Skip to Content

Same Numbers, Different Decisions: Why Your Board's Risk Numeracy Determines What Your Risk Data Actually Means

Identical risk figures produce different board decisions depending on the numeracy of the people reading them, which means risk communication is not a formatting choice but a governance control.
22 July 2026 by
Tony Ridley
Quick answer: Identical risk figures produce different board decisions depending on the numeracy of the people reading them. Risk communication is not a formatting choice, it's a governance control, and most organisations treat it as the former.

Originally published on LinkedIn: 29 January 2026.

A risk figure only means what the reader is able to make it mean. Present the same probability, the same percentage, the same "1 in 500" figure to two boards and you can get two different risk appetites, two different votes and two different levels of preparedness, without a single input changing. Risk numeracy, the ability to understand and use numbers, proportions and probabilities under uncertainty, is measurable through instruments such as the Berlin Numeracy Test, and it is unevenly distributed, including among professionals whose job is to interpret risk.

How numeracy shapes risk perception

People with lower numeracy tend to overestimate both risks and benefits and are less sensitive to actual differences in probability, according to Ellen Peters' research on numeracy and decision-making. A one per cent chance and a ten per cent chance both register as roughly bad, and a genuine risk reduction from a control barely moves their assessment. Lower-numeracy individuals lean more heavily on feelings and framing, so a gain-framed figure and a loss-framed figure describing the same outcome produce different responses from the same person, and vivid stories outweigh base rates. Given identical statistics on terrorism or burglary, lower-numeracy respondents report higher concern than higher-numeracy respondents looking at the same numbers. Higher-numeracy individuals anchor perceived risk more closely to the actual probability and base rate. Valerie Reyna's work on the psychology of risky decision-making shows they distinguish small risks from large ones more accurately and are less prone to overweighting low-probability events, and their emotional response tracks the size of the risk rather than firing at a constant level of generic anxiety. Two people can look at the same risk register entry and walk away with genuinely different risk pictures, and neither is being irrational. They are applying different cognitive tools to the same input.

Format is a control, not decoration

Gerd Gigerenzer's research on risk literacy points to a second lever beyond the reader's underlying numeracy, the format of the communication itself. Visual aids, icon arrays, pictograms and well-designed bar charts measurably improve comprehension for lower-numeracy audiences without degrading it for higher-numeracy audiences, and training in approximate arithmetic causally increases numeracy and produces more internally consistent risk judgements. Format choices that help across all numeracy levels include using absolute risk rather than relative risk, holding the denominator constant, attaching a clear time frame and avoiding "1 in X" phrasing. These are bias controls, not cosmetic style preferences, and they work whether or not the reader can do the arithmetic in their head. This is not only an audience problem. Physicians with higher numeracy give more complete, balanced information and are less likely to misread survival statistics, while lower-numeracy clinicians more often mislead patients through genuine miscalculation rather than bad faith. A numerically fluent risk adviser and a numerically confident one are not the same person, and confidence is not a proxy for competence.

A risk figure is not finished when it is calculated correctly. It is finished when it has been understood correctly, by the people who have to act on it.

Tony Ridley provides risk communication and board reporting advisory, helping organisations present risk in formats decision-makers can actually use. Contact us to discuss your requirements.

The SOCI Act Has Redefined the Board's Job on Critical Infrastructure
Positive security obligations under the Security of Critical Infrastructure Act now require boards to run continuous, documented assurance programs rather than periodic security reviews.