Risk Continuity

The Risk Register Changed. The Mitigation Did Not.

A TVA OIG evaluation found that OEM-reliance risk rose sharply in probability and financial impact while existing mitigation plans did not address the identified cause of the increase. The case shows why a current risk register is not enough: changed evidence must remain connected to requalified decisions and updated action.
Governance architecture representing a risk register whose updated evidence and context must remain connected to renewed decisions, mitigation actions, and future reuse.
Expand image

A risk register can be current while the organization’s response to the risk is stale.

An August 2026 evaluation by the Tennessee Valley Authority Office of Inspector General provides an unusually clear example. TVA’s enterprise risk process continued to identify and quantify its reliance on original equipment manufacturers. Between fiscal years 2023 and 2026, the assessed probability of that risk increased from 30 percent to 55 percent, while the estimated financial impact increased from $100 million to $300 million.

The institutional evidence changed.

The mitigation architecture did not change with it.

TVA still had eight ongoing action plans associated with the risk, but OIG found that those plans did not address the cause of the increase identified by management. The OIG recommended considering additional action plans.

This is not simply a risk-management finding. It exposes a continuity problem between what an institution currently knows and what it continues to do.

A Current Risk Record Can Still Produce Stale Action

Risk governance often emphasizes whether risks are identified, scored, assigned, reviewed, and entered into a portfolio. Those controls matter. They create a visible representation of institutional concern.

But the representation is not the response.

If probability changes, impact changes, dependencies change, or the cause of a risk changes, the institution has entered a new context. Existing mitigation may remain useful, but its continued use should be requalified against the new state.

Otherwise the organization can possess an accurate risk register while executing a response designed for an earlier version of the risk.

That is risk discontinuity.

The Continuity Topology Shows the Missing Transition

GovKM represents institutional work through the Continuity Topology:

Source → Evidence → Authority → Context → Decision → Action → Record → Institutional Memory → Future Reuse.

The TVA example is especially useful because several early relationships appear to have remained intact.

Source information about equipment dependence entered the risk process. Evidence was updated. The risk portfolio reflected a higher probability and a larger potential financial impact. Management identified a reason for the change: greater reliance on the same original equipment manufacturer as the gas fleet expands.

The break appears later.

Changed Evidence → Changed Context → Requalified Decision → Updated Action

did not occur strongly enough to produce new mitigation addressing the newly identified cause.

The institution knew more, but its action state did not fully move with its knowledge state.

Risk Awareness Is Not Risk Continuity

This distinction matters because organizations can easily mistake visibility for governance.

A dashboard can be current. A score can be recalculated. An owner can be assigned. A quarterly review can occur. A red indicator can become redder.

None of those facts establishes that the changed evidence altered institutional behavior.

Risk continuity requires the organization to preserve the relationship between the latest evidence and the latest authorized response. When material conditions change, existing action plans should not remain authoritative merely because they already exist.

They need to be tested against the new context.

Inherited Mitigation Is a Form of Future Reuse

The eight ongoing TVA action plans also illustrate a broader continuity principle. Reusing an existing mitigation strategy is a form of Future Reuse.

Future Reuse is not trustworthy merely because the prior action was once approved. The institution must determine whether the evidence, authority, assumptions, scale, dependencies, and operating conditions that made the earlier response reasonable still apply.

This is the same problem organizations face with policies, procedures, precedents, technical controls, lessons learned, and AI memories. Prior institutional knowledge can remain available while its relationship to the present has expired.

Reuse therefore requires requalification.

The Risk Register Is a Memory System

A mature enterprise risk register is more than a list of hazards. It is a form of Institutional Memory.

It should preserve what the organization believed, what evidence supported that belief, who owned the risk, what assumptions applied, which mitigations were selected, what those mitigations were intended to accomplish, and how the risk changed afterward.

Without those relationships, a risk register can preserve successive snapshots without preserving institutional learning between them.

Future leaders may see that a risk moved from 30 percent to 55 percent without being able to determine whether the response changed, why it changed, or why it did not.

The record exists. The governing trajectory does not.

AI Will Make This Distinction More Important

Organizations increasingly want AI systems to monitor risk signals, summarize changes, recommend mitigations, detect dependencies, and support enterprise risk analysis.

AI can make the risk register more current. It can ingest more sources and recognize change faster.

That does not guarantee continuity.

An AI system can correctly identify that a risk has worsened and still inherit an old response because the institution has not represented the relationship that requires mitigation to be re-evaluated when specified conditions change.

The problem is therefore not only whether the model detects the new evidence. It is whether governance connects that evidence to a decision point with enough authority to change action.

This suggests a practical requirement for continuity-aware risk systems: material changes in probability, impact, cause, dependency, or scope should create an explicit requalification event for the mitigations that currently govern the risk.

Controls Need Their Own Validity State

Organizations usually track whether a mitigation is open, closed, planned, implemented, or overdue. Continuity adds another question:

Is this mitigation still valid for the risk as it exists now?

That state may depend on evidence different from the evidence used when the control was created.

A supply dependency can deepen. A vendor can become less replaceable. A technology can become more critical. A legal requirement can change. A system can expand to new users. A threat actor can acquire new capability.

The control does not become invalid automatically. But its continued authority should not be assumed.

The GovKM Proposition

The TVA finding illustrates a continuity problem that appears far beyond energy infrastructure.

Organizations can have accurate risk data, competent risk professionals, active mitigation plans, and recurring governance meetings while still allowing action to lag behind current evidence.

A risk process is continuous only when material changes in evidence and context remain connected to renewed decisions and appropriately updated action.

The risk register should not merely tell the institution what changed.

It should preserve whether the institution changed with it.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.