Wehrspohn Risk Management

The most dangerous risks are not in the risk inventory.

April 30, 2026

The most dangerous risks are not in the risk inventory. Donald Rumsfeld once coined a famous distinction: • Known knowns • Known unknowns • Unknown unknowns This matrix is still cited in risk management today. But it has a blind spot. It distinguishes what we know and do not know, but not what we are allowed to say. In practice, there is a further category: Known but unspeakable Risks that everyone knows about, but that cannot be entered into the risk inventory. Examples? • Strategic misjudgments at board level • Misaligned incentives that systematically lead to rule violations • Risk methods that produce seemingly precise numbers but have not been validated The problem is not that these risks are unknown. The problem is: naming them is politically not permitted. And this makes things even more critical. Because it gives rise to a second, even more dangerous category: Unknown because unthinkable Risks we do not know about because we are not allowed to think in certain directions at all. What happens? • No scenarios are developed • No data is collected • No models are built → The entire search space remains unexplored This creates two systematic blind spots: • Known, but unspeakable • Unknown, because unthinkable Neither has anything to do with a lack of data. They are the result of: • incentive systems • hierarchies • organizational culture In this context, Stefan Hunziker, PhD recently made an important point: The most dangerous risks are often not assessed because they are hard to measure. That is absolutely correct. I would like to add: For the truly critical risks, data is often not even collected, because they are not supposed to be measurable. Because “lack of data” is often the outwardly plausible justification. The real reason often lies deeper: • No data is collected • No scenarios are calculated • No models are built Not because it would be impossible, but because it is not organizationally wanted. Conclusion: The biggest risks do not necessarily arise where we know too little. They arise where we: • are not allowed to say what we know • and do not investigate what we could know If you take this seriously, the focus in risk management shifts. Away from: → “Which risks have we not yet identified?” Toward: → “Which risks are we actually not allowed to name?” → “In which directions do we systematically not think?” This is not a methods problem. This is an organizational problem.

View image

This post was originally published on LinkedIn. View and join the discussion there