.

Why people, not percentages: Gerd Gigerenzer and Ulrich Hoffrage showed that “natural frequencies”, counts of people, make Bayesian reasoning far easier than conditional probabilities.22,23

To apply Bayes' theorem, first compute P(B):

Now update:

Even after a positive test, the chance of disease is about 16.1%, not 95%. The example is famous because it shows how easily people confuse “the chance of a positive test if you have the disease” with “the chance of the disease if your test is positive”.

If 1.0% of people have it, the test catches 95.0% of them and wrongly flags 5.0% of healthy people, then a positive result means a 16.1% chance of disease. Out of every 1,000 people tested, 59 test positive, and 10 of them are actually ill.

Drag any of the three numbers.

Portfolio variance and diversification

Markowitz's key insight is clearest with two assets. A portfolio's return R_p combines asset returns R_1 and R_2 with weights w_1 and w_2:

Its expected return follows from linearity of expectation:

and its variance is

where \sigma_1^2 = \operatorname{Var}(R_1) and \sigma_2^2 = \operatorname{Var}(R_2).

Proof. Start with

Square both sides and take expectations:

The formula shows why diversification is not just owning many assets. What matters is how their returns move together. If covariance is low or negative, portfolio risk can fall without expected return falling as much.

Where diversification comes from

Set two assets' volatility and how closely they move together, then slide the mix. Equation 33 is filled in live.

Prospect theory

Prospect theory is an empirical model, not a theorem of rational choice, but it uses a useful formal structure. A common simplified form is

where v(x_i) is the value of outcome x_i relative to a reference point, and \pi(p_i) is a decision weight applied to probability p_i. The value function is often written in two pieces:

Here \alpha and \beta usually lie between 0 and 1, so sensitivity diminishes, and \lambda > 1 captures loss aversion. Tversky and Kahneman's 1992 estimates were \alpha = \beta = 0.88 and \lambda = 2.25.24 What matters for a general reader is not the exact fit but the shape: gains and losses are treated differently, and probabilities are not felt in proportion.

How losses and odds are felt

Change loss aversion, curvature and probability distortion. The defaults are Tversky and Kahneman's 1992 estimates.

Weighting function: w(p) = pγ / (pγ + (1 − p)γ)1/γ, with γ = 0.61 for gains (Tversky and Kahneman, 1992).

Relations that are not universal laws

Some fields use multiplicative relations such as

where H is hazard, E_x exposure and V vulnerability. It is good for teaching, because it shows risk rising when hazards grow, more is exposed or vulnerability increases, and it is the logic of the flood figure in section 2. It should be treated as a rule of thumb, not a physical law. In practice each term can have many dimensions and behave non-linearly. Its value is clarity, not exact measurement.

What mathematics can and cannot do

These equations show that risk analysis can be rigorous. Rigour is not completeness. Expected loss says nothing about survival or fairness. Variance does not tell upside from downside. Bayes' theorem disciplines updating, but only within the model supplied. Prospect theory describes many real choices but does not tell an institution what to do. Mathematics is strongest when it clarifies a problem that is already well posed, and weakest when symbols are used to hide value judgements, disputed assumptions or poor data.

6Behaviour

Why We Misjudge Risk

People rarely calculate. They use shortcuts, and the shortcuts have patterns.

Heuristics and bounded judgement

Behavioural research starts from a simple observation: real people do not usually reason about risk by working out expected utilities from stable beliefs. They use heuristics.12 That is not always a flaw; shortcuts are fast and often sensible. But they produce systematic distortions. Availability makes us overestimate risks that are vivid, recent or emotional: a dramatic plane crash or ransomware attack can dominate judgement even when routine risks matter more. Representativeness makes us match cases to stereotypes and neglect base rates, as when a patient feels a disease is likely because some symptoms “fit”, even though the condition is rare. Anchoring makes early numbers stick: first cost estimates, first safety labels or first infection counts keep shaping judgement after new evidence arrives. Many failures of risk management are failures of interpretation and attention, not of information.

Prospect theory in practice

Prospect theory remains one of the most important descriptions of risky choice. People judge outcomes against a reference point, feel losses more than equal gains, and so tend to avoid risk when facing gains and seek it when facing losses.13 Take a manager choosing between a cautious launch with a modest sure gain and a riskier launch with a higher average. When the firm is comfortably above target, the sure gain looks attractive. When it is below target and must report soon, the same manager may gamble on the risky launch rather than lock in a loss against expectations. The options have barely changed. The reference point has.

Same options, different reference point

Put the firm above or below its target, then see which launch a prospect-theory manager picks, and why.

Prospect theory explains behaviour that expected utility struggles with, including loss aversion, framing effects and the habit of insuring against losses while gambling for gains. It is not a theory of institutions, but it is central to understanding real choices.

Perceived risk and calculated risk

Calculated and perceived risk often diverge because people respond not only to probabilities and outcomes but to control, choice, dread, fairness and trust.14 Flying is the familiar example: rare catastrophes are vivid and public, while driving, often more dangerous per journey, feels safer because we feel in control. This is not simply laypeople being irrational and experts being rational. The public often weighs things technical summaries understate: whether exposure is voluntary, whether harm falls on particular groups, whether the institution telling the story is trusted. A community may oppose a waste facility or a data-hungry system not because it cannot understand numbers but because it doubts the competence, fairness or honesty of those in charge. Perceived risk carries real social information.

Risk as feeling

Research on emotion shows that risk is often felt before it is analysed.15,25 Fear, dread, disgust, relief and excitement steer attention and action. That is why stories and images move people more than statistics, and why some chronic risks get too little attention: they lack drama, even when their total burden is huge. The lesson is not to ignore emotion but to respect how people actually process danger. If every security warning looks the same, people stop noticing. If health advice is precise but psychologically opaque, behaviour does not change.

Communicating risk

Risk communication fails for recurring reasons. One is confusing relative and absolute risk: “this doubles your risk” sounds alarming, but its meaning depends entirely on the starting point. Another is confusing conditional and posterior probabilities, as in the test example. A third is giving uncertainty without guidance: “unlikely but possible” may be true and still leave people unable to decide. Good communication says which event is meant, separates chance from consequence, uses plain frequencies or concrete comparisons, and connects information to action.22,26 “Three out of ten forecasts like this bring delays of more than twenty minutes, so leave half an hour early” beats a bare probability.

“Doubles the risk” of what?

Set the starting risk and the multiplier. The headline stays the same; the number of people affected does not.

7Applied

Eight Fields, Eight Meanings

Education, health, travel, finance, engineering, cybersecurity, business and policy.

The same word does different work in each field. Pick one to see how risk is framed there, what gets measured and which frameworks fit best. The full discussion of each follows.

How each field reads risk

Pick a field.

Education

Education shows risk working through accumulated conditions rather than one dramatic event. Research on absence and dropping out identifies many child, family, school and peer risk factors, including weak attachment to school, academic difficulty, low parental involvement, behaviour problems and social stress.27 These are risk factors, not verdicts: they mark patterns linked to a higher chance of harm. Education also shows why vulnerability matters. Two students may face the same timetable or transport problem, but one has family support, tutoring, reliable internet and a flexible school, and the other does not. The same hazard produces unequal risk, which is why educational risk is better understood as an ecology than as a table of odds.

Health

Health combines population statistics, individual judgement, biology and communication. Public health identifies major behavioural and environmental risk factors such as smoking, poor diet, inactivity, air pollution and unsafe water. Clinical medicine adds test results, history, age, other conditions and treatment effects. Health risk can be expressed as incidence, absolute risk, relative risk, attributable risk, survival probabilities and expected harm. It also shows the limits of numbers. Patients do not experience “a 5% complication rate” as an abstraction; they ask what it would mean for their body, family, work and future, and they react to how it is framed. Preparing for illness by exercising, vaccinating, screening, saving or buying insurance is risk management before the event: a relationship between exposure, behaviour, baseline health, financial resilience and the health system itself.

Travel

Travel risk depends on destination, itinerary, the traveller, season, infrastructure and behaviour. A short work trip to a well-equipped city is very different from a remote trek far from medical care, and the same destination can be riskier or safer depending on who goes, what they do and what backups exist. Travel also shows the gap between vivid fear and everyday threat. Travellers worry about plane crashes or political violence while underestimating dehydration, road accidents, lost medication or missed connections. Good travel planning combines statistics, practical preparation and judgement on the spot.

Finance

Finance has one of the richest vocabularies of risk: portfolio theory, credit models, duration, stress tests and tail-risk measures. It also shows that the meaning depends on who is asking. For a trader, volatility may be central. For a pension fund, long-run solvency and tail losses matter more. For a bank supervisor, liquidity and contagion can be decisive. For a household investor, permanent loss and panic selling may matter more than short-term swings. Herding, overconfidence, loss aversion and framing can destabilise even data-rich markets, which is why finance holds some of the most advanced quantitative tools and some of the clearest cases of models misused.

Engineering

Engineering risk centres on system failure, reliability, redundancy and chains of consequence. For bridges, aircraft, nuclear plants and factories, analysts ask which parts can fail, what sequences of events could follow, how likely each is and what it would cost: the scenario-based definition in its natural home. Formal methods matter greatly because some failures are catastrophic and because design changes can reduce risk directly. Redundancy, fault tolerance, safety margins and fail-safe design all reflect the understanding that risk depends on the system's architecture, not only the initiating hazard. Rare, high-consequence events stay hard, because history is thin and models may miss interactions, so engineering pairs calculation with conservatism and judgement.

Cybersecurity

Cybersecurity is both technical and strategic. Attackers adapt, vulnerabilities change with every software update, and exposure shifts when systems are connected, integrated, outsourced or opened to partners. Consequences range from nuisance to catastrophe, and long-run frequencies are less stable than in classic insurance. Take a software release. A coding flaw is a hazard. Deploying it on the open internet creates exposure. Weak monitoring and slow patching increase vulnerability. The real risk depends on the attacker's skill, the value of the target, the controls in place and how fast the team can detect, respond and recover, which is why security frameworks put governance, detection, response and recovery alongside technical scores.20

Business

Business risk spans strategy, operations, law, finance, reputation and supply chains. A company entering a new market faces uncertain demand, competitors' reactions, regulatory change, hiring limits and effects on its brand. Not all of these have stable probabilities, so business sits close to Knight's deep uncertainty. Businesses still have to decide, and they use scenario planning, sensitivity analysis, portfolio logic, internal controls and statements of risk appetite to structure choices. Risk is not only something to avoid. Firms create value partly by taking chosen risks. The question is which are worth taking, which need reducing and which exceed tolerance.

Public policy

Public policy is where risk analysis and ethics meet most openly. Regulators cannot remove every risk, and should not try. They must decide which risks justify intervention, how strongly to act, how to share the burdens and how to protect fairness, liberty and innovation.28 Policy also highlights distribution. Average risk can fall while vulnerable groups carry more of what remains. A flood barrier may protect one district and push danger downstream. A digital identity system may improve efficiency while excluding people with weak access. Policy needs a comparative understanding of risk because it has to balance numbers, institutions and justice.

8Practice

Managing Risk in Practice

Identify, analyse, evaluate, treat, monitor, communicate. Then do it again.

The cycle

Most practical systems follow a sequence of identification, analysis, evaluation, treatment, monitoring and communication.1 Identification asks what could affect objectives. Analysis asks about likelihood, consequence, causes, controls and uncertainty. Evaluation compares the result with criteria or thresholds. Treatment chooses whether to avoid, reduce, transfer, accept or monitor. Monitoring checks whether assumptions still hold and controls still work. Communication ties it together. The sequence turns vague worry into an organised workflow, and it supports learning: near misses, weak signals and small control failures become information rather than isolated annoyances.

Qualitative and quantitative assessment

Qualitative assessment uses categories, narratives, expert judgement, interviews, workshops, scenarios and heat maps. Quantitative assessment uses probabilities, distributions, expected losses, simulations and stress tests. The choice should follow the problem, not ideology. Where data are rich and pricing matters, numbers are indispensable. Where novelty is high, causes are poorly understood or the aim is ranking rather than pricing, qualitative methods may fit better. Most serious institutions combine them. The mistake is not qualitative reasoning; it is vague qualitative reasoning without clear definitions and accountability. Heat maps are the classic example, and the risk analyst Louis Anthony Cox has shown how they can mislead.29 Try one.

The risk matrix, and its blind spot

Drag each risk to the cell you think fits. Move the appetite line. Then switch on Cox's test.

Appetite, tolerance and thresholds

Risk appetite is the amount and type of risk an organisation is willing to pursue or keep in pursuit of its objectives. Risk tolerance is the acceptable range of variation around those objectives. Decision thresholds turn both into operational triggers. They matter because analysis alone does not tell an institution what to do. A university may tolerate uncertainty in enrolment forecasts but not in exam integrity. A hospital may tolerate scheduling inefficiency but not medication errors. A start-up may accept uncertainty about entering a market but not breaking critical law. Mature governance distinguishes types of risk rather than talking vaguely about “more” or “less”.

Governance, culture and incentives

Risk management fails when governance is weak, incentives are distorted or bad news is suppressed. Boards, managers, regulators, front-line staff, engineers, clinicians and customers see different risks because they hold different information and incentives, and no framework can fix that alone. The culture of escalation matters. If bad news is punished, warnings arrive late or softened. If ownership is vague, critical issues become everyone's problem and nobody's responsibility. Governance and culture are not side topics; in complex organisations they are part of the risk.

Resilience

Finally, risk management cannot be only prediction and prevention. Some harmful events cannot be prevented with certainty, so systems need buffers, redundancy, fallbacks and recovery plans. In cybersecurity that means detection, response, backup and restoration. In disaster management, preparedness, evacuation capacity and recovery planning. In business, cash reserves, varied suppliers and crisis communication. Resilience does not replace analysis. It complements it, by accepting that some uncertainty survives every model.

9Comparison

The Frameworks Side by Side

Tell the table what you need to do, and it will point to the tools that fit.

Which framework fits your problem?

Choose the task in front of you. The matching rows light up.

FrameworkCore definition of riskStrengthsWeaknessesBest use casesBest fit
Classical probabilityThe probability distribution of specified events or losses.Clear, measurable, comparable; strong where events repeat.Weak under novelty, ambiguity or structural change.Insurance, quality control, reliability studies, some epidemiology.Theory and practice, when data are stable.
Expected utility and decision theoryChoice among uncertain prospects, judged by utility rather than raw payoff.Coherent; disciplined trade-offs; explains rational risk aversion.Demanding assumptions; limited realism; sensitive to framing and ambiguity.Insurance decisions, formal policy analysis, structured investment choices.Normative theory and formal decision support.
BayesianUncertain belief, updated by evidence.Explicit learning; transparent assumptions; strong when data are sparse.Depends on priors and model structure; can look more certain than the evidence allows.Diagnosis, forecasting, intelligence, fault detection, cyber monitoring.Adaptive theory and practice.
Behavioural and psychologicalPerceived, framed and felt uncertainty that shapes judgement and action.Explains real behaviour, communication failure, loss aversion, trust effects.Less unified as a decision rule for institutions; findings can be fragmented.Public communication, clinical decisions, consumer behaviour, safety culture.Human behaviour and policy design.
Organisational and managerialUncertainty in relation to objectives, strategy and performance.Action-oriented; supports ownership, governance, escalation, monitoring.Can become vague or bureaucratic, detached from real judgement.Enterprise risk management, board oversight, public administration.Practice and governance.
Domain-specific institutionalRisk framed by field-specific causal structures, such as hazard, exposure and vulnerability, or scenario, likelihood and consequence.Highly actionable; matched to operational reality.Transfers poorly across fields; may fragment wider understanding.Engineering safety, disaster risk reduction, health and environmental assessment, cybersecurity.Specialised practice.

10Findings

What the Comparison Shows

Fit-for-purpose pluralism.

Risk is plural but not chaotic. Different fields define risk differently, but that does not make the idea useless. Each stresses a different side of the same problem: uncertain futures affecting things that matter. Probability frameworks stress measurable chance; decision theory, choice; Bayesian approaches, learning; behavioural research, perception and response; organisational frameworks, governance; domain frameworks, causal structure.

Risk is not any single number. Probability, expected loss, variance, value at risk and heat-map scores all describe parts of risk. None is the whole. Confusion begins when the measure is mistaken for the thing measured.

The quality of uncertainty matters. It is not enough to say an event has probability p. We need to ask where p came from, how stable the process behind it is, and how much the model itself might be wrong. That is why ambiguity and Knight's deep uncertainty remain central even in the most quantitative fields.

Human behaviour is central. A technically correct estimate can fail if it is not trusted, understood or acted on. Risk management that ignores perception and communication keeps underperforming.

Risk is tied to values. Decisions about acceptable risk cannot be made by mathematics alone. Fairness, responsibility, tolerability, dignity, distribution and legitimacy all matter.

There is no master framework. The best one depends on the purpose.

From these findings comes a practical conclusion. To price repeated losses, probability and expected loss may be enough. To choose rationally between uncertain prospects, expected utility is central. To learn from emerging evidence, Bayesian methods are powerful. To explain public reactions or improve communication, behavioural theories are essential. To run an organisation, governance frameworks are needed. The lesson is fit-for-purpose pluralism.

11Limitations

Where Every Approach Falls Short

Knowing a model's blind spots is part of using it well.

False precision. Numerical models can look exact when their assumptions are fragile, especially for tail risks, new technologies, adversarial settings and systemic crises. A precise-looking number can hide deep uncertainty.

Reductionism. Expected loss flattens the shape of a distribution. Variance treats upside and downside the same. Simple heat maps blur rare catastrophes with frequent small harms. Checklists can list dozens of risks while missing how they interact and cascade.

Descriptive weakness. Formal models often assume steadier preferences and more careful calculation than real people have. Used without behavioural insight, they mispredict how people respond to warnings, treatment options or policy changes.

Ethical incompleteness. Average risk can fall while the remaining burden piles onto those with less voice or fewer resources. Vulnerability and distribution are not optional extras.

Domain lock-in. Field-specific frameworks work well at home but are often stretched too far. A flood model is not a theory of financial risk, and portfolio variance is not a theory of social vulnerability.

None of this means current models fail. It means users must understand what each one captures and what it leaves out.

12Conclusion

Risk Is a Relationship

Between uncertain futures and the things we value.

Risk is one of the most universal conditions of human action, because people must decide before the future is certain. Yet no single definition works the same way across finance, medicine, engineering, cybersecurity, disaster governance, education and public policy. Different frameworks light up different parts of the same broad problem.

This paper has argued that risk is best understood by comparison. Probability models are strongest where events repeat and can be measured. Expected utility is strongest as a rule for coherent choice. Bayesian methods are strongest when evidence accumulates and prior knowledge matters. Behavioural approaches are strongest for understanding judgement, communication and trust. Organisational frameworks are strongest for governance, accountability and action. Domain frameworks are strongest where a field's causal structure is well understood.

So the most useful conclusion is not that one framework wins. Mature risk analysis is layered. Good judgement asks which sides of risk matter most for this decision, which uncertainties can be measured and which cannot, what is at stake, who is exposed, who is vulnerable, what the model assumes and what kind of action is needed.

Risk is not merely a number, a feeling or a checklist. It is the structured relation between uncertain futures and valued outcomes.

The stronger the analysis, the more honestly it joins mathematics, human behaviour, institutional design and moral consequence.

Sources

  1. International Organization for Standardization. (2018). ISO 31000:2018 Risk management: Guidelines. ISO.
  2. Knight, F. H. (1921). Risk, Uncertainty and Profit. Houghton Mifflin.
  3. United Nations General Assembly. (2016). Report of the open-ended intergovernmental expert working group on indicators and terminology relating to disaster risk reduction (A/71/644). Endorsed 2017. UNDRR.
  4. Bernoulli, D. (1954). Exposition of a new theory on the measurement of risk. Econometrica, 22(1), 23–36. (Original work published 1738.)
  5. Douglas, M., & Wildavsky, A. (1982). Risk and Culture: An Essay on the Selection of Technical and Environmental Dangers. University of California Press.
  6. Beck, U. (1992). Risk Society: Towards a New Modernity. Sage.
  7. von Neumann, J., & Morgenstern, O. (1944). Theory of Games and Economic Behavior. Princeton University Press.
  8. Savage, L. J. (1954). The Foundations of Statistics. Wiley.
  9. Allais, M. (1953). Le comportement de l'homme rationnel devant le risque: Critique des postulats et axiomes de l'école américaine. Econometrica, 21(4), 503–546.
  10. Ellsberg, D. (1961). Risk, ambiguity, and the Savage axioms. Quarterly Journal of Economics, 75(4), 643–669.
  11. Markowitz, H. (1952). Portfolio selection. Journal of Finance, 7(1), 77–91.
  12. Tversky, A., & Kahneman, D. (1974). Judgment under uncertainty: Heuristics and biases. Science, 185(4157), 1124–1131.
  13. Kahneman, D., & Tversky, A. (1979). Prospect theory: An analysis of decision under risk. Econometrica, 47(2), 263–291.
  14. Slovic, P. (1987). Perception of risk. Science, 236(4799), 280–285.
  15. Loewenstein, G. F., Weber, E. U., Hsee, C. K., & Welch, N. (2001). Risk as feelings. Psychological Bulletin, 127(2), 267–286.
  16. Kaplan, S., & Garrick, B. J. (1981). On the quantitative definition of risk. Risk Analysis, 1(1), 11–27.
  17. Committee of Sponsoring Organizations of the Treadway Commission. (2017). Enterprise Risk Management: Integrating with Strategy and Performance. COSO.
  18. National Institute of Standards and Technology. (2018). Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy (SP 800-37 Rev. 2).
  19. National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1).
  20. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0.
  21. Aven, T. (2016). Risk assessment and risk management: Review of recent advances on their foundation. European Journal of Operational Research, 253(1), 1–13.
  22. Gigerenzer, G. (2011). What are natural frequencies? BMJ, 343, d6386.
  23. Gigerenzer, G., & Hoffrage, U. (1995). How to improve Bayesian reasoning without instruction: Frequency formats. Psychological Review, 102(4), 684–704.
  24. Tversky, A., & Kahneman, D. (1992). Advances in prospect theory: Cumulative representation of uncertainty. Journal of Risk and Uncertainty, 5(4), 297–323.
  25. Slovic, P., Finucane, M. L., Peters, E., & MacGregor, D. G. (2004). Risk as analysis and risk as feelings: Some thoughts about affect, reason, risk, and rationality. Risk Analysis, 24(2), 311–322.
  26. World Health Organization. (2018). Communicating Risk in Public Health Emergencies: A WHO Guideline for Emergency Risk Communication Policy and Practice.
  27. Gubbels, J., van der Put, C. E., & Assink, M. (2019). Risk factors for school absenteeism and dropout: A meta-analytic review. Journal of Youth and Adolescence, 48(9), 1637–1667.
  28. Organisation for Economic Co-operation and Development. (2010). Risk and Regulatory Policy: Improving the Governance of Risk. OECD.
  29. Cox, L. A., Jr. (2008). What's wrong with risk matrices? Risk Analysis, 28(2), 497–512.

Credits

Research this paper builds on

Frank Knight; Daniel Bernoulli; John von Neumann and Oskar Morgenstern; Leonard Savage; Maurice Allais; Daniel Ellsberg; Harry Markowitz; Amos Tversky and Daniel Kahneman; Paul Slovic and colleagues; George Loewenstein and colleagues; Stanley Kaplan and John Garrick; Mary Douglas and Aaron Wildavsky; Ulrich Beck; Terje Aven; Gerd Gigerenzer and Ulrich Hoffrage; Louis Anthony Cox; Jorine Gubbels and colleagues; the authors of ISO 31000, COSO ERM, the NIST frameworks and the WHO and OECD guidance.

Corrections to the first draft

Aven's review is dated 2016, not 2015. The 1979 prospect theory paper is by Kahneman and Tversky, in that order.

Type and tools

Set in UnifrakturMaguntia, Noto Serif Display, Source Serif 4, Libre Franklin and IBM Plex Mono, under the SIL Open Font License. Equations typeset with KaTeX. Simulations run in your browser. No trackers, no ads.

About the paper

Written in August 2025, prepared for public readability and academic use. It contains no generated images.

Cite this paper

Raj, A. (2025, August). Risk factors, uncertainty, and decision-making: A comparative study of how risk is defined, measured, perceived, and managed across different frameworks. The Build Journal Research Supplement, No. 3. https://abhnv.in/p3/
@article{raj2025risk,
  author  = {Raj, Abhinav},
  title   = {Risk Factors, Uncertainty, and Decision-Making: A Comparative Study of How Risk Is Defined, Measured, Perceived, and Managed Across Different Frameworks},
  journal = {The Build Journal Research Supplement},
  number  = {3},
  year    = {2025},
  month   = aug,
  url     = {https://abhnv.in/p3/}
}

More from the supplement