Risk Compensation Premortem¶
Foresight exercise — instantiates Compensation-Aware Safeguard Design
Before a safeguard ships, imagines how users will spend the safety gain — so the offset is anticipated and wired into monitoring instead of discovered after harm.
Risk Compensation Premortem is the pre-deployment step that assumes the safeguard has already succeeded technically and then asks the uncomfortable follow-up: given that failure now feels cheaper, how did the people who control exposure spend the freed margin? It is deliberately an act of structured imagination, not measurement — you stand a year in the future, pretend the intended safety gain has been quietly eaten, and reconstruct the plausible ways that happened. Its whole job is to convert the archetype's core assumption — that safeguards do not operate in a behavioral vacuum — into an explicit, ranked list of predicted offset pathways before a single user touches the thing, so the offset can be watched for rather than autopsied.
Example¶
A payments company is weeks from launching an "instant fraud reimbursement" guarantee: any customer defrauded gets refunded automatically within 24 hours, no dispute process. Before shipping, the risk team runs a premortem. Standing in an imagined future where the guarantee is live and losses are up, they enumerate how the gain got spent: customers stop scrutinizing payment recipients because a mistake is now free; they click through more suspicious links knowing the money comes back; small merchants relax their own verification because chargebacks land on the platform; organized scammers treat the guarantee as a subsidy and industrialize a scheme around it.
For each pathway they name three things — what specifically feels cheaper now (the perceived downside drop), who captures the upside of being less careful, and the risk level each actor is likely to drift toward once caution is optional. The output is not a verdict on whether to launch. It is a ranked list — pathway by plausibility times harm — that becomes the launch's instrumentation and guardrail plan: the top three pathways each get a behavioral metric the monitor will watch from day one, plus a candidate friction (a per-claim cap, a warning interstitial) to hold in reserve.
How it works¶
- Fast-forward and assume the loss. Rather than asking "what could go wrong," assume the safety gain has already been consumed and work backward to how — prospective hindsight surfaces failure paths that forward-looking optimism skips.[n1]
- Map the change first. Name exactly what the safeguard makes safer, cheaper, faster, or less punishable — in both the engineering sense and the felt sense, since compensation follows perception.
- Anchor each pathway to a cost drop. Every predicted offset is tied to the specific downside that fell for a specific actor; a pathway with no cheapened failure behind it is discarded.
- Posit a target risk level. For each actor, state the risk level they will tolerate once failure is cheap — a testable prediction, not a mood.
- Hand off, don't file. Convert the top-ranked pathways into concrete signals for the behavior monitor and candidate guardrails, so the exercise ends in instrumentation.
Tuning parameters¶
- Imagination horizon — how far into the deployed future you pretend to stand. A longer horizon surfaces slow drift and habituation but adds speculation and dilutes urgency.
- Adversarial stance — whether actors are modeled as merely lax or as actively gaming the safeguard. The adversarial setting catches exploitation but can tip into paranoia that flags implausible schemes.
- Participant mix — engineers-only versus a room that includes frontline ops, support, and an adversary-minded outsider. Wider mixes catch more pathways at the cost of coordination.
- Ranking rule — ranking pathways by expected harm versus worst-case tail. A tail focus catches rare bystander and catastrophe displacement that an average-harm ranking buries.
- Handoff fidelity — whether pathways are merely listed or converted into named instrumented signals and guardrail specs. More conversion costs effort but is what makes the premortem bite.
When it helps, and when it misleads¶
Its strength is cost and timing: it is the cheapest possible intervention and the only one that runs before harm exists, so it lets a team enter deployment with the monitor already pointed at the right behaviors rather than reconstructing them after an incident.
Its central failure mode is that it is imagination, not evidence — you catch the offsets you can dream up and stay blind to the ones outside the room's experience, and a vivid, well-facilitated session can breed false confidence that all the offsets are now known.[n1] The classic misuse is running it as a compliance ritual: the list is generated, admired, filed, and never wired into monitoring, so the predicted offsets go unmeasured and the exercise buys nothing but a paper trail. The discipline that guards against this is a hard rule that every retained pathway leaves the room attached to either an instrumented signal or a guardrail, and that the list is re-opened against real behavior once data starts to land.
How it implements the components¶
safeguard_change_map— the session's opening move is naming precisely what the safeguard makes safer, cheaper, or less punishable, in both engineering and perceived terms.perceived_failure_cost_delta— each predicted pathway is anchored to the specific drop in actor-facing downside that fuels it, so no offset is proposed without a cheapened failure behind it.target_risk_setpoint_hypothesis— for every actor it posits the risk level they will drift toward once failure feels cheap, yielding a testable prediction the monitor can later check.
It produces no measured baseline or live drift signal — those belong to the Before / After Behavior Monitor — and it tallies no net gain, which is the Safety-Gain Offset Dashboard's job. The premortem only predicts.
Related¶
- Instantiates: Compensation-Aware Safeguard Design — it supplies the anticipated-offset map the rest of the machinery is built to catch.
- Sibling mechanisms: Before / After Behavior Monitor · Safety-Gain Offset Dashboard · Shared Downside or Deductible Rule · Use-Conditioned Protection Policy · Exposure Cap or Rate Limiter · Adaptive Safeguard Recalibration Gate · Post-Safeguard Incentive Audit
Editorial Notes¶
Form Classification¶
Form family: Experiment, Test & Rehearsal
Rationale: Risk Compensation Premortem operates as an active test, trial, simulation, drill, or rehearsal that generates evidence through a deliberate attempt or perturbation because it before a safeguard ships, imagines how users will spend the safety gain — so the offset is anticipated and wired into monitoring instead of discovered after harm.
Independent corroboration: The frozen evidence defines Risk Compensation Premortem as 'Before a safeguard ships, imagines how users will spend the safety gain — so the offset is anticipated and wired into monitoring instead of discovered after harm', so its operative form is Experiment, Test & Rehearsal.
Nearest alternative: Communication, Facilitation & Learning — Risk Compensation Premortem includes features of a designed message, facilitated interaction, ritual, or learning activity that changes shared understanding, but its defining operation is an active test, trial, simulation, drill, or rehearsal that generates evidence through a deliberate attempt or perturbation.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Behavioral Economics
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Risk compensation was canonically formalized in behavioral economics as behavior adjusting in response to perceived safety regulation. Psychology, engineering, and public policy contribute mechanisms of perception, design response, and regulatory adaptation used in the premortem.
Related originating lineages:
- Engineering & Design — engineering_design contributes lifecycle design, safety margins, rollback, verification, and systems assurance to the mechanism’s formative or independently convergent form; that contribution does not displace the primary behavioral_economics lineage.
- Psychology — psychology contributes social learning, group regulation, trust, behavior rehearsal, and expectation to the mechanism’s formative or independently convergent form; that contribution does not displace the primary behavioral_economics lineage.
- Public Administration & Policy — public_administration_policy contributes program oversight, public allocation, implementation, and continuity obligations to the mechanism’s formative or independently convergent form; that contribution does not displace the primary behavioral_economics lineage.
Review resolution: The blind reviewers disagreed on primary lineage (behavioral_economics versus psychology); authoritative or primary research supports behavioral_economics as the best historical origin. Risk compensation was canonically formalized in behavioral economics as behavior adjusting in response to perceived safety regulation. Psychology, engineering, and public policy contribute mechanisms of perception, design response, and regulatory adaptation used in the premortem. The cited Peltzman, The Effects of Automobile Safety Regulation directly supports the defining operation used in that choice. All independently supported contributing domains are retained without an arbitrary cap, while domain_reach=multi_domain records later applicability separately from provenance.
Review outcome: Researched adjudication after independent review; high confidence.
Sources consulted:
Notes¶
The premortem is strictly upstream — it is prediction, and its value is realized only when its pathways become the monitor's watch-list and the guardrail shortlist. Kept separate from those downstream mechanisms, it can be re-run and improved (better rooms, better adversarial framing) without disturbing whatever is already instrumented.
[n1] The premortem, a technique associated with decision researcher Gary Klein: imagining that a plan has already failed and reconstructing why. The prospective-hindsight framing measurably surfaces risks that ordinary forward-looking planning misses — but it remains bounded by what the participants can imagine. ↩a ↩b