Your risk aversion is riskier

I hear it in every serious conversation about testing something new with real people and real data. And I understand it, truly, it’s a very human instinct. Nobody wants to be the civil servant who signed off the pilot that lost someone's data, or waved through the experiment that let a bit of fraud slip past. Accountability is real - no-one wants their decision on the front of the Daily Mail, but more than that, no-one wants to be responsible for doing real harm to real people.

But don’t kid yourself. The safe option isn’t to refuse to do it. You don’t have a zero-risk option -  doing nothing can be just as reckless. Because refusing to learn something small is actually deciding to take a much bigger gamble. It just doesn't feel like a decision, because inaction rarely does.

When you won't test an idea on 20 people, you don't avoid the risk. You defer it. You save it all up for the day you ultimately roll it out out to two million. Because that’s when you start learning. After all, no design survives first contact with real users in real service operation.

Risk is not a reckon or a vibe. It’s a well established equation.

Risk = consequence × likelihood × exposure.

Consequence is how bad it is if the thing goes wrong. Likelihood is how probable it is that it goes wrong at all. Exposure is how many people are you testing with, for how long. And those three factors can be adjusted to match your risk appetite.

You get to decide how bad "wrong" is allowed to be

Start with consequence, because this is where the knee-jerk noes come from. People talk as though the consequences of getting it wrong are fixed, handed down, immovable - but they’re not. You can decide, in advance, how bad "wrong" is allowed to get.

On a piece of work I did last year, the risk posture was really simple: deliver quickly with a small group, and if/when we got it wrong, fix it immediately. When we underpaid, we issued top-up payments; where we’d overpaid, then providing the overpayment was our fault and under a certain %, we didn't claim it back. With all the bugs and errors we spotted, we quickly adjusted the calculations so that the specific mistakes couldn’t happen again. And we did all of this openly so the consequences people were worried about - irreversible harm, reputational damage, loss of trust - never came to pass.

Because we do have influence over the consequences. Legislation is often written so that you don't have to administer a fine if there's good reason not to. And exemptions are quite common, even codified. Departments can tell the 50 people in a test that they carry no liability for taking part, that nothing they do inside the experiment will be held against them. A huge amount of financial and legal risk evaporates the moment you decide, deliberately, to absorb it rather than pass it on. Financial loss can be compensated. A penalty can be waived. You need leadership appetite and an Accounting Officer who understands and is willing to bear the risk - but the flexibility is there.

Then there's the data itself. "Real user data" is not one undifferentiated lump of danger. Some of it is genuinely sensitive and a lot of it really isn't. You get to choose what's in scope. Strip out the high-risk categories. Test on the lower-risk data first. Only use what you need to use in order to learn what works - in IBCA their data minimisation principles were applied to experiment design, to ensure that data privacy worries didn't prevent us testing with real user data: we didn't need to know someone's HIV status to test the payments engine, for instance.

Likelihood is what guardrails are for

Likelihood is the easy one, and it's the one everyone already half-understands, because it's what people are really talking about when they say "controls". Every guardrail you put in reduces the probability. Human-in-the-loop checks, thresholds and caps, kill switches, separation of duties, tight eligibility criteria, a manual review before anything goes out of the door. This stuff exists to make the bad outcomes less likely.

So when someone says a test is too risky, the honest next question is almost never "then we can't do it". It's "then what would we need in place to make going wrong genuinely unlikely?". That is a design brief, and it's an answerable one. Moreover - guardrails are the perfect thing to test in a test and learn experiment, because you get to see if and how they’ll work, at a small scale, before you roll out more widely.

Start small

Then there’s exposure, which is the one people have the most control over but keep forgetting about.

You don’t have to start with the whole population. Start with 20. Start with 50 if you're feeling brave. Pick the group where the consequences of a wobble are smallest, but the learning potential is still high, and begin there. Twenty people is enough to test some risky assumptions, which is the entire point of the exercise, and it is few enough that if the whole thing falls over your comms team will be able to handle it. Heck it’s sufficiently small a group that you can call those 20 people up, explain, apologise and make it right. I’ve done that - it took me and a handful of claim managers one afternoon. Service users were remarkably understanding, appreciated the transparency and I think it earned us more trust.

Move beyond your knee-jerk risk posture and consciously work through the equation elements

A modest consequence, made recoverable on purpose.  A low likelihood, held down by guardrails.  A tiny exposure, chosen from the least consequential end. Multiply them and the risk of the experiment is small. Intentionally so.

Now hold that risk up against the risk of not testing your riskiest assumptions quickly. The delayed learning. The full rollout, built on assumptions that weren’t pressure-tested, because we "couldn't take the risk" of finding out sooner.

That’s what you should be scared of.

So the next time someone says we can't take the risk, do the equation out loud.  Ask which of the three numbers we mean, and how far down we could drive it if we actually tried.  Because the alternative is worse - as it guarantees that we learn the expensive lessons late, in public, at full scale, and long after it's too late to ring 20 people and say sorry.

Test small, learn fast, is a much better risk strategy.

Previous
Previous

Translucency

Next
Next

The Flinch