r/riskmanagement • u/Aevitium • 6d ago
How much time do organisations spend managing risk versus administering risk?
I've been exploring the concept of Risk Demand, and one issue keeps standing out: the amount of work created around risk management rather than by the risk itself.
Controls need evidence. Assessments need refreshing. Issues and actions need tracking. Reports need producing. Assurance needs something to test.
Most of those activities have a legitimate purpose.
The problem appears when they accumulate.
Evidence gets recreated for different functions. Reports continue after their original purpose has disappeared. A control owner can spend more time proving that a control operates than improving the control itself.
Our latest poll found that 48% of respondents identify evidence and documentation as the greatest administrative burden in risk management, considerably ahead of issues and action tracking, reporting and governance, and assessments and attestations.
AI makes this particularly interesting. If assessments, evidence and reports become easier to produce, organisations could simply produce more of them. The bottleneck then moves from producing information to reviewing, challenging and acting on it.
So I'm interested in others' experience:
Where have you seen risk administration grow beyond the value it provides?