The previous five domain posts in this series covered Governance, People, Operations, Finance, and Technology, and each already carries its own risk. A governance gap is a risk. A thin leadership bench is a risk. A subcontractor issue nobody caught early is a risk. An unpatched laptop is a risk. Risk does not arrive as a tenth function sitting off to the side of the other nine. It runs through all of them.

That is exactly what makes this domain easy to misunderstand. The question this post is actually asking is not whether risk exists somewhere in the business. It obviously does, in every business. The question is whether anyone is responsible for seeing that whole picture at once: identifying it, weighing it, and deciding what to do about it, rather than each domain quietly managing its own piece of risk in isolation with no one connecting the dots across the enterprise.

Every domain in this series carries its own risk. This domain asks who is watching all of them at once.

What the Risk Domain Includes

None of the topics below are about eliminating risk, which is not realistic for any business. They are about whether the business can see its own risk clearly enough to make a deliberate choice about it, rather than discovering it after something has already gone wrong.

Customer and Contract Concentration Risk

Many owners can state, if asked, what percentage of revenue comes from their largest customer or contract vehicle. Far fewer have actually thought through what happens operationally and financially if that customer or vehicle goes away, whether through a lost recompete, a change in agency priorities, or a program simply ending. Knowing the number is a start. Having an actual plan for the day it changes is the part most businesses skip.

Risk Awareness Versus Risk Documentation

Most GovCon businesses do manage risk in some form. It comes up in leadership meetings, shows up in the insurance policies the business carries, and gets built into contract pricing as a contingency and buffer. What is rare, even among growing companies well past the startup stage, is for any of that thinking to make it onto paper as an actual written plan. Risk registers are often discussed in advisory conversations, but a formal, maintained risk register is something few small or mid-sized GovCon businesses actually use. The gap is not that these owners are unaware of their risks. It is that the awareness never becomes a documented, assignable plan that survives past the meeting where it was discussed.

The Combined Annual Risk and Insurance Review

A lot changes in a business over the course of a year: new types of work, new service lines, new physical locations, new client relationships that carry their own exposure. Insurance coverage needs to be reviewed against that changed picture every year rather than renewed on autopilot, since a policy written for the business as it existed two years ago may not actually cover the business as it operates today. The practical move is to combine that annual insurance review with the risk conversation itself. The same meeting where coverage is reassessed is a natural place to write down, even briefly, the business’s top risks and who is responsible for addressing each. That single combined review does more for the business than a standalone risk register nobody maintains and an insurance renewal nobody questions.

Physical and Facility Security

Access control and facility requirements carry particular weight for businesses handling cleared work, where visitor logs, badge access, and controlled areas are not optional extras but baseline expectations. Even outside a cleared environment, basic physical security- who can get into the building and when- is a risk category some businesses have never formally reviewed.

Safety and Workplace Risk Management

For businesses with any physical, field, or manufacturing component, a defined safety program and a way to track incidents matter for both the people doing the work and the liability the business carries, whether or not anyone has calculated it recently.

Legal and Litigation Exposure

Contract disputes, employment claims, and intellectual property disagreements are all real possibilities for a growing GovCon business, and few owners have a clear sense of their actual exposure across all three until a specific situation forces the question.

Supply Chain and Subcontractor Concentration Risk

A single subcontractor or supplier that would be genuinely difficult to replace represents a concentration risk in its own right, distinct from the day-to-day performance monitoring covered in the Operations domain. This is less about whether the vendor is doing good work right now and more about what happens to the business if that vendor simply disappears.

What Weak Risk Management Costs

A business that has never mapped out what happens if its largest customer leaves can find itself restructuring under pressure the same month the contract ends, instead of having already planned for it. An insurance policy that was never updated to reflect a new type of fieldwork can leave a claim denied at the exact moment the business needs the coverage most. A single subcontractor failure, with no backup relationship in place, can halt delivery on a program, leaving no other option to turn to. And as part of due diligence, a buyer’s advisors often ask directly what the business considers its top risks and how each is being managed. A business whose honest answer is that it thinks about these things informally, without anything written down, is demonstrating the exact kind of undocumented exposure this domain is meant to address.

This series will continue working through the remaining domains one at a time. Risk is not confined to its own corner of the business. It runs through every domain this series has covered so far, and the real question this post has been asking is whether anyone owns the job of seeing that whole picture at once. The next post moves to the domain that governs how the business demonstrates it is managing risk to the people who require proof of it: Compliance.

This post is part of Building the Transferable Enterprise, a 13-part series working through the Enterprise Readiness Operating Model domain by domain.