You Cannot Manage A Risk You Do Not Properly Understand.
Updated: Sep 17
Risk registers are common. Most organisations have them. Risks are identified, scored, assigned an owner and reviewed through established governance. Red, amber and green provide a familiar indication of where attention may be required. But recording a risk and understanding it are not necessarily the same thing.
A risk can have an owner, a score and a mitigation plan while the organisation still has an incomplete view of what could happen, why it might happen and what the consequences would be. Before a risk can be managed effectively, it needs to be properly understood.
Start With the Business Impact
Risk discussions can quickly become focused on controls, scores and processes.
Those things matter, but they should not be the starting point. The stronger starting question is: What are we trying to protect, and what would happen if it failed?
For a critical service, that could mean disruption to customers, financial loss, regulatory exposure, operational interruption or reputational damage.
For a growing organisation, the risk may be different. Processes that worked effectively at one scale may begin to fail as volumes increase. Responsibilities may become unclear. Technology may struggle to support demand. Controls may not evolve as quickly as the business. Understanding the potential business impact gives risk context.
Without that context, organisations can spend significant effort managing risks that matter relatively little while more important exposures receive insufficient attention.
Understand How the Risk Could Materialise
A risk rarely exists in isolation. Services depend upon people, technology, suppliers, processes, information and facilities. Changes in one part of that environment can alter the exposure elsewhere. That makes dependencies particularly important. A service may appear resilient because its technology is highly available, for example, while depending on a single specialist team, supplier or process that has no practical alternative. Similarly, a documented control may appear strong until the organisation considers whether it would operate effectively during a real disruption.
Understanding risk therefore means looking beyond the description in the register.
It means understanding how the risk could materialise in practice.
Assess the Evidence
Once the context and dependencies are understood, the organisation can examine the evidence.
· What has happened previously?
· What do incidents, service performance, audit findings, control assessments, supplier performance and operational information tell us?
· Have circumstances changed since the risk was originally assessed?
· Are the existing controls reducing exposure?
· And does the evidence support the current risk rating?
This distinction is important. Risk assessments inevitably involve judgement. But judgement becomes much stronger when it is supported by evidence.
A risk rated low because nothing serious has happened recently may still represent significant exposure if the underlying controls are weak. Conversely, a risk with a high initial rating may have effective controls that reduce its remaining exposure. The assessment should distinguish between the inherent risk and the residual risk after controls are considered.”
Challenge the Assumptions
Over time, assumptions can become accepted as facts.
· “We have a recovery plan.”
· “The supplier is responsible for that.”
· “We tested this last year.”
· “The service has never failed.”
· “We have a control in place.”
Each statement may be true. But each deserves another question.
· Does the recovery plan reflect the environment as it operates today?
· Is the supplier responsibility clearly understood and tested?
· What changed after the last exercise?
· Does the absence of previous failure demonstrate resilience, or simply that the organisation has not yet experienced the right combination of circumstances?
· And is the control merely documented, or is there evidence that it works?
Constructive challenge is not about finding fault.
It is about testing whether the organisation's understanding of its risk position remains valid.
Risk Should Be Proportionate
Not every risk requires elimination. In most organisations, eliminating every conceivable risk would be neither practical nor economically sensible.
Leadership therefore must make choices. Some risks can be accepted. Some can be reduced. Some can be transferred. Others require immediate action because the potential impact is simply too significant.
The important point is that these decisions should be conscious and informed.
That means understanding the likelihood of an event, its potential impact, the effectiveness of existing controls and the organisation's tolerance for the remaining exposure.
A proportionate approach focuses investment and management attention where it matters most. It avoids both extremes: insufficient control on one side and unnecessary process, cost and complexity on the other.
Risk Is Not Just a Risk Team Responsibility
Risk functions provide important expertise, governance and oversight. But operational risk ultimately exists within the business. The people responsible for services, operations, suppliers, technology and change often have the closest understanding of how risks may emerge in practice.
Leadership has a different perspective again, understanding strategic priorities, customer commitments and the consequences of disruption.
A strong view of risk brings those perspectives together.
It connects business impact with operational reality and independent challenge.
That is when a risk register becomes more than a governance document. It becomes a useful management tool.
From Assumption to Confidence
Effective risk management should give leadership confidence that the organisation understands its significant exposures and is making informed decisions about them.
That confidence should not come simply from having a risk framework, a completed assessment or a green dashboard. It should come from being able to explain:
· What could happen.
· Why it could happen.
· What the impact would be.
· What is being done about it.
· And whether the remaining exposure is acceptable.
Because ultimately, a risk cannot be managed simply because it has been recorded.
You can only manage a risk effectively when you properly understand it.
Understand. Assess. Challenge.


