Home > Risk > Protiviti provides sound insights into risk management failures

Protiviti provides sound insights into risk management failures

February 15, 2011 Leave a comment Go to comments

If you haven’t seen this, download a copy of Protiviti’s “Ten Common Risk Management Failures and How to Avoid Them”.

They discuss, with clarity, ten mistakes:

  1. Poor governance and tone at the top
  2. Reckless risk-taking
  3. Inability to implement enterprise risk management
  4. Non-existent, ineffective, or inefficient risk management
  5. Falling prey to a “herd” mentality
  6. Misunderstanding the “if you can’t measure it, you can’t manage it!” mindset
  7. Accepting a lack of transparency in high-risk areas
  8. Not integrating risk management with strategy-setting and performance management
  9. Ignoring the dysfunctionalities and “blind spots” of the organization’s culture
  10. Not involving the board in a timely manner

Most of these are pretty straightforward. Turning to #3, “Inability to implement enterprise risk management”, I would have made it clearer that while some organizations have a risk management program, their program does not include all risks to the organization, including strategic risks and risks external to the enterprise. Too many have risk management programs that appear well-resourced and mature, but don’t go beyond looking at risks (in the case of financial services companies) in their portfolio or positions. Others continue to think of risk management from the perspective of insurance and safety, and are then taken by surprise by an adverse event related to reputation or credit risk.

I very much like the discussion in #4, where they bring up the term (a favorite of Jim DeLoach) “enterprise list management”. One of the failures I see time and again is relying on a ‘risk register’, and only monitoring and assessing risks in that list. Organizations put themselves in a box and are blind to risks that they have not previously included in the risk register.

Point #8 is, for me, critical if you are going to manage the risks that matter – the risks that may affect your ability to achieve your objectives.

I would add two more to the list. The first is Complacency: thinking that you have an effective risk management program that does not need improvement. The financial crisis saw several with touted risk management programs suffer the indignity of being proven wrong. The second is a lack of interpersonal skills. Strange as it may seem, if the Chief Risk Officer does not have the ability to influence and persuade management and inform the board, the whole program may be for naught.

 Related posts:

Risks to watch in 2011

Managing risk at the speed of business

Building the case for ERM

A Collection of Solid Guidance on Risk Management

An Interview on Risk Management Challenges and More

  1. David
    February 15, 2011 at 6:19 PM

    Norman,

    As always, this is a great post.

    I believe that #1 is #1.

    If you don’t have the right tone at the top, everything else seems set-up for failure.

    Regards,

    David

  1. February 26, 2011 at 10:27 PM

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: