Business Model Risk
Pronunciation: BIZ-nus MAH-dul RISK
Definition
Business model risk is the possibility that an organization's way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant. Business Model Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Business Model Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.
Overview
Business model risk arises when the assumptions connecting customers, pricing, costs, partners, regulation, and operational capabilities fail. Revenue may depend on temporary incentives, one customer segment, one payment rail, market appreciation, or cross-subsidies that cannot continue.
Crypto businesses may face additional exposure from token emissions, volatile treasury assets, uncertain legal classification, third-party liquidity, and demand driven mainly by speculation. Growth can hide negative unit economics or obligations that appear only during redemptions, disputes, or stress.
Management should test unit economics, concentration, retention, cash needs, compliance costs, and adverse scenarios. Diversified dependencies, clear value creation, measurable customer demand, and early warning indicators help distinguish a durable operation from temporarily financed activity.
Business model risk is the possibility that an organization’s way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant. A growing business can still carry severe model risk when revenue, incentives, dependencies, or legal assumptions are not sustainable.
For Business Model Risk, the assessment should evaluate the possibility that an organization’s way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant. The assessment record should separate observed evidence supporting the possibility that an organization’s way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that an organization’s way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about the possibility that an organization’s way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
A growing business can still carry severe model risk when revenue, incentives, dependencies, or legal assumptions are not sustainable.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)