risk-management
15 free lessons tagged risk-management across Business. Each one is a short sequence of focused steps with narration and a five-question quiz at the end — take them in any order, no signup required.
Position Sizing: The Arithmetic of Survival
Measuring risk and surviving it are different problems, and only the second is solved by a decision. This lesson covers the growth-optimal bet size, why practitioners deliberately use a fraction of it, the asymmetry that makes drawdowns so expensive to recover from, and why limits work as a control system rather than a prediction.
Margin, Leverage, and the Spiral
Leverage does not simply scale returns. It introduces a lender who can demand cash at the worst moment, which converts a paper loss into a forced sale. This lesson works through margin mechanics, shows why the liquidation price rather than the loss is what matters, and follows the feedback loop that makes market and funding liquidity reinforce each other.
When the Distribution Lies
Every risk number is a functional applied to an estimated distribution, so its errors are that distribution's errors. Returns have fat tails, volatility clusters, and correlations converge exactly when diversification is supposed to help. This lesson covers each failure, why they arrive together, and what stress testing does that no quantile can.
Value at Risk, and the Question It Refuses to Answer
Value at Risk compresses a whole loss distribution into one number, which is why it was adopted everywhere and why it misleads. This lesson builds it three ways, shows the arithmetic case where it says diversification increased risk, and covers the coherence axioms that explain the failure and the measure regulators moved to instead.
The Greeks: What a Hedged Position Is Still Exposed To
Delta-hedging removes the obvious risk and leaves the interesting ones. The greeks name each remaining exposure separately, which is what lets a trader hold some and neutralise others. This lesson covers what each one measures, why gamma and theta are two sides of one trade, and where the numbers stop behaving.
Where AI Fits in Project Management, and Where It Does Not
Project management is largely communication and judgement under uncertainty, which splits cleanly into work AI does well and work it cannot touch. This lesson separates the two, covers the administrative load that is the genuine target, and explains why estimation is the seductive case that mostly does not work.
The Competencies: What You Need to Know, and How Deep
AI governance sits at the intersection of four competency areas, and almost nobody arrives holding all of them. This lesson sets out what each requires and how deep it must go: regulatory literacy, enough technical understanding to ask the right questions, assurance discipline, and the organisational skill the function runs on. It closes on certifications and what they are worth.
The AI Governance Function: What the Work Is and Who Does It
AI governance is a body of work before it is a job title, and most of it is done by people whose title says something else. This lesson sets out what the work consists of, how it splits across legal, risk, data protection and engineering, why a dedicated role appears at some scales and not others, and what the data protection officer precedent does and does not tell you.
Contracts, Ongoing Management, and Exit
The contract is where a deployer's leverage lives, because almost every duty you hold depends on information the provider controls. This lesson covers the clauses that matter for AI, allocating AI Act obligations between the parties, change notification and substantial modification, monitoring a live system for drift, incident cooperation, and designing an exit before you need one.
What a High-Risk System Must Actually Do
Once a system is high-risk, Articles 8 to 15 set out what it must satisfy. This lesson works through them as engineering requirements rather than legal text: risk management as a continuous process, data governance including the 2026 change on special category data for bias detection, human oversight as a design property, accuracy and robustness, and transparency toward the deployer.
Technical Documentation and the Evidence Trail
Governance that leaves no trace is indistinguishable from no governance. This lesson covers the documentation the AI Act requires: Annex IV technical documentation and its simplified SME forms, the quality management system, instructions for use, log retention, the fundamental rights impact assessment, registration, and how to make documentation a byproduct.
Policy, Decision Rights, and the AI Risk Register
With an inventory in place, governance becomes a question of who decides what. This lesson covers the AI policy and what actually belongs in it, acceptable-use rules people can follow, decision rights mapped with RACI, the approval gate a new system passes through, an AI risk register with risks specific to these systems, and escalation that works when something goes wrong at eleven at night.
The Foundation: AI Inventory, Classification, and Ownership
An AI governance framework that starts with a policy is built on nothing. This lesson covers the artefact everything else depends on: finding the AI systems you actually run, including the ones inside software nobody bought as AI, recording the fields that make the inventory usable, classifying each system, assigning real ownership, and binding the whole thing to triggers so it stays true.
The Proportionate Path: Compliance Without a Legal Department
There is no small-business exemption in the AI Act, but there is proportionality, and the 2026 Omnibus widened it. This lesson covers the simplifications for SMEs and the new small mid-cap category, the minimum defensible position for a deployer, how to sequence work against the amended deadlines, where GDPR work can be reused, and when you genuinely need a lawyer.
Running the Project: Execution, Risk, and Stakeholders
A plan only matters if you can steer the project through reality. This lesson covers execution and control: tracking progress against the baseline, managing risk before it becomes crisis, handling change requests, and keeping stakeholders aligned through communication, the day-to-day work that actually delivers a project.

