Risk Management’s Tower of Babel
Risk Management’s Tower of Babel
I was a risk manager before risk management was cool!
It seems that everyone wants to be a risk manager today. This is great news because with more people thinking about risks the better. But there is uneasiness with risk management today that swings between a necessary evil and Risk as a Service set of expectations. The truth, as usual, lies in the details.
To date, no central self-regulatory group has emerged in risk management with the mission of defining the language of risk. Risk management has developed from the ground up with a diverse and eclectic set of specialized risk standards that span industry, government, sovereign entities and the military.
Risk management has become “hip” and very confusing as well!
Should risk management be codified?
How an organization defines its risks shape the expectations and duties of a risk manager. How one measures a risk management program depend, in large part, on the success of its outcomes? All too often organizational risk programs start with a definition of risks but fail to clearly define the expected outcomes of the program.
Vague definitions of risk outcomes are easily identified by statements such as “no surprises”, “proactive” and “look around corners”. Even regulatory prescriptions such as “prevent, detect and correct” are less than informative.
Are these realistic outcomes or the wishes of management and regulators to not deal with uncertainty and the messiness of bad judgment?
Uncertainty, by definition, cannot be anticipated including the vagaries of human behavior and random events that can disrupt operations. When unexpected events happen is it a failure of the risk program or a chance event? Risk happens, but all to often the inevitable second guessing of the risk program has become a competitive sport inside and outside of many organizations.
The imprecise use of the language of risk has led to unrealistic expectations of risky outcomes. Codifying risk management may be easy in theory but impractical in the real world.
There are benefits to standards and a common language in risk management. The development of risk standards and frameworks has broadened risk awareness. Less well understood is the difference between a risk and uncertain events.
Humans, including risk managers, are still prone to judgment error and have not evolved the skills to “prevent and detect” uncertainty before it happens. Judging a risk program when it fails to anticipate an uncertain event is like expecting risk management to accurately predict the weather 100% of the time. We joke when the Weather Channel over states adverse conditions but careers are not ruined if the storm is more or less severe than expected.
Is the next milestone in risk management a fuller recognition of human behavior? Standards and frameworks are less responsive to real-time risks. The Bill Gross/Pimco dilemma is an interesting example of uncertainty. And Gross is not the only example. It is instructive that human behavior is hard to anticipate. Maybe more instructive is the fact that most organizations don’t anticipate that uncertainty, not risk, is the big disruptor of organizational outcomes.
What is risk management?
Not surprisingly, if you research the definition of Enterprise Risk Management you will get more than two dozen slightly different versions. What other profession has 24 or more different definitions for one fundamental concept?
Risk, it’s complicated.
Let me give you one example of a definition for Enterprise Risk Management from a consultant in the Healthcare Industry. A true quote:
“Healthcare Risk management’s role was formally focused on claims & loss control. Over time the risk manager graduated to an expanded focus on clinical risk in-hospital. Unfortunately the position remained reactive versus proactive with a focus on [inspection check-off lists].” “Today’s Enterprise Risk Management approach must be system-wide, include a multidisciplinary approach and incorporate an integrated application designed to address risk across the continuum of care. ERM’s goals must assist the organization in achieving its objectives, reduce uncertainty, minimize process variability, promote patient safety, maximize return on assets and enhance asset preservation while recognizing the diversity of risk possibilities.”
There are brilliant risk managers in every organization and a few may actually have many of the skills described above but let’s assume that you are this person. Would you be given the leverage and decision-making ability to accomplish all of the expectations described in this job description? Risk management is seldom critical-path to strategic financial and business objective setting.
In reviewing each of the two-dozen or more definitions of enterprise risk management it is easy to understand why there would be some confusion given obtuse descriptions like the one above.
Risk management isn’t an effort conducted in the isolation of one department. Risk management is an outcome of grounded decision-making across an organization. Even great firms struggle with the challenge of coordinating the efforts of risk management and prioritizing the diversity of risks that are becoming more transparent.
Not all risks deserve the same attention
When things go badly in companies “culture” is typically cited as the true cause. Corporate culture may be overrated as a governance control. Who is responsible for an organization’s culture?
In most organizations senior management sets the tone for how aggressive or conservative an organization pursues risky ventures. Management incentives often determine which route is pursued yet risk management is often judged by the outcome of the decisions that work out versus the ones that fail.
The uncertainty of choosing between the two is the real challenge!
Risk, is in the eye of the beholder!
Research has shown that we each see risks differently. Heads of state must deal with different risks than their counterparts in non-profit organizations. Is it realistic to expect a framework to account for the nuisance inherent in all organizations? Some managers are risk adverse while others are risk takers. Aligning the organization with the risks taken is the art of risk management.
Removing the Tower of Babel
Let’s simplify the language of risk. If risk is in the eye of the beholder we must be able to discuss risk using terms that everyone understands. The importance of developing a common understanding of risks should not be underestimated. A lack of agreement on risks is one of the leading causes of a failure to execute.
But in order to simplify the language of risk it is important to talk in terms of how we each experience risk. Even very powerful people like Bill Gross have fears. Would things have turned differently if communication had not broken down? We will never know the answer but it is clear that risk management is as intimate as a broken relationship.
Sometimes, risk management is just about listening and being heard.
James Bone is a Behavioral Risk Consultant with more than 20 years of experience in senior risk management roles across a variety of complex industries. Follow James at TheGRCBlueBook.com