The True Cost of a Missed Risk Signal: Building an Honest ROI Model for Risk Intelligence

By Mike North Jul 2, 2026

In almost every pricing conversation about risk intelligence, two responses come up. The first is some version of “we haven’t had a major incident, so this isn’t urgent.” The second is “one bad deal could end the fund, so clearly we need this.”

Both are wrong. Or, more precisely, both skip the math.

The first reaction quietly relies on survivorship bias. The second confuses tail risk with expected cost. Neither holds up in a partner meeting where someone has to defend a six-figure line item.

What follows is the math. A model fund operators can populate with their own numbers, not a vendor’s slide deck. It won’t produce a heroic ROI figure. It will produce a defensible one, which is more useful.

Why most ROI numbers in this market are broken

The figures circulating in risk and compliance marketing tend to fall into two camps. Neither survives scrutiny.

Vendor math takes a recent enforcement action — say, a sanctions violation that ended in a $50M fine — claims the platform would have caught it, and multiplies. Buyer math goes the other direction: “we haven’t been burned, therefore the value is zero.” Neither helps you build a budget.

The honest question is narrower. Across our portfolio, over the next twelve months, what is the expected cost of operating without continuous visibility into the entities we’re exposed to? That’s expected value: probability times impact, summed across realistic outcomes. Built carefully, it produces a range. The range is what you defend.

What “the cost of a missed signal” actually includes

Most cost analyses stop at direct loss. That misses where the real number lives.

A material missed signal — a sanctioned counterparty discovered too late, an undisclosed founder history, an impersonation campaign that drains user funds — generates costs across five layers. They are not optional add-ons. They are how the bill actually arrives.

Direct loss. Capital exposed to a sanctioned, fraudulent, or defunct entity. The cleanest figure, and usually the smallest.

Regulatory cost. Fines, remediation orders, license consequences, and the cost of demonstrating a remediation program after the fact. The U.S. Treasury’s OFAC recent actions page gives a clear sense of the volume and scale. FinCEN’s enforcement actions log is the other reference point. Six-figure penalties are routine. Eight-figure penalties are not rare. The fine itself is rarely the largest component of the regulatory bill.

Legal cost. Outside counsel, internal investigation, disclosure obligations to LPs and co-investors, settlement risk. These accrue whether or not a fine is ever assessed.

Reputational cost. Harder to model. Easy to underestimate. LP confidence is measurable, and it drops after operational incidents. Surveys from the Principles for Responsible Investment (PRI) and industry groups consistently rank operational due diligence in the top three screening factors for institutional allocators. The next fundraise feels it, sometimes for years.

Opportunity cost. Senior partner hours pulled into incident response are hours not spent sourcing, supporting portfolio, or fundraising. For a lean partnership, this is often the largest invisible line on the bill.

Sum the five layers, and the blended cost of a single material missed signal lands, for most mid-sized funds with meaningful regulatory exposure, somewhere between $1M and $2M. That’s consistent with what we see across our customer base. Your number will move based on jurisdictional mix, LP composition, and the headline value of the deals you run.

Probability is half the equation

A missed signal is not the same thing as a realized loss. Most adverse signals never escalate. Some do. The math depends on three inputs.

Base rate of critical signals per portfolio company per year. This varies more by sector than by anything else. Crypto and cross-border exposure carry meaningfully higher rates than domestic SaaS. Chainalysis’s annual crypto crime reports are the cleanest public reference for crypto-specific base rates. For broader compliance categories, ACAMS resources give useful sector benchmarks.

Conditional probability of escalation. Not every adverse signal becomes a problem. But a signal left unaddressed for ninety days has materially higher escalation odds than the same signal addressed inside twenty-four hours. The relationship is non-linear, which is the part most funds underestimate.

Detection delay. The gap between when a signal first appears in a public source and when an operator can act on it. For funds running quarterly reviews, the average sits around eighty-nine days. Cutting that to under twenty-four hours moves the model more than any other single input. It’s the lever traditional review cycles structurally cannot pull.

The model

In plain language:

Expected annual cost of unmonitored risk = (number of portfolio entities) × (critical signals per entity per year) × (probability of escalation given detection delay) × (blended cost of a realized event)

Each variable should be a range, not a single point. The version of this model that survives scrutiny produces a band. The midpoint becomes your expected case. The upper bound becomes the figure you plan against.

A worked example

A hypothetical mid-sized venture firm:

  • 40 portfolio companies, mixed sector, including crypto and cross-border holdings
  • Critical-signal base rate of roughly 0.6 per entity per year (sector-blended)
  • Current cadence: quarterly reviews, detection delay averaging 80 to 90 days
  • Blended event cost in the $1M–$2M range, using the five-layer breakdown above

Working through it:

40 × 0.6 × ~12% escalation probability at quarterly cadence × $1.5M average event cost ≈ $4.3M expected annual cost.

Running the same model with continuous monitoring (sub-24-hour detection, escalation probability falling to roughly 3%):

40 × 0.6 × 3% × $1.5M ≈ $1.08M expected annual cost.

The delta — the expected annual benefit of moving from quarterly to continuous — comes to roughly $3.2M for a firm of this size and exposure profile. Against a platform subscription in the low six figures, the ratio is not subtle.

Your own inputs will produce a different number. Smaller portfolio, lower-risk sectors, less regulatory exposure: the absolute figure drops. But across realistic input ranges for funds operating in venture, crypto, or alternative assets, the model lands in the same neighborhood. Continuous monitoring pays for itself, usually by a wide margin.

What actually moves the answer

Run the model with enough inputs and three things become clear.

Detection delay matters more than portfolio size. Cutting the delay from ninety days to one day moves expected cost more than doubling AUM. It’s also the lever traditional review cycles, by definition, cannot operate.

Sector mix dominates base rates. A fund heavily exposed to crypto, emerging markets, or regulated industries operates with critical-signal rates several times higher than a domestic technology fund. Most of the variance between funds shows up here.

The tail dominates the mean. One material event accounts for most of expected cost. Which is exactly why “we haven’t been burned” is not a refutation of the model. It’s the setup. The model is calculating the cost of the event that hasn’t happened yet, weighted by the probability that it does.

The asymmetry that closes the case

Risk intelligence is one of a small set of fund expenditures where the downside of underinvesting is unbounded and the cost of overinvesting is capped.

A platform subscription is a known number. A material missed signal is not. A fund can pay too much for risk intelligence and recover. A fund cannot always recover from the event the risk intelligence would have caught.

That asymmetry is the actual investment thesis. It doesn’t require assuming the platform catches every event. It only requires accepting that base rates are non-zero, that escalation probabilities rise sharply with detection delay, and that the realized cost of a single material event clears the platform spend by an order of magnitude. All three are observable in the data.

A note on certainty

This model produces an expected value, not a guarantee. Some funds will run for years without a material event. Others will see two in a quarter. Neither outcome refutes the math.

What the model does is quantify the cost of operating blind across a portfolio, in a form that survives partner-meeting scrutiny. For most funds with thirty-plus portfolio companies and any meaningful exposure to crypto, cross-border holdings, or regulated sectors, the case is clear without needing the headline figures or the worst-case framing. It only needs honest math.

If you want to run the model with your own numbers, Beady AI can walk through it on your actual portfolio. Book a working session and we’ll build the calculation against your real inputs — including the ones your current risk vendor probably won’t share.

Mike North
Ceo and Cofounder of Company Name

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris tincidunt vulputate efficitur. Pellentesque nec massa sed ante pharetra elementum. Phasellus ac ante vitae quam ultricies tincidunt ac vel odio.

Lorem ipsum dolor sit amet

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Lorem ipsum dolor sit amet

    Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Ready to get started?

    Helping you go live in days, not weeks.