Home > Risk > Norman’s list of top (downside) risks

Norman’s list of top (downside) risks

Everybody seems to be sharing their list of top risks with potentially significant negative effects on the organization.

Of course, every organization should determine what are its greatest sources of downside risk to the achievement of its own objectives, given its unique facts and circumstances.

Blindly following someone else’s list is a risk in itself.

But these lists are food for thought. Here is my list of 15 things to consider. (Of course there are more.) It’s nothing like the other lists I have seen!

In fact, I would suggest that they are usually not included in either the CRO’s or the CAE’s list of top risks.

These are not necessarily in order of their significance. That’s for each enterprise to decide.

  • Cash and cash flow. Cash is king, but if you don’t have the liquidity to be agile, you will become a pauper.
  • Selfish executives, very often including the CEO, who put their interests ahead of the team and the organization.
  • A failure to innovate. (Such as with products and services, technology adoption, and so many more areas.)
  • Poor quality product development, production, and management.
  • Inattention to customers and their feedback.
  • An unwillingness to take risks. It’s often more dangerous than taking too many.
  • Poor decision-making processes.
  • Decision-makers who know it all and don’t listen.
  • Unreliable, incomplete, or untimely information.
  • Stale technology and infrastructure.
  • A lack of loyalty to employees. (An example is fast and across-the board layoffs, with slow training and staff development. Another is unwillingness to pay performing individuals.)
  • Poor teamwork.
  • Human Resources inhibiting the hiring of the people you need to excel.
  • A blindness to reality, both to the current situation and to what lies ahead.
  • A board that is dominated by the CEO.

What do you think of them?

What would you change, delete, or add?

  1. Anonymous
    April 29, 2024 at 10:06 AM

    I usually treat lists like this as biased and therefore read them bottom up.

    Also these are the ‘Known Risks’. The ‘Unknown Risks’ are more important.

    • Norman Marks
      April 29, 2024 at 11:33 AM

      Can you explain what that means and its practical benefits use?

  2. rhsturgeon17a67364ab
    April 29, 2024 at 11:27 AM

    Great article Norman. I’m relatively new to your work and I’m curious what you mean with “downside” risks?

    • Norman Marks
      April 29, 2024 at 11:32 AM

      Good question. Per the global risk management standard, ISO 31000, risk is the effect of uncertainty on objectives. That means, and CISO ERM agrees, risk can be positive as well as negative. I try to make it clear what I am talking about.

      • rhsturgeon17a67364ab
        April 29, 2024 at 11:57 AM

        Thanks Norman…I haven’t heard it distinguished in that way.

  3. David Griffiths
    April 29, 2024 at 1:00 PM

    I would add; information which is irrelevant, incomplete, inaccurate and not used.

    • Norman Marks
      April 29, 2024 at 1:23 PM

      Yes. Could modify my point on information

  4. Anonymous
    April 29, 2024 at 9:38 PM

    believing your own BS/propaganda

  5. Anonymous
    April 30, 2024 at 12:12 AM

    I would leave out poor management. It’s too much of a container concept whereas the specific risks are allready in the list (negelect of staff, self interest, poor decision making, blindness to reality, etc.)
    My experince is that using this kind of phrasing does not help to pinpoint specific threats and design the right mitigation strategy.
    (Wim Schreuder)

    • Norman Marks
      April 30, 2024 at 6:30 AM

      I hear you, but we need to be aware that poor leadership sinks every ship.

  6. Anonymous
    April 30, 2024 at 3:03 AM

    Non compliance with statutory/regulatory issues

    • Norman Marks
      April 30, 2024 at 6:30 AM

      I thoughth about that, but it rarely causes the ship to sink.

  7. Anonymous
    May 2, 2024 at 3:16 PM

    Refreshing that not many risks on the list appear in the typical lists published out there e.g. cyber, climate change, regulatory etc…. Norman, many if the risks on your list are internal in nature to the organization and to a large extent within their control compared to those with external sources where you really only control the extent of the impacts and your ability to respond quickly.

    • Norman Marks
      May 2, 2024 at 3:27 PM

      That is true – although the ability to respond to what happens outside is 100% dependent on your people and systems.

  1. No trackbacks yet.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.