Useless Risk Management Edifices that Organisations Build

Norman Marks in his blog post called "Time to wake up to risk reality" said that "This is a post about news we should have known for a long time.
It’s time to recognize the truth about risk management." 

Hans Læssøe commented that: "I guess too many companies have a risk management function only for the sake of being able to say, that they have it – and to produce reports that shows “we are doing well”. Executives had (and have) no intention of letting risk people involve themselves or tamper with decisions they are making or how they execute/operate."

Roger responded as below.


Your first paragraph (3 April) makes an astute observation. The essentially useless ‘risk management’ edifices that organisations build, play no meaningful role in assisting the daily task of making sound decisions – from top to bottom. (I put ‘risk management’ in inverted commas, incidentally, because although the expression is common, there is little that is common across all its users as to what it means or consists of!)

These edifices are established at great cost and inconvenience either because of regulatory pressures as illustrated by John Fraser’s later anecdote (such regulations are often a forlorn hope by governments that this will somehow avoid society being disadvantaged in some way or other) or because of supply chain obligations which, as with Covid-19, spread up and down the chain with ease, or because of virtue signalling by the new breed of woke directors who are not focused on their real job of adding shareholder value.

The fact is, as you say, these ‘risk management’ edifices exist as an externality to the real management activity (including strategy setting) that is providing the engine room for the organisation.

This is why ‘risk management’ has little influence or, worse still, why it has an adverse effect which is the more common consequence as a consequence of its distractive effect and resource wastage. At very least, it’s not seen as helpful to the daily challenge of making sound decisions because as the world has shown, repeatedly, that with or without ‘risk management’ it is perfectly possible to make both good decisions and bad decisions.

One doesn’t have to invert normality in order to make good decisions – just become a little more skilled in the steps that are already followed. There is no need for a ‘system’ or ‘framework’ (for which, read ‘edifice’) just decision-making skill.

Go Hard and Go Early

This was posted recently on LinkedIn and attracted many comments, most supportive.

Some of you will know that I’m critical of the monstrous belief system that risk management has become; with its own language, codes, symbols, rituals and high priests. Few would now dare to say they don’t believe in ‘risk management’ – even those most (if not all) don’t know what that phrase means. It’s certainty transmogrified (like Frankenstein’s monster) from a simple activity involved with the testing of assumptions as an input to decision making to the vast, self-serving edifices we see today.

I’ve previously said that you won’t find many leaders in the world who are making difficult decisions during the current global crisis reaching for their risk registers or risk appetite statements. One thing we know about good leaders is that they are great at decision making: they are decisive and don’t procrastinate. They gather the views of others about context, look at a range of options and make sure they are clear on the assumptions and the level of certainty each option will lead to their desired outcomes. Then they decide and act swiftly.

All this is true of great surgeons, corporate raiders and generals. They all act hard and act early. (And most would not know a risk register if they tripped over it!)

An excellent analysis has been produced by the (Australian) ABC and shows clearly the difference in the rate of Coronavirus infections and the spread of the disease in countries whose leaders acted hard and early, and those that were or are still dithering. You can access it here.

I’ll let you form your own opinion of your country’s leaders and their decision-making based on this transparent analysis. One thing is clear though, if leaders’ procrastinate – because, variously it will damage their election chances, their population has a good diet, or their people don’t get sick – then it will cost many lives.

Coronavirus and the effect on ‘risk management’

Norman Marks, in his blog post called "How will risk management change as we emerge from this crisis?" pointed of that "Even before the crisis, few on boards or in executive management believed their risk management programs were helping them run the organization for success. At best, it helped anticipate and avoid failure – which is hardly the same as achieving success. At worst, it was a cost center that helped comply with regulations."  Here is my response. 


Crises like that from the Coronavirus that we all face now, just expose the total folly of the ‘risk management’ edifices organisation’s have built. Leaders are making decisions that in some cases, and often quickly in retrospect, either prove inspired or, mostly, highly defective. But the overall impression is that, despite the claims of the risk management fraternity (or whatever three letter acronym you like to label yourself particular brand of belief system with), its all very ‘hit or miss’! 

Form what I can see, no one is reaching for their ‘risk register’ or ‘risk appetite statement’ or ‘risk matrix’ (etc. etc.) to help them make a decision. Some decision-makers are clearly listening to others, thinking out assumptions and choosing between options so that they end up with a decision which they are sufficiently certain will lead to the outcomes they desire. However many, including some of the most important ‘leaders’ in the world, are making decisions based simply on gut feel, ignoring the advice of others or the experiences elsewhere. They seem to lurch from crisis to crisis, with precious little monitoring taking place to see if decisions lead to the outcomes desired or whether the original basis for a particular decision still remains valid.

Some misguided politicians are still bandying around nonsense words like ‘risk’ and ‘risk management’ as though just uttering those phrases as part of their ‘spin’ will solve problems and pacify people. Fat chance!

In my real world, practical experience over the last few weeks I’ve seen clear evidence that the distraction of ‘risk management’ has in some case led to poor decisions or, mostly, just impeded the process of making a decision with sufficient certainty of outcomes. Similarly, most organisation’s Business Continuity Plans (another three letter acronym) have proved useless because they focused on specific events and not generally the organisation’s vulnerability and how that can be reduced, and how decision making can be enhanced when a disruption occurs. Mostly, they’ve been cast aside by decision makers as totally irrelevant!

At this time, mankind needs leaders (not politicians worried about getting elected) who are capable of making the best possible decisions – for the sake of us all. Even if people say this is ‘risk management’ they are simply deluding themselves. 

If anything, this awful crisis just proves we have wasted years and $billions building ‘risk management’ edifices that have ended up like the Maginot Line in WW2: they have created a false sense of security, and exposed us all to the perils of inflexible strategies, poorly defined assumptions, insularity and blindness to wider context and ineffective monitoring.

Now we are facing our biggest challenge in a generation, our various ‘risk management ‘frameworks’, ‘systems’ and ‘programs’ and all the paraphernalia that comes with them, manifestly are not only failing to respond but are actually impeding good decision making. 

When we get through this, we must remember all this and never fall for a similar ‘con job’ again.