Policies, risk registers and risk committees do not necessarily mean that a company is managing risk. The system begins to add value when it helps to take better decision before a mistake becomes irreversible. This article looks at how to connect risk with business objectives, involve the risk function earlier and turn indicators into management action.
Corporate fraud is usually blamed on the individuals involved. But there is another question worth asking: which management decisions allowed the misconduct to begin, spread and remain undetected? Drawing on two anonymised cases, Elina Moshkovich shows how conflicts of interest, poorly designed KPIs and weak control functions can turn isolated abuse into a systemic business risk.