What it is
A fragility audit lists everything a recommendation depends on, then asks what the plan loses if each dependency fails. It looks for concentrated damage: the supplier, customer, platform, person or price whose failure hurts far more than its size suggests. Forecasting asks which future arrives. This asks which dependency can ruin the plan across many futures, so the answer is a position rather than a prediction.
Where it comes from
The name has no single author, and the method marries two older things.
The concept is Nassim Nicholas Taleb's. In Antifragile (Random House, 2012), the fourth book of his Incerto, fragility is defined as a concave response to volatility: past some threshold, harm grows faster than the shock causing it. His practical claim matters more than the definition: fragility can be detected in a plan without predicting the shock that will hit it, because the shape of the exposure is visible now. Taleb set that out formally with the mathematician Raphael Douady in "Mathematical Definition, Mapping, and Detection of (Anti)Fragility" (2012), whose abstract offers a "fast-and-frugal, model-free" test for the property.
The procedure is older than the vocabulary. Listing components, describing how each fails and rating the consequence is Failure Mode and Effects Analysis, written into United States military procedure MIL-P-1629 on 9 November 1949 and later used by NASA contractors on Apollo and Voyager. A fragility audit runs that engineering routine over a business commitment rather than a machine, and follows Taleb in reading consequence before probability.
What it corrects
A dependency is easy to mistake for a forecast variable. Told that one customer is 40% of revenue, a careful analyst estimates the odds that this customer leaves, gathers evidence and lands on a number. The estimate may be good, and it still leaves the company where being wrong once ends the story. Accuracy does not change the position.
Ordinary care fails for a second reason. Dependencies hide inside the stable parts of a plan, and nobody writes down what they assume will keep working. The payment processor, the visa regime, the one engineer who understands the billing code, the shelf space a retailer holds for you: none of them appear in the model, because none of them have ever moved.
How it works
- State the recommendation as a commitment with a date and a size, so there is something concrete to break.
- List what must keep working for it: suppliers, customers, channels, platforms, regulators, key people, a price or rate that holds.
- For each, write the break in one sentence. What stops, and how soon it stops.
- Rate consequence first, then likelihood, and sort by consequence. Cheap and likely waits behind ruinous and rare.
- Ask of the top two whether the damage is recoverable or terminal. Terminal means the strategy is not there next year.
- Act on the terminal ones now: remove the single point of failure, cap the exposure, or buy the option while nobody is bidding for it.
- Name the first observable sign of each break, so the audit leaves behind something to watch.
Worked example
On 17 March 2000, lightning struck a power line in Albuquerque, New Mexico, and started a fire in a Philips semiconductor plant. It burned for ten minutes. The plant made radio frequency chips for Nokia and Ericsson, and Philips needed weeks to return to capacity.
Nokia bought the same chips from more than one source and had already made its phones able to take chips from different suppliers. Its people noticed the disrupted chip flow before Philips reported a problem, sent about thirty officials across Europe, Asia and the United States within two weeks, redesigned chips and pushed other suppliers for volume. Production stayed on target. Ericsson single-sourced the chips. Its marketing director for consumer goods, Jan Ahrenbring, later told the Wall Street Journal: "We did not have a Plan B." The company put its lost revenue at $400 million or more. By January 2001 Nokia's share of the handset market was about 30%, up from 27%, while Ericsson's had fallen to 9% from about 12%, and Ericsson announced it was handing handset manufacturing to Flextronics.
Neither company predicted the lightning. One had audited the dependency and paid, in design work and supplier relationships, for the ability to survive it.
In a Business Case Weekly case
In the Nike case, Consumer Direct Acceleration in mid-2020 traded wholesale accounts for Nike's own stores and apps. The margin arithmetic behind it was genuinely better. A fragility audit at that fork asks instead which dependency the plan creates: Nike's own channels become the only place casual buyers meet the brand, and the shelf space being vacated is held by someone who can fill it with On, Hoka or New Balance. Then it asks the question that decides the fork. If that space is filled, can it be bought back, at what price, and for how long?
In your answer
- "This recommendation depends on X holding; here is what stops if it does not."
- "The consequence is terminal rather than expensive, because …"
- "I am not forecasting that break. I am limiting what it costs me by …"
- "The first sign I would see is …, which is why I would watch it monthly."
Common misuse
The usual counterfeit is the risk register: twenty rows, a likelihood score, an impact score, a colour, an owner, and a plan that goes ahead unchanged. It has the audit's shape and does none of its work, because scoring is not positioning. The one-line test: if the audit changed no commitment and bought no option, it was a description.
The opposite misuse is redundancy everywhere. Second suppliers, spare capacity and standby contracts cost money and add complexity, and a dependency whose failure is merely annoying earns none of them. Read the consequence first, then pay only where the failure would be terminal.
References
- Nassim Nicholas Taleb, Antifragile: Things That Gain from Disorder, Random House, 2012. The chapters on the barbell and via negativa carry the practical method.
- Taleb & Douady, "Mathematical Definition, Mapping, and Detection of (Anti)Fragility" (2012), the formal version and the source of the detection claim.
- Almar Latour, "Trial by Fire: A Blaze in Albuquerque Sets Off Major Crisis for Cell-Phone Giants", Wall Street Journal, 29 January 2001, the primary account of the worked example, readable in twenty minutes.
- Sunil Chopra & ManMohan S. Sodhi, "Managing Risk to Avoid Supply-Chain Breakdown", MIT Sloan Management Review, Fall 2004, on rating dependencies without buying redundancy everywhere.
