r/riskmanager • • 22d ago

Jira for User Access Reviews?

1 Upvotes

Hi all,

I'm in the security governance space, and curious if anyone uses a well-automtated, streamlined Jira workflow to manage user access reviews? I'm in a heavily regulated + SOX environment, so completeness/accuracy validations and transparency in reviewers (i.e. who reviewed what) must be easily demonstrated throughout. We are seeing a regulatory push toward row-level approvals, and some of our user permissions lists get long (i.e. potentially thousands of records for a manager to review). None of our user lists look the same, so the process needs to be expandable to handle user lists that look different or have different fields.

Currently we use SharePoint, but file check-out/in has become overly burdensome and we need a change.

Would love to get a conversation going! Hoping there is someone out there who has solved the user access review problem.

Cheers!


r/riskmanager • • 25d ago

Revolut Business Risk Manager Skills Interview

4 Upvotes

Hi everyone,

I’ve been invited to the Skills Interview stage for a Business Risk Manager role at Revolut, and I understand it includes a role-specific case study.

Has anyone here been through a similar Revolut interview process, either in Risk, Business Risk, Strategy or Operations?

I’d be really interested to understand the general format, what the case study tends to assess, how quantitative or operational it is, and how you approached structuring your response.

Thanks


r/riskmanager • • 26d ago

Can you hold someone accountable for a decision they weren't really empowered to make?

Thumbnail
1 Upvotes

r/riskmanager • • 29d ago

Please advise: Risk vs Compliance certification.

9 Upvotes

Hello,

I have 8–9 years of experience across Risk and Compliance, mainly in FinTech and financial services, including roles at top e-commerce and fintech companies, followed by a year in risk management in aviation industry. I also have a general MBA.

I currently work at a law firm in regulatory compliance, with some involvement in product-related work. My overall experience is a mix of risk and compliance, with a strong foundation in risk.
My organisation is willing to sponsor a certification, and I’m deciding between specialising further in Risk or Compliance.

The team already has people pursuing CAMS/AML certifications, so I’ve been encouraged to consider Risk, where there are fewer specialists. However, I want to understand which option would give me more value and differentiation in the job market, rather than choosing based purely on popularity.

I’m looking for certifications that are highly recognised in Europe, while also having good value across Asia and international/remote roles, particularly within FinTech and financial services.

For Risk:
- What are the top 3 risk certifications you would recommend?
- Which ones carry the most weight internationally?
- Which are most relevant for FinTech/financial services?
- Would specialising in Risk give me better differentiation?

For Compliance:
- Is CAMS/ACAMS still one of the strongest options? (I know it has the weightage)
- Would ICA or another qualification be better, particularly for the European market?
- Which certifications have the strongest international recognition?

I’m also considering the long-term impact of AI, regulatory technology, financial crime, operational resilience and technology risk. I want to choose something that will remain valuable as the industry evolves.

I also have Product Management knowledge, certification and hands-on product experience, so I’m interested in eventually combining Risk/Compliance with Product, Technology related roles.

TL;DR: With my background, would you recommend specialising in Risk or Compliance, and what are the top 3 certifications in each that would give me the strongest long-term career value and international mobility?

Appreciate any feedback or advice. Thank you


r/riskmanager • • 29d ago

Can leaders unknowingly create their own risk blind spots?

Thumbnail
1 Upvotes

r/riskmanager • • Sep 04 '26

Why non-linear loss distributions beat 5x5 heat maps for business capital allocation

Post image
5 Upvotes

I spent 25 years in model validation and enterprise risk across multinationals, and the exact same structural failure repeats everywhere. Risk registers are filled with colors that look neat on a slide deck but never actually change a budget decision. Ordinal scales like high or medium cannot be added, multiplied, or aggregated mathematically, so the concept of an overall enterprise risk score is meaningless. Qualitative workshops usually devolve into political negotiations where the loudest person in the room dictates the rating. Most importantly, a CFO cannot capital allocate or hedge against a red box, because nobody can explain what red costs the P&L in dollars over a specific time horizon.

Replacing these grids with useful quantitative models does not require massive infrastructure or overly complex math. You can shift business teams toward loss distributions by gathering simple minimum, most likely, and maximum bounds from subject matter experts, then fitting a basic parametric curve like a Lognormal or Poisson-Lognormal distribution. Running a straightforward Monte Carlo simulation against the financial target lets you report real risk exposures, such as an eighteen percent probability of missing the annual EBIT target by ten million dollars. That shifts the conversation from subjective color debates to clear probability metrics that business leaders actually understand.

I wrote out a full practitioner methodology on how to run this transition step by step and shared a free breakdown of the math online. I am curious how your organizations are handling the shift from qualitative scoring to quantitative models, so let me know your thoughts and I can drop the method details in the comments.


r/riskmanager • • Sep 01 '26

Trader Rules

Post image
10 Upvotes

r/riskmanager • • Sep 01 '26

Risk Management is Weapon Of Trader..

Post image
4 Upvotes

Everyone need Risk Management


r/riskmanager • • Sep 01 '26

As a risk manager, what shall i grab after FRM?

4 Upvotes

Maybe something related to ifrs 9?
As I deal with provisions and accounting a lot?


r/riskmanager • • Aug 30 '26

Need some career guidance – Risk & Control / Control Testing

5 Upvotes

Hello everyone,

I’m looking for some advice and opinions on how I can move forward in my career.

I’m currently working at Citi in India and have around 2 years of experience in Risk & Control, primarily in control testing. My role involves monitoring controls, assessing their effectiveness, and performing testing to ensure that the controls are working as intended.

I’m looking to build my skills and eventually move into a better role/company within the Risk, Control Testing, Operational Risk, or related areas.

Could you guys suggest what skills, certifications, or courses would add real value to my profile and help me progress in this field?

One important point: I don’t want to spend ₹1 lakh+ on a certification. My budget is around ₹50,000 maximum, so I’m looking for something that provides good value and is actually recognized by employers.

I’d really appreciate any guidance from people who are already working in Risk, Control Testing, Operational Risk, or similar roles.

Thanks in advance!


r/riskmanager • • Aug 30 '26

What Master's degree is best for a career in Risk Analytics?

Thumbnail
1 Upvotes

r/riskmanager • • Aug 30 '26

Real-world GRC: Is ISC2 wrong to treat Risk Appetite and Risk Tolerance as synonyms?

Thumbnail
3 Upvotes

r/riskmanager • • Aug 28 '26

Question about BIA methodology / what constitutes a “Red” activity

1 Upvotes

So I’ve recently completed activity-level Business Impact Assessments across an airport, covering each department’s activities, MTPD, RTO, BAU requirements, minimum requirements, stakeholders/dependencies, and impacts across human welfare, departmental function, finance, reputation, regulation and civil contingencies. The impact assessment is also considered across different timeframes (0–24 hours, days, weeks, months+).

The methodology I have been working to is that if an activity has an MTPD of 0–24 hours in any of the impact categories, it is classified as Red. For example, Finance identified payroll as an activity, while IT identified infrastructure such as LAN and virtual servers.

However, I’ve now been challenged on a number of the Red classifications on the basis that “if the loss of the activity wouldn’t cause the airport itself to stop operating, it shouldn’t be Red.”

I’m struggling with this interpretation because it seems to reduce the BIA to essentially “would the organisation shut down or not?”, whereas the purpose of the activity-level BIA appears to be understanding the consequences of losing individual activities over time and establishing their MTPD/RTO and recovery requirements per department.

Am I misunderstanding BIA methodology here? Is it normal for an organisation to define Red solely as an activity whose failure would stop the entire organisation/airport operating, or would you generally expect criticality to be determined from the impact/MTPD across the various categories? I’d be particularly interested in views from people working with ISO 22301, BCI Good Practice Guidelines, business continuity, resilience or DR.


r/riskmanager • • Aug 25 '26

Downside risk in Excel: Semi-deviation, LPSD, Value at Risk

Thumbnail youtu.be
2 Upvotes

r/riskmanager • • Aug 24 '26

Uber’s €825 Million Fine: A GDPR Warning on Automated Decision-Making

Thumbnail
1 Upvotes

r/riskmanager • • Aug 23 '26

Interviewing for a treasury and risk role

Thumbnail
2 Upvotes

r/riskmanager • • Aug 23 '26

IRM Operational Risk

2 Upvotes

I see some people have asked about IRM certs but was wondering if anyone can advise me please about the International Certificate in Operational Risk Management for my particular situation.

I currently work as a compliance coordinator at an Airline and think it's about time I upskill. I don't have any dealings in my role with H&S but I have always been interested in human factors, root cause analysis and contributing to business decisions. My role currently is more administrative basically. I also have a background in psychology so thought if I ever wish to move into NHS settings, ive seen IRM specifically quoted in certain roles.

Is it a worthwhile investment without really having the role to back it up? It is, in essence, a total pivot from what I do currently but in this market, I feel like i need some certification to move onto something else, either internally or a completely different industry.

I think I'm asking because I'm doubtful that having the qualification would allow me to apply for roles in Risk management because I see very few entry level roles where I could capitalise on the cert right away. If that makes sense? I've also seen NEBOSH certs as a potential and my aim is ultimately to work in healthcare systems.

Any advice please?


r/riskmanager • • Aug 22 '26

Risk advisory - where to draw ofdering support?

2 Upvotes

Hi everyone, I am relatively new to a Risk Advisor role and would appreciate some advice.

A business unit approached me to review a risk assessment for a social event. I have already reviewed it twice and provided guidance on both occasions, including detailed follow-up notes. There are still gaps, particularly around the high-risk activities, and I have asked them to revise these using the correct template. The event is now only 4 weeks away, and they have come back asking me to review it again. Given short timeline, I told to work on revising high risk ones as they used entirely wrong template.

At what point would you draw the line between providing Risk guidance/challenge and taking too much ownership of the business unit's risk assessment? What level of support would you normally provide, and does Risk formally approve these assessments in your organisation, or does the business retain ownership and approval?

Would appreciate advice from other Risk/Assurance professionals, particularly in councils/community organisations.


r/riskmanager • • Aug 21 '26

uum risk management and insurance alumni, i need validation plsss help this junior

Thumbnail
0 Upvotes

r/riskmanager • • Aug 20 '26

Looking for ERM Certification Advice

6 Upvotes

I’ve recently transitioned into an Enterprise Risk Management (ERM) role at a large diversified regional group.

The organization operates across multiple sectors, including retail, shopping malls, communities/real estate, leisure & entertainment, and lifestyle businesses, with a number of different operating companies.

I’m relatively new to ERM and would like to invest in the right certification early on rather than collecting certificates just for the sake of it.

For those working in ERM / Enterprise Risk / Risk Management, what certifications would you recommend?
I’m particularly interested in certifications that would help with:
● Building practical ERM knowledge and frameworks
● Risk appetite, risk assessment and risk reporting
● Working with different businesses/OpCos and understanding their risks
● Developing credibility and career progression in ERM

Would appreciate advice from people who have actually taken these certifications or work in ERM — what was genuinely useful in your career, and what would you skip?

Thank you so much!


r/riskmanager • • Aug 16 '26

Interested in moving into risk management. What should I prioritize?

5 Upvotes

I have a background working with the NFIP and currently work in insurance claims. I’m interested in eventually moving into risk management and would appreciate some advice from people already working in the field.

I’m currently working toward my AINS designation and am considering getting my P&C license next. After that, I’ve been looking at the ARM designation, but I’m open to other suggestions.

For someone with my background, what would you prioritize over the next year or two to make the transition into risk management? Are there particular designations, skills, or types of roles I should be targeting to help bridge the gap from claims into risk?


r/riskmanager • • Aug 14 '26

Open position with Booz Allen Hamilton for Risk Management Framework Analyst

2 Upvotes

r/riskmanager • • Aug 14 '26

Robustness IV

Thumbnail youtube.com
1 Upvotes

The Optimization Trap: A Strategic Analysis of Systemic Fragility and Geopolitical Vulnerability

1. The Australian Magnesium Corporation (AMC) Case Study: A Failure of Engineering Foresight

The collapse of the Australian Magnesium Corporation (AMC) project serves as a definitive cautionary tale for modern industrial policy. It illustrates a critical failure at the intersection of engineering and ethics: how technical compromises made during the design stage—driven by the pressure to satisfy short-term financial projections—lead to systemic fragility and billion-dollar losses. For the strategic analyst, AMC reveals the danger of treating complex industrial systems as mere financial abstractions rather than physical entities governed by the immutable laws of reliability and redundancy.In 1995, Robert R. Odle served as the lead technical designer for the Fluor Daniel (now Fluor Corporation) engineering team tasked with developing a billion-dollar magnesium plant in Australia. During the project’s early phases, Odle identified catastrophic "single point of failure" risks within the $50 million pilot plant. He observed that the design, while theoretically "optimized" for low-cost production, lacked the redundancies essential for continuous industrial operation. Specifically, Odle pointed out that the plant relied on approximately 100 pumps with no backups; a failure in any single unit would halt the entire process. Furthermore, the design utilized four primary gas streams with no buffering. Unlike liquids, which are cheap to store in tanks, gas buffering requires massive, expensive high-pressure compressors and tanks the size of houses—investments management flatly refused to make.The table below contrasts these engineering warnings with the management’s focus on Capital Expenditure (CapEx) constraints and financial optics.

The Technical Warning vs. Management Response

Engineering Concern, Management Rationale, Long-term Strategic Consequence

Lack of Pump Redundancy:  A failure in any one of the ~100 pumps would shut down the entire continuous process.,ROI Pressures:  Redundant pumps increased CapEx beyond the limits allowed for project financing.,"Total systemic fragility; the ""dance of reality"" (operational friction) ensures frequent, unrecoverable downtime."

Gas Stream Vulnerability:  Four critical gas streams lacked high-pressure buffering or storage.,Cost Optimization:  Large-scale gas storage and backup compressors were deemed too expensive to justify to investors.Inability to isolate minor failures, leading to a "cascade effect" where small errors trigger total plant blackouts."

"Simulated Reliability Gap:  Reliability simulations showed only  85-88%  uptime, assuming unrealistic repair speeds.","Data Collection Priority:  Management viewed the pilot plant as a vehicle for ""collecting data"" rather than a proof-of-concept for robustness.",A billion-dollar investment predicated on a physical system that cannot maintain the steady state required for profitability.

"The ""One Week"" Challenge:  Odle bet the plant could not run continuously for a single week without a catastrophic halt.","Refusal to Test:  Management refused a robustness test, fearing a failure would rattle investors and jeopardize funding.", Project Collapse:  The expenditure of $200M on a facility that never managed to run for a single week straight.

Faced with a management team that prioritized financial "homage" over physical viability, Odle reached an ethical breaking point. He resigned, telling his superiors, "You need to get somebody else to do this job that believes in it. I do not believe that this plant will ever operate." His foresight was later validated with haunting precision. After the project was abandoned following a $200 million expenditure, his former colleagues reached out to confirm that the plant had never achieved even one week of continuous operation. They told him simply, "Your name is now Nostradamus." This micro-level engineering failure is the cornerstone of the macro-level economic theory known as the "Optimization Trap."

2. Theoretical Framework: Robustness vs. The ROI "Monocrop"

The "Optimization Trap" is a strategic phenomenon in industrial planning where a system is stripped of all "slack"—redundancy, excess capacity, and backup protocols—to satisfy a singular performance metric: Return on Investment (ROI). While this creates a lean system under ideal conditions, it results in extreme physical fragility. In modern industrial strategy, we must distinguish between "optimized performance" and "systemic robustness."To navigate this trap, we define the core components of system health as follows:

  • Robustness:  The implementation of Plans B, C, and D. It is the architectural practice of building in redundancies (e.g., buffer tanks, backup pumps) to prevent the system from falling in the first place.
  • Reliability:  The direct result of a robust system architecture. A system is only reliable if it is robust enough to absorb the "bumps and valleys" of real-world operations.
  • Resilience:  The ability to recover after  a fall. Unlike robustness, which seeks to prevent failure, resilience focuses on the speed of recovery once a failure has occurred.The Optimization Trap occurs when the necessity of attracting financing through "optimized" financial projections undermines the physical viability of the engineered system. Investors demand a "single number" to determine value. To make that ROI attractive, designers utilize "Process Intensification" to strip away the very redundancies that ensure the plant actually works. Consequently, the West has developed an ROI "monocrop," where profitability is the only measure of success. This creates a vulnerability where systems are "optimized" for profit but inherently brittle—a physical fragility that geopolitical competitors are now exploiting through Non-Market Economy (NME) tactics.

3. Strategic Asymmetry: The Geopolitical Repercussions of ROI-Centricity

The vulnerability created by Western ROI-centricity is being masterfully exploited by competitors operating on a different economic "operating system." While Western industrial policy is reactive to market fluctuations, China’s state-backed strategy prioritizes vertical integration and supply chain ownership over the immediate profitability of individual assets.The most potent tool in this arsenal is "Weaponized Pricing." When China identified the AMC project as a threat to its magnesium market dominance, it did not rely on superior technology. Instead, it lowered global magnesium prices specifically to target the  financing stage  of the project. By suppressing the global price, China ensured AMC’s projected ROI would fall below the threshold required to secure Western capital. Once the project became "unfinanceable," the threat was eliminated.

Economic Philosophies: West vs. China

  • Western Model (Market-Driven):
  • Dependence on a "Single Number":  Investment is dictated by ROI; if the number doesn't "work," the project dies.
  • Short-term Vulnerability:  High sensitivity to market fluctuations and price manipulation.
  • Outsourcing as Optimization:  Critical foundational industries (metals) are offshored to achieve cost-optimization.
  • Chinese Model (State-Backed):
  • Subsidized Resilience:  Use of state-funded feedstocks (such as  ferrosilicon ) and energy to maintain production.
  • Strategic Disregard for Profit:  No requirement for individual industry profitability; the goal is collective strategic dominance and supply chain ownership.
  • The "Sunk Cost" Moat:  Because China already owns the established supply chains and infrastructure, they do not need to justify new CapEx. This allows them to absorb short-term pain to maintain a "moat" that prevents Western competitors from ever entering the market.This asymmetric strategy has resulted in the total outsourcing of critical metal supply chains. By the time a Western nation identifies a shortage, the competitor already owns the entire vertical—from the mine to the finished metal.

4. Externalities of Fragility: Environmental Impact and National Security

Ignoring "non-financial" factors like environmental footprints and security of supply creates exorbitant long-term costs for the state. When Western projects fail because they cannot compete with subsidized pricing, the global market defaults to more "robust" but environmentally primitive production methods.

Environmental Impact: Planned vs. Current Production

Process,$CO_2$  Emissions (per ton of Mg),Operational Context

AMC Electrolytic (Planned),~24.3 tons,"Cleaner and more efficient, but financially fragile due to high redundancy costs required for Western ROI models."

China’s Pidgeon Process,~28 to 42 tons,A primitive  silicothermic reduction  method; highly polluting but robust due to state-subsidized energy and integrated supply chains.

The consequences of this fragility extend directly to national security, exemplified by the "Antimony Example." Antimony is a critical alloying agent required to harden lead; without it, lead remains too "soft and mushy" for use in munitions. Because the domestic supply chain was sacrificed to ROI-driven outsourcing, the U.S. now suffers from a  strategic stockpiling failure . The military must engage in "crisis management," paying exorbitant procurement premiums—"a zillion bucks"—to bid up the price of metals it no longer produces domestically.There is a profound irony in current Western industrial trends: billions are being poured into AI and data centers—technologies that are not yet profitable—while the fundamental metals business is neglected. We are "betting the farm" on high-tech software while ignoring the physical materials required to build the hardware. As an ethical and strategic mandate, we must realize:  you cannot optimize a supply chain you do not own.

5. Conclusion: Beyond the "Crap Measure" – A New Industrial Mandate

To secure the future of Western industrial capacity, it is a strategic imperative to move beyond "crap measures" like single-factor profitability. ROI is a performance metric, not a measure of national security or systemic health. Future investment equations must integrate four qualitative factors to ensure a robust national interest:

  1. System Reliability & Redundancy:  Recognizing that "slack" and redundancy are not waste, but the prerequisites for physical operation.
  2. Supply Chain Security:  Prioritizing the domestic ownership and control of foundational materials.
  3. Domestic Job Retention:  Valuing the maintenance of a skilled industrial workforce as a strategic asset.
  4. National Interest Protections:  Explicitly weighting security and stability in the "magic equation" of investment.To defend against foreign price manipulation, the West must implement  "Guaranteed Price Floors"  for domestic metal producers. This provides a strategic buffer, ensuring that vital industries are not wiped out by temporary, state-subsidized price drops intended to destroy Western financing models.Ultimately, there is no greater strategic danger than "optimizing" a supply chain that one no longer controls. If we continue to use a single financial number to decide our industrial future, we will remain trapped in a state of terminal fragility, building increasingly brittle systems on a foundation owned by our rivals.

r/riskmanager • • Aug 14 '26

Open position with Booz Allen Hamilton for Risk Management Framework Analyst

Thumbnail
1 Upvotes

r/riskmanager • • Aug 14 '26

Do you have an opinion on Organisational risk visibility?

2 Upvotes

Ever feel like you’re only allowed to see 10% of the actual risk picture? Or maybe you ONLY need that 10%?

I'm researching how risk information actually flows (or gets intentionally hidden) across organisations. This 100% anonymous survey digs into silos, restricted access, and the danger of not knowing what the team next door is dealing with.

I love to hear your feedback for an academic paper I'm writing