Home · Risk management

Risk management a board can actually use

A risk register full of technical findings does not help a board reach a decision. Risks are translated into the language of continuity, liability and budget, with reasoning that holds up at audit.

The problem is rarely a shortage of risk information

Most organisations we encounter already have a risk register. Often several: one from quality, one from IT, one from the last audit report. What is missing is not information but translation: a picture in which the board can see which risks genuinely affect service delivery, what the choices are, and what it costs not to make them.

As long as risks are written in the language of technology (vulnerabilities, CVE numbers, outdated firmware), it remains a list a board cannot act on. The question the board asks is a different one: what goes wrong, how bad is it, and what is being done about it?

From technology to board language

The work runs from the outside in. First the services you deliver and the processes they rest on. Then the systems carrying those processes. Only then the vulnerabilities. That sounds roundabout, but it is the only order in which a risk acquires meaning: a flaw in a system carrying nothing critical is a task for operations. The same flaw in the system driving your delivery is a board decision.

The result is a risk picture on a consistent scale, in which technical findings and organisational weaknesses sit side by side and are weighed the same way. That lets you prioritise, justify budget and, increasingly important, demonstrate that you prioritised.

Frameworks: useful, not governing

Established frameworks are used because they provide a shared language and because regulators and customers recognise them. Which framework fits depends on your sector and maturity.

A framework is a tool, not an objective. We have no interest in the heaviest possible implementation: we sell no software, no licences and no certificates.

Governance: who decides what

A risk register without ownership changes nothing. The part of this work that lasts longest is usually the least spectacular: recording who accepts which risk, at what level a decision must go to the board, how often the picture is refreshed and what happens when a measure is not carried out.

Under the Cyber Security Act this is no longer a matter of prudent stewardship. The management body approves the measures, oversees implementation and must demonstrably have sufficient knowledge to make the trade-off. A governance structure that does not support that is a liability risk in itself.

Reporting to the board and to regulators

Reporting is delivered at two levels, because a single document rarely serves both audiences. A board report readable in fifteen minutes, showing the choices and the trend. And an underlying account with the findings, the reasoning and the status of measures, suitable for an auditor or regulator.

That second document is what you need at the moment things go wrong. Demonstrating that you knew a risk, weighed it deliberately and took a reasoned decision is a fundamentally different position from having to reconstruct afterwards what you knew.

What a risk management engagement delivers

Further reading

A risk picture your board can actually work with?

Your risks are reduced to the choices that genuinely matter, with reasoning that holds up under supervision. Schedule an introductory call.

Schedule an introductory call