A side-by-side comparison of Risk and Harm. It explains how a likelihood-and-severity assessment differs from the adverse effect experienced by a person, group, organization, or system.
Quick Verdict: Use risk for potential adverse outcomes before or during assessment; use harm for the adverse effect that has occurred or may be concretely described.
Risk defines combination of the likelihood of an adverse event and the severity of its potential harm.
Context: Most relevant when assessing possible adverse outcomes and deciding what controls are needed.
Harm describes adverse effect experienced by an individual, group, organization, or system.
Context: Most relevant when describing the actual or concrete adverse effect that governance controls seek to prevent or remedy.
| Aspect | Risk | Harm |
|---|---|---|
| Definition | Risk combines the likelihood of an adverse event with the severity of its potential harm. | Harm is the adverse effect experienced by an individual, group, organization, or system. |
| Practical difference | Risk is forward-looking and supports assessment, prioritization, and control design. | Harm describes the adverse effect itself, whether actual, anticipated, or used as a severity reference. |
| Typical use case | Use risk in risk assessments, control selection, acceptance decisions, and monitoring plans. | Use harm in incident reports, impact assessments, rights analysis, and remediation planning. |
| Common mistake | A common mistake is treating a low likelihood rating as proof that no harm matters. | A common mistake is discussing harm only after an incident, rather than using harm analysis in design and prevention. |
| Governance implication | Governance should define risk criteria, tolerance, owners, controls, and review cycles. | Governance should define affected parties, harm categories, remediation routes, and evidence for impact analysis. |
In practice, weak AI risk registers often list risks without clearly naming the harm. A defensible assessment should connect each risk to who may be harmed and how.
Using risk and harm interchangeably in assessments
Assigning risk scores without identifying affected people or harm types
Treating unmaterialized harm as irrelevant to prevention controls
Use Risk when evaluating the possibility and severity of adverse outcomes before or during AI system development, deployment, or monitoring. It is the better term for assessments, controls, and risk acceptance decisions.
Use Harm when describing the adverse effect that may occur, has occurred, or should be prevented. It is the better term for impact analysis, incident response, and remediation discussions.
AI governance frameworks and regulations often require both risk assessment and harm analysis. Risk helps decide which controls are needed, while harm defines what the organization is trying to prevent, detect, or remedy.
No. Risk is the combination of likelihood and severity of potential harm. Harm is the adverse effect itself.
Yes, if likelihood is assessed as low. However, severe harms may still require strong controls depending on legal obligations, uncertainty, and affected rights.
Clear harm definitions make risk scoring more consistent and auditable. They also help identify affected stakeholders and appropriate controls.
No recently viewed comparisons yet.