Skip to main content
Back to insights

Risk Management

Turning Uncertainty into Strategic Advantage

Published 12 May 20263 min read
A narrow mountain ridge trail leading towards a bright sunrise

Why forward-looking organisations are embracing risk management as a driver of growth and resilience.

Most organisations still treat risk management as a defensive function — a register maintained because an auditor asks for it, reviewed quarterly, and largely disconnected from how the business actually makes decisions. That framing is expensive, because it wastes the one thing a good risk process produces: better information than your competitors have.

The organisations that get real value from risk management share a common trait. They use it to decide where to place bets, not only where to place controls.

From register to decision tool

A risk register that lists forty items scored red, amber and green tells leadership almost nothing. It cannot be used to choose between two investments, because it does not express exposure in a comparable unit. The first shift is to quantify: what is the plausible annual loss, what is the range, and what would it cost to move that range?

This does not require elaborate modelling. A structured estimate with explicit assumptions and a stated confidence range beats a colour-coded matrix every time, because it can be argued with — and arguing productively about assumptions is how organisations learn.

Consider the difference in practice. "Ransomware — high likelihood, high impact, red" cannot be acted upon. "A ransomware event affecting order processing would cost us between €400,000 and €2.1 million, driven mainly by four to nine days of manufacturing downtime; segmenting the production network and proving our restore path would move the upper bound below €700,000 for a one-off spend of €95,000" is a business case. The second version invites challenge on every number, which is exactly what makes it useful.

The colour-coded matrix also hides a technical flaw: ordinal scores cannot legitimately be multiplied or averaged. Ranking a "4 × 4" above a "5 × 3" implies arithmetic that the underlying scale does not support. ISO 31000 is deliberately agnostic about method, but it is explicit that analysis should suit the decision being made — and investment decisions are made in currency and time, not in colours.

Risk appetite as a permission structure

A well-defined risk appetite is not a constraint document. It is a permission structure that lets teams move faster within known boundaries, escalating only when they approach a threshold that genuinely warrants senior attention.

When appetite is undefined, every non-standard decision travels upwards. Leadership becomes a bottleneck, and the organisation slows down precisely where speed matters most.

Useful appetite statements are specific enough to be self-applying. "We accept outages of up to four hours on internal tooling, but no unplanned downtime on customer-facing order capture during business hours" lets an engineer decide on a Friday afternoon whether a deployment needs sign-off. "We take a prudent approach to operational risk" does not, and functions mainly as decoration in a governance pack.

The test of an appetite statement is whether anyone has ever declined something because of it. If nothing has been refused, deferred or escalated by reference to the threshold in a year, it is not calibrated — it is aspirational, and the organisation is still deciding case by case.

Make the trade-off visible

Risk work earns credibility when it shows what an option costs as well as what it protects. Every control consumes something scarce: capital, engineering time, operational flexibility, or speed to market. A recommendation that acknowledges only the upside reads as advocacy rather than analysis, and experienced executives discount it accordingly.

Presenting three options — accept, mitigate at a stated cost, or transfer — with the residual exposure attached to each moves the conversation from whether the risk function is being alarmist to which trade-off the business prefers. That is a conversation leadership is equipped to have, and it is the one where their judgement genuinely adds value.

Where to start

Pick the three decisions your organisation will make in the next twelve months where uncertainty is highest and the cost of being wrong is greatest. Build the risk analysis around those decisions rather than around the control framework. The register can follow.

Set a review rhythm that matches how quickly the underlying exposure actually changes. Quarterly review of a register that moves annually is theatre; annual review of a supplier concentration that shifts every month is negligence. Tie the cadence to the volatility of the thing being measured, not to the governance calendar.

Done well, risk management stops being the function that says no and becomes the function that explains what it would take to say yes.

Portrait of Olha Mann, Founder and Principal Consultant of LEONIS

Olha Mann

Founder & Principal Consultant

CISSP · CISM · CEH · ISO/IEC 27001:2022 Lead Auditor

Related insights