Reputational risk is not a risk

Despite the clickbait title, the messages are in the article are important to the risk profession and are purely practical. First few caveats, corporate reputation is important, even a perception of wrongdoings can affect funding, sales and cost of doing business.  Importance of reputations for both profits and non-profits is not up for a debate.… Continue reading Reputational risk is not a risk

Risk management 2 is both a control and decision making tool

In 2018 I attempted to coin the distinction between “Risk Management 1” – cosmetic, governance-driven risk management, and “Risk Management 2” – value-adding risk management that drives better decision-making  https://riskacademy.blog/rm1-vs-rm2-which-side-will-you-choose/  I have been following walking the talk, in both my consulting practice, personal life and in the corporate employment, ever since. In 2021 the company… Continue reading Risk management 2 is both a control and decision making tool

5 red flags 🚩 when doing a risk assessment

Risk assessments are probably the most common activities within the risk management profession and there is a very fine line between being a total waste of time and a useful risk management approach. So what are the most common pitfalls, how to avoid them and how to turn risk assessments into a useful decision making… Continue reading 5 red flags 🚩 when doing a risk assessment

3 disruptive risk management trends that will shape 2023 and will totally surprise you

When I set out to write this article I thought to myself, top trends are boring because they are always too obvious and have been going on for years. So I went on a quest to find the trends that will completely reshape the profession and yet will catch most of the risk managers completely… Continue reading 3 disruptive risk management trends that will shape 2023 and will totally surprise you

8 best risk management blogs

So much has been written about risk management and yet most of it is RM1. Before the year end I went on the quest to find worthwhile RM2 blogs moving the risk profession within the non-financial sector forward. #1 Nassim Taleb Nassim Taleb is an author of the INCERTO a philosophical and practical essay on uncertainty (Skin… Continue reading 8 best risk management blogs

Gestión de Riesgos: RM1 versus RM2

La gestión de riesgos está en el borde de algo muy interesante y emocionante en este momento. Por un largo tiempo, se creyó que haciendo una buena gestión de riesgos todos los actores clave de una compañía estarían satisfechos, pero la realidad es que los distintos tipos de actores quieren cosas completamente diferentes: La RM1… Continue reading Gestión de Riesgos: RM1 versus RM2

Desafío de las Cinco Semanas: Integrando la Gestión de Riesgos a la Toma de Decisiones

Cuando se quiere abordar la implementación de sistemas o marcos de trabajo para la gestión de riesgos en una organización entera, usted se puede llegar a encontrar con un desafío insuperable. Para ayudar a que una organización pueda alcanzar sus objetivos de forma más segura, es conveniente comenzar a mejorar tan sólo una instancia de… Continue reading Desafío de las Cinco Semanas: Integrando la Gestión de Riesgos a la Toma de Decisiones

What is a risk? It’s not what you think it is

If there is one thing I learned as a CRO, it is crucial to understand the nature of each and every risk we have to work with. I will no doubt write a separate article about the mistake of aggregating various risks into a risk register or attempting to use the same methodology to quantify… Continue reading What is a risk? It’s not what you think it is

Why Board Audit Committee is the worst place for risk management and having a separate Board Risk Committee is even worse

Over the last 10 years it became almost dogmatic that risk management effectiveness has to be disclosed at the Board level. It seems to be equally accepted that full Board is responsible for risk management oversight, who, however can and often do, delegate this oversight responsibility to the Audit Committee. This is in fact so… Continue reading Why Board Audit Committee is the worst place for risk management and having a separate Board Risk Committee is even worse

ISO and COSO haven’t got a clue. You can and should quantify compliance risks

Every organisation is required to comply with laws within the countries it operates in, the legal and regulatory requirements vary between different regions adding to the need to have understanding and confidence in the risk management processes in place. Organisations face considerable uncertainty when making decisions and taking actions that may have significant compliance consequences. The management… Continue reading ISO and COSO haven’t got a clue. You can and should quantify compliance risks