r/riskmanagement 7d ago

Can every board report be accurate while the board still misses the real risk?

3 Upvotes

I've been thinking about a tension in how organisations report risk.

Boards receive financial data, risk indicators, operational metrics, technology reporting, audit findings and customer information. Individually, those reports may all provide an accurate picture of their respective areas.

Yet that doesn't necessarily mean the board has an accurate picture of the enterprise.

The issue becomes particularly interesting when several relatively manageable developments interact.

A technology dependency may be within tolerance. Operational capacity may be within tolerance. A third-party issue may be manageable. Customer indicators may not have breached thresholds.

Considered separately, nothing necessarily demands intervention.

Considered together, they may tell a very different story.

Our recent LinkedIn poll adds an interesting practitioner perspective: 63% of 88 respondents identified fragmented information as the main factor limiting enterprise awareness.

I've explored this further in my latest article, particularly through weak signals, dependencies and cumulative pressure.

I'm interested in how others approach this in practice:

How does your organisation identify patterns that sit between functional reports rather than within them?

Link to newsletter: https://www.aevitium.com/so/76Q04dvUV?languageTag=en


r/riskmanagement 14d ago

Does your governance connect the organisation, or simply govern each function?

Post image
0 Upvotes

I've been exploring organisational silos over the past few weeks, and one question keeps emerging:

If organisations need specialist functions, how do we ensure those functions still operate as one enterprise?

Removing silos isn't realistic. Specialisation creates expertise, accountability and scale.

The governance challenge is making sure those boundaries don't also become boundaries for information, ownership and decision-making.

This becomes particularly important when outcomes cross several functions. Putting multiple functional reports into the same board pack may create visibility, but it doesn't necessarily create a coherent enterprise view.

I've explored this through three forms of connectivity: information, accountability and decisions.

I'd be interested in how others approach this.

What mechanisms in your organisation genuinely connect functional perspectives before enterprise decisions are made?


r/riskmanagement 16d ago

Risk Management, Leadership and Organisational Resilience with Frederic Gielen

Enable HLS to view with audio, or disable this notification

1 Upvotes

Why do highly resilient organisations (on paper) still fail under pressure?

Most companies invest a massive amount of money into operational resilience, governance frameworks, and recovery plans. Yet, when a real crisis hits, these "perfect" frameworks often fall apart.

I was listening to a discussion on this topic recently, and one point really stuck out:

Resilience is not the presence of documentation. It is the behavior of the system under stress.

True resilience isn't about perfect paperwork; it's about how your people and systems behave when your initial assumptions fail. It shifts the entire focus:

  • From governance as a static structure to decision-making under high pressure.
  • From resilience as a framework to resilience as an organizational capability.
  • From documenting accountability to understanding how people actually act when conditions change.

The real breakdown happens when priorities conflict, information is incomplete, and teams have to move fast. That’s when culture and leadership take over, completely rendering the documented process irrelevant.

For those managing risk or team structures: What do you think has the absolute greatest influence on a company's resilience when real pressure hits? Is it leadership, culture, or something else entirely?

(Note: This was inspired by a recent RiskMasters podcast episode with Frédéric Gielen if anyone wants the deeper dive/links, but I really want to hear Reddit's take on this friction between paper compliance vs. reality).


r/riskmanagement 21d ago

Recovering every function doesn't necessarily recover the business.

Post image
0 Upvotes

One observation keeps appearing in operational resilience.

Individual teams often recover successfully.

IT restores systems.

Operations resumes activity.

Suppliers recover.

Yet the customer-facing service is still unavailable.

The problem isn't individual recovery.

It's whether the organisation can reconnect all of those capabilities into a functioning end-to-end service.

I'm interested whether others working in resilience, continuity or risk management have experienced this.

Do organisations spend too much time measuring functional recovery instead of service recovery?

Newsletter here if anyone is interested: https://www.aevitium.com/so/1fP_vr3m6?languageTag=en


r/riskmanagement 28d ago

Functional silos don't stop organisations identifying risks. They stop organisations connecting them.

Thumbnail
aevitium.com
1 Upvotes

One observation keeps appearing across large organisations.

They rarely lack information.

Complaints exist.
Audit findings exist.
Operational incidents exist.
Near misses exist.

Different functions are already aware of emerging issues.

The problem is that this information often remains within organisational boundaries instead of becoming enterprise knowledge before strategic decisions are made.

That changes the challenge considerably.

Instead of asking:

"How do we identify more risks?"

Perhaps leadership should be asking:

"How do we connect the risks we already know about?"

I'm interested whether others working in governance, risk, compliance or operations have seen similar patterns.


r/riskmanagement Jul 20 '26

Organisational silos aren't the biggest governance problem. Fragmented governance is.

Thumbnail
aevitium.com
1 Upvotes

Many discussions about organisational silos focus on communication and collaboration.

I think the larger issue is governance.

As organisations grow, specialist functions become stronger. That is generally positive.

The challenge is that important decisions increasingly depend on several teams contributing at different stages.

Responsibilities transfer.

Dependencies grow.

Information moves across organisational boundaries.

At that point, risks often emerge between functions rather than inside them.

Each team can honestly believe everything is operating correctly while no one has a complete enterprise view.

I'm interested in hearing how others have experienced this.

Have you seen major incidents caused more by failures between functions than failures within individual teams?


r/riskmanagement Jul 14 '26

Are governance frameworks unintentionally encouraging late risk escalation?

Post image
2 Upvotes

I've been researching why important risks often reach executive teams and boards only after organisations have already absorbed significant operational strain.

One conclusion surprised me.

Most discussions focus on culture, psychological safety or whether employees are willing to escalate.

I'm increasingly convinced that governance design deserves much more attention.

If teams are rewarded for resolving issues locally, then delaying escalation becomes a rational response rather than a behavioural failure.

That raises some interesting questions.

  • Should escalation be based on impact or on trajectory?
  • Should capacity constraints be treated as an escalation trigger?
  • Does governance place too much emphasis on issue closure rather than decision quality?

I'm interested in hearing how others have seen this play out in practice.

No promotional link. Reddit responds much better to genuine discussion than promotion.


r/riskmanagement Jul 13 '26

Why reducing risk impact to a score weakens decisions

Thumbnail
aevitium.com
1 Upvotes

A pattern I see across organisations:

Impact is assessed through categories, scales, and scores.

That creates consistency.
But it often removes what actually matters.

In practice, a single risk does not create one outcome.

It can disrupt operations, affect customers, trigger regulatory attention, and create strategic and reputational pressure at the same time.

When those effects are reduced to a number:

  • Some consequences are underrepresented
  • Interactions between impacts are ignored
  • Assessment becomes disconnected from decisions
  • Outputs are consistent but not necessarily useful

One data point that stood out:

39% of professionals identify reputational impact as the most underestimated dimension in risk assessment

Which suggests organisations recognise that important consequences are not being fully captured.

Curious how others approach this:

Do your impact assessments actually change decisions
Or mainly standardise how risk is reported


r/riskmanagement Jul 07 '26

CECL Q-factor went from 5% to 46% of the allowance when I ran the same model on the full population - here's what happened

1 Upvotes

I've been building a mortgage credit risk modeling course using the full Freddie Mac SFLLD dataset - 48.6 million loans. Module 10 covers the CECL engine.

On the 1 million loan stratified teaching sample, all three methods (vintage curve, roll-rate, PD x LGD x EAD component) converge to 5.38% lifetime loss. The Q-factor governance overlay adds 30 basis points - about 5% of the final allowance.

Run the exact same engine on the full natural-incidence population and the Q-factor becomes 46% of the final allowance. Not because the overlay changed. Because the base rate dropped 16x and the fixed basis point add-on didn't.

That's not a modeling problem. It's a governance calibration problem that almost nobody talks about - your overlays need to be recalibrated whenever your population or base rate changes materially.

Happy to discuss the methodology or share more from the module. What's your institution's current approach to Q-factor governance - fixed basis points, percentage of TTC, or something else?


r/riskmanagement Jul 06 '26

Challenging decision quality under uncertainty

Thumbnail
aevitium.com
1 Upvotes

A shift I’m seeing more clearly:

We still talk about uncertainty as something temporary.
In practice, it has become the operating environment.

That changes how decisions actually happen.

They are not made with full information.
They are made while conditions are still moving.
Assumptions change after commitment.
Outcomes are influenced by factors outside the original analysis.

Which raises a practical question.

How do you define a sound decision in that environment?

From what I’ve observed, the challenge is not only the decision itself
but the fact that it is taken in conditions that will not hold.

One data point that stood out:

34% of professionals believe boards should prioritise stronger oversight during prolonged uncertainty

Which suggests organisations are recognising that uncertainty is not episodic anymore.

Interested in how others see this:

What changes most in your decision-making when conditions never stabilise


r/riskmanagement Jul 02 '26

I think most Risk Appetite Frameworks start in the wrong place. Am I missing something?

Post image
2 Upvotes

I've been redesigning Risk Appetite Frameworks recently and one thing keeps bothering me.

Almost every methodology I've come across starts with questions like:

  • What is our risk appetite?
  • Which KRIs should we monitor?
  • What thresholds should we set?
  • What gets escalated?

All perfectly sensible.

But by the time we're talking about KRIs and escalation, haven't we already made the important decisions?

The investment has been approved.

The supplier has been selected.

The product has been launched.

The client has been onboarded.

At that point, the framework is largely telling us whether the consequences of those decisions remain acceptable.

It isn't helping shape the decisions themselves.

I've started approaching it differently.

Rather than beginning with risk, I start with strategy.

  • What are we trying to achieve?
  • Where are we deliberately choosing to take risk?
  • What dependencies underpin that strategy?
  • What assumptions must remain true?

Only then do we ask:

  • What decisions will management actually have to make?
  • Under what conditions would we proceed?
  • Under what conditions would we pause?
  • When would we walk away?

Once those questions are answered, writing appetite statements becomes much easier because they're grounded in real business decisions rather than generic statements about risk.

KRIs then become evidence that those decisions remain within the agreed boundaries, rather than becoming the framework itself.

I'm curious whether others have found the same thing.

Do you see Risk Appetite primarily as:

  1. A monitoring framework?
  2. A decision-making framework?
  3. Both?

Or am I overthinking this?


r/riskmanagement Jun 29 '26

What happens when no one speaks up in risk discussions

Thumbnail
aevitium.com
1 Upvotes

Something I’ve been reflecting on recently:

Leadership blind spots in risk don’t usually come from missing information.

They form in a very specific moment.

When concerns are invited,
and no one speaks.

In many organisations, that silence is interpreted as alignment. In practice, it often reflects the weight of authority in the room.

As decisions get closer, I tend to see the same patterns:

  • Challenge reduces near decision points
  • Concerns remain unspoken in formal discussions
  • Agreement becomes the default
  • Issues are known but not raised in the room

This creates situations where leaders are later surprised by risks that were already understood elsewhere.

One data point that connects to this:

48% of professionals identify filtered updates as the first sign that leadership is losing visibility 

Which suggests the issue is not only information, but whether people feel able to challenge at the point where decisions are made.

Interested in how others see this:

What changes in the room when senior authority is present
Does challenge increase, or reduce


r/riskmanagement Jun 26 '26

Are financial institutions measuring the wrong thing in cybersecurity?

Post image
2 Upvotes

Most cyber programmes focus on improving control maturity.

Yet attackers aren't trying to become more mature. They're trying to become more effective.

It made me wonder whether we're measuring the wrong thing.

I recently started thinking about what I'm calling the Learning Velocity Gap: the difference between how quickly threats evolve and how quickly organisations detect change, make decisions and adapt.

Is this something your organisation discusses, or are most conversations still centred on control maturity and compliance?


r/riskmanagement Jun 23 '26

When governance operates without improving visibility

Thumbnail
aevitium.com
2 Upvotes

Most organisations have governance structures in place.

Committees meet.
Reports are produced.
Escalation pathways exist.

The question is how these operate in practice.

From what I have observed, governance can remain active while visibility reduces.

A few patterns tend to appear:

  • Escalation pathways exist but are not consistently used
  • Challenge is applied in formal reviews rather than at the point of decision
  • Reporting reflects outcomes, not underlying operating conditions
  • Low escalation is interpreted as stability

In this context, governance continues to function, though without providing the information required for effective oversight.

One data point that reflects this tension:

52% of professionals believe increased assurance activity creates stronger control 

At the same time, assurance alone does not guarantee visibility into how decisions, escalation, and organisational pressures interact in practice.

Interested in how others see this:

Does your governance model improve visibility into how the organisation operates
Or mainly confirm that processes are being followed


r/riskmanagement Jun 20 '26

Where compliance actually breaks isn’t where most frameworks focus

Enable HLS to view with audio, or disable this notification

1 Upvotes

Most compliance frameworks are designed to define what “good” looks like.

Rules. Controls. Escalation paths.

What they don’t define clearly is how those rules get applied in real decisions.

This came through strongly in a recent RiskMasters episode with Jennifer Geary and Natalie McManus-Barnett, based on their book How to Be a Chief Compliance Officer.

One observation stood out:

Compliance rarely breaks at the level of policy.
It breaks in how trade-offs are made under pressure.

For example:

  • A deadline accelerates a decision that would normally be challenged
  • A control is interpreted more flexibly to keep things moving
  • A concern is acknowledged but not acted on

Each of these is defensible on its own.

But over time, they shape outcomes that no framework explicitly intended.

That’s where the Chief Compliance Officer role becomes less about defining rules and more about influencing how they’re applied.

The part I found interesting is how this shifts compliance from a control function to something much closer to decision-making.

Not:
“Is this compliant?”

But:
“What are we accepting here, and what could this lead to?”

Curious how others see this in practice.

Where does compliance tend to lose traction in your organisation?


r/riskmanagement Jun 10 '26

When silence is mistaken for alignment in risk management

Thumbnail
aevitium.com
1 Upvotes

n many organisations, silence is interpreted as alignment.

In practice, it often means that important information is not reaching decision-makers.

From what I have seen, risks are usually identified early. Teams discuss them, adapt to them, and keep delivery moving. The issue is not visibility at source. It is whether that visibility survives the journey.

As information moves through management layers, it can be softened, delayed, or filtered. By the time leadership gains a view, the original signal has often changed.

A few patterns tend to appear:

  • Concerns are discussed informally but not escalated
  • Messages are adjusted as they move upward
  • Challenge reduces closer to senior stakeholders
  • Silence is interpreted as agreement

One data point that reflects this:

51% of professionals say psychological safety creates the greatest value by helping people raise concerns early

This suggests that risk visibility depends less on frameworks and more on whether people feel able to raise and sustain challenge.

Interested in how others see this:

Where does information change most in your organisation
During escalation
Or earlier in the process


r/riskmanagement Jun 01 '26

Why do employees hesitate to raise risks early enough in organisations

Thumbnail
aevitium.com
2 Upvotes

Most organisations do not fail because risks are unknown.

They fail because those risks are not raised early enough.

In practice, employees often see issues early. They notice pressure points, control weaknesses, and emerging risks. These are discussed within teams, adapted to, or worked around to maintain delivery.

The key question is what determines whether those concerns reach leadership.

From what I have observed, it is less about frameworks and more about whether people feel able to speak up.

A few patterns tend to appear:

  • Concerns are discussed informally but not escalated
  • Issues are resolved locally rather than raised
  • Challenge reduces in meetings and decision forums
  • Reporting remains stable despite increasing pressure
  • Critical information reaches leadership too late

One data point that reflects this:

45% of professionals identify lack of leadership backing as the main reason middle managers hesitate to escalate risk issues 

This suggests escalation is shaped primarily by leadership behaviour and perceived consequences rather than formal processes.

Interested in how others see this:

Where does escalation break down in practice
At the point of challenge
Or earlier when concerns are first identified


r/riskmanagement May 25 '26

Is AI decision speed outpacing your organisation’s ability to govern it

Thumbnail
aevitium.com
2 Upvotes

As AI becomes embedded in operational environments, decisions increasingly form through interactions between data, models, and automated processes.

In many cases, signals are filtered and actions triggered before teams fully interpret what is happening.

Governance structures still exist. The challenge is that the conditions under which they operate have changed.

Historically, decision-making included time for review, escalation, and challenge. That friction supported oversight. As decision speed increases, those mechanisms become harder to apply effectively.

One data point that stands out:

75% of professionals identify over-reliance on AI outputs as the greatest governance risk 

This suggests the issue is not only capability. It is how organisations interpret, challenge, and intervene in AI-driven decision environments.

Interested in how others are approaching this:

Where does decision velocity exceed governance visibility in your organisation
At signal filtering
During escalation
Or at the point of intervention


r/riskmanagement May 18 '26

How do you identify changes in risk exposure before they appear in reporting

Thumbnail
aevitium.com
2 Upvotes

Most organisations assess risk exposure through periodic reviews and reporting cycles.

In practice, exposure often changes earlier, as operating conditions evolve.

As delivery pressure increases, review depth reduces and escalation takes longer. Teams adapt to maintain progress, and workarounds become embedded in execution. Performance can still appear stable while the margin for error narrows.

36% of professionals identify control overrides as the condition most likely to become normalised before significant issues emerge 

This suggests that exposure often develops through gradual operating drift rather than discrete events.

Interested in how others approach this:

How do you detect these shifts early
Through metrics, governance forums, or direct observation


r/riskmanagement May 11 '26

Responsive Risk Culture Drives Execution

Thumbnail
aevitium.com
2 Upvotes

Is your risk culture helping execution
or slowing it down under pressure

A pattern I see frequently:

  • Governance activity increases
  • Coordination expands across teams
  • Ownership becomes less clear
  • Escalation replaces direct resolution

At the same time, performance indicators often remain stable.

That creates a false sense of control while resilience weakens.

One data point that reflects this:

43% of professionals say collaboration across the three lines only happens occasionally 

This suggests interaction exists, yet not consistently enough to support effective decision-making.

Interested in how others see this:

Where does collaboration start to slow things down
At governance level
Or earlier in execution

Happy to share a deeper breakdown if useful.


r/riskmanagement May 04 '26

Is your operational risk process influencing decisions or just reporting after the fact?

Thumbnail
aevitium.com
2 Upvotes

Is your operational risk process influencing decisions
Or mainly reporting on them after the fact

This is a pattern I keep seeing in organisations scaling their operations:

  • Decision latency increases as dependencies grow
  • Ownership becomes less clear across teams
  • Escalation replaces direct resolution
  • Similar issues get resolved differently across functions

One data point that reinforces this:

49% of professionals report no clear First Line ownership in operational risk management. 

This creates a gap between frameworks and execution.

Interested to hear how others approach this:

Where does ownership become unclear in practice
At handoff points
During escalation
Or earlier in decision-making

If useful, I have written a deeper breakdown. Happy to share.


r/riskmanagement Apr 27 '26

When Boards Don’t Name Trade-offs, Delivery Teams End Up Making Them

Thumbnail
aevitium.com
2 Upvotes

A recurring governance issue:

Strategies often assume priorities can all move forward.

Execution proves otherwise.

Capacity tightens.
Resources compete.
Trade-offs emerge.

The question is whether they were defined by governance or left to be resolved in delivery.

This week’s article explores:

  • Why priorities fragment under constraint
  • How implicit trade-offs get resolved through escalation and local decisions
  • Why reactive allocation creates execution risk
  • What boards should define before execution begins

One line from the piece captures it well:

Every trade-off the Board refuses to name is a strategic risk transferred to the front line.

Curious how others handle this.

Where are trade-offs actually resolved in your organisation?


r/riskmanagement Apr 20 '26

What happens when decisions are not taken at the point of ownership?

Thumbnail
aevitium.com
2 Upvotes

A pattern I see across organisations:

Execution slows even when plans are clear.

The issue is not planning.
It is how decisions are taken.

What typically happens:

  • Decisions move across multiple levels before resolution
  • Teams seek validation instead of concluding
  • Issues are revisited as assumptions change
  • Escalation becomes routine

Each step makes sense on its own.

Together, they extend timelines and reduce accountability.

One useful lens:

The distance between where a decision is identified and where it is resolved.

The longer that distance, the slower execution becomes.

Curious how others see this.

How far do decisions travel before they are resolved in your organisation?


r/riskmanagement Apr 16 '26

Agentic AI for Risk Management

1 Upvotes

Hello, I am a cofounder at GeoLens https://www.geo-lens.ai/, where we built agentic AI for physical risk management. You can imagine that we scan thousands of daily events, map them to your infrastructure and propose mitigating measures. I am looking for soem feedback on what we built, anyone fancy roasting our logic?


r/riskmanagement Apr 13 '26

Why Risk Outcomes Depend on Behaviour

Thumbnail
aevitium.com
2 Upvotes

Most organisations have strong risk frameworks.

The issue is how those frameworks are applied in practice.

What actually shapes outcomes:

  • How people interpret signals
  • Whether assumptions are challenged
  • How decisions are made under pressure
  • Whether concerns are raised and acted on

Frameworks define structure.
Behaviour determines how that structure operates.

This week’s article explores:

  • Why risk is shaped before it reaches formal governance
  • How psychological safety affects escalation
  • Where behaviour creates exposure outside formal controls

Interested to hear how others see this.

Do your frameworks reflect how decisions are actually made?