two men sitting in a cafe window on devices

If Risk Management Is the Answer, What Is the Question?

5 minute read
Norman Marks avatar
We need to stop coming up with new words and phrases when all we need to address is the effectiveness of management.

Roger Estell made this insightful comment on my blog. It merits our thoughtful consideration.

Let’s start with some thoughts about the fundamentals underlying any successful enterprise, whether large or small. If we assume we are all working together to deliver success for the enterprise, how is success measured?

Choosing the Right Metrics to Measure Success

The executive team, from CEO on down, is usually measured based on whether the organization has achieved targets (or metrics) approved by its owners (of their representatives on the board).

Rather than (as in the case of COSO ERM and ICF) assuming those are the right metrics to measure success, I suggest considering:

  • Have the best objectives been set? Were all opportunities and potential hazards of significance considered during the objective (and strategy) setting process?
  • Have the right targets been set? Are they too low, so the executives don’t stretch as much as they should? If they are too easily achieved, there is a temptation to store opportunities for the next period. If they are too high, management may take a level of risk (a potential for harm in this case) that is beyond what the owners consider acceptable.
  • Have performance targets and incentives been established throughout the organization that are consistent with the targets set for the enterprise as a whole? Does everybody understand what is needed from them for the organization to succeed? Are there performance metrics that will lead management (at any level) to act in a way that is inconsistent with enterprise goals?
  • Are objectives, strategies and related metrics adjusted as necessary when conditions change?
  • In other words, is there a reasonable level of assurance that the right objectives (and strategies) are set to deliver optimal levels of shorter and longer-term success?

In a video, risk management advisor Alexei Sidorenko talks about how he worked with the management team to ensure the objectives they set had a reasonable likelihood of success. He used scenario planning and other tools to help management understand that the first targets they set were unreasonable, with only a 1% (or less) likelihood of being achieved. The target was revised and the new one, approved by management and the board, had a projected 70% likelihood of being achieved.

Management and the board accepted that there was a 30% chance of failing to achieve their objective. (A far more reasonable and practical approach than the concept of risk appetite, as the latter only considers the downside and not the big picture of upside and downside.)

Sidorenko used the tools and techniques he learned for risk management to help the organization set reasonable and appropriate objectives, targets, and metrics for success and the measurement of executive performance.

The question to be asked first is: how can we assess the likelihood of success (achievement of our objectives) given a reasonable understanding of what might happen? The answer is not really "risk management," because success is not achieved by managing downside risk. We want to manage for success rather than for avoiding failure.

The answer is the use of the tools and techniques traditionally only used for assessing and evaluating the downside — you can call that risk management if you like. I don’t.

Related Article: Transforming Risk Management in 2019 and Beyond

It's Just Plain Management 

Once the objectives, strategies, metrics for measuring performance, and so on are set, management has to run the business to achieve them.

Learning Opportunities

Management runs the business by making decisions. We hope they are informed and intelligent decisions: informed about what might happen that would affect their achievement, both for the better and for the worse.

How do they get the information about what might happen, both good and bad, on which they will base their decisions? How will they determine whether their decision will improve or negatively affect the likelihood of achieving their objectives? In Sidorenko's case, will each decision they make increase the likelihood of success to above 70% or will that likelihood drop below acceptable levels?

Is the answer to those questions "risk management"? Certainly, the tools and techniques used to assess adverse events and situations, and their effect on objectives, can be used to paint the larger picture.

But I don’t think the answer is "risk management." It’s also not "objective management." It’s effective and intelligent management. It’s the ability to make informed and intelligent decisions, which is the core of effective management.

Related Article: A Basic Principle Most People Don't Understand About Risk

No Need for a New Vocabulary

We need to stop coming up with new words and phrases when all we need to address is the effectiveness of management. So stop talking about ERM, IRM or even objective assurance, and start thinking about how to obtain reasonable assurance that the management of the organization, including how it sets objectives and makes related execution decisions, is effective.

I welcome your thoughts.

About the author

Norman Marks

Norman Marks, CPA, CRMA is an evangelist for “better run business,” focusing on corporate governance, risk management, internal audit, enterprise performance, and the value of information. He is also a mentor to individuals and organizations around the world, the author of World-Class Risk Management and publishes regularly on his own blog.

About CMSWire

For nearly two decades CMSWire, produced by Simpler Media Group, has been the world's leading community of customer experience professionals.


Today the CMSWire community consists of over 5 million influential customer experience, digital experience and customer service leaders, the majority of whom are based in North America and employed by medium to large organizations. Our sister community, Reworked gathers the world's leading employee experience and digital workplace professionals.

Join the Community

Get the CMSWire Mobile App

Download App Store
Download google play