For quantitative risk management to work: a governance problem Many discussions about Enterprise Risk Management have revolved for years around expert assessments, risk maps, and colorful traffic lights, without much changing in practice. Perhaps the real problem lies one step earlier: in the governance of risk management. In their governance, companies often simply demand what is checked externally. • Is there a risk inventory with risk owners? • Are risks surveyed regularly? • Is there a report to the board? • Is everything documented? What is barely demanded, on the other hand: • an explicit causal model • traceable parametrization • validation of the risk assessment • systematic review of the inventory's completeness In other words: Governance does not reward the quality of insight. For better governance, you would not need to require auditors to reassess every risk model on the merits. It would already be enough to introduce structured minimum requirements. For example: 1️⃣ An explicit model must exist for every risk. The auditor does not need to decide whether the model is perfect. Only whether it was modeled in a structured way at all. 2️⃣ A model should contain at least: • a clear description of the risk's mechanics • drivers and influencing factors • documented assumptions • probability of occurrence and loss estimate as a result of the model • date of the last review This, too, can be checked without difficulty. 3️⃣ Not just the assessment, but also validation of the assessment should be required. For example: • review of the risk drivers and the assumptions • comparison against actual loss events • data or benchmarks for risk drivers • documented model revisions The auditor does not validate it themselves, they only check whether validation took place. 4️⃣ Minimum requirements for the completeness of the risk inventory Another lever would be a structured negative proof that risks typical for the business model are indeed absent. • no cyber risk? • no supply chain risk? • no product liability risk? • no staffing shortage risk? This would make many of today's omission errors considerably harder. Governance cannot guarantee that the “true” risk situation has been recognized. But a company should require, within its governance, that risks be structured rationally. Governance can ask: “Is what you did even suitable for generating insight?” That alone would already be enormous progress. My thesis: As long as governance does not address analysis quality, risk management will inevitably become a mere reporting function. If governance instead demands structural and model quality, quantitative approaches would automatically become standard tools of the trade. In aviation, safety did not improve through more experience, but through better checklists. Perhaps ERM today faces a similar governance question.

This post was originally published on LinkedIn. View and join the discussion there