
Most corporate risk registers are thorough documents. Market risk, regulatory risk, competitive risk, operational risk, key person risk. Finance teams spend real time maintaining them, reviewing them quarterly, and presenting them to boards that expect to see a comprehensive picture of what could go wrong.
What almost no risk register includes is the category of risk that has produced more expensive surprises in my experience than any of the external categories combined: the assumptions baked into the financial model itself.
The projection that assumes 15% year-over-year growth because that is what the last three years produced. The cost structure built on a vendor relationship that has never been formally tested at the volume the model requires. The revenue timeline that assumes a sales cycle length that reflects the best historical quarter rather than the median one. The margin assumption that holds only if the product mix stays roughly constant, which it has, so far.
These are not risks the company is monitoring. They are inputs the company is running on. And when they turn out to be wrong, the failure gets attributed to execution, to market conditions, to timing, to anything except the assumption error that was present in the model before a single decision was made against it.
Why Assumptions Get Treated as Inputs Rather Than Risks
The structural reason assumptions do not appear on risk registers is that risk registers are built to capture what might happen, and assumptions feel like descriptions of what is already known. An assumption is not a future event. It is a current belief about how the business works, how the market behaves, how customers will respond. It feels like a baseline, not a bet.
The problem is that a belief held with confidence is still a bet. The confidence does not make it less uncertain. It makes it less examined, which is a different and considerably more dangerous condition.
The assumptions that cause the most damage are almost always the ones that have been in the model the longest, because longevity creates the appearance of validation. An assumption that has been in every financial model for four years feels like a fact. It has survived four annual planning cycles without being challenged. The budget was built around it repeatedly and the business ran roughly in line with it, which feels like confirmation. What it actually is, most of the time, is a period during which the assumption happened to be approximately right and nobody had a reason to look at it closely.
The conditions that made the assumption valid can change before the assumption does. When they do, the financial model continues producing projections based on a belief that no longer reflects reality, and the gap between the model and the business accumulates until it is large enough to force a reforecast that should have happened quarters earlier.
What Assumption Risk Looks Like in Practice
The clearest version of this I have seen involved a company whose growth model assumed that the average deal size would hold relatively constant as they moved upmarket. The sales team was actively targeting larger accounts. The pipeline looked healthy. The model showed strong revenue growth based on the same close rates and deal sizes that had produced consistent results in the mid-market.
What the model did not capture was that enterprise sales cycles were running two to three times longer than the mid-market cycles the close rate assumptions were built on. The pipeline was real. The revenue was real. The timing was wrong, and the timing was wrong because an assumption about sales cycle length had been carried forward from a market segment the company was deliberately moving away from.
This was not a market risk. It was not a competitive risk. It was an assumption in the financial model that had not been updated to reflect a strategic decision the company had already made. The risk was internal, invisible to the risk register, and entirely foreseeable if anyone had asked the question: which assumptions in this model are we least certain about, and what would it cost us if they were wrong?
The Practice That Catches It Earlier
The CFOs and finance leaders who catch assumption risk earliest share one practice that is absent from most financial planning processes: they maintain a separate, explicit list of the assumptions the financial model is most sensitive to, and they treat updating that list as a standing agenda item rather than an annual planning exercise.
This is not the same as sensitivity analysis, though sensitivity analysis is a useful tool. Sensitivity analysis tests what happens to the model output when a specific variable changes. Assumption risk review asks a prior question: which of the beliefs this model is built on are we least certain about, and are those beliefs still current?
The distinction matters because sensitivity analysis starts from the model and asks what happens if inputs change. Assumption risk review starts from the assumptions themselves and asks whether they should still be in the model at all.
The practical output is a short list, rarely more than five to eight items, of the assumptions that carry the most model sensitivity and the least current validation. Each item gets a named owner, a review cadence, and a threshold that would trigger a model update. The list lives alongside the risk register, not inside it, because assumptions are not future events. They are current beliefs that require the same ongoing scrutiny as any other category of business risk.
What This Changes for Corporate Strategy
The strategic implication of treating assumptions as a risk category is that it changes how strategic decisions get made and reviewed.
A strategy built on an assumption that has been explicitly named, owned, and given a review cadence is a strategy that the organization will catch faster when the assumption starts to weaken. A strategy built on an assumption that is embedded invisibly in the model will continue to be executed against a belief that may no longer hold, until the gap between belief and reality is large enough to be undeniable.
For companies using technology to support financial planning and risk management, the question worth asking of any financial planning system is not whether it can run sensitivity analysis. It is whether it makes the assumptions underlying the model as visible and reviewable as the outputs the model produces. Most systems are built to make outputs clear and assumptions invisible. Partnering with an app development company that understands how financial workflows actually work, not just how financial data flows through a system, produces tools that surface assumptions rather than bury them.
The risk register that does not include your own assumptions is not comprehensive. It is a document that describes every threat the organization is watching except the ones it is carrying.
