Delivery Risk
Pronunciation: dih-LIH-vur-ee RISK
Definition
Delivery risk is the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all. Delivery Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Delivery Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.
Overview
Delivery risk arises when one party performs or pays before the other completes an expected obligation. It can affect physical shipments, digital products, software projects, payment instructions, token transfers, data feeds, and outsourced services.
Causes include fraud, operational failure, incorrect addresses, network congestion, vendor dependency, customs, technical defects, ambiguous acceptance criteria, or counterparty insolvency. Irreversible payments may increase exposure when delivery cannot be independently confirmed before settlement.
Controls include milestones, escrow, confirmation evidence, service levels, acceptance tests, tracking, limits, insurance, and dispute procedures. The chosen evidence should match the deliverable because transaction confirmation proves payment movement, not successful receipt or quality of the underlying product.
Delivery risk is the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all. Payment confirmation does not prove delivery; contracts and controls need evidence tied to the actual goods, service, data, or asset expected.
For Delivery Risk, the assessment should evaluate the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all. The assessment record should separate observed evidence supporting the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about the possibility that expected goods, services, messages, assets, or system outputs arrive late, incomplete, incorrect, or not at all to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
Payment confirmation does not prove delivery; contracts and controls need evidence tied to the actual goods, service, data, or asset expected.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)