Execution Risk
Pronunciation: ehk-suhk-YOO-shun RISK
Definition
Execution risk is the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely. Decision-makers use Execution Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. A score for Execution Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions.
Overview
Execution risk appears when intended decisions are translated into actual orders, transfers, configurations, deployments, or procedures. Errors can arise from incorrect parameters, market movement, system failure, unclear ownership, manual mistakes, or dependency delays.
In trading, execution risk includes slippage, partial fills, rejected orders, poor routing, and price changes before completion. In operations, it includes sending to the wrong address, applying an unsafe configuration, or failing to complete every required approval step.
Controls include validation, segregation of duties, transaction simulation, limits, confirmation screens, staged deployment, reconciliation, and rollback procedures. Critical actions should capture who approved, what was executed, when it occurred, and whether the observed result matched the intended outcome.
Execution risk is the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely. A sound decision can still produce loss when execution parameters, timing, ownership, verification, or recovery procedures fail.
For Execution Risk, the assessment should evaluate the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely. The assessment record should separate observed evidence supporting the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about the possibility that an approved transaction, strategy, control, or operational action is implemented incorrectly, late, or incompletely to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
A sound decision can still produce loss when execution parameters, timing, ownership, verification, or recovery procedures fail.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)