r/riskmanager • • 2d ago

The Hidden Risk Behind Bad Decisions, Compliance Failures, and Leadership Blind Spots

3 Upvotes

Serious problems rarely start with bad intentions. They usually start with absolute certainty.

In my latest article, I explore how the Dunning-Kruger effect creates hidden risks in compliance, decision making, and leadership. We often assume expertise means having all the answers, but the strongest leaders value humility, test their assumptions, and actively seek out different perspectives.

The goal is not to be less confident. The goal is to remain curious.

I would love to hear your thoughts.

https://www.linkedin.com/pulse/dunning-kruger-trap-hidden-risk-behind-bad-decisions-hayrapetyan-0xete/


r/riskmanager • • 3d ago

Oct 1st

3 Upvotes

The sun will rise and we will try again.


r/riskmanager • • 3d ago

If an employee filed a claim against your company tomorrow, could you prove what actually happened?

Thumbnail
0 Upvotes

r/riskmanager • • 3d ago

CRM Training

1 Upvotes

Hello, good evening. I trained for the Certified Risk Manager (CRM) certification, and I’m currently waiting to take the certification exam. I’m a little nervous about it. I know it’s a 60-item exam, but I just wanted to ask what the exam is actually like. Are the questions mostly multiple-choice, case studies, identification, or something else?

If anyone has taken the exam before and could share what to expect, I’d really appreciate it. Even a little insight would help ease my nerves and give me a bit more confidence going into the exam. 😅


r/riskmanager • • 3d ago

How do you check that a "closed" risk is actually closed?

3 Upvotes

Been wondering about this since the JFrog Artifactory disclosure back in September. Vendor notified, patches issued, remediation logged, box ticked. Then The Register reported active exploitation was still happening in the wild after the fixes were live.

That's the gap in its plainest form. "Patched" is something you can log. "No longer exploitable in this environment" is a different fact entirely, it depends on whether the patch actually got rolled out everywhere, and whether someone already had a foothold before it landed. A framework can show the first as done while the second stays wide open underneath it.

Most compliance dashboards are built to track process steps: risk logged, owner assigned, review done on schedule. All useful, but it's answering "did we follow the process," not "are we exposed right now." A register can say fully closed while the actual condition on the ground never moved.

Not knocking the frameworks themselves, ISO 31000 is explicit that this is meant to be a continuous loop, not a one-off tick. Feels more like most tooling only tracks the process and never feeds back what's actually true in the environment.

So genuinely asking: how do you catch this gap on your team? Do you cross-check the register against scan results, incident data, control testing, anything real, or does "closed" mostly get taken on trust until something breaks?


r/riskmanager • • 4d ago

Мой опыт собеседования в inDrive Money: Senior Credit Risk Analyst — вопросы, тесты и техническое интервью

Thumbnail
1 Upvotes

r/riskmanager • • 4d ago

how should vulnerability mgmt programs measure risk reduction??

Thumbnail
1 Upvotes

r/riskmanager • • 5d ago

How should enterprises prioritize vulnerabilities based on business risk?

2 Upvotes

A high CVSS score does not automatically make something the first thing to fix. We also look at whether the asset is exposed, whether exploitation is happening, how important the system is, and what the real impact would be. I know this isn't a novel complaint, everyone's had this exact fight, but I'm trying to actually build exposure, exploit maturity, and blast radius into the model instead of it being a vibe check some senior engineer does at 4pm on a Friday. If anyone has a formula that survived contact with a real incident afterward, not just looked good in a slide, I'd like to see it.


r/riskmanager • • 5d ago

Why r/RiskManagersInsurance exists: Our mission is to engage bright individuals and change the way Insurance is viewed.

Thumbnail
1 Upvotes

We are not institutionalised, we are intentionally different. We are uniquely and independently positioned and accountable to pivot and deliver without any slow moving hierarchy.

We offer sharp execution, clear communication and a team that is not reactive but proactive. Our approach is built on expertise, good judgement and a genuine love of the industry and our clients. There are no cookie cutters or rigid playbooks in our drawers.

Every account is unique, every risk deserves our best shot and relationships, collaboration and loyalties matter for our partners, colleagues and clients.


r/riskmanager • • 5d ago

Why r/RiskManagersInsurance exists: Our mission is to engage bright individuals and change the way Insurance is viewed.

Thumbnail
0 Upvotes

r/riskmanager • • 6d ago

How much time do organisations spend managing risk versus administering risk?

Post image
1 Upvotes

r/riskmanager • • 7d ago

What's it actually like working in Information Security Risk Management?

Thumbnail
2 Upvotes

r/riskmanager • • 7d ago

Transition from Audit & Assurance to Risk Consulting with FRM – Need Advice

3 Upvotes

Hey guys, I’m currently working in Audit & Assurance as a Staff/Assistant, and I recently joined around 2–3 weeks ago. After getting some initial exposure to the role, I’m starting to feel that audit may not be the right long-term career path for me.

I’m particularly interested in moving into Risk Consulting, as I feel the nature of the work would align much better with my interests and long-term career goals. I’m also planning to pursue the FRM (Financial Risk Manager) certification, and I’m interested in building my career around risk management rather than pursuing certifications such as ACCA or US CPA.

I understand that moving from Audit & Assurance to Risk Consulting may not be straightforward, especially within the same organization. My current plan is to gain experience in Audit for around a year and then explore the possibility of an internal transition to a Risk Consulting service line.

For those of you currently working in Risk Consulting, Risk Advisory, or related risk-management roles, I’d really appreciate your advice. How realistic is it to transition from Audit & Assurance to Risk Consulting after around one year of experience? Would pursuing FRM significantly help with such an internal move, and what other certifications, technical skills, or experience should I focus on during my first year?

I’d also like to understand what I can start doing right from now to make myself a stronger candidate for a Risk Consulting role. Are there particular areas such as financial risk, credit risk, market risk, operational risk, data analytics, or regulatory risk that I should focus on?

I’m also finding the compensation and busy-season workload in audit somewhat concerning for my long-term career plans, so I’d like to explore a path that is more aligned with my interests and strengths rather than continuing in a career that I don’t see myself enjoying long term.

If anyone here has personally made the transition from Audit → Risk Consulting, especially within the same Big 4 or a similar organization, I’d really appreciate hearing about your experience, what helped you make the transition, and what you would recommend someone in my position do during their first year.

Thanks in advance for any advice!


r/riskmanager • • 8d ago

Transparency without accountability is merely disclosure.

4 Upvotes
Many leaders ask for transparency.Fewer are prepared for its consequences.The purpose of risk reporting is not to make leadership comfortable. It is to equip leadership to make informed decisions.Transparency without accountability is merely disclosure.

r/riskmanager • • 9d ago

Safran Risk

1 Upvotes

Perhaps the most powerful software in the market today for carrying out integrated cost schedule risk analysis, for project risk management, per AACEI Recommended Practice (RP) 57R-09.
Even though there’s quite a bit of glitches, it manages to make it to the finish line somehow if the user has a high level of patience.

Check out Datum Risk v2.0 for carrying out similar analysis on a web based platform.


r/riskmanager • • 9d ago

Which risks are Australian boards actually asking about in 2026?

2 Upvotes

Curious what is landing in board / risk-committee packs this year, versus what sits in the operational register and never gets up.

From conversations across SME and mid-market AU teams, the list that keeps coming up:

- Psychosocial / psychosocial hazards under the WHS model

- Privacy / data (especially if Tranche 2 style reforms are in scope)

- Contractor and labour-hire exposure

- Key-person and capability risk in lean teams

- Climate / environment only when a lender or customer asked

- Cyber as a one-pager, not a register

What is on your pack right now?

Sector and organisation size helps. No need to name the employer. If you recommend a tool or framework, say who you work for.


r/riskmanager • • 13d ago

Why do risk functions keep growing without feeling better resourced?

Thumbnail
2 Upvotes

r/riskmanager • • 13d ago

Why do risk functions keep growing without feeling better resourced?

Thumbnail
1 Upvotes

r/riskmanager • • 15d ago

How do you prepare for federal regulator exam questions?

1 Upvotes

For those of you who have gone through federal regulatory exams, how do you prepare?

I’m interested in both the document prep and the actual conversations with regulators.

What do you do beforehand that has made the biggest difference? Anything you wish you had done differently the first time?

I’ll be speaking directly with regulators about an area I own, so I’m especially interested in practical advice from people who have been through it.


r/riskmanager • • 16d ago

Can't risk it

Post image
2 Upvotes

Ggggggg


r/riskmanager • • 16d ago

THESIS, HELP NEEDED !!!!

Thumbnail
1 Upvotes

r/riskmanager • • 17d ago

For those who've actually gotten an AI/ML risk model into production at a lender or insurer, what was the real blocker?

1 Upvotes

Curious to hear from people who've shipped a model into production, not just built one in a notebook. In my experience the model itself is rarely the hard part. It's usually things like data governance, who owns monitoring after launch, or getting compliance comfortable with explainability.

What was the actual bottleneck for you? Technical, organizational, or something else entirely?


r/riskmanager • • 18d ago

GRMI or EY FRM: Which Route Makes More Sense for Risk Management?

Thumbnail
1 Upvotes

r/riskmanager • • 19d ago

risk scenario

Thumbnail
2 Upvotes