Does your risk management connect to anything?
The Board puts risk on the agenda; the CEO presents an Excel spreadsheet. The Board discuss in great operational detail just two of them, and the minutes record that risk was reviewed. Six months later, the same spreadsheet comes back, barely changed.
Meanwhile, the CFO is managing cashflow. The Comms team is watching the organisation’s reputation. The Operations team are running procedures that contain multiple risk controls. The actual risk management is scattered across the organisation, largely invisible to the board, and entirely disconnected from the register everyone just reviewed.
Who cares – this kinda works, no? It matters because when unmanaged risk manifests, the only way to manage it is with capacity somewhere in the system. If we haven’t built our policy, strategy, plans, people and processes with this in mind, when risk becomes an issue it overwhelms the organisation.
This isn’t a governance failure in the usual sense. It’s a Stack problem. (If the Stack is new to you, the first article in this series gives the overview.) Risk shows up at every level of the organisation, but the conversations about it are happening at the wrong levels, between the wrong people, in the wrong language.
Where risk lives
Look at the Stack and you’ll find risk appears at three levels, each time doing a different job.
Some of the places risk management shows up in the organisation
At the Enduring level sits the Risk Framework – the mechanisms of governance. This is how the board oversees risk: the register format, reporting requirements, escalation triggers. It’s the scaffolding. Most governance advisors spend a lot of time here, and for good reason; scaffolding is important. But scaffolding isn’t a building.
Bridging Enduring and Strategic sits the Risk Appetite - and this is where most organisations have a gap. The Appetite is a fundamental operating instruction to the Executive. It tells the CEO what risks the board will and won’t accept in pursuit of the organisation’s purpose. Without it, they cannot assess and act on an opportunity or determine where to focus their efforts.
Below that, risk shows up throughout the Operational and Continuous layers in multiple places: in the choice of business model, hiring decisions, how fast you implement a new system, the double sign-off procedure for invoices. These aren’t usually called ‘risk management’, but they are.
Risk Appetite shouldn’t be the runt of the Governance litter
Here’s a board red flag: spending more time developing your Values than your Risk Appetite.
Values are important, but they don’t enable your CEO to determine whether to pursue a partnership, develop a new service model, or shut down a business unit.
A clear Appetite is clarifying. An organisation with a low tolerance for financial risk cannot have an aggressive growth strategy - the two are incompatible. An organisation with a high tolerance for creative risk can build programming around controversy. At the moment a new CEO is being recruited, the Appetite will shape the brief: don’t hire a transformer if your Appetite suggests you need a consolidator.
When the Appetite is absent or vague, every decision at the Operational level becomes a first-principles debate. Leaders often fall back on historic experiences or culturally-built professional standards: ‘my job as CFO is to reduce expenditure’ vs ‘my job as CMO is to spend big to bring in new customers’. No-one’s objectively right or wrong - they have no reference point to work from – so they just stall in a recursive argument.
Board and Executive should stay at their level
The board’s role in risk is not to manage it. That’s the executive’s job. The board’s role is to set the frame within which the executive manages it.
Specifically, the board needs to do three things well. First, design the framework once - the mechanisms, the reporting, the escalation paths. Do this properly and you won’t need to revisit it often. Second, set and maintain the Appetite at the Strategic level. This is the board’s most important risk contribution, and the one most often left undone. Third, at each meeting, review what the executive brings up: the top risks, the current status, anything being escalated. Ask the questions that only the board can ask -- the ones about direction and tolerance, not operational detail.
What it looks like when it works
I worked with a small member organisation last year that was finalising a transition to a CLG structure. Their Risk Appetite, Operational category stated
Would tolerate ‘Unforeseen interruptions in member services due to uncontrollable events for up to 7 days’
Would not tolerate ‘Failure to develop and implement relevant procedures related to the change in organisation status’
In practice this meant the CEO did not over-resource to ensure continuous member services, but placed operational slack into issues around the transition from Association to CLG. Staff were clear that the ringing phone wasn’t a crisis. The Board did not set the CEO a KPI around ‘perfect service’, but they did set a target for completion of procedural development for their new structure.
The Board should not get into the weeds. The risk register is an executive tool. The board reads a summary of it, asks strategic questions about it, and trusts the executive to manage it. When a board spends meeting time debating the likelihood rating on a specific operational risk, it is drifting into operational.
It is difficult. Most directors have built their careers by getting into detail and solving problems. Sitting at the Enduring and Strategic levels, with limited visibility into what’s actually happening below, requires a particular kind of discipline. ‘Noses in, fingers out’ is never more required than with risk, but it can feel like ‘not doing enough’ to a Board.
When my daughter first rode without training wheels, I watched in terror. A broken wrist seemed inevitable. But it’s not good parenting to keep holding the bike - not because the risk isn’t real, but because holding on prevents her from learning to balance.
The board’s job is to set the conditions for the CEO to manage risk well, not to manage it alongside them.
In the next article I’ll look at what happens when the Strategic layer itself is the problem -- when the organisation strategy is either missing or doing a job it wasn’t built for.
First published in Strategy, Applied.