I. Introduction

Risk has become a preoccupation of states,1 businesses,2 and individuals.3 What once was the subject of a Tom Cruise science fiction film4 is now before the U.S. Supreme Court.5 There is even an emergent theory of “proactive law” that seeks broadly to “shift[ ] the focus of attention from dispute-resolution to . . . legal risk management.”6 In the U.N. Security Council, we may be seeing a third generation of sanctions—not sanctions that apply with a broad brush to entire states, nor even measures that apply to designated individuals, entities or items, but sanctions triggered when a state believes that an individual, entity or item poses a particular risk; a similar point can be made with respect to U.N. peacekeeping missions, which are increasingly authorized to protect civilians at risk. More broadly, at the U.N., the new Secretary-General, in his first briefing of the Security Council, stressed the critical role of prevention,7 which, in turn, requires a framework for assessing the risk of conflict or atrocities occurring.8

Risk, of course, can mean different things in different contexts. In this Article, I use “risk” in two specific ways: what might be termed “known” and “unknown” risk, or “risk” and “uncertainty.”9 “Known” risk is the probability of occurrence of an event coupled with the magnitude of the resulting harm.10 “Known” risk thus entails a certain measurability. Examples might be the risk presented by Russian roulette, where there is a known one-in-six chance of death,11 or the risk of car crashes entailed by particular highway driving conditions, which insurance companies have been able to assess based on statistical analyses.12 “Unknown” risk is more inchoate potential peril about which we lack information either on the likelihood of the harm materializing or knowledge of the effect it would have if it did. An example might be the potential effect of introduction of an invasive species into a new ecosystem.13 Of course, this division into categories is something of an oversimplification, since risk operates along a quantifiability continuum.14 I also count “threats” as a form of “known” risk. Threats—at least as that term is used in this Article—are risks that tend to be assessed on an individual, qualitative basis rather than as a statistical measure. An example might be the threat that a particular individual will commit a terrorist attack.15

Risk is distinct from, and antecedent to, harm. That is, the existence of risk may permit or require a state to act before harm has occurred. For instance, those who support the legal availability of anticipatory self-defense argue that a state may use force even before an armed attack has occurred where the attack is believed to be imminent.16 Likewise, the International Court of Justice (ICJ) and the Seabed Disputes Chamber of the International Tribunal for the Law of the Sea (ITLOS) have recently asserted that states have an obligation to conduct environmental impact assessments (EIAs)17 where there is sufficient risk of environmental harm, but before the relevant action has been taken.

Risk in these senses is taking off at the international level, and not just at the U.N. In particular, the last few years have been characterized by ever greater expansion of the field of application of prevention rules—rules requiring efforts to prevent harm, often by seeking to mitigate “known risks of harm”18—and due diligence obligations, or “best efforts” obligations of conduct.19 Prevention and due diligence are related, as due diligence is generally the relevant standard of conduct for the implementation of prevention rules.20 That is, even if a state has an obligation to prevent harm when a certain quantum of risk of that harm materializing exists, the obligation is seldom absolute. Rather, it more frequently takes the form of an obligation to take measures to mitigate the risk of the harm materializing. That prevention rules and due diligence obligations have risen to prominence at the same time is thus no surprise.21 These concepts are now being applied broadly, including to business activities,22 cyberspace,23 and assistance to states and armed groups during armed conflict.24 Legal regimes predicated upon threats, too, are gaining increasing significance in international law, and not just the question of self-defense. Thus, for instance, the Security Council has begun to require states to take measures to halt the proliferation threat that certain items or transactions may pose.25

While there is robust literature on the role of risk in various areas of domestic law,26 and while certain risk-related international law topics such as prevention27 (and the precautionary approach) have been considered exhaustively, scholarship on those topics has generally remained within topical silos. Prevention, for instance, has principally been discussed in the context of international environmental law.28

Other aspects of risk, such as due diligence, not only suffer from a deficit of cross-cutting analysis, but are also under-studied.29 Risk also remains under-theorized in the sense that there has been little analysis of the variety of roles risk can play in legal regimes. By “role” I mean the effect the existence of the risk has on state conduct. For instance, risk could be either obligating or authorizing. The Security Council sanctions regimes I have briefly described above are examples of “risk as obligation”: that is, if there is sufficient risk, the state is obligated to freeze the assets or stop the transaction. On the other hand, with respect to anticipatory self-defense, risk (or threat) provides a legal authorization for a state to use force.30 What a state is obligated or authorized to do may also vary. Thus, for instance, a prevention obligation might require a state to undertake an environmental impact assessment. This would be a procedural obligation (like an obligation to negotiate or cooperate in good faith), in the sense that it does not speak to the ultimate legality of the proposed activity. By contrast, anticipatory self-defense is a substantive authorization, in that it renders the actual use of force lawful, subject to necessity and proportionality.31 Finally, risk can be judged on a case-by-case basis, or specific activities can be categorized as more or less risky in advance—that is, risk can be relevant either as applied (or contextually), or facially.32

Risk analysis can also be scoped more broadly or more narrowly—for instance, is it the risk to one’s own citizens that matters, the risk to neighboring states or their citizens, or the risk to all states or their citizens?33 Likewise, one could take account of more or fewer sources of risk. For instance, under what circumstances should risk presented by purely private conduct be relevant?

International law has increasingly begun to put these myriad forms of risk to use. As one commentator put it, prevention has “resurfac[ed] spectacularly.”34 Likewise, while due diligence has a deep pedigree, it was not until the late 1980s and early 1990s that it began to be applied more broadly, in particular through human rights instruments and jurisprudence regarding violence against women.35

On one level, a turn to risk analysis should not be surprising given the attractiveness of prevention over response in situations where the consequences of wrongful or injurious conduct are increasingly grave (or at least where our collective tolerance for such consequences continues to diminish). Moreover, it is a truism that the world is only growing more interdependent, and thus it makes sense that techniques developed in the context of transboundary environmental disputes are now being applied more broadly.36 On a deeper level, however, while under domestic law risk analysis can sometimes be seen as anti-democratic (insofar as it may rely on experts rather than popular will),37 at the international level, it may actually be a way to appeal to and involve an audience beyond other states. That is, if international law claims are increasingly directed not just to other states, but also to civil society and individual citizens, risk (and the empirical approach it can bring with it) may be an attractive tool. The turn to risk may also be of a piece with the growth of a “global administrative space.”38

This Article seeks to unpack the rise of risk at the international level and make three contributions. First, it uses illustrative episodes, particularly from the history of prevention (and, to a limited extent, precaution39) and due diligence, to sketch the story of this rise. It strives to go beyond the usual account, to look across disciplines, and to apply a more rigorous taxonomy to the roles risk has played. Second, it posits and seeks to illuminate a recent trend in favor of increasing use of risk in international law.

Third, and finally, the Article offers tentative explanations for this trend and thoughts on the potential consequences thereof. For example, one such consequence is that international courts and tribunals may not be well suited to reviewing risk analysis (or the decisions that flow from such analysis). A second consequence might be the potential for horizontal fragmentation (that is, the potential for differences of understanding of international law among states as they reach different conclusions about the risks presented by particular activities and hence the potential that state practice and opinio juris will begin to diverge, creating different “international laws”).

The Article proceeds in six parts. In Part II, I set the stage by describing the U.N. Security Council’s increasing use of risk-based approaches. In Part III, I go back in time to explain how we got to where we are today, focusing in particular on the development of the prevention and due diligence doctrines. In Section IV, I identify the broad range of areas and issues that are now addressed through the prism of risk, and use the taxonomy I have sketched above to describe them. In Part V, I offer potential reasons for why the use of risk may be increasing (and the consequences thereof), and in Part VI, I provide a brief conclusion.

II. The U.N. Security Council and Risk

In this Part, I describe recent Security Council practice to give some sense of how prevalent risk-based approaches have become. The Security Council increasingly functions as a legislative or administrative body; at the same time, treaty-making has declined, making Council practice a useful lens for understanding risk analysis.40 I focus on two areas of Council practice in particular: sanctions and the related area of suppression of terrorist financing, and the protection of civilians. An analysis of these two areas shows how the Council is using risk in myriad ways: as obligation and as authorization, as process and as substance, and as a tool to be applied broadly or narrowly depending on the situation.

A. Sanctions

In this Section, I turn first to the ways in which the Security Council has made sanctions regimes more risk-based. The Security Council has traditionally used two principal tools in the sanctions space: (1) arms embargoes or other restrictions on transactions with or destined to a particular state; and (2) asset freezes or travel bans on identified individuals or entities.41 There are hybrid forms, such as the arms embargoes on particular individuals in Yemen42 and on individuals and entities associated with Al Qaeda,43 but, at the risk of over-generalization, the former principally speaks to what is being transferred whereas the latter concerns with whom one is dealing. Moreover, the “what” and the “who” have tended to be predicated upon past conduct or an assessment of the current state of affairs.44 The basis for imposing sanctions has not tended to be the likely future effect of a particular transaction or a person’s probable future conduct.45

That recently changed.46 Thus, for instance, the first sanctions resolution on the Democratic People’s Republic of Korea (DPRK or North Korea), Resolution 1718,47 took a relatively traditional approach, banning the export of certain identified items to the DPRK. But the next resolution, Resolution 1874, contained a provision calling upon states to prevent their nationals or entities organized under their laws from providing financial services that “could contribute” to the DPRK’s weapons of mass destruction (WMD) or missile programs.48 This was risk-based (most akin to a threat analysis), albeit hortatory. Only those services each state itself believed posed a sufficient risk of contributing to the DPRK’s prohibited activities triggered the provision. Resolution 2094 went even further by making this provision binding.49

The next DPRK sanctions resolution, Resolution 2270, added a new formulation—obligations triggered by a “determination” regarding whether items or services could contribute to activities of concern.50 Thus, for instance, the resolution prohibits the sale or supply of “any item, except food or medicine, if the State determines that such item could directly contribute to the development of the DPRK’s operational capabilities of its armed forces.”51

Measures of this form are not limited to the DPRK context. For instance, in Resolution 1929, the Council prohibited the transfer of items to Iran “if the State determine[d] they could contribute” to enrichment52 and prohibited the provision of financial services if the state had reasonable grounds to believe they could contribute to Iran’s proliferation-sensitive nuclear activities.53

These resolutions not only are using risk, but using risk in different ways. A prohibition on transactions that pose a sufficient risk of contributing to prohibited programs relies on risk to impose a substantive obligation. Resolution 2270, on the other hand, which speaks of determinations regarding the sale or supply of certain items, is at least suggestive of a potential role for risk assessment procedures.54

More broadly, the Security Council has increasingly imposed similar (albeit less reticulated) prevention and due diligence obligations on states with respect to terrorist financing. Thus, for instance, Resolution 1373 requires states to prevent and suppress the financing of terrorist acts.55 Likewise, in the context of the Al Qaeda/ISIL asset freeze, states are required to prevent their nationals, individuals, and entities within their territory from making funds, financial assets, or economic resources available to designated individuals or entities.56 As one commentator has put it:

Before the 9/11 terrorist attacks, states focused their compliance with the Terrorism Suppression Conventions almost exclusively on criminal law enforcement. . . . [I]ts application to terrorist offence is post facto and therefore not strictly preventive. Following 9/11 with the adoption of Security Council Resolution 1373 (2001) . . . states began to report on measures taken to prevent terrorists from gaining access to funds or from using their territories as a base of operations or indoctrination.57

My argument in this Section is not that this trend in Security Council sanctions practice means it has abandoned other tools. Of course, blunter approaches remain in the Security Council’s arsenal. Thus, for instance, Resolution 2371 prohibited all trade with the DPRK in certain sectors (including, for instance, coal and iron). And, Resolution 2375 extended those prohibitions to natural gas and textiles, and imposed a cap on the amount of refined petroleum that could be sold to the DPRK. Indeed, as the crisis regarding the DPRK has deepened, and in particular in light of the way in which all sectors of the DPRK economy have some relationship to the DPRK’s nuclear and ballistic missile programs, risk-mitigation measures may be insufficient. Rather, my argument here is that the Council has begun to use risk-based tools in its sanctions practice; and the Council will surely use them again in addressing threats for which they are appropriate.58

B. Protection of Civilians

In this Section, I turn next to a second area of recent Security Council practice that has relied on risk assessments: protection of civilians mandates. In general, unlike the sanctions regimes I described in the prior Section, pursuant to which the Council imposed obligations on states where there was sufficient risk, these examples are of authorizations to take action on the basis of risk.59

Historically, peacekeepers were expected to respond to outbreaks of violence when they occurred. The Brahimi report, for instance, suggested peacekeepers should be authorized to respond when they “witness violence against civilians.”60 More recently, however, peacekeeping missions with protection-of-civilians mandates have been expected to analyze threats and prevent them from materializing.

Protection of civilians mandates are more and more common in contemporary peacekeeping missions,61 often taking the form of an authorization to use force to protect (without prejudice to the primary responsibility of the territorial state) “civilians under threat of physical violence.”62 The way the Council has glossed such mandates makes clear that in the sense used here, “threat” is risk-based. For instance, the United Nations Multidimensional Integrated Stability Mission in Mali (MINUSMA) has been tasked with stabilizing “areas where civilians are at risk,” and protection of civilians is defined to include “active and effective patrolling in areas where civilians are at risk.”63 Likewise, the United Nations Mission in South Sudan (UNMISS) has been mandated to identify threats against civilians “in areas at high risk.”64

U.N. doctrine documents confirm this. The 2011 Framework for Drafting Comprehensive Protection of Civilians (POC) Strategies in U.N. Peacekeeping Operations counseled “[a]rticulat[ing] actual and potential POC risks in the mission area.”65 Likewise, a Department of Peacekeeping Operations/Department of Field Support policy document speaks of “[f]orward-looking threat and risk assessment [that] will enable the mission to anticipate and prevent violence before it occurs.”66

Beyond U.N. peacekeeping, the Security Council has also authorized states to use force in Libya where civilians were under threat of attack.67 And, the U.N. has promulgated a human rights due diligence policy that provides that where U.N. entities are contemplating support to non-U.N. security forces, they must make an “assessment of the risks”68 and must not provide support under certain conditions.

But the Council has not only considered the question of whether to apply risk-based standards, and not only used risk to create both obligations (sanctions) and authorizations (protection of civilians), but has also had to wrestle with the question of how to scope risk analysis. That is, the Council has had to consider the question, “what risk”—posed by whom and to whom—“should matter.” Here, again, protection of civilians is a useful lens. For instance, there has long been a robust debate regarding how to address risk to civilians posed by the host government. The U.N. Operation in Cote d’Ivoire (UNOCI), for example, was authorized to use force to protect civilians, in particular from the use of heavy weapons.69 This “effectively . . . allowed for much greater intervention by the U.N. mission in the conflict” against outgoing President Gbagbo, who refused to relinquish power.70 We have also recently begun to see discussion of risk to whom, beyond simply civilians. Thus, for instance, Resolution 2304 also called for the regional protection force in South Sudan to respond to potential attacks against international and national humanitarian actors.71

III. The Birth of Risk-Based International Law

The Security Council practice I have described is only the tip of the iceberg. In this Part, I take a step back and offer a brief (and necessarily not exhaustive) history of risk analysis, principally through the lens of the work of the International Law Commission (ILC), focusing in particular on prevention and due diligence. In Section IV, I show how this evolving practice has culminated in the broad use of risk, in various ways, across various areas of law.

Early on, risk principally arose in two contexts. The first was state responsibility for harm to foreign nationals (as courts and tribunals wrestled with whether states had done enough to prevent such harm, that is, whether they had exercised due diligence in implementing a proto-prevention rule72). The second was states’ authority to address threats, for instance when neutral states failed during armed conflict adequately to mitigate the risk of belligerent behavior in their waters. In both cases, although the relevant rules appeared facially to speak to a state’s prevention obligations, they essentially functioned as authorizations. That is, state responsibility for harm to foreign nationals fundamentally focused on the question of whether the state of nationality was entitled to bring a claim against the territorial state. Likewise, the law of neutrality was most concerned with whether, based on the threat presented by a belligerent operating in neutral waters, another belligerent should be authorized to use force despite the fact that force was being used on neutral territory. These two early examples of risk analysis differed, however, in that the risk element in the doctrine of state responsibility was at least in part assessed in more categorical terms, whereas the law of neutrality prescribed a more case-by-case approach.

During a second phase, which coincided with the ILC’s early work on state responsibility as currently conceived (i.e., not limited to harm to foreign nationals), risk analysis began to be applied more broadly (that is, to additional areas of law). But the dominant paradigm remained one of risk as authorization, and prevention qua prevention was subordinate to the question of whether a claim could be brought for failure to exercise due diligence. During a third phase, however, risk as obligation began fully to emerge with a focus on prevention of transboundary harm (and, more broadly, the development of international environmental law).73 At the same time, risk as authorization became perhaps less salient. During this phase, there was frequent resort to procedural obligations (such as an obligation to conduct an environmental impact assessment), which differed from earlier more substantive risk authorizations. I trace each of these three phases in the Sections that follow.

A. Phase 1: Early Due Diligence—State Responsibility and Neutrality

In this Section, I describe the early uses of risk analysis and make the case that the focus of risk analysis was on when and whether a state was authorized to act—whether to bring a claim or to use force. This origin story is twofold. The first part concerns the early law of state responsibility for harm to foreign nationals,74 and in particular whether the lack of due diligence by one state permitted another state to pursue a claim against it, and the second part concerns the law of neutrality.75 I will describe each in turn.

The paradigmatic example of a claim predicated upon harm by private citizens to a state’s national was where the territorial state failed to offer justice in the wake of the harm.76 Thus, for instance, in a claim brought by a U.S. national arising from the death of her husband and son in Mexico, Mexico was found liable “by its failure to put the perpetrators to justice.”77 This was not risk-based.78

But this was not the only question relevant to such inter-state claims. Also relevant were: (1) whether the territorial state knew of a risk to the foreign national79; and (2) whether the territorial state had the capacity to address the risk. These were more risk-based, although the former only insofar as knowledge could be constructive knowledge (since where the territorial state was explicitly warned of a credible threat, there was very little risk assessment for the state to make).80

The question of state capacity as a basis for claims is perhaps most interesting for these purposes. In the British Claims in Morocco81 case, for instance, the arbitrator focused on what the territorial state could reasonably achieve.82 As Riccardo Pisillo-Mazzeschi has explained, by these lights the due diligence rule at the time concerned “possessing, on a permanent basis, a legal and administrative apparatus normally able to guarantee respect for the international norm on prevention.”83 As another author pointed out at the time, the early doctrine of protection of nationals was “ultimately concerned with the possibility of maintaining a unified economic and social order for the conduct of international trade and intercourse among independent political units.”84

Thus, insofar as risk featured in the early law of due diligence regarding protection of nationals, it was with respect to the risk of general lawlessness, or, occasionally, as proof of indirect knowledge. This was categorical risk assessment, in the sense that the question was whether the territorial state had structures in place to address kinds of risk (for example, crime). The law was little concerned with the specifics of individual cases. The focus, moreover, remained principally upon whether there were adequate local remedies.85 As a consequence, risk ultimately played an authorizing function—that is, the existence of risk, often coupled with a failure to address the consequences of its materialization, authorized a state to make claims. There was little attention paid to the contours of states’ prevention obligations.

I will turn now to the law of neutrality. I contend that risk in this area of law was considered more contextually, but again it provided authorization for states to act. The focus was not on what states were expected to do to address risk. The seminal early case in the law of neutrality was the Alabama Claims Arbitration of 1872. These claims involved British failure to halt construction of vessels that were armed and used by the Confederacy during the U.S. Civil War, despite U.S. warnings of the risk these vessels’ construction posed. The Treaty of Washington, which established the arbitral tribunal that decided these claims, reflected agreement by the parties that a neutral state was expected to use due diligence to prevent the fitting out of a vessel it had reasonable grounds to believe was intended to cruise or carry out war.86 The tribunal went on to hold the U.K. liable, relying in part on the warnings the U.S. had offered.87 The tribunal specifically concluded that “‘due diligence’ . . . ought to be exercised by neutral governments in exact proportion to the risks to which either of the belligerents may be exposed, from a failure to fulfil [sic] the obligations of neutrality on their part.”88 Thus, the tribunal appeared to require that a neutral government assess on a case-by-case basis the risk posed by particular activities. Subsequent treaties included language to similar effect.89

But the law of neutrality was actually little concerned with glossing ex ante what a state was required to do to fulfill those obligations—characterized as a “comparatively simple duty”90—and instead often focused on whether a belligerent was justified in taking action against an opposing vessel in a neutral’s territorial waters on the basis of the threat it presented where the neutral had failed to execute its duties.91 Norway’s investigation of the Altmark, and the U.K. action against that vessel, are good examples of this.92

Thus, as one commentator has put it more generally, during the League of Nations period—and indeed, I would say, through World War II—there was “little attention given to prevention.”93 Rather, to the extent risk arose, it arose principally in the context of substantive rules regarding authorization to take particular actions (whether with respect to claims or the use of force) on the basis of a failure to exercise due diligence or the resulting threat. In the next Section, I describe how the role risk played remained roughly similar through World War II and the post-war period in the sense that risk generally functioned as an authorization; I also demonstrate, however, how a predicate was being laid to risk’s expansion, both with respect to its role and with respect to a broadening of the areas of law to which it was relevant.

B. Phase 2: Trail Smelter and the ILC’s Initial Work on Modern State Responsibility

In this Section, I trace the story of due diligence through the World War II and post-war periods. This period is one of transition in that risk’s role remained relatively static but two developments laid the groundwork for the subsequent dramatic expansion of risk’s relevance to international law. Starting with the latter, the two key developments were: (1) the focus of state responsibility broadened, beyond exclusively harm to foreign nationals94 and to include transboundary harm, as well as harm caused by non-state actors over which a state exercised sufficient control; and (2) increasing attention was paid to the quantum of harm (as had been the case with respect to neutrality doctrine), which started a more robust conversation about how to assess harm (and, ultimately, the risk thereof). Nevertheless, while risk began to feature more prominently, risk remained principally relevant with respect to questions of whether a state was authorized to act.

The first major change of this period was that due diligence mattered in areas of law beyond injury to foreign nationals. Perhaps the most prominent reflection of this is the Trail Smelter case.95 That case concerned transboundary harm. Likewise, within the ILC in the early 1960s, there was robust debate about whether state responsibility should be made broader than the question of responsibility for harm to non-citizens96 (and of course it was). Coupled with this subject-matter expansion, there was increasing focus on state support to non-state actors and when that should trigger state responsibility (as opposed simply to when it should be triggered by direct state action or state inaction). For instance, one author cites a Soviet complaint to the U.S. about the activities of anti-Castro forces in Cuba who were alleged to have shelled a Soviet merchant ship.97 This line of logic ultimately (albeit later) culminated in the ICJ’s Nicaragua case, in which the court focused on whether the U.S. exercised “effective control” of the contras for purposes of state responsibility.98 These two developments opened the aperture with respect to what and whose risks were relevant.

The second major change was that attention was increasingly being paid to how to understand harm. Thus, while Trail Smelter is often cited in discussion of prevention of transboundary harm, the tribunal essentially assumed potential state responsibility for injurious acts by private parties.99 Instead, its focus was on the definition of an injurious act.100 Indeed, the tribunal’s famous pronouncement is that the injury must be “of serious consequences and . . . established by clear and convincing evidence.”101 This effected an important shift in focus from the conduct of the state alone to the harm. It was a predicate to a more robust use of risk analysis, which often requires understanding likely harm, and not just what a state did or did not do.

Despite these changes, risk analysis remained principally a source of authorization—and not just under the law of neutrality (although that continued to be an important focus102. For example, while the theory of defense of nationals was debated by this point, any right to use force that was recognized was seen not as arising from a breach of an obligation, but rather as the exercise of a right.103 Similarly, a focus on authorization continued to characterize the discussion of state responsibility.104 Indeed, the very use of the term “responsibility” in the ILC’s papers was initially understood to mean the consequence of unlawful conduct (whereas “liability” described a primary obligation).105

Another element of continuity is that risk continued to be considered generally (facially) under a variety of circumstances, rather than on a case-by-case basis. Thus, F.V. García Amador (the ILC’s first special rapporteur on state responsibility) characterized what was at issue in Trail Smelter as a breach of a general duty “implicit in the function of the State . . . namely, the duty to ensure that in its territory conditions prevail which guarantee the safety of persons and property.”106 Likewise, the prevention obligations of the Vienna Convention on Diplomatic Relations with respect to the inviolability of diplomatic missions and personnel were little considered107 until a subsequent rash of kidnappings and hostage takings prompted the General Assembly to adopt a new Convention on the Prevention and Punishment of Crimes against Internationally Protected Persons, including Diplomatic Agents. Even that latter Convention focused principally on criminalization (akin to the earlier debate about whether the territorial state had seen justice done for crimes against a foreign national), rather than setting forth a more detailed set of risk-based obligations. This is also the period when there is considerable growth in treaty-based investment protections.108 Many such treaties included a requirement that “[i]nvestment shall . . . enjoy full protection and security.”109 During the immediately post-war period, this was generally seen as protection against risks of an unfair legal system.110

Thus, the role risk played remained relatively static. But as the scope of legally-relevant risk broadened, and as harm increasingly came into focus, the way was cleared for risk to play new legally-relevant roles. In the next Section, I turn to those developments.

C. The Rise of Risk as Obligation

In this Section, I outline how risk began playing different roles beginning roughly in 1970, when the ILC inaugurated its work on international liability for injurious consequences arising out of acts not prohibited by international law. In particular, this period was marked by a flowering of risk as obligation, as opposed to authorization, by virtue of a sustained focus on what prevention rules entail when married with a due diligence standard. Risk also began to give rise to procedural obligations and was considered more frequently on a case-by-case rather than categorical basis (although case-by-case analysis was not always a deep look).

At the same time, through roughly 2001, while the question of which risks were relevant continued to receive ever more expansive answers (for instance, private actions, and not just those of which the state had knowledge or that the state supported, were deemed to present legally relevant risks), with respect to subject matter, risk analysis stayed in a somewhat narrow lane (generally transboundary environmental harm). Likewise, while risk-based law began to move slightly away from the dyadic paradigm‑which had, to a certain extent, flowed from the concept of risk as claims-authorization111‑the conversation about which risk bearers were relevant was only just beginning.

To illustrate these trends, in this Section I focus in particular on the evolution of the law governing transboundary harm (and related developments with regard to due diligence and prevention), the development of the precautionary approach (and its treatment in litigation, in particular before the ICJ, the WTO Appellate Body, and the ITLOS), and debate regarding the defense of nationals. This is necessarily something of a sketch, given the vast literature on the first two topics in particular.

Perhaps the most important development—and certainly the first—was that, in 1970, the ILC divided its project on state responsibility into state responsibility and “risk liability,”112 which was understood to be a set of rules governing the relationship between states with respect to activities that might cause or had caused harm, but which were not internationally wrongful. A key difference between state responsibility and state liability was that state responsibility required wrongful conduct, but not necessarily harm, whereas state liability required harm (or at least a risk thereof), but not unlawful conduct.113 This greater focus on harm, and, indeed, risk of harm,114 as opposed to the attribution of wrongful conduct,115 opened the door significantly to risk analysis.116 As Gunther Handl has said, the ILC’s work exceeded “a study of reparation . . . [and began to cover] the management, in general, of transnational risks.”117

The state liability project relied on risk to impose prevention-type obligations, in particular not to cause harm, or to mitigate the risk thereof.118 As Robert Quentin-Baxter, the ILC’s first special rapporteur on the subject, said, liability was meant as “a negative asset, an obligation, in contra-distinction to a right.”119

The ILC also had long debates regarding how to assess risk, in particular how categorical or how contextual an approach should be taken. The ILC sought to establish a threshold of potential harm that would trigger application of what ultimately became draft articles on the prevention of transboundary harm (in other words, de minimis risk of harm was not foreseen as within the scope of coverage).120 This led to questions regarding: whether risk should have a qualitative detectability;121 whether the ILC should promulgate a list of risky activities, which could then be periodically updated;122 and at what level of specificity risk should be assessed (for example, at the level of an “activity” or as applied in particular circumstances).123 All of this evidenced a critical inquiry into whether to apply a contextual or categorical approach, and what each would mean.124

Finally, while the draft articles the ILC ultimately proposed included a due diligence obligation with respect to the prevention of harm, the ILC’s work on risk assessment procedures was more detailed.125 Indeed, this period saw the inauguration of reticulated procedural obligations. Elements of the schematic outline that the ILC originally considered in its work on the topic were entirely procedural in nature.126 And, ultimately, commentators127 and the ILC began to focus on environmental impact assessments.128 As one commentator has put it, “[i]ncreasingly, the international legal community deals with the need to mitigate risks and prevent environmental harm through a sophisticated network of international procedural obligations.”129

The focus on harm, and its prevention, not only reflected a turn to risk as obligation (rather than risk as authorization), but it also broadened the aperture to permit greater scrutiny of non-state actor conduct. That is, a greater set of risks became legally relevant. As Quentin-Baxter said in his first report, “[a] State within whose jurisdiction such an injury or danger is caused is not justified in refusing its co-operation upon the ground that the cause of the danger was not, or is not, within its knowledge or control.”130 Moreover, the ILC not only wrestled with the question of whose conduct should be covered, but also whose rights were implicated where harm occurred. This is the era of the ICJ’s decision in Barcelona Traction, in which the court appeared to move away from a necessarily dyadic, inter-state concept.131 While the ILC was hesitant to address general environmental risk,132 the issue had been joined, and it began to arise in other areas of risk-based law.133 It has continued to grow in prominence.

Despite these profound advances, however, the ILC’s project remained tethered to a limited set of harms. For instance, the ILC explicitly restricted the coverage of its draft articles on prevention of transboundary harm to acts causing physical damage134 emanating from the territory or areas under the jurisdiction or control of another state.135 Even if not explicitly, the ILC’s work was also understood principally to concern environmental law.136

The second significant development of the period was the explosive growth of the concept of precaution. This too fueled the rise of risk as procedural obligation, to be assessed contextually. There has been some question whether precaution should be understood to concern authorization137 or obligation138—that is, does uncertainty require states to regulate (or prohibit) risky activity or does uncertainty authorize states (despite countervailing norms) to promulgate such regulations (or prohibitions). But litigation during this period tended to reject precaution as authorization in favor of precaution as obligation.139 Thus, for instance, in the Case Concerning the Gabcikovo-Nagymaros Project the ICJ considered a claim that a state of ecological necessity, or “ecological risk,”140 excused abrogating a treaty. The Court concluded, however, that because the risk was insufficiently certain, it did not give rise to a state of necessity.141 Around the same time, the question of precaution as authorization was joined in litigation under the WTO Agreement on the Application of Sanitary and Phytosanitary Measures, which requires that WTO members ensure that measures “are based on an assessment . . . of the risks.”142 The U.S. and Canada challenged European prohibitions on importing beef from cows treated with certain growth hormones, arguing that European regulations had not relied on a risk assessment. The European Communities argued on the other hand that “[t]he precautionary principle is . . . a general customary rule of international law” and asserted that it permitted them to rely on the possibility of risk to regulate in advance of a full understanding of the risks of the hormones.143 The Appellate Body concluded that “the precautionary principle does not, by itself . . . relieve a panel from the duty of applying the normal (that is, customary international law) principle of treaty interpretation . . . [and] the precautionary principle does not override the provisions of Articles 5.1 and 5.2 of the SPS Agreement.”144

Courts proved (at least somewhat) more sympathetic to claims that precaution required state action.145 For instance, in the New Zealand v. France146 case before the ICJ, while the court did not reopen its 1974 dismissal of New Zealand’s claim, in a much cited dissent Judge Weeramantry characterized the “precautionary principle” as a rule to help parties who lack sufficient information to show a threat nevertheless to litigate whether an opposing party, who might have greater access to information, has indeed done enough to avert the potential risk.147 The concept of precaution as obligation was also raised in a dispute between Ireland and the U.K. regarding potential radioactive discharge from a mixed oxide (MOX) nuclear reprocessing plant in the U.K.148 Ultimately, the Tribunal gave Ireland some measure of satisfaction by requiring that the U.K. and Ireland continue to exchange further information (although it did not necessarily rely on precaution to do so).149 Thus, to the extent one can detect trends in the interpretation of the precautionary approach during this period, they would favor reading it in the vein of risk as obligation, rather than risk as authorization.

What was clear, however, was that precaution included procedural elements (and did not concern only substance). Thus, for instance, Jacqueline Peel has persuasively argued in favor of precaution as a process providing for the taking into account “of scientific uncertainty in decision-making.”150 Indeed, a number of the litigated cases ultimately resulted in orders to exchange information (this was true of the MOX plant case as well as an ITLOS dispute between Singapore and Malaysia regarding a Singaporean land reclamation project.151). The precautionary approach also operated both in contextual and categorical terms.152

Finally, states also appeared to become increasingly skeptical of risk as authorization for the use of force, at least with respect to the defense of nationals. The theory of defense of nationals dates to the pre-U.N. Charter era153 and its legal underpinnings appear not to have been much considered at the time.154 But in the post-Charter period, there began to be robust debates about when the risk to one’s nationals might justify the use of force on the territory of another state. While the U.S. invoked defense of nationals to justify (at least in part) the use of force in the Dominican Republic, Grenada and Panama,155 and while John Dugard sought to include in the ILC’s draft articles on diplomatic protection a reference to the possibility of using force under limited circumstances to defend nationals,156 states were leery.157

This then was the state of play at the end of the twentieth century—a marrying of due diligence and prevention, which led to the rise of risk as obligation as opposed to authorization, coupled with the ability to see it both as procedural or substantive, something to be considered by category or on a case-by-case basis, and an expanding, but as yet limited, scope. The last fifteen or so years, however, have seen the use of risk truly flower, with risk analysis deployed across a wide variety of fields and in myriad ways. It is to this I turn in the next Section.

IV. The Rise of Risk

In this Section, I describe the role of risk in international law (and soft-law commitments) since 2001.158 That role has increased dramatically, not only in that risk is now used in many ways, but also with respect to risk’s scope of application. In the first Section below, I show how risk has become relevant to new actors, new harms, and new areas of law. In the Section that follows, I describe how risk is now the subject of increasingly sophisticated analysis.

A. New Actor, New Harm

In this Section, I assess in turn two expansions of the role of risk in international law—the first concerning who should undertake risk analysis and the second regarding new types of harm and areas of law to which risk has become legally relevant. Prior to the recent developments I describe here, risk was something states were expected to assess, even where it was the conduct of non-state actors that gave rise to the risk of harm and “harm” was (in the context of environmental law, which was the principal area of law where risk played a role) physical, transboundary harm to (the territory of) another state.159 But as Rebecca Bratspies and Russell Miller note in the introduction to their useful volume on the Trail Smelter case, “[r]edefining ‘harm’ also means confronting new actors and new victims.”160 Thus, for instance, as John Ruggie has said of corporate human rights due diligence, which I discuss in greater detail below, “[human rights impact assessments] should deviate from the [environmental impact assessments] approach of examining a project’s direct impacts, and instead force consideration of how the project could possibly interact with each and every right.”161 In the next two sub-sections, I describe how such an expansion has occurred—covering new actors, new acts, and new victims.

1. New Actors

The first expansion concerns who should undertake risk analysis. Increasingly, there is an international normative expectation that non-state actors will also do so. This is evidenced by the widespread uptake of the U.N. Guiding Principles on Business and Human Rights (GPs),162 which are a non-binding set of guidelines for states and businesses endorsed by the U.N. Human Rights Council and constructed around a “protect, respect, and remedy” framework.163 Under the U.N. GPs, businesses are expected to “respect” human rights. Specifically, Guiding Principle 15 asserts that businesses should have a “human rights due diligence process to identify prevent, mitigate and account for how they address their impacts on human rights,”164 and Guiding Principle 17 recommends that businesses evaluate both actual and “potential human rights impacts.”165 I discuss the substance of human rights due diligence by businesses in greater detail below but suffice it to say that an international expectation that non-state actors themselves undertake risk assessments and seek to prevent harm reflects a dramatic expansion in the role of risk at the international level.

The flip side is that states are also increasingly expected to assess the risk posed by the conduct of a variety of other actors, beyond just private actors on their territory whose conduct may have transboundary effects (that is, the question of ‘risk by whom posed’ now has a more expansive set of answers). First, states are supposed to evaluate the risk that other states, or armed groups with which they may engage extraterritorially, may present. For instance, in the Genocide Convention166 case, the ICJ held that Serbia had a due diligence obligation with regard to the risk of genocide being perpetrated by Bosnian Serb forces, which Serbia was then supporting.167 Perhaps even more broadly, the International Committee of the Red Cross (ICRC) has recently168 adopted a new interpretation of Common Article 1 of the Geneva Conventions to the effect that states have an obligation to “do everything reasonably in their power” to ensure respect for IHL by third parties169 on the basis of risk analysis.170

A similar due diligence principle is also increasingly applied to the risks posed by non-state actors operating around the world where they may have a territorial link to the state but their conduct occurs principally extraterritorially, such as with respect to terrorists, or where their link may be contractual rather than territorial, such as with respect to private security contractors.171 Thus, for instance, there has been considerable debate about whether to consider self-defense against non-state actors under the rubric of attribution (in other words, a state may invoke self-defense to respond to an attack by a non-state actor under circumstances where that attack is attributable to the territorial state, which would require a greater quantum of control by the state over the non-state actor) or under a due-diligence-like rubric (that is, a state may invoke self-defense to respond to an attack by a non-state actor where the territorial state is unable or unwilling to address the threat).172 The latter is increasingly the dominant paradigm,173 and turns on risk (both with respect to expectations of conduct by the territorial state174 and the question of when a state threatened by a non-state actor may exercise its right of self-defense). Likewise, the Montreux Document on Pertinent International Legal Obligations and Good Practices for State Related to Operations of Private Military and Security Companies During Armed Conflict provides that states have an obligation to “take appropriate measures to prevent[ ] any violations of international humanitarian law by personnel of [private military and security companies].”175

With respect to this broader range of actors, risk is relevant both as obligation and as authorization. For instance, due diligence with respect to the conduct of an armed group on a state’s territory involves both risk as obligation and risk as authorization (insofar as if the state is unwilling or unable to suppress a threat, it may give rise to a right of self-defense on the part of another state on that state’s territory176). Risks posed by these various actors may also give rise to both procedural and substantive obligations. Thus, for instance, the Arms Trade Treaty requires risk assessments (procedural) and prohibits transfers (substantive) under certain circumstances.177 And finally, risk may be assessed contextually or categorically. Consider the question of whether certain activities of private security contractors are inherently risky178 or whether certain business conduct should be likewise so considered (such as transactions involving minerals from the Democratic Republic of the Congo).179

2. New Harm

The second expansion is that a risk-based approach is also increasingly being applied to non-physical, territorially-diffuse harms. For instance, a large number of commentators have begun suggesting that due diligence norms be applied to cyberspace.180 While in some cases, cyber activity could produce physical effects that would bring cyber within the realm of what the ILC historically focused upon,181 in many cases cyber activities would not have such effects.182 Moreover, cyber activities also pose challenging questions of geography insofar as their effects may not be transboundary (meaning crossing a border shared by two states) (and cyber activities may transit the territory of uninvolved states).183

This concept of due diligence with respect to cyber activities is increasingly risk-oriented. The Cybercrime Convention reflects a traditional approach to deterring the use of a state’s territory for malicious activities (harkening back to the earlier concept of due diligence)—that is, a requirement to criminalize.184 But an obligation to prosecute—standing alone—may be insufficient.185 Thus, scholars are increasingly focused on strictly preventative measures, such as risk-evaluation procedures186 and notice and consultation provisions.187 And, Beatrice Walton has proposed to import the ILC’s concept of liability for transboundary harm to the world of low-intensity cyber conduct.188

Nor is the debate confined to cyber activities. Some, for instance, have sought to apply due diligence norms to the development and potential deployment of autonomous weapons systems, seeking to analogize to the due diligence standard applicable to ultra-hazardous environmental activities.189

B. Enhanced Obligations and Particularized Risk

In this Section, I make the case that risk has not just propagated to other actors and other topics, but it is increasingly reticulated. That is, obligations that were uncertain (and in particular procedural obligations) have been firmed up; and areas of law that had a risk element have begun to require more detailed risk analyses.

1. Deeper Acceptance of Risk

The first development has been the clarification of uncertain risk-based obligations. While in 2003, Xue Hanqin stated that “it is questionable whether [a duty to undertake environmental impact assessments] can be claimed on the basis of customary international law,”190 matters have advanced considerably since then.191 Indeed, in two recent decisions of the ICJ and a decision of the Seabed Disputes Chamber of the ITLOS, tribunals have asserted such an obligation.192

Not only have the ICJ and ITLOS suggested that environmental impact assessments should be seen as on a sturdier footing,193 they have also given some guidance regarding when in their view such assessments are required, beginning the work of identifying the level of risk that necessitates more careful scrutiny,194 which has further contributed to the firming up of what the ICJ has said is an obligation.195 In Certain Activities and Construction of a Road, the court examined “the nature and magnitude of the project and the context in which it was to be carried out” and concluded that there was a sufficient risk that Costa Rica should have carried out an environmental impact assessment.196 Litigation between Malaysia and Singapore before ITLOS also yielded useful practice on bilateral environmental factfinding,197 especially as prompted by an ITLOS provisional measures order.198 Finally, the South China Sea arbitral award glossed Article 206 of the U.N. Convention on the Law of the Sea in evaluating whether China had in fact carried out an EIA.199 One commentator has argued that the Panel’s emphasis on the importance of a “comprehensive” assessment provides important guidance.200

2. Risk Specificity

The second development has been that even where risk had previously been relevant, the expectation is now that a harder look will be taken at particular risks, in both categorical and contextual analyses.201 This can most clearly be seen in the context of human rights due diligence, both by states and by corporations.

Human rights due diligence has principally developed through instruments and international case law regarding violence against women.202 Early on, the focus was on having the appropriate laws203 and on the need to investigate potential abuses.204 This paralleled the way due diligence was conceived with respect to the protection of foreign nationals. As the then-Special Rapporteur on Violence Against Women said, “the application of the due diligence standard, to date, has . . . [been] limited to responding to violence when it occurs, largely neglecting the obligation to prevent . . . .”205 Likewise, one commentator contrasted the Inter-American Commission’s recent casework with earlier cases, saying that the latter “only explored how the lack of an official investigation violated the victim’s right to judicial remedy and to a fair trial . . . [and not] the State’s obligation to prevent the severe domestic violence.”206

More recently, however, the focus has truly turned to preventing risk, including by analyzing risk more closely. Thus, a 2005 Council of Europe recommendation requested states to “ensure that measures are taken to protect victims effectively against threats and possible acts of revenge.”207 The recommendation went beyond earlier recommendations regarding legislation and gave specificity to calls for the availability of restraining orders, suggesting “enabl[ing] the judiciary to adopt . . . interim measures aimed at protecting the victims, the banning of a perpetrator from contacting, communicating with or approaching the victim, residing in or entering defined areas.”208 Most recently, the Council of Europe adopted a convention on violence against women and domestic violence that includes specific preventive obligations,209 predicated upon risk assessments.210 Likewise, the European Court of Human Rights has recently begun to take this approach211 in, for instance, Opuz v. Turkey.212 While Opuz applied an attribution test turning on knowledge, as Cheryl Hanna has put it, “Opuz provides a useful starting point for framing the affirmative duty to undertake a risk assessment in all cases made known to state authorities.”213 Courts and other bodies have also focused recently on the specifics of laws regarding restraining orders,214 which in effect reflect judicial judgments regarding risk.215 As one commentator has put it, the “evolution in case law . . . [has been moving toward] the theory of foreseeable risk.”216

With respect to corporate human rights due diligence, while the concept is new, and therefore this is not an evolution, the expectation has been similar: that corporations will look at very particular risks. The concept of corporate human rights due diligence has been shaped by analogous domestic law,217 which is decidedly specific. 218 And, this concept of specific due diligence has been replicated at the international level.219 Indeed, one prominent report seeking to gloss due diligence under the U.N. Guiding Principles has specifically argued that “an investigative process must be undertaken for the purpose of preventing harm,”220 including such specific measures as field visits under certain circumstances.221 The same has been true of recent OECD work on the subject.222

V. Reasons for Risk’s Rise and Consequences Thereof

A. Why Risk?

In this Section, I seek to offer potential reasons for the trend I have sought to identify. I offer six such potential reasons. First, as I have sought to show, risk-based obligations may be (and often are) procedural (e.g., a requirement to undertake an environmental impact assessment); if substantive, the obligation is usually one of conduct and not of result (e.g., due diligence). These kinds of obligations are attractive because they permit meaningful legal development without being overly prescriptive. Consider for instance the Security Council resolutions on the DPRK. A requirement to prohibit transactions that are likely to benefit the DPRK’s nuclear and ballistic missile programs is a useful compromise between states with different perspectives: Those states that wish to further constrain the DPRK are able to make incremental progress (insofar as such a provision provides a hook to lobby other states regarding pending transactions with a view to getting them to prohibit them and, in some cases, may provide a domestic legal basis for those states to act); at the same time, such a provision leaves a margin of discretion for states that may be less willing to take significant steps (to the extent those states are prepared to argue that risky transactions are not sufficiently likely to benefit the DPRK’s prohibited programs as to come within the ambit of the resolution). Likewise, where risk plays a role in authorization, it tends to be self-judging, which is appealing to states, especially in the national security space.

Lest this appear too cynical an account, risk can also permit states to “legalize” desirable caution (along the lines of the precautionary approach, but also more broadly). Take, for example, recent developments with respect to proportionality and precautions in the conduct of hostilities. Scholars have increasingly asserted the importance of robust assessments of the risk of civilian casualties223 and the Obama administration issued presidential policy guidance (what one commentator has called “folk law”224), which required that “direct action will be taken only if there is near certainty that the action can be taken without injuring or killing non-combatants.”225 Moreover, whatever one thinks of precaution, it is undoubtedly true that traditional treaty-making may be an imperfect fit for situations where our collective understanding of the problem is subject to rapid change.226 Thus, risk assessment, which is a static principle with dynamic output based on probabilities, may be useful. The bottom line is that risk can be very helpful to policymaking insofar as it can facilitate solving a variety of problems that require carefully calibrated responses.

A second potential reason for the rise of risk may be related to a broader shift toward ex ante compliance rather than ex post reparation (a shift described in part above as well). As Dinah Shelton has pointed out, “[b]reach[es] [today are] unlikely to injure another state directly or give rise to a classic claim for reparations.”227 Part and parcel with this change in the nature of disputes, as she argues, is that we tend increasingly to see ex ante compliance mechanisms.228 Risk fits neatly within that paradigm, both because risk (assessed ex ante) helps to identify situations where non-compliance may occur (before it does) and because it can be harnessed to the broader array of modes of compliance that different bodies are now pioneering (as opposed to more traditional inter-state litigation after the fact). More broadly, at the domestic level, the increasing use of risk assessments has characterized the rise of modern administration, and there is a colorable argument that states are increasingly acting as regulators at the international level (whether through international organizations229 or simply by virtue of the extraterritorial effects that their decisions may have). On this account, risk analysis is increasing because of the kinds of decisions states are now taking, which may also lend themselves to risk analysis.230

Third, a risk-based approach accounts for the multiplicity of actors relevant to international decision-making, both actors potentially involved in causing harm and actors who may be victims of harm. Risk-based norms, of course, better account for the potential harms caused by non-state actors than do state-attribution rules; risk also has a flexible aperture and is readily susceptible to being widened to capture as many or as few as may be desired with respect to the question of whose exposure to risk is relevant.231 In a world where “interdependence . . . has become painfully evident,”232 risk may play a useful role in calibrating the scope of a state’s response to a particular issue. (In fact, the concept of adaptive management, pioneered in environmental law but susceptible of application elsewhere, presupposes that risk assessments may change over time and contemplates a continual process of adjustments.233)

Fourth, a risk-based approach also can facilitate engagement by a broader array of actors with respect to state conduct. Smaller states and civil society are increasingly clamoring to have their voices heard. Thus, for instance, Micronesia recently sought an environmental impact statement from the Czech Republic,234 and civil society is heavily engaged on numerous issues, such as participating in the governance of mechanisms for evaluating and assessing risk presented by particular forms of corporate conduct.235 Risk-based analysis may facilitate such participation. To the extent it is procedural or turns on expertise, states may more readily heed outside inputs. This has certainly been the experience of international environmental law. (To give one example, the Aarhus Convention Compliance Committee has suggested that foreign nationals should be permitted to engage a state’s domestic environmental decision-making.236 And as one commentator has put it, it is undoubtedly the case that “procedure serves to enable, guide and at times even compel interaction between states and other international actors, including non-state actors.”237)

There are a number of reasons why the tandem of risk assessment and greater engagement by outside actors may be appealing for states. “Recent work on the legitimacy of international institutions has highlighted the importance of ‘input legitimacy,’ as well as ‘output legitimacy.’”238 Engagement by non-traditional actors may also produce better results.239 In this regard, many of the arguments made regarding civil society engagement with “global governance” institutions obtain here, too, in that state action increasingly affects a range of actors that the acting state may not represent.240

Fifth, states and other actors have access to much greater amounts of data and may feel confidence in making decisions on the basis of risks they discern from that data. The impact of (and potential hidden problems with) “Big Data” have been discussed in a variety of domestic law areas, from anti-discrimination law241 to policing.242 But states may nevertheless feel like they can harness data to make better-informed decisions at the international level.243 The first turn to risk was prompted by technology244 and risk analysis lends itself to reliance on data because it is essentially an exercise in forecasting. Moreover, grounding a claim in empiricism can amplify its perceived legitimacy. For many, decisions based on data are inherently more trustworthy than those predicated upon other factors, because an empirical approach (it is argued) screens out politics and other preferences that might reduce the likelihood of the “right” decision being taken.245 Indeed, some have argued that risk-based action can help to address a legitimacy deficit in international law for this reason.246 And “concepts of ‘threats’ and ‘risk’ have become closely associated with scientific knowledge.”247

Sixth, use of risk assessments may create greater vertical congruence—that is, between domestic and international approaches. As David Wirth has noted, the “‘internationalization’ of environmental law . . . raised expectations of congruence between the international system and national decision-making procedures.”248 The uptake of environmental impact assessments from the national to the international level is a good example of this phenomenon.249 But the vector can go both ways. Thus, for instance, the regulations implementing the Dodd-Frank provisions on conflict minerals required that companies follow a nationally or internationally recognized due diligence framework, and the OECD’s Due Diligence Guidance was deemed to satisfy this.250

B. Is Risk Risky?

While the prior Section highlighted potential reasons (many of them salutary) for risk’s rise, in this Section, I explore ways in which risk may not be an unalloyed good. To that end, I offer a preliminary assessment of the consequences of the increasing use of risk in international law. At least two sets of questions can be asked: (1) how risk-based decisions can be and are reviewed; and (2) whether risk analysis promotes horizontal harmonization or fragmentation.

The first consequence of the rise of risk is the corollary to a number of the reasons I have adduced for why it has occurred—that is, while risk-based decisions may be easier for external actors to shape, and may have (or be perceived to have) a certain objectivity to the extent decisions are predicated upon assessments of risk (or based on empirics), they may also be less susceptible to judicial review. For one thing, courts tend to be more deferential with respect to procedural law than they are with respect to substantive law.251 Moreover, empirical claims regarding risk are fundamentally difficult to adjudicate. Consider for instance the long-standing and thorny domestic law conversation about how to analyze risks under the National Environmental Policy Act (NEPA),252 including in particular high-impact, low-probability events,253 or the way courts have struggled with scientific evidence. As Robert McCorquodale has asserted with respect to one risk-based area at the international level, “it is difficult to establish a clear standard of business due diligence that is adjudicated by dispute settlement bodies.”254 A further difficulty is that science, which underlies many risk claims, changes quickly, but judgments do not—that is, even if one were able to obtain reliable judgments, would one really want to revisit them every few years if the underpinnings have fallen away?255

These difficulties are compounded before international bodies that tend to be less experienced with—and may have fewer authorities to engage in—rigorous factfinding, which in turn may be necessary for a true evaluation of a risk-based claim.256 Thus, for instance, while there have been some recent positive examples of judicial engagement with scientific questions,257 the ICJ’s treatment of science in the Pulp Mills and Certain Activities and Construction of a Road cases has been roundly criticized. For instance, in Pulp Mills, the court considered an argument that Uruguay was not required to consider remote risks258 and did appear not to delve deeply into certain evidentiary questions.259 Sophie Schiettekatte has summarized that the “ICJ [was] heavily criticized for its deference when it comes to evidence of a highly scientific or technical matters [sic] . . . .”260 Even in the ICJ’s recent decision in the Certain Activities and Construction of a Road cases, which marked a certain amount of progress in my view, Judge ad hoc Dugard expressed concerns261 and Diane Desierto argued that “the Court ultimately remained opaque on the method and criteria it used to assess the degree of ‘risk of transboundary harm’ that would be sufficient to trigger a State’s obligation to conduct an EIA.”262 Moreover, while in theory a ‘public accountability’ mechanism could be effective at the international level, there are significant differences between NEPA practice in the U.S. and international decision-making. For one thing, the Aarhus Convention notwithstanding, those across a border who are affected by potential decisions may have few rights to intervene.263

Second, risk-based law may be unevenly applied, both as a matter of principle and as a matter of practice. This may or may not be a good thing. For instance, risk-based law tends to distinguish between states based on their capacity to detect risk.264 Such differentiation would in the case of human rights, for example, be problematic. Moreover, to the extent that risk assessments disguise underlying value judgments,265 risk-based law may polarize states. Further, the risk threshold remains substantially uncertain. Consider for instance the many standards for when to apply a precautionary approach, ranging from “reasonable scientific plausibility” to “credible” to “non-negligible.”266

States may also simply judge risk in specific cases differently and risk may be a vehicle for biases and exaggerations. Thus, for instance, any number of the disputes to which I have referred in this Article evidence that states may reach different conclusions regarding risk (e.g., whether Japanese fishing plans were hazardous to bluefin tuna stocks). There are also many ways to get risk “wrong” or ways in which individuals’ biases may be manifest in their identification of risks to evaluate.267 This suggests that the possibility that states will increasingly disagree regarding what risk-based law is telling them to do—at least to the extent it is substantive and not only procedural. Moreover, it even suggests that states could invoke risk to overreact to particular phenomena.

VI. Conclusion

In this Article, I have sought to show that risk-based law is on the rise. It has enormous potential to help frame solutions to today’s most difficult problems. That said, there are significant enough differences in the way risk analysis is formulated outside the environmental law area that much work remains to be done if the trend I have identified is truly to bear fruit. This is not just a matter of selecting the right tool from the tool set I have sought to depict—obligation versus authorization, substantive versus procedural, contextual versus categorical. It is also a more specific question about how to construct the risk-based rule.

  • 1. Jacqueline Peel, Science and Risk Regulation in International Law 34 (2010) (“Risk . . . has become a central concern of advanced regulatory states over the last few decades.”); see generally Monika Ambrus et al., Risk and International Law, in Risk and the Regulation of Uncertainty in International Law 1, 5 (Monika Ambrus et al. eds., 2017) (discussing the “dialectical relation between law and uncertainty”); Ulrich Beck, Risk Society: Towards a New Modernity (1992).
  • 9. Cf. Jose Luis Bermudez & Michael S. Pardo, Risk, Uncertainty, and ‘Super Risk’, 29 Notre Dame J.L. Ethics & Pub. Pol’y 471, 473 (2015) (“Decisions under risk involve circumstances in which the probabilities and costs associated with possible outcomes can be quantified; whereas decisions under uncertainty involve circumstances in which the probabilities and costs associated with possible outcomes are not amenable to quantification.”).
  • 10. See Arie Trouwborst, Prevention, Precaution, Logic and Law: The Relationship Between the Precautionary Principle and the Preventative Principle in International Law and Associated Questions, 2 Erasmus L. Rev. 105, 117 (2009). Cf. Glossary, in Understanding Risk: Informing Decisions in a Democratic Society 215–16 (Paul C. Stern & Harvey V. Fineberg eds., 1996) (defining risk).
  • 11. See Nicolas de Sadeleer, Environmental Principles: From Political Slogans to Legal Rules 74–75 (2002).
  • 12. See René Ureña, Risk and Randomness in International Legal Argumentation, 21 Leiden J. Int’l L. 787, 790–91 (2008).
  • 13. See Rosie Cooney & Andrew T.F. Lang, Taking Uncertainty Seriously: Adaptive Governance and International Trade, 18 Eur. J. Int’l L. 523, 525 (2007).
  • 14. Both “known” and “unknown” risk are, however, different from risk in the sense of individualized reasonable suspicion, which I exclude. Reasonable suspicion—and similar such standards—does not turn on the likelihood of a hazard materializing, but rather on whether there is sufficient information to deem that a hazard has materialized (even if it later turns out that it has not).
  • 15. While Professor Nicholas Tsagourias has suggested conceptual differences between risk and threat, he acknowledges that the two are merging in some contexts. See Nicholas Tsagourias, Risk and the Use of Force, in Risk and the Regulation of Uncertainty in International Law, supra note 1, at 13, 15.
  • 16. Compare Matthew C. Waxman, Regulating Resort to Force: Form and Substance of the UN Charter Regime, 24 Eur. J. Int’l L. 151, 157 (2013) (explaining that those who reject “anticipatory self-defense” believe that the “legality of resort to force . . . should operate as an on-off switch, flipped by the manifestation of readily identifiable factual preconditions”), with id. at 158 (explaining that those who support anticipatory self-defense prefer something more akin to a balancing test, one that would include the probability of an anticipated attack materializing and the consequences thereof—in other words, a risk assessment). See also Noam Lubell, The Problem of Imminence in an Uncertain World, in The Oxford Handbook of the Use of Force in International Law, 1, 18–21 (Marc Weller ed., 2014). In a widely-cited paper regarding self-defense against non-state actors, former U.K. Legal Adviser Daniel Bethlehem included “the probability of an attack” among the relevant factors that might justify anticipatory action. Daniel Bethlehem, Principles Relevant to the Scope of a State’s Right of Self-Defense Against an Imminent or Actual Armed Act by Nonstate Actors, 106 Am. J. Int’l L. 1, 6 (2012); see also Brian Egan, International Law, Legal Diplomacy and the Counter-ISIL Campaign, U.S. Dep’t of St. Off. Legal Adviser (Apr. 1, 2016), https://perma.cc/E5D4-295Q.
  • 17. See Pulp Mills on the River Uruguay (Arg. v. Uru.), Judgment, 2010 I.C.J. Rep. 113, ¶ 204 (Apr. 20) [hereinafter Pulp Mills]; Certain Activities Carried Out By Nicaragua in the Border Area (Costa Rica v. Nicar.) and Construction of a Road in Costa Rica Along the San Juan River (Nicar. v. Costa Rica), Judgments, 2015 I.C.J. Rep. 665, ¶ 104 (Dec. 16) [hereinafter Costa Rica v. Nicar.]; Responsibilities and Obligations of States Sponsoring Persons and Entities with Respect to Activities in the Area (Request for Advisory Opinion submitted to the Seabed Disputes Chamber), Case No. 17, Advisory Opinion of Feb. 1, 2011, 11 ITLOS Rep. 10, ¶ 145 (Seabed Disputes Chamber).
  • 18. Trouwborst, Prevention, Precaution, Logic and Law, supra note 10, at 117.
  • 19. Timo Koivurova, Due Diligence, in Max Planck Encyclopedia of International Law ¶ 1 (2010), https://perma.cc/BP2E-A9TM.
  • 20. See id. at ¶ 2 (describing due diligence as focusing on “preventive measures expected of a State”).
  • 21. The precautionary approach, see, for example, U.N. Conference on Environment and Development, Rio Declaration on Environment and Development, U.N. Doc. A/CONF.151/26/Rev.1 (Vol. I), annex I (Aug. 12, 1992) [hereinafter Rio Declaration], is also ever more salient (or at least ever more discussed), although I count that as a form of prevention applicable under conditions of uncertainty. See Arie Trouwborst, Evolution and Status of the Precautionary Principle in International Law 39 (2002) [hereinafter Evolution and Status]; Jacqueline Peel, The Precautionary Principle in Practice: Environmental Decision-Making and Scientific Uncertainty 64 (2005). As Professor Arie Trouwborst has succinctly put it, “[i]f the environmental effects of a particular activity are known, measures to avoid them may be termed preventative. If such effects are uncertain, the same measures may also be labelled precautionary.” Trouwborst, Prevention, Precaution, Logic and Law, supra note 10, at 116. The lack of clarity regarding the precise contours of the precautionary approach, and its principal role (at least in my view) as a decision-making tool rather than an obligation or authorization, makes it however only an ancillary focus of this Article. Where I do address it, I use the terms “precaution” or “precautionary approach” rather than the term “precautionary principle,” although I mean what is often described in the literature as the latter. Cf. Jacqueline Peel, Precaution—A Matter of Principle, Approach or Process?, 5 Melb. J. Intl L. 483, 485 (2004).
  • 22. See, for example, Office of the High Commissioner for Human Rights, Guiding Principles on Business and Human Rights: Implementing the United Nations ‘Respect, Protect and Remedy’ Framework at 18–22, U.N. Doc. HR/PUB/11/04 (2011) [hereinafter Guiding Principles] (asserting the need for human rights due diligence and measures to mitigate risk). I recognize that businesses are not subjects of international law. That said, given the prominence of the U.N. Guiding Principles on Business and Human Rights, I include discussion of how those Principles are being understood and implemented. Cf. Kenneth W. Abbott & Duncan Snidal, Hard and Soft Law in International Governance, 54 Int’l Org. 421, 422 (2000) (discussing the salience of certain non-binding commitments).
  • 23. See, for example, Tallinn Manual on the International Law Applicable to Cyber Warfare 27 (Michael N. Schmitt ed., 2013); Michael N. Schmitt, In Defense of Due Diligence in Cyberspace, 125 Yale L.J. Forum 68, 70 (2015) (“[E]xperts unanimously agreed that states shoulder a due diligence obligation with respect to both government and private cyber infrastructure on, and cyber activities emanating from, their territory.”); David E. Graham, Cyber Threats and the Law of War, 4 J. Nat’l Sec. L. & Pol’y 87, 93–94 (2010); Karine Bannelier-Christakis, Cyber Diligence: A Low-Intensity Due Diligence Principle for Low-Intensity Cyber Operations?, 14 Baltic Y.B. Int’l L. 1, 8 (2014) (“Does due diligence imply an obligation for States to monitor cyber activities on their territory? The answer to this question is positive because, as it will be seen later, due diligence implies not only an obligation to react but also to prevent. Vigilance and monitoring thus go hand in hand.”); Jeffrey T.G. Kelsey, Note, Hacking Into International Humanitarian Law: The Principles of Distinction and Neutrality in the Age of Cyber Warfare, 106 Mich. L. Rev. 1427, 1445 (2008) (arguing that “[t]he international community could adopt such a test to govern cyber warfare: the neutral state could satisfy its duty under IHL as long as it had applied the means at its disposal to detect and repel a belligerent’s incursions”); Beatrice A. Walton, Note, Duties Owed: Low-Intensity Cyber Attacks and Liability for Transboundary Torts in International Law, 126 Yale L. J. 1460, 1502 (2017) (“[W]here attribution to a state is impossible, but attribution to private entities operating within a state’s territory or via infrastructure located in a state is possible, an attack should only give rise to liability if the state failed to act diligently in preventing it. That is, the applicable standard of care imposed upon states in these cases should be due diligence.”); Katharina Ziolkowski, General Principles of International Law as Applicable in Cyberspace, in Peacetime Regime for State Activities in Cyberspace 135, 135, 169 (Katharina Ziolkowsi, ed., 2013) [hereinafter Peacetime Regime]; Daniel Ortner, Comment, Cybercrime and Punishment: The Russian Mafia and Russian Responsibility To Exercise Due Diligence To Prevent Trans-Boundary Cybercrime, 2015 B.Y.U. L. Rev. 177, 208 (2015) (“[T]he government should independently seek to measure and evaluate its progress by conducting impact assessments.”); see also Benedikt Pirker, Territorial Sovereignty and Integrity and the Challenges of Cyberspace, in Peacetime Regime, supra, at 189, 208 (asserting that there “may be a certain minimum standard of control over cyber activities that needs to be respected”). Cf. Joshua E. Kastenberg, Non-Intervention and Neutrality in Cyberspace: An Emerging Principle in the National Practice of International Law, 64 A.F. L. Rev. 43, 47, 56 (2009) (discussing a neutral state’s obligation of due diligence and what a belligerent might do if the neutral state fails to take action).
  • 24. See, for example, International Committee of the Red Cross, Commentary on the First Geneva Convention: Convention (I) for the Amelioration of the Condition of the Wounded and Sick in Armed Forces in the Field 150 (2d ed. 2016) [hereinafter ICRC Revised Commentary] (advancing a new interpretation of Common Article 1 that states have “a general duty of due diligence to prevent and repress breaches of the Conventions by private persons over which a State exercises authority . . . This is an obligation of means, whose content depends on the specific circumstances, in particular the foreseeability of the violations and the State’s knowledge thereof, the gravity of the breach, the means reasonably available to the State and the degree of influence it exercises over the private persons.”).
  • 25. See, for example, S.C. Res. 2094, ¶¶ 11, 15 (Mar. 7, 2013) (requiring states to “prevent the provision of financial services . . . that could contribute to the DPRK’s nuclear or ballistic missile programmes” and not to provide financial support for trade with the DPRK “where such financial support could contribute” to the DPRK’s prohibited programmes or activities); S.C. Res. 2270, ¶¶ 8, 17, 27, 35, 36 (Mar. 2, 2016); S.C. Res. 1929, ¶ 13 (June 9, 2010).
  • 26. Compare Cass R. Sunstein, Laws of Fear: Beyond the Precautionary Principle (2005), with Dan M. Kahan et al., Fear of Democracy: A Cultural Evaluation of Sunstein on Risk, 119 Harv. L. Rev. 1071 (2006) (book review).
  • 27. In this Article, I use the terms “prevention,” “preventive principle” and “preventative principle” interchangeably.
  • 28. For instance, an interesting recent volume on risk in international law addresses a number of topics separately. See Ambrus et al., supra note 1.
  • 29. See Michael N. Schmitt, In Defense of Due Diligence in Cyberspace, 125 Yale L.J.F. 68 (2015). Perhaps the most robust study of due diligence was that conducted by the International Law Association, which formed a study group on the subject that produced two thorough reports: Study Group on Due Diligence in International Law, 76 Int'l L. Ass'n Rep. Conf. 947 (2014) [hereinafter ILA Study Group, First Report]; and Study Group on Due Diligence in International Law, 77 Int'l L. Ass'n Rep. Conf. 1062 (2016) [hereinafter ILA Study Group, Second Report]. Joanna Kulesza’s recent monograph on due diligence is a useful source regarding the ILC’s work, see Joanna Kulesza, Due Diligence in International Law (2016), and Monica Hakimi’s work on state responsibility for the acts of third parties is an excellent and important contribution, see Monica Hakimi, State Bystander Responsibility, 21 Eur. J. Int’l L. 341 (2010).
  • 30. See note 14, supra. This is not to say that there is a stark dichotomy here. Sometimes, a breach of an obligation to prevent a risk may give rise to an authorization on the part of another state to take action. I do not wish to engage debates regarding the relationship between obligations and rights.  Rather, my claim is more descriptive—I classify risk as obligation or authorization based on where the legal focus has tended to lie.
  • 31. See generally Pulp Mills, supra note 17, for distinction between procedural and substantive obligations. Cf. Stefan Talmon, Jus Cogens after Germany v. Italy: Substantive and Procedural Rules Distinguished, 25 Leiden J. Int’l L. 979, 984 (2012) (distinguishing procedural obligations from “procedural rules,” which do not address the lawfulness of the conduct at issue).
  • 32. Two examples are the placement of species on lists, such as Appendix II of the Convention on International Trade in Endangered Species, Appendix II art. (2)(a), Mar. 3, 1973, 27 U.S.T. 1087 [hereinafter CITES], and the identification of specific wastes by the Bamako Convention on the Ban of Import into Africa and the Control of Transboundary Movement and Management of Hazardous Wastes Within Africa, art. 2, Jan. 29, 1991, 30 I.L.M. 773.
  • 33. Cf. Consejo de Desarrollo Economico de Mexicali, AC v. United States, 438 F. Supp. 2d 1207, 1233 (D. Nev. 2006) (“Nothing in NEPA’s language suggests Congress intended NEPA to apply outside United States territory.”), vacated 482 F.3d 1157 (9th Cir. 2007).
  • 59. Cf. Scott Sheeran & Catherine Kent, Protection of Civilians, Responsibility to Protect, and Humanitarian Intervention: Conceptual and Normative Interactions, in Protection of Civilians 29, 56 (Haidi Willmot et al. eds., 2016) (“[W]hile mandates provide a right to use force, whether they imply an obligation as such is unclear.”); Siobhan Wills, International Responsibility for Ensuring the Protection of Civilians, in Protection of Civilians, supra, at 224, 228–31. The U.N.’s human rights due diligence policy is an example of risk giving rise to an obligation in a related area.
  • 60. See U.N. Secretary-General, Rep. of the Panel on United Nations Peace Operations, ¶ 62, U.N. Doc. A/55/305-S/2000/809 (Aug. 21, 2000); see also S.C. Pres. Statement 1999/6 (Feb. 12, 1999).
  • 61. Sheeran & Kent, supra note 59, at 42 (“A critical development in U.N. peacekeeping since the late 1990s has been the inclusion of the use of force to protect civilians as a mission task.”). The first peacekeeping mission to have such a mandate was the U.N. Mission in Sierra Leone in 1999. As of 2016, fourteen missions had such a mandate. Id. at 44.
  • 62. See, for example, S.C. Res. 2295, ¶ 19(c)(1) (June 29, 2016); S.C. Res. 2327, ¶ 7(a)(1) (Dec. 16, 2016); S.C. Res. 2301, ¶ 33(a)(i) (July 26, 2016).
  • 63. S.C. Res. 2295, supra note 62, at ¶ 19(c)(ii).
  • 64. S.C. Res. 2327, supra note 62, at ¶ 7(a)(ii); see also S.C. Res. 2301, supra note 62, at ¶ 33(a)(i) (“To protect . . . at risk communities, while mitigating risks to civilians posed by its military and police operations.”); S.C. Res. 2348, ¶ 34(i)(b) (Mar. 31, 2017) (“[I]dentify[ing] threats to civilians and implement[ing] existing prevention and response plans . . .”) (emphasis added).
  • 65. U.N. Office for the Coordination of Humanitarian Affairs, Framework for Drafting Comprehensive Protection of Civilians (POC) Strategies in UN Peacekeeping Operations, 1 (2011), https://perma.cc/M6VB-QEDX.
  • 66. U.N. Department of Peacekeeping Operations, Department of Field Support, The Protection of Civilians in United Nations Peacekeeping, ¶ 34 (Apr. 1, 2015), https://perma.cc/C73U-YHKX; see also Rep. of the Indep. High-Level Panel on U.N. Peace Operations, Uniting Our Strengths for Peace—Politics, Partnership and People, ¶ 37, U.N. Doc. A/70/95–S/2015/446 (June 17, 2015).
  • 67. S.C. Res. 1973, ¶ 4 (Mar. 17, 2011) (authorizing force “to protect civilians and civilian populated areas under threat of attack in the Libyan Arab Jamahiriya”).
  • 68. U.N. Secretary-General, Identical Letters Dated Feb. 25, 2013 from the Secretary-General Addressed to the President of the General Assembly and to the President of the Security Council, annex I ¶ 2(a), U.N. Doc. A/67775–S/2013/110 (Mar. 5, 2013); id. at ¶ 14(f).
  • 69. S.C. Res. 1975, ¶ 6 (Mar. 30, 2011).
  • 70. Wills, supra note 59, at 230.
  • 71. S.C. Res. 2304, ¶ 10(c) (Aug. 12, 2016).
  • 72. See Koivurova, supra note 19, at ¶ 4 (“[A] State could be held responsible if it was manifestly negligent, i.e. failed to exercise due diligence in trying to prevent, redress or punish the damage to the alien.”). I call it “proto-prevention” since much of the focus was in fact ex post rather than ex ante.
  • 73. In part, this is the story of how due diligence in the context of state responsibility shifted from being a way to attribute conduct to a state to a primary norm of conduct. Cf. Koivurova, supra note 19, at ¶¶ 5–6.
  • 74. ILA Study Group, First Report, supra note 29, at 3 (“During the 19th and 20th centuries, due diligence had particular relevance in the context of the protection of aliens.”).
  • 75. As Justice Moore said in the S.S. Lotus Case, as early as 1927, “[i]t [was] well settled that a State [was] bound to use due diligence to prevent the commission within its dominions of criminal acts against another nation or its people.” The Case of the S.S. Lotus (Fr. v. Turk.), Judgment, 1927 P.C.I.J. (ser. A) No. 10, ¶ 269 (Sept. 7, 1927), https://perma.cc/A9JA-RQRP.
  • 76. As Dr. Robert Barnidge has put it, “[t]he Janes claim [which was based on failure to respond to murders of Americans] ‘may be considered as the prototype.’” Robert P. Barnidge, Jr., The Due Diligence Principle Under International Law, 8 Int’l Community L. Rev. 81, 93 (2006) (citing Janes v. United Mexican States (U.S. v. Mex.), 4 R.IA.A. 82 (1925)) (internal quotation marks omitted). Cf. id. at 94 (labeling this the “nonrepression” theory). See also Clyde Eagleton, Denial of Justice in International Law, 22 Am. J. Int’l L. 538, 540 (1928); F.V. García Amador (Special Rapporteur on State Responsibility), Rep. on International Responsibility, 173, 222, U.N. Doc. A/CN.4/96 (Jan. 20, 1956) (quoting the Sub-Committee report of the League of Nations Committee of Experts for the Progressive Codification of International Law) [hereinafter García Amador, First Rep.]. For instance, the Harvard Draft Convention on Responsibility of States for Damage Done in their Territory to the Person or Property of Foreigners stated that state responsibility may be incurred where the state failed to prevent injury and “local remedies have been exhausted without adequate redress.” Edwin M. Borchard, The Law of Responsibility of States for Damage Done in their Territory to the Person or Property of Foreigners, 23 Am. J. Int’l L. 131, 134 (1929).
  • 77. Kulesza, supra note 29, at 66. Many of the seminal cases of the U.S.-Mexico Claims Commission concerned this kind of “denial of justice.” Edwin M. Borchard, Important Decisions of the Mixed Claims Commission United States and Mexico, 21 Am. J. Int’l L. 516, 521 (1927). For a good example in another context, see Poggioli (It. v. Venez.), 10 R.I.A.A. 669 (1903), in which the umpire concluded that Venezuela was responsible where “the local government failed to take ordinary and necessary precautions and allowed the offenses complained of to go unpunished after becoming known.” Id. at 690. See also Kulesza, supra note 29, at 69 (discussing Poggioli and describing “the inaction of state bodies resulting in a gross denial of justice”).
  • 78. In this regard, I am not fully persuaded by the characterization by the International Law Association that the U.S.-Mexico Claims Commission articulated a set of objective factors to be taken into account in determining the content of the due diligence obligation. ILA Study Group, First Report, supra note 29, at 3.
  • 79. Thus, for instance, in Boyd v. United Mexican States (U.S.-Mex.), 4 Rep. of Int’l Arbitral Awards (1928), the U.S.-Mexico Commission relied in finding Mexico not liable on the fact that only minor crime had occurred before bandits shot and killed an American national, and no complaint of lack of protection had earlier been made to the Mexican government. Id. at 380. That is, under those circumstances, Mexico might not have known of the risk. By contrast, in Chapman v. United Mexican States (U.S.-Mex.), 4 Rep. of Int’l Arbitral Awards 632 (1930), a case where the Commission found Mexico liable, the Commission emphasized that the U.S. national who suffered harm had warned the Mexican government, but no Mexican official “had manifested more than a passing interest.” Id. at 633. Cf. Barnidge, supra note 76, at 96 (discussing a case where “Mexico had knowledge . . . [and how that] likely figured into the General Claims Commission’s calculus in reaching a finding of state responsibility”).
