Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

The Missing Fifth Transformation in WEF’s Vision for Risk Management

The Missing Fifth Transformation in WEF’s Vision for Risk Management

By
Key Takeaways
  • WEF Identifies Four Major Shifts: The World Economic Forum calls for risk management to move toward preparedness, strategic involvement, continuous risk intelligence and AI-augmented human judgment.
  • Mission-Critical Objectives Should Come First: ERM should be organized around the objectives most important to value creation and preservation rather than around risk registers or taxonomies.
  • Risk and Performance Belong Together: Organizations cannot judge whether uncertainty around an objective is acceptable without understanding actual performance against that objective.
  • Boards Need an Integrated View: CEOs should provide boards with reliable risk and performance information tied directly to mission-critical objectives, raising an important question about who assures that information.
  • A Fifth Transformation Is Needed: Moving from risk-centered ERM to objective-centered ERM would give continuous risk intelligence a clear purpose: determining whether the organization is likely to achieve what matters most within an acceptable level of uncertainty.
Deep Dive

The World Economic Forum’s new Risk Management, Reimagined: Outlook to 2035 is one of the more thoughtful critiques of traditional risk management I have read in some time. It also stops one important step short.

The report, published September 18, argues that risk management needs to undergo four fundamental shifts over the coming decade. Organizations need to move from trying to predict disruptions toward preparing for the unpredictable. Risk management needs to become involved earlier in strategic decision-making rather than reviewing decisions after they have been made. Static and periodic risk reviews need to give way to continuous monitoring and risk intelligence. And artificial intelligence needs to augment human judgment rather than exist apart from it.

I strongly agree with all four. They describe a risk function that looks considerably different from the one that still exists in many organizations. It is less concerned with maintaining a process for its own sake and more concerned with giving decision-makers useful intelligence when decisions actually have to be made. That is real progress.

The report goes further by arguing that risk management should move beyond simply protecting value and contribute to creating and sustaining it. This is an important distinction. If risk management exists primarily to catalogue what might go wrong, maintain risk registers and periodically report changes in risk ratings, it will always struggle to become as relevant to CEOs and boards as the profession says it wants to be.

But there is a question underneath all of this that I believe deserves considerably more attention. Risk intelligence about what? That is where I believe a fifth transformation is needed.

Start With What the Organization Is Trying to Achieve

Enterprise risk management should be organized around an organization’s mission-critical objectives. Not around a risk taxonomy. Not around a risk register. Not around a collection of risk categories that have gradually accumulated over years of workshops and reporting cycles.

Start with the objectives that matter most to the organization’s success and its ability to create and preserve value. Then ask what uncertainty exists around achieving them. That changes the architecture of ERM.

The relationship should run from mission-critical objectives to risks and opportunities, from those risks and opportunities to treatments and responses, and from there to actual performance information, the current level of uncertainty and ultimately a decision about whether that uncertainty is acceptable. This is more than a change in terminology. It changes the question risk management is there to answer.

Traditional risk management often begins by asking what the organization’s risks are. An objective-centered approach begins somewhere more fundamental. What are we trying to accomplish, how are we actually performing against it, what could help or hinder its achievement, and given everything we currently know, how uncertain are we that we will get where we intend to go?

That is a much more useful conversation for management and boards.

Risk Information Is Not Enough

The WEF paper places considerable emphasis on continuous sensing, scenario analysis, assumptions, risk intelligence and the possibilities created by AI. Those capabilities can make risk management faster, more responsive and more useful. The problem is that better risk intelligence does not by itself solve the underlying architecture.

If that intelligence is not explicitly connected to the objectives that matter most, organizations risk becoming considerably better at understanding risks without becoming equally better at understanding whether they will achieve what matters.

There is another problem. Risk information without performance information is incomplete information. Suppose management is told that the uncertainty surrounding a mission-critical objective has increased. That may be important. But how can management determine whether the current level of uncertainty is acceptable without also knowing how the organization is actually performing against that objective?

The reverse is equally true. Performance information without an understanding of uncertainty can create false confidence. An objective may currently be on target while emerging conditions make its future achievement increasingly doubtful. A dashboard can remain green right up until the assumptions beneath it stop holding.

Risk and performance therefore should not arrive in separate conversations. They are different views of the same question. Are we likely to achieve what we have decided matters most?

The Governance Question

Once ERM is organized this way, another issue becomes difficult to avoid. Are CEOs giving boards reliable risk and performance information linked directly to the organization’s mission-critical objectives? And if they are, who provides assurance that the information is reliable?

Boards do not need another layer of risk reporting simply because technology has made it possible to produce one. Nor do they need ever larger volumes of continuously updated risk data. They need reliable information that helps them understand whether the organization is likely to accomplish its most important objectives within an acceptable level of uncertainty.

AI can help organizations process more information, identify patterns, monitor changing conditions and challenge assumptions at a scale that was previously impossible. The WEF report is right to see considerable potential in combining those capabilities with human judgment. But increasing the volume and speed of risk intelligence only makes the question of relevance more important.

A system capable of telling management more and more about uncertainty still needs to know which uncertainty matters. Mission-critical objectives provide that anchor.

The Fifth Transformation

The WEF has done an excellent job of reimagining how risk management should work. Preparedness rather than prediction. Strategic involvement rather than retrospective review. Continuous intelligence rather than periodic assessment. AI working with human judgment rather than apart from it.

I would add a fifth. Move from risk-centered ERM to objective-centered ERM. Make mission-critical objectives the starting point. Connect risks and opportunities to them. Connect treatments to those risks and opportunities. Bring performance information into the same view. Continuously assess the uncertainty surrounding achievement. Then give management and boards the information they need to decide whether that uncertainty is acceptable.

Otherwise, we may succeed in building much better risk intelligence while still failing to answer the question that matters most. What is the current likelihood that we will achieve what matters most, with an acceptable level of uncertainty and risk? That, ultimately, is the question enterprise risk management should be designed to answer.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong