Why Single-Number Risk Scores Fail
The financial industry runs on risk scores. Moody's rates sovereign debt. Standard & Poor's grades corporate credit. ESG raters compress environmental, social, and governance performance into a single letter. These scores share a structural flaw: they compress multidimensional reality into a single symbol, then present that compression as insight.
This is the measurement problem at the heart of strategic intelligence. The Forreast Score was built to solve it—not by producing a better single number, but by refusing to produce one at all. The problem is mathematical: when you average nine independent variables into one number, you destroy information. A company that scores 2 on sanctions exposure and 8 on supply chain concentration is not a "5." A single-number score makes a company with one catastrophic exposure look identical to one with uniformly moderate exposure. They are not the same. They require different decisions.
The Forreast Score measures organizational vulnerability across nine distinct vectors, each scored on a 0–10 scale, each calculated independently, each accompanied by falsification conditions that specify what would invalidate the assessment. The nine numbers are presented together as a profile. They are never collapsed into a composite.
This post goes deep on each vector. For every one of the nine, we explain what it measures, give a concrete example from real intelligence work, explain why it must be read independently of the other eight, and state the conditions under which our assessment would be proven false. That last element—the falsification condition—is not a disclaimer. It is an epistemological commitment. Every claim Forreast makes is testable. If our reasoning is wrong, we tell you how you would know.
Vector 1: Sanctions Exposure
What it measures. Direct or indirect connection to sanctioned entities, jurisdictions, or individuals. This includes obvious cases—a company appearing on the OFAC Specially Designated Nationals (SDN) list—but more importantly, it includes hidden cases: beneficial ownership chains that obscure ultimate control, correspondent banking relationships with sanctioned institutions, and trade patterns that create secondary sanctions liability under frameworks like Executive Order 14114.
Concrete example. In a 2026 country-risk assessment of Kazakhstan, Forreast's OFAC screening pipeline (19,926 entries) identified 847 Kazakhstan-domiciled entities with potential Russia sanctions nexus. NebulaGraph traversal found 1,247 edges between Kazakh entities and OFAC-listed Russian entities within three hops. The critical finding was not that any single Kazakh company was sanctioned—it was that 14 of Kazakhstan's 22 commercial banks maintained correspondent relationships with Russian banks under OFAC sanctions. A company paying suppliers through those Kazakh banks could face secondary sanctions exposure even with no direct Russian counterparty. That is a sanctions exposure of 7/10—high, driven not by direct designation but by indirect financial plumbing.
Why it matters independently. Sanctions exposure is binary in consequence but indirect in mechanism. A company can have flawless operations, a clean balance sheet, and excellent management—and still face a total freeze on dollar-denominated transactions because its bank's correspondent network touches a sanctioned entity. This risk does not correlate with financial health or operational quality. Averaging it into a composite score lets a high sanctions exposure disappear inside an otherwise strong profile.
Falsification condition. A sanctions exposure score of 7/10 is invalidated if the identified correspondent banking relationships are confirmed to have been severed prior to the assessment date, or if the referenced OFAC designations are delisted by the issuing jurisdiction. If the ownership chain we traced is broken by a divestment we did not detect, the score drops and the methodology is corrected.
Vector 2: Supply Chain Concentration
What it measures. Dependency on a single supplier, geography, or logistics corridor for a critical input. This is not a measure of supplier reliability—it is a measure of fragility. A perfectly reliable supplier in a single jurisdiction is still a concentration risk if that jurisdiction imposes export controls, experiences political instability, or suffers a climate event.
Concrete example. In a systemic vulnerability assessment of 20 major consumer goods entities, Forreast's NebulaGraph traversal (2M+ vertices) revealed that 14 of 20 entities sourced palm oil derivatives from the same cluster of three Malaysian/Indonesian suppliers: IOI Group, Wilmar International, and Sime Darby Plantation. Average supply chain depth was five hops. The EU Deforestation Regulation, effective June 2025, requires all palm oil imports to be deforestation-free and geo-located to specific plantation plots. All three suppliers have been flagged by NGOs for traceability gaps. A single regulatory enforcement event against any one of them would simultaneously impair 70% of the assessed portfolio. That is supply chain concentration of 8/10—not because the suppliers are failing, but because the portfolio has no fallback.
Why it matters independently. Supply chain concentration is a portfolio-level risk that individual entity analysis will never surface. Each company looks diversified at its own Tier-1 level. The concentration only becomes visible when you map the shared dependency across the network. This risk is orthogonal to financial opacity, regulatory vulnerability, or geopolitical positioning. A company can be financially transparent, regulation-compliant, and geopolitically neutral—and still be one NGO report away from a supply chain shock.
Falsification condition. A supply chain concentration score of 8/10 is invalidated if the entities identified as the shared Tier-1 supplier cluster are confirmed to have been replaced by diversified alternatives prior to the assessment date, or if the regulatory framework cited (EUDR) is withdrawn or its enforcement postponed beyond the 12-month horizon. If the five-hop traversal paths are broken by supplier substitutions we did not detect, the score drops.
Vector 3: Counterparty Network Risk
What it measures. The aggregate vulnerability of the entities a company does business with, weighted by transaction volume and criticality. This vector uses the WorldGraph to map commercial relationships and assess the combined risk profile of that network. It is not enough to know who your counterparties are—you need to know who their counterparties are, and whether the network as a whole carries hidden contagion paths.
Concrete example. In the same consumer goods portfolio assessment, Forreast found that 11 of 20 entities maintained significant credit facilities with a common syndicate led by DBS Bank, OCBC Bank, and UOB—totaling $14.2 billion in revolving credit and term loans. If any single entity in that syndicate experiences credit deterioration, the syndicate may trigger covenant reviews across all 11 entities simultaneously. The counterparty network risk here is not that any single bank is fragile—it is that 55% of the portfolio shares the same financial counterparties, creating a contagion pathway that no individual entity's risk assessment would reveal.
Why it matters independently. Counterparty risk is network risk, and network risk is invisible at the entity level. A company's own balance sheet can be pristine; if its counterparties share a common exposure, the company is part of a contagion path. This vector measures a topological property—network structure—that is fundamentally different from scalar properties like sanctions designation or input dependency. Aggregating a topological measure with scalar ones produces a number that means nothing.
Falsification condition. A counterparty network risk score of 7/10 is invalidated if the shared syndicate exposure is confirmed to have been reduced below the 30% portfolio threshold through facility refinancing or syndicate diversification, or if the covenant trigger mechanisms cited are confirmed to be structured in a way that prevents cross-entity activation. If the WorldGraph edges we traced are based on stale filings that no longer reflect current credit arrangements, the score drops.
Vector 4: Geopolitical Positioning
What it measures. Exposure to specific geopolitical fault lines: trade disputes, territorial conflicts, regime instability, or diplomatic realignments that could disrupt operations. This is not a measure of general country risk—it is a measure of where the entity sits relative to active and emerging geopolitical stress points.
Concrete example. A logistics company operating across three jurisdictions—two of which are subject to active territorial disputes—carries a geopolitical positioning score of 7/10. The risk is not that the disputes will escalate to conflict (a low-probability scenario in most cases). The risk is that the disputes will trigger export controls, visa restrictions, or trade corridor closures that materially disrupt operations. For example, a company with manufacturing capacity in a region subject to territorial claims by multiple powers faces the possibility that any diplomatic deterioration could sever access to that capacity overnight.
Why it matters independently. Geopolitical positioning does not correlate with financial metrics. A company can be profitable, well-capitalized, and competently managed—and still be sitting on a geopolitical fault line that makes its operations uninsurable. This vector captures a form of risk that financial analysis is structurally blind to: the risk that geography imposes regardless of management quality.
Falsification condition. A geopolitical positioning score of 7/10 is invalidated if the territorial disputes cited are resolved through binding diplomatic agreement within the assessment horizon, or if the entity is confirmed to have relocated its critical operations out of the disputed jurisdictions prior to the assessment date. If the geopolitical fault lines we identified are downgraded by credible diplomatic sources, the score drops.
Vector 5: Regulatory Vulnerability
What it measures. Exposure to pending or probable regulatory action: antitrust investigations, sector-specific crackdowns, compliance failures, or jurisdictional shifts in enforcement posture. This vector monitors regulatory filings, enforcement actions, and legislative signals to identify entities operating in the path of regulatory change.
Concrete example. In the Kazakhstan assessment, the EAEU customs union membership creates a regulatory vulnerability that is invisible to conventional country-risk analysis. Goods entering Kazakhstan can technically transit to Russia without separate customs clearance. Under US and EU sanctions prohibiting the export of dual-use goods to Russia via third countries, any cargo transshipped through Kazakhstan— even without the company's knowledge—creates regulatory liability. This is a regulatory vulnerability score of 6/10: the company is not currently under investigation, but it operates in a regulatory environment where enforcement posture can change rapidly and retroactively.
Why it matters independently. Regulatory vulnerability is a forward-looking risk, not a backward-looking one. Financial metrics tell you what happened. Regulatory vulnerability tells you what could happen next. It is driven by legislative momentum, enforcement agency priorities, and political incentives that have nothing to do with the company's current financial position. A company with strong financials and a clean compliance record can still face a regulatory crackdown if the political winds shift. The timeline and mechanism of regulatory risk are fundamentally different from those of financial or operational risk.
Falsification condition. A regulatory vulnerability score of 6/10 is invalidated if the referenced regulatory framework (EAEU customs union rules, US/EU dual-use export controls) is amended to explicitly exempt the entity's operations, or if the enforcement agency confirms in writing that the entity's activities fall outside the scope of active investigation. If the legislative signals we tracked are withdrawn or the enforcement posture is publicly downgraded, the score drops.
Vector 6: Financial Opacity
What it measures. The degree to which a company's financial structure obscures its true position. Companies with complex holding structures, offshore entities, inconsistent reporting across jurisdictions, or beneficial ownership chains that resist tracing score higher on financial opacity. This is not a measure of fraud—it is a measure of how much you cannot see.
Concrete example. A company whose holding structure spans four jurisdictions—two with limited disclosure requirements—carries a financial opacity score of 6/10. The structure is legal. The filings are technically compliant. But an analyst attempting to trace the ultimate beneficial owner must navigate through layers of holding companies in jurisdictions that do not require public ownership disclosure. The risk is not that the company is doing something illegal; the risk is that you cannot verify what it is doing, which means you cannot assess the risks you cannot see. Financial opacity is the vector that determines how much confidence you can place in all the other vectors.
Why it matters independently. Financial opacity is a meta-risk: it degrades the quality of every other assessment. If you cannot trace ownership, your sanctions exposure score is less reliable. If you cannot see the holding structure, your counterparty network map has gaps. Its effect is multiplicative, not additive. A high opacity score means every other score in the profile carries wider error bars.
Falsification condition. A financial opacity score of 6/10 is invalidated if the entity is confirmed to have consolidated its holding structure into a single transparent jurisdiction with full public disclosure, or if the beneficial ownership chain is independently verified by a credible third party (GLEIF LEI registration, audited ownership attestation). If the opacity we attributed to the structure is actually a function of our data access limitations rather than the entity's reporting practices, the score drops and we flag the data gap.
Vector 7: Technology Dependency
What it measures. Reliance on specific technologies, platforms, or infrastructure that could be disrupted, sanctioned, or weaponized. This includes cloud platform dependency, critical software vendor lock-in, reliance on specific hardware supply chains (semiconductors, specialized chips), and dependence on infrastructure (cables, data centers, satellites) located in jurisdictions subject to export controls or political pressure.
Concrete example. A company running its entire supply chain management system on a cloud provider headquartered in a jurisdiction with active export control enforcement carries a technology dependency score of 7/10. The cloud provider is reliable, the service is excellent, and the platform is technically superior to alternatives. The risk is not performance—it is jurisdictional. If the cloud provider's home government expands export controls to include the company's sector or country, the company could lose access to its own operational systems. This is not hypothetical: the US Entity List has been expanded multiple times since 2018, and cloud access restrictions have followed.
Why it matters independently. Technology dependency is a single-point-of-failure risk structurally different from supply chain concentration. Supply chain concentration is about inputs; technology dependency is about infrastructure. A company can have a diversified supply chain and still be completely dependent on a single technology platform for operations. If that platform is pulled—by sanctions, by export controls, by a provider's own geopolitical exposure—the company loses operational capability even though its supply chain is intact. The mitigation strategies differ: supply chain concentration is addressed by diversifying suppliers; technology dependency by building redundancy, migrating to alternative platforms, or adopting open-source infrastructure.
Falsification condition. A technology dependency score of 7/10 is invalidated if the entity is confirmed to have migrated its critical systems to a multi-provider or self-hosted architecture prior to the assessment date, or if the export control framework cited is confirmed to explicitly exempt the entity's sector and jurisdiction. If the platform dependency we identified has been replaced by a redundant architecture we did not detect, the score drops.
Vector 8: Human Capital Concentration
What it measures. Dependency on key personnel, specialized labor pools, or talent geographies. This includes reliance on a small number of individuals whose departure would materially impair operations, concentration of technical teams in a single city or region subject to visa restrictions or political disruption, and dependence on specialized labor markets where talent supply is constrained or geographically concentrated.
Concrete example. A biotechnology firm whose core research team of 40 scientists is concentrated in a single city subject to emerging visa restrictions carries a human capital concentration score of 7/10. The scientists are not planning to leave. The company pays above market. The risk is not voluntary departure—it is involuntary disruption. If visa policy changes restrict the ability of foreign nationals on the research team to remain in the country, or if political instability in the region makes the city unsafe or inaccessible, the company loses its primary asset: the team. Human capital concentration is the vector that captures the risk that talent is not fungible. You cannot replace a specialized research team in a quarter.
Why it matters independently. Human capital concentration is a risk that financial and operational metrics will never flag. The company's financials may be strong. Its supply chain may be diversified. Its technology may be redundant. But if the people who make the company valuable are concentrated in one place subject to one set of political risks, the enterprise is fragile. Its mitigation requires a fundamentally different strategy: not financial hedging or supplier diversification, but geographic distribution of key personnel, cross-training, and succession planning.
Falsification condition. A human capital concentration score of 7/10 is invalidated if the entity is confirmed to have distributed its key personnel across multiple geographies prior to the assessment date, or if the visa restrictions cited are confirmed to have been lifted or explicitly exempted for the entity's sector. If the team concentration we identified has been reduced through hiring in alternative locations that we did not detect, the score drops.
Vector 9: Reputational Surface
What it measures. Exposure to reputational risk from public associations, media coverage, or social media sentiment. This vector monitors the information environment for emerging narratives that could affect valuation, partnerships, or regulatory attention. It is not a measure of current reputation—it is a measure of the surface area available for reputational attack and the momentum of narratives that are building but have not yet reached critical mass.
Concrete example. In the consumer goods portfolio assessment, Forreast identified that 14 of 20 entities are held in MSCI ESG Leaders Index funds. A single ESG rating downgrade—driven by the palm oil sourcing findings from Vector 2—could trigger automatic passive fund divestment. Estimated mechanical selling: $1.8–2.4 billion across the 14 entities if ESG ratings fall below BBB. The reputational surface score here is 6/10: the narrative exists (NGO reports on palm oil deforestation), the mechanism exists (ESG rating → index inclusion → passive selling), and the exposure is concentrated (14 entities sharing the same narrative risk). The reputational risk is not a story that has broken—it is a story that is structurally available to break.
Why it matters independently. Reputational surface is a second-order risk: it amplifies the impact of other vectors. A supply chain concentration problem that generates no media attention is an operational issue. The same problem that triggers an ESG downgrade and $2 billion in mechanical selling is a portfolio crisis. Its effect is conditional on the other vectors: a company with high reputational surface but no underlying vulnerabilities faces minimal risk. A company with high reputational surface and high supply chain concentration faces systemic risk. The interaction matters, and averaging destroys the interaction.
Falsification condition. A reputational surface score of 6/10 is invalidated if the narrative sources cited (NGO reports, ESG rating triggers) are confirmed to have been retracted or corrected, or if the index inclusion mechanism (MSCI ESG Leaders → automatic divestment) is confirmed to have been restructured to prevent mechanical selling. If the reputational narrative we tracked has been credibly countered by verified evidence we did not detect, the score drops.
Why Preserving Dimensionality Matters
The Forreast Score does not produce a single number. This is a design choice, not a limitation. The nine vectors are independent because the risks they measure are independent. Sanctions exposure does not predict supply chain concentration. Financial opacity does not predict geopolitical positioning. A company can be strong on eight vectors and catastrophic on one—and the one that matters depends on the decision-maker's context, not the analyst's weighting.
When you average nine independent risks into a single score, three things happen, all bad:
-
You lose the ability to act. A composite score of 5.2 does not tell you what to do. A profile showing 2 on sanctions and 8 on supply chain concentration tells you to diversify your supply chain. Dimensionality enables action. Compression prevents it.
-
You hide the worst case. The dominant risk is the highest vector, not the average. A company with one 9 and eight 1s is more dangerous than a company with nine 5s. A composite score makes the first look safer. That is backwards.
-
You destroy accountability. A composite score cannot be falsified because the methodology that combines the vectors is opaque. If the score moves, you cannot tell which vector changed or why. The Forreast Score's nine independent vectors, each with its own falsification conditions, create accountability at the vector level. When a vector score changes, you can trace it to the evidence. When a falsification condition is met, you know exactly which claim was invalidated.
Dimensionality is not complexity for its own sake. It is precision. A nine-vector profile gives you the resolution to make specific decisions about specific risks. A composite score gives you a number to put in a slide deck.
The Forreast Score costs $5,000 per month. The cost of an undetected concentration, an untraced ownership chain, or an unmonitored geopolitical fault line is substantially higher. The cost of not knowing which vector is the problem is the highest of all.
Forreast Intelligence provides AI-augmented strategic intelligence with the Forreast Score's nine-vector vulnerability assessment. Every vector is independently calculated, transparent in methodology, and accompanied by falsification conditions. Request a sample score at forreast.com for any company in your portfolio.
