Skip to content

High-Risk Targeting List

Targeting artifact — instantiates Pareto Focus

Ranks cases, sites, or suppliers by predicted contribution to harm or cost so scarce scrutiny lands on the riskiest few — and holds the risk scores themselves to account.

A High-Risk Targeting List ranks entities — cases, people, sites, suppliers, assets, or events — by their predicted contribution to harm, cost, or failure, and names the top tier for added scrutiny, support, or review. What distinguishes it from the archetype's other ranking tools is that it looks forward from a risk model rather than backward from observed loss, and that its defining discipline is holding the risk score itself to account: because a score can encode a proxy for something it should not, verifying that a high score reflects real, addressable risk is part of the mechanism, not an afterthought.

Example

A city health department can inspect only a fraction of its ~6,000 food establishments each year. Instead of a fixed rotation, it scores each establishment by predicted violation risk — prior-inspection history, complaint volume, cuisine-type base rates, time since last inspection — ranks them, and sends inspectors to the top tier more often. Before trusting the list, the department checks whether "complaint volume" is measuring real risk or merely how vocal a neighborhood is, since the latter would push scrutiny toward loud areas and away from quiet ones with genuine hazards. The artifact is a focus rule (who gets extra visits, who stays on baseline) bolted to an accountability check on the very score that built it.

How it works

Three things make the list what it is. It scores entities on predicted contribution, so it can target risk before it materializes rather than after. It applies a threshold that names a critical few for elevated attention while everyone else holds at baseline — a live allocation rule, not a chart. And it interrogates the score for validity: whether a feature is a defensible risk signal or a proxy for a protected or over-surveilled group, and whether inspecting the listed more heavily is inflating their scores through a feedback loop.

Tuning parameters

  • Score features — which signals feed the risk model. Each added feature can sharpen prediction or smuggle in a proxy for something the list should not be sorting on.
  • Threshold / list length — how many entities make the high-risk cut. A longer list catches more true risk but dilutes the scarce scrutiny the list exists to concentrate.
  • Refresh and feedback handling — whether inspection outcomes retrain the score, and how the feedback loop is broken. Left unchecked, you only find problems where you already look, and those entities' scores climb regardless of true risk.
  • Override channel — how much human discretion can add or remove an entity the model plainly misjudges.

When it helps, and when it misleads

Its strength is concentrating scarce enforcement, support, or maintenance where harm is most likely, instead of a blind rotation that treats a spotless site and a repeat offender alike. In risk-bearing domains that is often the difference between catching a hazard and finding it in the news.

Its failure modes are the ones the archetype flags for risk scoring specifically: a score can encode bias when a feature is a proxy for a protected group, producing disparate impact even with no intent, and a self-reinforcing loop can manufacture the very risk profile it claims to measure.[1] Its classic misuse is treating the score as objective truth rather than a contestable prediction — or running it to justify targeting a group already under suspicion. The discipline that keeps it honest is to audit features for proxies, calibrate against a held-out sample of un-targeted entities, and keep a human override in the loop.

How it implements the components

  • critical_few_identification — it draws the boundary around the entities with the highest predicted contribution to harm or cost.
  • causal_verification_check — it audits whether a high score reflects real, addressable risk or an artifact, proxy, or feedback loop; this is the bias guard the archetype requires.
  • focus_rule — the list directs added inspection, support, or review to the top tier and holds the rest at baseline.

It does not rank by *value or revenue — that is the Key Account List; it does not protect the low-risk long tail from being stranded once attention narrows — that is the Long-Tail Monitor; and it does not build the graded service structure the tiers imply — that is the Tiered Support Model.*

  • Instantiates: Pareto Focus — implements the pattern in risk-bearing domains by targeting the cases most likely to drive harm.
  • Consumes: Top-Driver Analysis — supplies the vetted drivers a defensible risk score is built from.
  • Sibling mechanisms: Key Account List · Tiered Support Model · Long-Tail Monitor · Top-Driver Analysis · Pareto Chart · Defect-Cause Prioritization · Cumulative Contribution Curve · Marginal Reallocation Review · Top-Cost-Source Intervention

Notes

When the "cases" being ranked are people, this artifact is ethically loaded in a way a defect tally is not. The causal-verification check and the human override stop being nice-to-haves and become the conditions under which the list is legitimate to use at all — a risk list nobody is allowed to contest is a mechanism for entrenching yesterday's suspicions.

References

[1] Disparate impact describes a practice that is neutral on its face but falls more heavily on a protected group. A risk model can produce it when a feature acts as a proxy for group membership, which is why validating features and calibrating against un-targeted samples is a required step, not an optional audit.