Risk Management as Part of Decision-Making
Hundreds of entries in the risk register. A colour-coded heat map. Regular risk committee meetings. Yet no clear answer to the question that matters most: what needs to change in the decision?
That is what risk management looks like when it becomes a compliance exercise. The risk function is brought into discussions about investments, new products or market entry too late, when the decision has effectively been made and all that remains is a formal sign-off.
Elina Moshkovich, a risk management consultant and former Chief Risk Officer at Allianz and MetLife, believes risk management should not sit alongside decision-making as a separate control process. It should be built into the decision itself.
Risk Exists Only in Relation to an Objective
Risk is often defined as any adverse event or potential loss. The definition is so broad that it offers little practical help to managers.
A more useful view is that risk represents uncertainty around events that may affect the achievement of an objective. The same development may be critical for one company and largely irrelevant to another. Its significance depends on the strategy, current priorities and time horizon.
The same event may or may not represent a risk

A decline in revenue among major borrowers, for example, becomes a risk for a bank that is trying to reduce non-performing loans. A three-week delay by a sole supplier is a clear risk for a manufacturer committed to opening a plant by a fixed date. The arrival of a similar product in another market segment, however, is not automatically a risk for a technology company. That depends on what the company is trying to achieve.
Uncertainty can also work in a company’s favour. A currency movement, the withdrawal of a competitor or the early award of a major contract may create an opportunity. A company that prepares only for adverse events, but cannot move quickly when conditions turn favourable, leaves potential value on the table.
A shared language is also essential. If the CFO thinks of risk as the probability of financial loss, the COO sees it as any unexpected event and the legal team defines it as apotential breach of regulatory requirements, they are not really discussing the same thing.
Why the Formal Model Stops Working
Traditional risk management is often presented as a sequence: identify the risks, assess them, define mitigating actions and monitor the outcome. The process may be perfectly well designed and still run in parallel with the company’s actual management cycle.
The better approach is to make risk management part of strategic planning and everyday business activity. Its elements then work together rather than appearing as a series of separate exercises.
This also changes the purpose of the risk function. Its job is not to compile the longest possible list of threats. It is to test the assumptions behind a decision and show where those assumptions may fail.
In practice, formal risk management systems tend to break down in four places.
1. The Risk Register Captures Concerns, Not Decisions
Risks are often identified through past incidents, standard taxonomies and issues that make executives uncomfortable. Before long, the organisation has a spreadsheet containing hundreds of entries.
A risk register can be methodologically sound and still be of little use to management

It may contain categories, owners, probability and impact scores, and detailed mitigation plans. But a statement such as “economic instability may affect the business” tells management very little. It does not identify the objective at risk, the circumstances that would require intervention or the decision that may need to change.
At one international company, the COO was listed as the owner of more than 40 risks taken from a group-wide taxonomy. Although he had participated in the annual reassessment for several years, he did not understand 13 of them. In practice, the exercise had become a matter of assigning scores and avoiding the red zone.
This does not make the risk register redundant. It does mean that every material entry needs to be linked to a specific objective and to the decisions it could influence.
2. A Heat Map Does Not Speak the Language of Business
Qualitative scoring based on probability and impact is useful at the start of a discussion. It helps establish priorities, particularly when reliable quantitative data is not available.
But a colour on a heat map does not answer the questions management will ask. What does a risk in the upper-right corner mean in practical terms? What could it cost? How might it affect the sales plan, budget, margin, investment decision or delivery date?
Wherever possible, the impact needs to be expressed through financial consequences, capital, margin, timing or another measurable result. The point is not simply to rate the risk, but to show which management choice sits behind that rating.
3. The Risk Function Arrives After the Decision
The pattern is familiar. A new product has been designed, its budget approved and the main commitments made. Only then do the documents reach the Chief Risk Officer.
The company has completed the formal approval process, but the risk function has little real room to influence the outcome. Too much time, money and management attention have already been invested.
At that point, the risk manager is acting as a controller rather than contributing to the decision. Expertise cannot compensate for being brought in too late.
Companies need to identify the decisions where early risk involvement matters most. These usually include strategic investments, market entry, product launches, major partnerships, automation programmes and significant organisational changes.
4. Indicators Measure Activity, Not Emerging Risk
Key risk indicators are meant to show when an important assumption is beginning to fail. In many companies, however, they simply duplicate operational metrics such as process speed, equipment utilisation, rejection rates or incident volumes.
The business receives a large amount of data but still cannot see that it is moving closer to a strategic risk event. The dashboard creates a sense of control, although it may be tracking the wrong things.
An indicator becomes useful only when it is tied to a threshold, a decision owner and an agreed response. It is not enough to report that a measure has entered the yellow or red zone. The organisation needs to know who acts, what they do and how quickly they do it.
A Practical Chain from Objective to Action
The different elements can be connected through a clear chain:
Strategic objective → Key performance indicators → Risks → Key risk indicators → Risk appetite
Key performance indicators show whether the company is achieving its strategic objective. Risks describe the uncertainties that could affect achievement of that objective. Key risk indicators track changes in relevant risk exposures, drivers or conditions and, where possible, provide early warning before their impact becomes visible in performance. Risk appetite defines the level and type of risk the organisation is prepared to accept in pursuit of the objective and provides the basis for setting escalation thresholds and management triggers.
Suppose a company aims to increase revenue by 30% within a year without sacrificing margin. One customer already accounts for a substantial share of income. In that context, customer concentration becomes a risk to the growth objective.
Management might set a concentration threshold of 25% and treat 30% as a stop signal. If that level is reached, the response should go beyond marking the indicator red. The company may need to reconsider its customer mix, target segments or rules for accepting new business.
Risk Analysis Belongs in the Business Case
For significant decisions, a short pre-decision risk assessment can be included directly in the business case. It does not need to become another lengthy report.
The assessment can set out the proposed decision, the strategic objective, the key assumptions, the consequences if those assumptions prove wrong, the safeguards required and the position of the risk function. This brings uncertainty into the discussion while alternatives are still open, rather than after management has selected its preferred option.
The timing matters more than the format. The Chief Risk Officer needs to be involved while the alternatives are being developed, when the structure of a transaction, product or project can still be changed.
Disagreement Needs a Clear Route
Early involvement will make little difference if objections from the risk function are simply recorded in the meeting minutes and then ignored.
The escalation route needs to be agreed before a disagreement occurs. The organisation should know who raises the issue, which committee or governing body considers it, how quickly the matter must be reviewed and who makes the final decision. Without a clear route, the outcome is likely to depend on hierarchy and the political influence of the people involved.
A Pre-Mortem Can Reveal Risks Before They Materialise
One practical technique for projects and new products is a pre-mortem.
The team imagines that a year has passed and the project has failed. Each participant identifies possible reasons. The group then compares the answers and considers which risks have been overlooked, which assumptions appear too optimistic and which safeguards are missing.
This creates room for honest scepticism and reduces the influence of groupthink. Participants do not have to challenge an approved idea or contradict a senior executive directly. They are analysing an agreed failure scenario, which makes it easier to raise concerns that might otherwise remain unspoken.
What Companies Should Check
A company does not need to redesign its entire risk management framework at once. Three questions offer a useful starting point.
At what stage did the Chief Risk Officer first see the company’s last three strategically important decisions? If it was only after management had chosen an option and approved the budget, the risk function entered too late.
When did one of the five most significant risks in the register last change a specific business decision? If nobody can provide an example, the register may exist for reporting rather than management.
What happens when the Chief Risk Officer disagrees with the business? If the escalation route, thresholds and deadlines are unclear, the process remains largely formal.
Risk management does not become part of the business simply because the risk manager has a seat at the table. It becomes part of the business when their involvement creates a genuine opportunity to change the decision.
Fraud in fintech: the price of convenience
Fraud in fintech is no longer just a security concern. It shapes growth, trust and regulatory scrutiny. This article explores the trade-offs between convenience and control, what works in practice, and how risk strategy evolves as companies mature.
BI for KPI Monitoring: How to Manage Performance Every Day
Managing KPIs throughout the month takes more than frequent reporting. It requires consistent data, agreed calculation rules and a system that highlights performance gaps while managers can still act. Freedom Bank Kazakhstan built this model step by step, moving from Excel reports to a DWH and the daily use of BI.