In this series ...

Governing risk & how to be at ease with it

We opened this blog series with a post that showed how risk is part of all our actions and all the decisions we make. Even when we take an action to avoid some danger, we are exposing ourselves to another set of risks. For example, one may choose to spend some time on leisure activities outdoors to remediate the negative consequences of desk work; and while that generally is a great idea, by doing so he or she unavoidably increases the risk of acute injuries, sunburn, and the long-term risk of skin cancer. Simply put, avoiding risk completely is impossible.

Car driving near a cliff at dusk

We accept many risks on a daily basis, mostly subconsciously, by not even thinking about them. But many of us struggle when we start to manage risk formally, as almost certainly there is a non-trivial amount of risk left open. Before we look at concepts that should provide some comfort, let’s first discuss the functions present when handling risk. Sometimes these functions are played by a single person, but in bigger organisations they are typically executed by different people.

Risk governance, management and ownership

Most of us have an intuitive understanding of the difference between governance and management, when talking about the terms in a single context:

  • Governance is about creating a vision, providing direction and setting boundaries.
  • Management, on the other hand, deals with execution and daily operation.

What makes things complicated is that these concepts apply on multiple levels throughout the hierarchy of an organisation. To deal with any issue is, in a sense, to manage it, so management has also become a vague term that can be used for almost anything. For risk, some reputable training materials teach:

In the workplace, every individual has a vital part in ensuring daily safety and supporting a strong risk management culture. Whether a senior executive or a new employee, everyone is considered to be a risk manager.

If we add to that the differences in corporate structures between jurisdictions and legal forms (one-tier boards, two-tier boards, no boards at all), it becomes really difficult to assign these functions to specific roles within an organisation. Instead, it is better to keep them in mind as a lens for analysing the responsibilities within any given scope.

For example, if on the corporate level the overall direction and strategy is set by an executive board, then, in this context, the board has a governing function over the overall corporate operation and the associated risk, while the appointed managers who report to the board carry the highest-level management responsibilities. But if we focus our attention on a specific domain — let’s say technology — then the CTO, or a similar role, who otherwise has a management function from the corporate perspective, now has a governing one: setting the strategy, policies and boundaries within the domain for others to follow.

What matters most for us is to analyse the responsibilities these two functions carry in respect to risk:

  • Governance sets the risk appetite, tolerance and the overall attitude towards risk.
    Those who govern also own the overall risk exposure and are typically held accountable for it.
  • Management owns individual risks within their domain and is responsible for identifying, analysing, evaluating, reporting, treating and monitoring them.
    Management is typically held accountable by those with the governing responsibility.

risk owner
person or entity with the accountability and authority to manage risk
ISO 31073:2022

Pay attention to the authority criterion above. An analyst, for example, never owns a risk; he may help identify and assess it, but he does not have the authority to decide on its treatment. A CTO (to draw from the example above) has delegated authority to decide on issues related to technology. She controls the assigned budget, resources and execution plans, and can therefore reorganise them to effectively treat the individual risks within her domain. But the CTO depends on the budget and other resources provided to her by the executive board. While she is responsible for reporting, requesting and guiding the executives on the matter, it is ultimately their decision how much resource is allocated — and, as a consequence, how much technology risk can be treated overall. The CTO, in this scenario, owns the individual risks within her domain, and the board owns the aggregated, overall risk related to technology, as well as to all other domains.

Our aim here was to clarify the functions themselves and the logic by which ownership follows authority. There are, of course, nuances and limitations we have deliberately left aside: what happens when a risk exceeds the authority of its owner, for instance, or how ownership formally transfers when it does. These deserve proper treatment, and we will return to them later in the series when we cover risk escalation and the operation of the risk management process.

Formalising risk boundaries — a silver bullet against risk anxiety

Research shows that people worry less about the size of a threat than about not knowing where they stand with it (Grupe & Nitschke, 2013 ). Yes, the section heading is an overstatement, but what we discuss below comes as close as possible to a generic remedy that a risk management framework can offer against risk-driven anxiety.

We all have boundaries

Whether they are written down or not, every person or organisation already has boundaries on what risk is acceptable. Every decision, every activity, and the overall culture of an organisation reflect them. However, when those boundaries are not formalised, they need to be deduced from our behaviour. When written down, they become the primary criteria for deciding what is acceptable and what is not.

Implicit boundaries have two failure modes. They are inconsistent: two managers facing the same risk decide differently, and the same manager decides differently on a Friday afternoon than on a Monday morning. And they are indefensible: when a decision goes wrong, there is no record that the risk was evaluated against any standard at all. Therefore the task is not to invent boundaries, but rather to express accurately what we already have.

Fun fact

A famous study, known as the “hungry judge effect” , found that judges granted parole in about 65% of the cases early in the morning, or right after a lunch break, with approvals dropping almost to zero as more time passed since their last break. Its findings have since been disputed but the broader point survives: our decisions are not immune to decision fatigue, hunger and mental depletion.

Risk capacity, appetite and tolerance

There are three types of boundaries that are commonly recognised across frameworks:

  • Risk capacity is typically recognised as an organisation’s ability to absorb risk without compromising its financial stability.
  • Risk appetite is typically recognised as an organisation’s willingness to pursue or retain risk.
  • Risk tolerance is typically recognised as an organisation’s readiness to bear a risk.

We intentionally do not provide specific definitions of the terms here because, while the terms are common across frameworks, there are nuances and occasionally significant discrepancies in how they are used or in the concepts they represent.

For example, ISO does not formally define risk capacity at all. Risk appetite and tolerance are defined in ISO’s risk management vocabulary (ISO 31073 ), yet ISO 31000 itself never uses the term risk appetite, but rather expresses the same idea through risk criteria. Sometimes risk tolerance is set to be a quantitative expression of risk appetite, while at other times — as in COSO’s enterprise risk management framework — capacity and appetite are the boundaries, and tolerance is seen as an acceptable variation in performance relative to the achievement of objectives.

For the target audience of our blog it is safe to understand risk appetite as a threshold which ideally sits above our overall risk. Risk tolerance is an uncomfortable higher threshold below which we can still accept a risk, but typically only temporarily and if strongly justified. Risk capacity is the highest threshold and the most objective one. Materialised risk beyond it puts the survival of the organisation in question.

For the rest of this post we will only consider risk capacity as a factor that informs the other two boundaries, and we will focus our attention on risk appetite and tolerance, the two thresholds on which most risk decisions depend.

Formalising risk appetite

As mentioned above, a manager who makes risk decisions already has a mental model of what the organisation’s risk appetite is. But, as also stated above, it is those who have the governance function within a certain scope who are held accountable for the overall risk, and therefore ultimately responsible for setting the risk appetite. In practice, the governing body and the managers must work together to produce an appetite statement that is useful for both parties.

At minimum, the mental model should be written down and signed off. Either the managers express their understanding and ask for approval from the governing body, or the governing body proactively produces the statement and consults management on whether they can work with it. This can look something like:

To support our growth objectives, we accept substantial risk when entering new markets and developing new products, as long as no single initiative can endanger more than one quarter’s operating profit. We accept only minimal risk to the confidentiality of customer data and to our standing with regulators, and we accept no risk to life and safety.

Such statements already have a positive effect in reducing anxiety around risk: managers don’t have to guess what is acceptable, and those who govern don’t have to worry whether the managers share their understanding of it. But descriptive language leaves a lot of room for interpretation. What exactly is “substantial”, and where does “minimal” end? Vague wording invites disagreement after the fact, as well as finger-pointing when a materialised risk lands in the grey zone. This is why we prefer a quantified expression of risk appetite.

Decision theory offers a method for doing this. A decision-maker’s attitude to risk is described by a utility function . The function attaches a perceived value to outcomes of different types and sizes. A risky option is then acceptable when its expected utility — the probability-weighted value of its possible outcomes — is higher than that of the alternative.

Example of three utility curves

A risk-seeking (risk-inclined) person has a utility function which, when plotted, produces a convex curve (bending upwards). A risk-averse person has a concave utility curve (bending downwards). A truly risk-neutral person has a utility function that plots as a straight line. Most people (and by extension organisations) are risk averse in most situations, but the real problem is how to define a utility function that accurately represents the degree of risk aversion (or perhaps inclination) one has. Additionally, most people have a different risk appetite for different types of risk.

A practical solution is to observe the behaviour of the organisation with respect to different types of risk, and to propose a function that roughly expresses the perceived aversion or inclination — typically a power function. A more sophisticated approach is to elicit the function through a structured series of choices between certain outcomes and gambles — the certainty-equivalent method from expected utility theory.

Exploring these concepts deeper is far from what a blog post or two can do. But we encourage you to lookup the key concepts and explore them further.

A more practical approach — the risk tolerance curve

If you find the quantification of risk appetite above appealing, you can skip this section. If you modelled your risk appetite using a utility function, then tolerance can simply be defined as a certain offset from it. However, defining a good utility function is difficult and, we argue, unnecessary.

One obvious question that you might have asked yourself by now is: why do we need two boundaries for accepting risk? If risk tolerance is the actual upper limit and we try to minimise the overall exposure, what do we need risk appetite for?

Well, there are two reasons. Traditionally, risk appetite is defined as a level of risk the organisation is willing to take. This is not simply a level of risk the organisation is OK with, but a level of risk the organisation intentionally seeks in order to pursue some goal. Imagine a bank that minimises default risk and lends only to flawless borrowers; it will earn almost nothing, as the margin lives in lending to imperfect ones. This is true for any case where risk is the source of the reward. The other reason is more procedural and has to do with who is authorised to decide on the treatment of a certain level of risk: risk that sits below the appetite level is considered business as usual and is decided on by managers, while risk above the appetite threshold needs decisions by those with the governing function.

Chances are, if you are reading this blog, you are not in the business of lending money, nor do you directly capitalise on the level of risk you are taking. For most projects, programmes and organisations, instead of defining a risk appetite that assumes a certain level of reward, it is more practical to define a threshold up to which risk can be tolerated, and to balance the return from risk treatment options by comparing the cost (investment) of the option to the gain (reduction of risk) — traditional return on investment (ROI), or, as we will discuss in later posts, return on control (ROC).

To quantify the risk tolerance we follow Hubbard’s method of defining a risk tolerance curve (RTC). The method follows an elicitation process similar to that for a utility function, but instead of asking the rather abstract question of how much we value things, it asks a more concrete one: how much loss are we prepared to accept, given a certain probability? The acceptable loss is defined for several probabilities, and the complete curve is interpolated from those points.

Example of a risk tolerance curve

With the risk tolerance curve approved (signed off) by the governing function, risk management becomes a game of keeping the overall risk below the curve. If a lower boundary is needed for the procedural reasons above — assigning the responsibility for deciding — it can be derived from the RTC.

It is worth noting that, while this approach is more straightforward and more concrete, we are still human and we still suffer from our biases and other cognitive flaws. How the questions are asked during elicitation, or even the time of day at which the elicitation meetings happen, still impacts the answers provided. Calibration training, the certainty-equivalent method and other techniques, which are beyond the scope of this blog, remain beneficial for improving both accuracy and precision.

Free template

Our risk management workbook contains a sheet for defining your own risk tolerance curve. Enter the elicited points and the workbook interpolates the full curve, ready for review and sign-off. The workbook is a LibreOffice file that will grow alongside this series ultimately providing tools such as aggregating risk and Monte Carlo simulation.

What’s next

In this post we looked at governance and management as two functions related to risk management, and briefly discussed the responsibilities they imply. Those with a governing position own, and are held accountable for, the overall risk. They provide a vision, give direction, set boundaries, and oversee. Managers own the individual risks within their domain and act on them according to the direction and boundaries they are provided with. We also looked at a few of the most common risk boundaries (capacity, appetite and tolerance), and discussed some practical approaches to quantifying them. The main premise of this post is that ambiguity feeds anxiety and, by formalising the roles and responsibilities as well as the risk boundaries, we create clarity which relieves it. As a bonus, to help readers quantify their risk boundaries, we added a downloadable workbook that implements some of the techniques covered.

In the next post we turn to risk assessment — and its first sub-step, risk identification.

Two approaches to managing risk