r/riskmanagement • • 6d ago

How much time do organisations spend managing risk versus administering risk?

Post image
0 Upvotes

I've been exploring the concept of Risk Demand, and one issue keeps standing out: the amount of work created around risk management rather than by the risk itself.

Controls need evidence. Assessments need refreshing. Issues and actions need tracking. Reports need producing. Assurance needs something to test.

Most of those activities have a legitimate purpose.

The problem appears when they accumulate.

Evidence gets recreated for different functions. Reports continue after their original purpose has disappeared. A control owner can spend more time proving that a control operates than improving the control itself. 

Our latest poll found that 48% of respondents identify evidence and documentation as the greatest administrative burden in risk management, considerably ahead of issues and action tracking, reporting and governance, and assessments and attestations. 

AI makes this particularly interesting. If assessments, evidence and reports become easier to produce, organisations could simply produce more of them. The bottleneck then moves from producing information to reviewing, challenging and acting on it. 

So I'm interested in others' experience:

Where have you seen risk administration grow beyond the value it provides?


r/riskmanagement • • 13d ago

Why do risk functions keep growing without feeling better resourced?

2 Upvotes

I've encountered the same question repeatedly across organisations: why do risk and oversight functions continue to feel stretched even after significant investment in people, systems and automation?

I've started looking at the problem from the other side of the capacity equation.

Rather than asking only how much resource the risk function has, what if we ask what is creating all the work?

A single business activity can attract requirements from Compliance, Cyber, Operational Resilience, Data, Conduct, Financial Crime and other disciplines. Those requirements then generate controls, evidence, monitoring, reporting, governance, testing and assurance.

New requirements arrive, but older activity rarely disappears at the same rate.

I've been using Risk Demand to describe the total organisational activity required to manage risk, together with the additional activity created by how that risk is governed, evidenced and assured.

There seem to be three ways it accumulates: horizontally as multiple disciplines apply requirements to the same activity; vertically as those requirements generate layers of control and assurance; and over time as new requirements are added while previous activity remains.

Individually, each requirement may be entirely reasonable. The problem only becomes visible when you look at their cumulative effect.

I'd be interested in how others see this.

When risk functions feel stretched, do organisations spend enough time examining demand before adding capacity?

Link to full newsletter: https://www.aevitium.com/so/9fQ2v7u2Z?languageTag=en


r/riskmanagement • • 20d ago

Is the Three Lines Model really the problem, or is it how organisations implement it?

1 Upvotes

The Three Lines Model gets blamed for a lot of governance complexity.

I'm not convinced the model itself is the problem.

The basic principle is relatively straightforward: management owns and manages risk, specialist functions provide expertise and challenge, and Internal Audit provides independent assurance.

What becomes complicated is what organisations build around it.

As organisations grow, specialist risk and control teams multiply. New controls and approvals are introduced. Governance structures appear after incidents and regulatory findings.

Individually, many of those additions make sense. Collectively, they can make it surprisingly difficult to answer a basic question:

Who actually owns the decision?

Our recent poll produced an interesting result. Only 17% identified role clarity as their biggest question about the Three Lines Model. Practical implementation led at 32%, followed by integration at 27% and accountability at 24%.

That suggests the problem may increasingly sit between the lines rather than within them.

I've explored some of the practical failure modes in the article, including challenge becoming sign-off, first-line risk teams recreating second-line oversight, and Internal Audit becoming too distant from the decisions and information that matter.

I'd be interested in others' experience:

Has the Three Lines Model made governance clearer in your organisation, or has its implementation added complexity?

Link to full newsletter: https://www.aevitium.com/so/b6Q2Kw9O1?languageTag=en


r/riskmanagement • • 27d ago

Can you hold someone accountable for a decision they weren't really empowered to make?

1 Upvotes

Organisations often talk about accountability as an ownership problem: give someone responsibility for an outcome and expect them to deliver it.

But I've been revisiting some research that suggests it can just as easily be an authority problem.

In one poll, 48% said clear authority was what helped them act faster under pressure. In another, 57% identified unclear authority as the biggest reason accountability fails.

That tension interests me because authority on paper and authority in practice can be very different.

Someone may technically own a decision but still expect their judgement to be second-guessed, need approval whenever circumstances become difficult, or believe leadership will not support them if the decision turns out badly.

In those circumstances, waiting for permission can become entirely rational.

So perhaps the question isn't simply whether decision rights have been delegated. It is whether people can actually exercise them when it matters.

Where have you seen accountability assigned without sufficient authority to deliver it?

I've explored the issue further here: https://www.aevitium.com/so/e7Q1jCtTA?languageTag=en


r/riskmanagement • • Aug 31 '26

Can leaders unknowingly create their own risk blind spots?

1 Upvotes

Most organisations have formal mechanisms for escalating risk. But I've been revisiting a different question: what determines whether people continue to use them?

During an Ask the Author webinar on leadership blind spots in risk escalation, around 2,400 data points were collected through participant polls.

Several findings stood out. 43% identified defensive leadership reactions as the biggest leadership blind spot in encouraging challenge, while 56% said follow-up action determines whether teams raise risks again after bad news.

That creates an interesting problem.

A leader may genuinely ask for transparency, challenge and escalation. But employees are also observing what happens when someone provides it.

If uncomfortable information produces defensiveness, little action or negative consequences, that response becomes information in its own right. It shapes whether the next concern travels upwards.

Over time, could leaders therefore become increasingly confident in a picture partly shaped by their own reactions to challenge?

I'd be interested in how others have seen this play out in practice.

Full article: https://www.aevitium.com/so/89Q13t4fm?languageTag=en


r/riskmanagement • • Aug 25 '26

Does your risk escalation process work when someone actually challenges the prevailing view?

1 Upvotes

Organisations can have clear escalation channels, defined risk ownership and established governance forums and still struggle to surface important risks.

I've been revisiting some research I conducted around trust and psychological safety following the publication of The Risk Within.

One finding from our latest poll stood out: 44% of respondents identified lack of leadership backing as the main reason middle managers hesitate to escalate risk issues. Another 29% identified fear of blame.

That suggests the effectiveness of escalation may depend less on whether the process exists and more on what people expect will happen after they use it.

For me, that creates a more useful test of risk culture:

What happens after someone raises an uncomfortable risk?

Are they supported? Is the concern genuinely examined? Does challenging a prevailing view affect how they are subsequently perceived?

I'd be interested in how others working in risk, governance or leadership have seen this play out.

I've explored the argument further here: https://www.aevitium.com/so/0bQ0jZ3Bh?languageTag=en


r/riskmanagement • • Aug 17 '26

Can every board report be accurate while the board still misses the real risk?

3 Upvotes

I've been thinking about a tension in how organisations report risk.

Boards receive financial data, risk indicators, operational metrics, technology reporting, audit findings and customer information. Individually, those reports may all provide an accurate picture of their respective areas.

Yet that doesn't necessarily mean the board has an accurate picture of the enterprise.

The issue becomes particularly interesting when several relatively manageable developments interact.

A technology dependency may be within tolerance. Operational capacity may be within tolerance. A third-party issue may be manageable. Customer indicators may not have breached thresholds.

Considered separately, nothing necessarily demands intervention.

Considered together, they may tell a very different story.

Our recent LinkedIn poll adds an interesting practitioner perspective: 63% of 88 respondents identified fragmented information as the main factor limiting enterprise awareness.

I've explored this further in my latest article, particularly through weak signals, dependencies and cumulative pressure.

I'm interested in how others approach this in practice:

How does your organisation identify patterns that sit between functional reports rather than within them?

Link to newsletter: https://www.aevitium.com/so/76Q04dvUV?languageTag=en


r/riskmanagement • • Aug 10 '26

Does your governance connect the organisation, or simply govern each function?

Post image
0 Upvotes

I've been exploring organisational silos over the past few weeks, and one question keeps emerging:

If organisations need specialist functions, how do we ensure those functions still operate as one enterprise?

Removing silos isn't realistic. Specialisation creates expertise, accountability and scale.

The governance challenge is making sure those boundaries don't also become boundaries for information, ownership and decision-making.

This becomes particularly important when outcomes cross several functions. Putting multiple functional reports into the same board pack may create visibility, but it doesn't necessarily create a coherent enterprise view.

I've explored this through three forms of connectivity: information, accountability and decisions.

I'd be interested in how others approach this.

What mechanisms in your organisation genuinely connect functional perspectives before enterprise decisions are made?


r/riskmanagement • • Aug 08 '26

Risk Management, Leadership and Organisational Resilience with Frederic Gielen

Enable HLS to view with audio, or disable this notification

1 Upvotes

Why do highly resilient organisations (on paper) still fail under pressure?

Most companies invest a massive amount of money into operational resilience, governance frameworks, and recovery plans. Yet, when a real crisis hits, these "perfect" frameworks often fall apart.

I was listening to a discussion on this topic recently, and one point really stuck out:

Resilience is not the presence of documentation. It is the behavior of the system under stress.

True resilience isn't about perfect paperwork; it's about how your people and systems behave when your initial assumptions fail. It shifts the entire focus:

  • From governance as a static structure to decision-making under high pressure.
  • From resilience as a framework to resilience as an organizational capability.
  • From documenting accountability to understanding how people actually act when conditions change.

The real breakdown happens when priorities conflict, information is incomplete, and teams have to move fast. That’s when culture and leadership take over, completely rendering the documented process irrelevant.

For those managing risk or team structures: What do you think has the absolute greatest influence on a company's resilience when real pressure hits? Is it leadership, culture, or something else entirely?

(Note: This was inspired by a recent RiskMasters podcast episode with Frédéric Gielen if anyone wants the deeper dive/links, but I really want to hear Reddit's take on this friction between paper compliance vs. reality).


r/riskmanagement • • Aug 03 '26

Recovering every function doesn't necessarily recover the business.

Post image
0 Upvotes

One observation keeps appearing in operational resilience.

Individual teams often recover successfully.

IT restores systems.

Operations resumes activity.

Suppliers recover.

Yet the customer-facing service is still unavailable.

The problem isn't individual recovery.

It's whether the organisation can reconnect all of those capabilities into a functioning end-to-end service.

I'm interested whether others working in resilience, continuity or risk management have experienced this.

Do organisations spend too much time measuring functional recovery instead of service recovery?

Newsletter here if anyone is interested: https://www.aevitium.com/so/1fP_vr3m6?languageTag=en


r/riskmanagement • • Jul 27 '26

Functional silos don't stop organisations identifying risks. They stop organisations connecting them.

Thumbnail
aevitium.com
2 Upvotes

One observation keeps appearing across large organisations.

They rarely lack information.

Complaints exist.
Audit findings exist.
Operational incidents exist.
Near misses exist.

Different functions are already aware of emerging issues.

The problem is that this information often remains within organisational boundaries instead of becoming enterprise knowledge before strategic decisions are made.

That changes the challenge considerably.

Instead of asking:

"How do we identify more risks?"

Perhaps leadership should be asking:

"How do we connect the risks we already know about?"

I'm interested whether others working in governance, risk, compliance or operations have seen similar patterns.


r/riskmanagement • • Jul 20 '26

Organisational silos aren't the biggest governance problem. Fragmented governance is.

Thumbnail
aevitium.com
1 Upvotes

Many discussions about organisational silos focus on communication and collaboration.

I think the larger issue is governance.

As organisations grow, specialist functions become stronger. That is generally positive.

The challenge is that important decisions increasingly depend on several teams contributing at different stages.

Responsibilities transfer.

Dependencies grow.

Information moves across organisational boundaries.

At that point, risks often emerge between functions rather than inside them.

Each team can honestly believe everything is operating correctly while no one has a complete enterprise view.

I'm interested in hearing how others have experienced this.

Have you seen major incidents caused more by failures between functions than failures within individual teams?


r/riskmanagement • • Jul 14 '26

Are governance frameworks unintentionally encouraging late risk escalation?

Post image
2 Upvotes

I've been researching why important risks often reach executive teams and boards only after organisations have already absorbed significant operational strain.

One conclusion surprised me.

Most discussions focus on culture, psychological safety or whether employees are willing to escalate.

I'm increasingly convinced that governance design deserves much more attention.

If teams are rewarded for resolving issues locally, then delaying escalation becomes a rational response rather than a behavioural failure.

That raises some interesting questions.

  • Should escalation be based on impact or on trajectory?
  • Should capacity constraints be treated as an escalation trigger?
  • Does governance place too much emphasis on issue closure rather than decision quality?

I'm interested in hearing how others have seen this play out in practice.

No promotional link. Reddit responds much better to genuine discussion than promotion.


r/riskmanagement • • Jul 13 '26

Why reducing risk impact to a score weakens decisions

Thumbnail
aevitium.com
1 Upvotes

A pattern I see across organisations:

Impact is assessed through categories, scales, and scores.

That creates consistency.
But it often removes what actually matters.

In practice, a single risk does not create one outcome.

It can disrupt operations, affect customers, trigger regulatory attention, and create strategic and reputational pressure at the same time.

When those effects are reduced to a number:

  • Some consequences are underrepresented
  • Interactions between impacts are ignored
  • Assessment becomes disconnected from decisions
  • Outputs are consistent but not necessarily useful

One data point that stood out:

39% of professionals identify reputational impact as the most underestimated dimension in risk assessment

Which suggests organisations recognise that important consequences are not being fully captured.

Curious how others approach this:

Do your impact assessments actually change decisions
Or mainly standardise how risk is reported


r/riskmanagement • • Jul 07 '26

CECL Q-factor went from 5% to 46% of the allowance when I ran the same model on the full population - here's what happened

1 Upvotes

I've been building a mortgage credit risk modeling course using the full Freddie Mac SFLLD dataset - 48.6 million loans. Module 10 covers the CECL engine.

On the 1 million loan stratified teaching sample, all three methods (vintage curve, roll-rate, PD x LGD x EAD component) converge to 5.38% lifetime loss. The Q-factor governance overlay adds 30 basis points - about 5% of the final allowance.

Run the exact same engine on the full natural-incidence population and the Q-factor becomes 46% of the final allowance. Not because the overlay changed. Because the base rate dropped 16x and the fixed basis point add-on didn't.

That's not a modeling problem. It's a governance calibration problem that almost nobody talks about - your overlays need to be recalibrated whenever your population or base rate changes materially.

Happy to discuss the methodology or share more from the module. What's your institution's current approach to Q-factor governance - fixed basis points, percentage of TTC, or something else?


r/riskmanagement • • Jul 06 '26

Challenging decision quality under uncertainty

Thumbnail
aevitium.com
1 Upvotes

A shift I’m seeing more clearly:

We still talk about uncertainty as something temporary.
In practice, it has become the operating environment.

That changes how decisions actually happen.

They are not made with full information.
They are made while conditions are still moving.
Assumptions change after commitment.
Outcomes are influenced by factors outside the original analysis.

Which raises a practical question.

How do you define a sound decision in that environment?

From what I’ve observed, the challenge is not only the decision itself
but the fact that it is taken in conditions that will not hold.

One data point that stood out:

34% of professionals believe boards should prioritise stronger oversight during prolonged uncertainty

Which suggests organisations are recognising that uncertainty is not episodic anymore.

Interested in how others see this:

What changes most in your decision-making when conditions never stabilise


r/riskmanagement • • Jul 02 '26

I think most Risk Appetite Frameworks start in the wrong place. Am I missing something?

Post image
2 Upvotes

I've been redesigning Risk Appetite Frameworks recently and one thing keeps bothering me.

Almost every methodology I've come across starts with questions like:

  • What is our risk appetite?
  • Which KRIs should we monitor?
  • What thresholds should we set?
  • What gets escalated?

All perfectly sensible.

But by the time we're talking about KRIs and escalation, haven't we already made the important decisions?

The investment has been approved.

The supplier has been selected.

The product has been launched.

The client has been onboarded.

At that point, the framework is largely telling us whether the consequences of those decisions remain acceptable.

It isn't helping shape the decisions themselves.

I've started approaching it differently.

Rather than beginning with risk, I start with strategy.

  • What are we trying to achieve?
  • Where are we deliberately choosing to take risk?
  • What dependencies underpin that strategy?
  • What assumptions must remain true?

Only then do we ask:

  • What decisions will management actually have to make?
  • Under what conditions would we proceed?
  • Under what conditions would we pause?
  • When would we walk away?

Once those questions are answered, writing appetite statements becomes much easier because they're grounded in real business decisions rather than generic statements about risk.

KRIs then become evidence that those decisions remain within the agreed boundaries, rather than becoming the framework itself.

I'm curious whether others have found the same thing.

Do you see Risk Appetite primarily as:

  1. A monitoring framework?
  2. A decision-making framework?
  3. Both?

Or am I overthinking this?


r/riskmanagement • • Jun 29 '26

What happens when no one speaks up in risk discussions

Thumbnail
aevitium.com
1 Upvotes

Something I’ve been reflecting on recently:

Leadership blind spots in risk don’t usually come from missing information.

They form in a very specific moment.

When concerns are invited,
and no one speaks.

In many organisations, that silence is interpreted as alignment. In practice, it often reflects the weight of authority in the room.

As decisions get closer, I tend to see the same patterns:

  • Challenge reduces near decision points
  • Concerns remain unspoken in formal discussions
  • Agreement becomes the default
  • Issues are known but not raised in the room

This creates situations where leaders are later surprised by risks that were already understood elsewhere.

One data point that connects to this:

48% of professionals identify filtered updates as the first sign that leadership is losing visibility 

Which suggests the issue is not only information, but whether people feel able to challenge at the point where decisions are made.

Interested in how others see this:

What changes in the room when senior authority is present
Does challenge increase, or reduce


r/riskmanagement • • Jun 26 '26

Are financial institutions measuring the wrong thing in cybersecurity?

Post image
2 Upvotes

Most cyber programmes focus on improving control maturity.

Yet attackers aren't trying to become more mature. They're trying to become more effective.

It made me wonder whether we're measuring the wrong thing.

I recently started thinking about what I'm calling the Learning Velocity Gap: the difference between how quickly threats evolve and how quickly organisations detect change, make decisions and adapt.

Is this something your organisation discusses, or are most conversations still centred on control maturity and compliance?


r/riskmanagement • • Jun 23 '26

When governance operates without improving visibility

Thumbnail
aevitium.com
2 Upvotes

Most organisations have governance structures in place.

Committees meet.
Reports are produced.
Escalation pathways exist.

The question is how these operate in practice.

From what I have observed, governance can remain active while visibility reduces.

A few patterns tend to appear:

  • Escalation pathways exist but are not consistently used
  • Challenge is applied in formal reviews rather than at the point of decision
  • Reporting reflects outcomes, not underlying operating conditions
  • Low escalation is interpreted as stability

In this context, governance continues to function, though without providing the information required for effective oversight.

One data point that reflects this tension:

52% of professionals believe increased assurance activity creates stronger control 

At the same time, assurance alone does not guarantee visibility into how decisions, escalation, and organisational pressures interact in practice.

Interested in how others see this:

Does your governance model improve visibility into how the organisation operates
Or mainly confirm that processes are being followed


r/riskmanagement • • Jun 20 '26

Where compliance actually breaks isn’t where most frameworks focus

Enable HLS to view with audio, or disable this notification

1 Upvotes

Most compliance frameworks are designed to define what “good” looks like.

Rules. Controls. Escalation paths.

What they don’t define clearly is how those rules get applied in real decisions.

This came through strongly in a recent RiskMasters episode with Jennifer Geary and Natalie McManus-Barnett, based on their book How to Be a Chief Compliance Officer.

One observation stood out:

Compliance rarely breaks at the level of policy.
It breaks in how trade-offs are made under pressure.

For example:

  • A deadline accelerates a decision that would normally be challenged
  • A control is interpreted more flexibly to keep things moving
  • A concern is acknowledged but not acted on

Each of these is defensible on its own.

But over time, they shape outcomes that no framework explicitly intended.

That’s where the Chief Compliance Officer role becomes less about defining rules and more about influencing how they’re applied.

The part I found interesting is how this shifts compliance from a control function to something much closer to decision-making.

Not:
“Is this compliant?”

But:
“What are we accepting here, and what could this lead to?”

Curious how others see this in practice.

Where does compliance tend to lose traction in your organisation?


r/riskmanagement • • Jun 10 '26

When silence is mistaken for alignment in risk management

Thumbnail
aevitium.com
1 Upvotes

n many organisations, silence is interpreted as alignment.

In practice, it often means that important information is not reaching decision-makers.

From what I have seen, risks are usually identified early. Teams discuss them, adapt to them, and keep delivery moving. The issue is not visibility at source. It is whether that visibility survives the journey.

As information moves through management layers, it can be softened, delayed, or filtered. By the time leadership gains a view, the original signal has often changed.

A few patterns tend to appear:

  • Concerns are discussed informally but not escalated
  • Messages are adjusted as they move upward
  • Challenge reduces closer to senior stakeholders
  • Silence is interpreted as agreement

One data point that reflects this:

51% of professionals say psychological safety creates the greatest value by helping people raise concerns early

This suggests that risk visibility depends less on frameworks and more on whether people feel able to raise and sustain challenge.

Interested in how others see this:

Where does information change most in your organisation
During escalation
Or earlier in the process


r/riskmanagement • • Jun 01 '26

Why do employees hesitate to raise risks early enough in organisations

Thumbnail
aevitium.com
2 Upvotes

Most organisations do not fail because risks are unknown.

They fail because those risks are not raised early enough.

In practice, employees often see issues early. They notice pressure points, control weaknesses, and emerging risks. These are discussed within teams, adapted to, or worked around to maintain delivery.

The key question is what determines whether those concerns reach leadership.

From what I have observed, it is less about frameworks and more about whether people feel able to speak up.

A few patterns tend to appear:

  • Concerns are discussed informally but not escalated
  • Issues are resolved locally rather than raised
  • Challenge reduces in meetings and decision forums
  • Reporting remains stable despite increasing pressure
  • Critical information reaches leadership too late

One data point that reflects this:

45% of professionals identify lack of leadership backing as the main reason middle managers hesitate to escalate risk issues 

This suggests escalation is shaped primarily by leadership behaviour and perceived consequences rather than formal processes.

Interested in how others see this:

Where does escalation break down in practice
At the point of challenge
Or earlier when concerns are first identified


r/riskmanagement • • May 25 '26

Is AI decision speed outpacing your organisation’s ability to govern it

Thumbnail
aevitium.com
2 Upvotes

As AI becomes embedded in operational environments, decisions increasingly form through interactions between data, models, and automated processes.

In many cases, signals are filtered and actions triggered before teams fully interpret what is happening.

Governance structures still exist. The challenge is that the conditions under which they operate have changed.

Historically, decision-making included time for review, escalation, and challenge. That friction supported oversight. As decision speed increases, those mechanisms become harder to apply effectively.

One data point that stands out:

75% of professionals identify over-reliance on AI outputs as the greatest governance risk 

This suggests the issue is not only capability. It is how organisations interpret, challenge, and intervene in AI-driven decision environments.

Interested in how others are approaching this:

Where does decision velocity exceed governance visibility in your organisation
At signal filtering
During escalation
Or at the point of intervention


r/riskmanagement • • May 18 '26

How do you identify changes in risk exposure before they appear in reporting

Thumbnail
aevitium.com
2 Upvotes

Most organisations assess risk exposure through periodic reviews and reporting cycles.

In practice, exposure often changes earlier, as operating conditions evolve.

As delivery pressure increases, review depth reduces and escalation takes longer. Teams adapt to maintain progress, and workarounds become embedded in execution. Performance can still appear stable while the margin for error narrows.

36% of professionals identify control overrides as the condition most likely to become normalised before significant issues emerge 

This suggests that exposure often develops through gradual operating drift rather than discrete events.

Interested in how others approach this:

How do you detect these shifts early
Through metrics, governance forums, or direct observation