RSS Amplifier

Risk Governance by Crestview.io · May 19, 2026

Responding to Risk in the Organization

0
Sign in to vote or save

Brian Howell · Risk Governance by Crestview.io

If business is the pursuit of economic opportunity despite the associated risks, then business is inherently full of risk. Knowing the potential risks involved in any business process will help leaders consider in advance how they will manage and respond to those potential outcomes.

Rethinking Risk: A Governance-Led Risk Strategy

You can respond to all risk, both personal and professional, in one of three ways:

Also known as risk mitigation, you can manage business risk through a combination of controlling, avoiding or transferring the risk. This approach requires a clear understanding of your organizational goals, the business processes built to support them, and the risks that can impact them.

Without a clear understanding of your goals and business processes, it will be hard to make decisions to manage the risk consistent with the concepts explored in the Core Strategies for Managing Business Risk article.

Assuming you do not have contractual or regulatory requirements to address the risk, the business could certainly make the business decision to accept the risk. Knowing the consequence and likelihood of the risk coming to fruition would certainly factor into any decision to accept a risk. This assumes that business leaders are aware of the risk, the impact of accepting it, and have the authority to take that risk on behalf of the organization.

A formal risk acceptance process can improve risk management outcomes as noted in the Building an Effective Risk Acceptance Process article.

As explored in the Four Stages of Risk Management Maturity article, there are two plausible reasons risk is ignored in an organization. The first is that leadership is effectively ignorant of the risk, lacking the visibility or knowledge required to recognize it. The second is willful ignorance, where leaders either know, or should know, the risk exists and choose not to address it.

To know you have a risk and to not formally make a decision to manage or accept the risk is irresponsible and actually exposes you to a greater degree of uncertainty.

At least with accepting the risk, the organization will have done the work to understand the likelihood and consequence of taking the risk and how it could impact the goals of the organization.

Perhaps you have a wildly successful business, but you have never taken the time to consider the business through a risk management lens. A short roadmap could look like this:

  • Identify strategic risks that if realized would result in an increased likelihood that the organizational objectives would not be met.

  • Identify business process risks that if realized would put the business process operating as designed in jeopardy.

  • Identify operational risks that if realized would result in a negative financial outcome that is not tenable to the stability of the business.

While there are many ways to methodically step through this process, using a framework to guide the conversation will shorten the time to understand and manage risk within the organization and provide a greater chance to sustain the effort. As an example, Crestview.io is a risk governance platform designed to help leaders identify, assess and visualize the risk within their organization.

  • For risks that you are currently managing, how often do you review your risk mitigation strategy?

  • If you have any accepted risks, were those decisions made in view of the organization’s risk appetite?

  • Are there any current risks that your business is currently ignoring?

Would you like to discuss this topic further? Contact Brian Howell from Crestview.io

Find this article helpful? Thank you for sharing Risk Governance by Crestview.io with others!

Share

No posts

Read the original on riskgovernance.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.