Skip to content
Line chart dropping then recovering, illustrating reputational risk and how it is assessed

What is reputational risk?

Reputational risk is the risk that what stakeholders conclude about an organisation changes how they behave towards it: customers going elsewhere, staff resigning or declining offers, partners pausing, lenders repricing, regulators looking more closely. It is not the risk of being disliked. It is the risk of a belief becoming expensive. Almost all of it is second-order, meaning it arrives as the consequence of some other failure and of how that failure was handled. This page covers what the risk is and where it comes from. Managing it as a governed programme is a separate subject.

What reputational risk actually is

The distinction matters because it makes the risk assessable. "People might think badly of us" cannot be evaluated. "If this becomes public, our two largest distributors have contractual review rights and our graduate hiring pipeline runs through a campus that will notice" can be. Reputational risk is only tractable when it is stated as a chain: an event happens, a group of people learns about it, they draw a conclusion, and they do something differently.

Financial regulators have treated it as a named category for a long time. The Office of the Comptroller of the Currency lists reputation risk among the categories of risk it supervises banks against, which is why the vocabulary of registers, owners and appetite reached reputation work from finance rather than from communications.

Why reputational risk behaves differently from other risks

Three properties make it awkward to handle with standard tools.

It is second-order. A product defect is a product risk. The reputational risk is what people conclude about the organisation from the defect, and more often from the response to it. That means the same underlying event can produce very different reputational outcomes, and the variable is usually behaviour after the fact rather than the fact itself.

It is correlated with everything. Operational, conduct, environmental, employment, cyber and supply-chain failures all have a reputational tail. A register that lists reputational risk as one line item next to the others misses that it is a consequence of most of them.

It is slow to recover and fast to move. The loss can arrive in a day. The published record of it persists for years in search results, archives and databases, long after the operational issue is closed. Business continuity planning is built for a different shape of loss, and Ready.gov's business continuity planning guidance is a useful contrast: a business impact analysis identifies time-sensitive functions and recovery objectives, which works when the damaged thing is a process. Reputation has no recovery time objective, because the constraint is other people's memory and the public record.

The sources of reputational risk

Most organisations can list their reputational risks in an afternoon once the categories are on the table.

Source A typical trigger An early signal Who usually sees it first
Product or service failure Defect, safety issue, repeated outage Complaint clustering around one theme Support and frontline staff
Conduct Harassment, discrimination, misuse of funds Exit interviews, grievances, sudden turnover Human resources
Data and systems Breach, misuse of personal information Security alerts, third-party notification Security or IT
Supply chain Labour or environmental practices at a supplier Audit findings, campaigner enquiries Procurement
Marketing and claims Overstated claims, undisclosed endorsements, review practices Regulator enquiry, competitor complaint Marketing or legal
Leadership and association Conduct of a named executive, a partnership, a donation Journalist enquiry, social platform activity Communications
Third parties speaking for you Franchisees, resellers, contractors, agencies Customer confusion, inconsistent claims Field or partner teams

The pattern in the right-hand column is the useful part. The people who see a reputational risk first are almost never the people who own the response, and most of the delay in real cases sits in that handover rather than in the decision itself.

Assessing likelihood and impact

Reputational risk gets scored the same way other risks do, on likelihood and impact, but both need translating or the scoring becomes theatre.

Likelihood is not the probability of the event. It is the probability that the event becomes known to a group that acts on it. Those are very different numbers. An internal issue with three people aware of it and an internal issue documented in an email chain across two departments carry the same underlying facts and different likelihoods.

Impact should be written as behaviour, not as sentiment. Name the stakeholder group, name what they would do, and where possible attach the commercial consequence: a contract with a reputation clause, a recruitment channel, a licence condition, a lender covenant. A score without a named behaviour behind it cannot be challenged, which sounds convenient and means the number never improves.

The research literature on how audiences assign responsibility is relevant here, because impact depends heavily on whether people read an event as an accident or as something preventable. The Institute for Public Relations on crisis management and communications summarises that work, and the practical implication is that two events with identical facts can carry very different impact scores depending on what the organisation was told beforehand.

Early warning signals

The signals that precede reputational events are almost always internal and unglamorous.

  • Complaints clustering on a single theme rather than spreading evenly.
  • Turnover concentrated in one team, or exit interviews repeating a phrase.
  • A supplier audit finding that gets closed administratively rather than fixed.
  • A journalist asking a specific question rather than a general one.
  • The same criticism appearing in reviews, forums and employee-review sites within a short window.
  • Anyone senior asking whether something needs to be disclosed.

None of these require a monitoring platform to notice. What they require is a route by which the person who saw it can tell someone whose job includes acting on it, and that route is what most organisations are missing rather than the data.

Mitigation, and what it can reach

Mitigation for reputational risk splits into three honest categories. Prevention addresses the underlying failure, and it is the only category that reduces the risk rather than the damage. Preparation shortens the response: a plan, a named team, pre-cleared statements, rehearsals. Presence is the long, slow work of having an accurate, current, well-structured published record so that an incident lands beside context rather than into a vacuum.

What mitigation cannot do is make an accurate account of a real failure go away. The people who do this work professionally are largely communications specialists, and the Bureau of Labor Statistics profile for public relations specialists describes the actual job: writing, media relations, and managing what an organisation publishes about itself. Nothing in that description involves deleting other people's accounts, because that is not a service anyone can honestly offer.

Where an assessed risk gets recorded

Once a reputational risk is described, scored and assigned a mitigation, it belongs in the same register as everything else, with a named owner and a review date. That machinery, along with escalation thresholds and what gets reported upward, is covered in reputation risk management.

What reputational risk is not

It is not bad reviews. A pattern of poor reviews is usually evidence that a risk already materialised, not the risk itself. It is not negative coverage, for the same reason. And it is not the same as brand risk, which concerns the assets an organisation controls.

If the question is what people would find today rather than what might happen tomorrow, that is answerable now, and it is the first thing a reputation audit sets out.

Questions about what is reputational risk?

What is reputational risk?

The risk that a change in what stakeholders believe about an organisation changes how they behave towards it, in a way that costs money, access, people, or operating freedom. The belief is the mechanism and the behaviour change is the loss.

How do you assess reputational risk?

By scoring likelihood and impact, with both translated. Likelihood is the probability the event becomes known to a group that acts on it, not the probability of the event. Impact is written as a named stakeholder behaviour with a commercial consequence, not as a sentiment score.

What are the main sources of reputational risk?

Product and service failure, conduct, data and systems incidents, supply chain practices, marketing claims, leadership and association, and third parties who speak for the organisation such as franchisees and resellers.

Is reputational risk the same as brand risk?

No. Brand risk concerns assets the organisation controls, such as identity, positioning and trademarks. Reputational risk concerns conclusions other people draw, which sit in reviews, coverage, records and search results.

Have your case reviewed

Find out which of your reputational risks have already left a public record.