Caesar AI Atlas
Common ConfusionBeginner

Risk vs Harm

A side-by-side comparison of Risk and Harm. It explains how a likelihood-and-severity assessment differs from the adverse effect experienced by a person, group, organization, or system.

Quick Verdict: Use risk for potential adverse outcomes before or during assessment; use harm for the adverse effect that has occurred or may be concretely described.

At a Glance

Risk

Risk defines combination of the likelihood of an adverse event and the severity of its potential harm.

Key Characteristics
  • Combination of likelihood of an adverse event and severity of potential harm
  • May relate to health, safety, fundamental rights, people, organizations, society, or the environment
  • Supports prioritization, controls, and acceptance decisions
Watch Out For
  • Risk is not the same as a realized incident or harm
  • Risk ratings should not hide uncertainty about likelihood, severity, or affected groups

Context: Most relevant when assessing possible adverse outcomes and deciding what controls are needed.

VS
Harm

Harm describes adverse effect experienced by an individual, group, organization, or system.

Key Characteristics
  • Adverse effect experienced by an individual, group, organization, or system
  • May be social, physical, financial, legal, reputational, or privacy-related
  • Can arise from misuse, system failure, bias, or unauthorized disclosure of personal information
Watch Out For
  • Harm can occur even when the original risk assessment underestimated likelihood or severity
  • Different stakeholders may experience different types of harm from the same system

Context: Most relevant when describing the actual or concrete adverse effect that governance controls seek to prevent or remedy.

Key Differences

AspectRiskHarm
DefinitionRisk combines the likelihood of an adverse event with the severity of its potential harm.Harm is the adverse effect experienced by an individual, group, organization, or system.
Practical differenceRisk is forward-looking and supports assessment, prioritization, and control design.Harm describes the adverse effect itself, whether actual, anticipated, or used as a severity reference.
Typical use caseUse risk in risk assessments, control selection, acceptance decisions, and monitoring plans.Use harm in incident reports, impact assessments, rights analysis, and remediation planning.
Common mistakeA common mistake is treating a low likelihood rating as proof that no harm matters.A common mistake is discussing harm only after an incident, rather than using harm analysis in design and prevention.
Governance implicationGovernance should define risk criteria, tolerance, owners, controls, and review cycles.Governance should define affected parties, harm categories, remediation routes, and evidence for impact analysis.
Caesar AI Note

In practice, weak AI risk registers often list risks without clearly naming the harm. A defensible assessment should connect each risk to who may be harmed and how.

Notes

Common Mistakes

1

Using risk and harm interchangeably in assessments

2

Assigning risk scores without identifying affected people or harm types

3

Treating unmaterialized harm as irrelevant to prevention controls

When to Use Each

risk

Use Risk when evaluating the possibility and severity of adverse outcomes before or during AI system development, deployment, or monitoring. It is the better term for assessments, controls, and risk acceptance decisions.

harm

Use Harm when describing the adverse effect that may occur, has occurred, or should be prevented. It is the better term for impact analysis, incident response, and remediation discussions.

Compliance Note

AI governance frameworks and regulations often require both risk assessment and harm analysis. Risk helps decide which controls are needed, while harm defines what the organization is trying to prevent, detect, or remedy.

FAQ

Is risk the same as harm?+

No. Risk is the combination of likelihood and severity of potential harm. Harm is the adverse effect itself.

Can a high-severity harm have low risk?+

Yes, if likelihood is assessed as low. However, severe harms may still require strong controls depending on legal obligations, uncertainty, and affected rights.

Why should harm be defined before scoring risk?+

Clear harm definitions make risk scoring more consistent and auditable. They also help identify affected stakeholders and appropriate controls.

Recently Viewed

No recently viewed comparisons yet.