Perspectives · 5 min read

Risk management is a leadership discipline. Not a register.

Most organisations I have worked with have a risk register. Fewer have risk management.

The register is usually in good shape. Colour-coded, scored on likelihood and impact, updated before the audit committee meets. It looks like control. And that is precisely the problem: it looks like control to the people who most need to know when control is missing.

I have spent years on the advisory side of risk – in Big Four risk advisory, running information security and business continuity management systems across Nordic organisations – and later on the other side of the table, as a CEO with a budget, a board and risks that did not wait for the quarterly review. The distance between those two seats taught me more about risk management than any framework did.

This is what I would tell a board or an executive team today.

The register is not the work

A risk register is a snapshot of what someone was willing to write down at a particular moment. It is useful. It is also the least important part of risk management.

The work is the conversation that happens before the register is filled in: which risks are we actually prepared to take, who owns them, and what would we do differently if we took them seriously? When that conversation does not happen, the register becomes a compliance artefact – something produced for the board rather than by the leadership.

You can usually tell within a few minutes. Ask the executive who "owns" a top-five risk what they have changed in the last six months because of it. If the answer is a longer pause than the question deserved, the risk is being reported, not managed.

What good looks like

Good risk management is unglamorous. It is a small number of risks that leadership actually talks about, connected to decisions they actually make.

In my experience the organisations that do this well share a few traits:

They start from the strategy, not from a taxonomy. The question is not "what could go wrong in category 4.2?" but "what has to be true for our strategy to work – and what would break it?" That reframing turns risk from a defensive exercise into a strategic one.

Risk owners are people with budgets. If the owner of a risk cannot move money or change priorities, they are not an owner. They are a reporter. I have seen far too many risk registers where the "owner" of cyber risk was a security manager three levels below the person who could actually fund the mitigation.

Appetite is stated in words the business understands. "Low appetite for operational risk" means nothing. "We will not launch a customer-facing product without a tested rollback plan" means something. The second one costs the leadership team a decision. That is the point.

The board asks about what is not on the list. A mature board spends less time validating the top ten and more time asking what has been left out, what has changed since last quarter, and where management is more comfortable than it should be.

Do and don't

Do limit the executive risk conversation to the handful of risks that could genuinely change the company's trajectory. Everything else belongs in the line.

Do insist that every material risk has a named owner with the authority and the budget to act – and check that they have actually acted.

Do connect risk to decisions. If the register is not referenced when the company makes an investment, enters a market or restructures, it is not doing its job.

Do revisit the register when the world changes, not when the calendar says so. A regulatory shift, a new supplier dependency, a key resignation: these are triggers, not agenda items for next quarter.

Don't confuse scoring with thinking. Likelihood × impact is a way to order a list. It is not a way to understand a risk.

Don't let the risk function own the risks. Risk, compliance and security teams should challenge, aggregate and facilitate. The moment they become the owners, the business has quietly outsourced its responsibility.

Don't treat a green rating as a reason to stop asking. Green often means "no one has looked recently".

Don't hide behind the audit committee. If the full board only hears about risk through a sub-committee summary, the board is not governing risk. It is being informed of it.

A reminder

The purpose of risk management is not to avoid risk. It is to take the right risks deliberately, with open eyes, and to know early when one of them is turning against you.

Everything else – the register, the heat map, the framework – is scaffolding. Useful while you build. A problem if you mistake it for the building.

---

Maj Britt Arberg is the founder of House of Moon. She has spent years in Big Four risk advisory, has run information security and business continuity management systems across Nordic organisations, and has carried risk from the CEO's chair. She advises boards and leadership teams on risk, governance and resilience.