Awakening the self-healing powers of risk management Does a risk manager really trust the risk assessments reported to them? And do they trust the risk inventory coming from the business units? In many cases, probably not. Because the risk inventory is rarely complete, and expert estimates are ill-suited to realistically working out, in one's head, the overlap of causes and causal relationships. This is not about bias or a lack of diligence, but simply about being overwhelmed: the relationships are too varied, the uncertainties too large. And the assessments often come from the very people who caused the risk themselves. Someone who triggered a risk themselves is hardly unbiased when asked to assess it. How can you create a system that regulates itself, one in which assessments once again deserve trust? I propose two rules: 1. Risk management bears the cost of all risks that materialize. It does not matter whether the risk was in the inventory or not, risk management pays for all of it. Because its mandate is to capture, assess, and make risks financeable, completely. 2. Every originator sells their risks to risk management. No risk may be taken on unless it is acquired by risk management at an agreed price. After that, risk management manages the risk, it decides on measures, priorities, and hedging. This would make risk management truly what it should be: a market for risks that brings together trust, accountability, and price formation. What is your view of this form of organization? If you are looking for software you can trust for your risk assessments, feel free to reach out to me.

This post was originally published on LinkedIn. View and join the discussion there