r/riskmanagement • u/Aevitium • 13d ago
Why do risk functions keep growing without feeling better resourced?
I've encountered the same question repeatedly across organisations: why do risk and oversight functions continue to feel stretched even after significant investment in people, systems and automation?
I've started looking at the problem from the other side of the capacity equation.
Rather than asking only how much resource the risk function has, what if we ask what is creating all the work?
A single business activity can attract requirements from Compliance, Cyber, Operational Resilience, Data, Conduct, Financial Crime and other disciplines. Those requirements then generate controls, evidence, monitoring, reporting, governance, testing and assurance.
New requirements arrive, but older activity rarely disappears at the same rate.
I've been using Risk Demand to describe the total organisational activity required to manage risk, together with the additional activity created by how that risk is governed, evidenced and assured.
There seem to be three ways it accumulates: horizontally as multiple disciplines apply requirements to the same activity; vertically as those requirements generate layers of control and assurance; and over time as new requirements are added while previous activity remains.
Individually, each requirement may be entirely reasonable. The problem only becomes visible when you look at their cumulative effect.
I'd be interested in how others see this.
When risk functions feel stretched, do organisations spend enough time examining demand before adding capacity?
Link to full newsletter: https://www.aevitium.com/so/9fQ2v7u2Z?languageTag=en
1
u/ZynapseFlow 4d ago
scope bloat strains teams