No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

14 Risk Oversight Principles You Haven’t Heard Before

Are you doing enterprise list management or enterprise risk management?

by Jim DeLoach
March 24, 2026
in Risk
executive risk oversight mini figurines

Protiviti’s Jim DeLoach offers 14 principles on risk oversight that you probably haven’t heard before — and even if you have, now’s a good time to review them. 

Last month, I shared 14 risk principles that you’ve probably heard before. Here are 14 more; these, you may not have heard before. Even if you have heard them, I hope they stimulate your thinking.

No matter what you think about your risk reporting, it can be improved

If leaders are drowning in data with little knowledge or insight, it is easy to assume that risk reporting needs improvement. But in the digital age, risk reporting is a process that should be continuously improved as the needs of executives and directors evolve. Real-time data integration and AI-powered data analytics enable continuous risk monitoring by merging information from multiple systems and sources, both external and internal. Interactive dashboards make risk data more transparent for leaders. Automation streamlines data collection and reporting, reducing manual errors, saving time and ensuring timely risk reports for decision-makers and stakeholders. Digital tools make it an imperative to keep risk reporting fresh and informative on an ongoing basis.

Embed risk management processes into the rhythm of the business

A process for reporting risks upstream, including all the way to the boardroom, is important. But it is just as critical to integrate capabilities for identifying, assessing, mitigating and reporting risks within the business itself consistent with how it is run and managed. Otherwise, these enterprise risk management (ERM) capabilities, which are intended to inform decision-making, remain a mere appendage to the core management processes that matter.

Board the digital train or be left at the station

Digital transformation is the big game in town. Every function of the business is embracing digital innovation to improve quality, time and cost performance. But is risk management keeping up? If risk managers still devote hours preparing manual reports and presentations and decision-makers lack real-time risk information, it is just a matter of time before the relevancy of risk management is called into question. 

ERM should harness the organization’s collective expertise

Risk management works best when diverse perspectives — including those from managers in customer service, production and procurement — inform strategic decisions. Annual Protiviti and NC State University ERM surveys over the past 14 years show that the risk perspectives of C-level executives and directors differ. Thus, broad involvement ensures risk responses are grounded in practical experience. Even in the digital age, collaboration and varied viewpoints remain essential for robust risk discussions and monitoring. The bottom line: What gets discussed gets understood.

rhinos in brush
Governance

Back to Basics: 14 Risk Oversight Rules You Know (But May Be Ignoring)

by Jim DeLoach
February 23, 2026

Cognitive bias, concentration risk and third-party dependencies haven't disappeared just because we have advanced digital tools to identify patterns and anomalies

Read moreDetails

Just because something hasn’t happened to us doesn’t mean it can’t

It is human nature to assume a bad thing won’t happen to us, but readiness requires asking, “What if it does?” For example, cyberattacks, natural disasters or supply chain breakdowns may seem unlikely — until they happen. The reality is this: Those who are unprepared often face the most severe consequences.

Focusing solely on risk without considering opportunity reduces access to senior leaders

How many senior executives and directors can name a chief risk officer who has advised them that the organization is too risk averse? In the digital age, not enough. For sure, risk is important. No one will admit it, but discussions of risk without linkage to opportunity create a limited attention span for senior leaders focused on transforming the business, achieving top-line growth and improving margins. An exception might be when the risk discussion provides fresh insights and decision-making options on significant threats that leaders didn’t previously understand. Otherwise, a narrow focus on risk can be seen as setting boundaries around opportunity-seeking behavior, e.g., risk is a constraint. In reality, it can be — and in some cases, it should be. But opportunity is the language of growth, a priority in most C-suites and boardrooms. The point is clear: Discussions of risk linked with opportunity and vice versa are more interesting to senior leaders.

Establish balanced incentives to drive behavior

Incentives underpin behavior, decision-making and overall organizational culture. Properly designed, they can drive individuals and teams to prioritize risk awareness, compliance and proactive management of potential threats. Conversely, poorly designed incentives may lead to reckless risk-taking, as seen during the 2007-08 financial crisis. By designing incentive structures to enhance accountability, promote collaboration and sharpen the focus on risk, organizations can improve their ability to mitigate risks as they pursue their objectives. Effective incentive systems balance entrepreneurial opportunity-seeking with a sound control structure so that neither one is too disproportionately strong relative to the other.

Focusing on agility and resilience transforms how one thinks about risk management

In today’s markets, flexibility and the ability to pivot is crucial. All risks are important, but some can be existential in disruptive markets. In the 2007-08 financial crisis, institutions that tested asset values in selected markets were able to identify a steep decline in housing prices across the US before it became common knowledge. They got a head start of as much as 14 months in reducing their exposure, a time advantage that made a huge difference. Early movers to exit an obsolete strategy always end up in a better position.

If you just keep a list, you’re not managing risk

Periodic risk assessments generate lists of risks. If nothing is done beyond the assessment itself, the organization is practicing what I call “enterprise list management,” not enterprise risk management. Management needs to incorporate actionable steps in the business plan to address the priority risks and establish accountability for their timely execution.

Agree at the top when to play it safe and when to roll the dice

Discussions on risk appetite at the top of the organization regarding how much risk it is prepared to accept in pursuing its objectives is foundational for aligning risk-taking with its strategy, culture and values. It is not a mere documentation exercise. Used effectively, the risk appetite dialogue ensures managers understand the risk/benefit trade-offs — determined at the top — that frame the boundaries within which decisions are made, thus providing a critical prerequisite for actionable decision-making and the allocation of capital and resources to initiatives that best match the organization’s capacity for risk. As a strategic tool and guiding framework, it transforms second-line risk functions from perceived obstacles to valued partners in safely pursuing opportunities. In its absence, decision-making processes can become ad hoc, directionless, inconsistent and slower across the business.

High-quality decisions should be made at market speed

Risk oversight drives decisions, and the speed of business dictates the speed of oversight. To that end, decision quality is not enough. Many large companies make high-quality decisions but make them slowly. Fast decision-making means simplifying processes, avoiding excessive structure, minimizing overplanning, prioritizing customers, accepting calculated risks and valuing feedback. Most choices can be made with around 70% of the desired information; waiting for more often delays progress. Leaders should adjust as needed and address misalignment promptly.

Every action has a reaction; watch out for unintended consequences

Thoughtful decision-makers consider the potential for unintended consequences when formulating strategy and planning risk responses. Companies operate in interconnected environments in which actions in one area may ripple across others. These cascading effects can lead to financial loss, reputational damage, regulatory penalties or operational disruptions. Examples include layoffs affecting culture and morale, or technology upgrades increasing security risks. Proactively planning for these outcomes enables better choices and preparedness.

The best risk discussions may be the ones taking place informally

Within a culture of collaboration, transparency and open dialogue, spontaneous daily exchanges between functional and unit leaders about their impact planning, execution and response decisions are the ideal time and place for addressing risk all across the organization. This kind of risk awareness and savviness reflects a culture where everyone shares responsibility for managing risk. If these conversations occur naturally across the company, they can be as influential as scheduled formal discussions in the C-suite and boardroom.      

There is a cost to ignoring risk

Every decision carries inherent risks. Organizations have a risk appetite whether they choose to acknowledge it explicitly or not. Integrating risk into decision-making is crucial for pursuing growth responsibly. Failing to identify or address risks can lead to greater costs over the long run, including financial losses, reputation damage and missed opportunities for innovation.

Perseverance, diligence and strategic thinking are key to understanding and managing organizational risks. As expressed in the saying, “The best view comes after the hardest climb,” effective risk oversight is challenging but leads to valuable insights for better decisions and resilience. Ultimately, strong risk management helps organizations achieve their goals amid uncertainty.

To that end, I hope the risk oversight truisms I have shared above and in my previous article offer some useful ideas and pathways for elevating the effectiveness of ERM and risk oversight. While I am sure there are others, I am confident the ones I have suggested offer sufficient food for thought.   

Tags: Board of DirectorsEnterprise Risk Management (ERM)
Previous Post

Measles Is on the Rise. Have You Reviewed Your Vaccine Policies Since Covid?

Next Post

Effective AI Policy Is Not a Crock-Pot; You Can’t Just Set It and Forget It

Jim DeLoach

Jim DeLoach

Jim DeLoach, a founding Protiviti managing director, has over 35 years of experience in advising boards and C-suite executives on a variety of matters, including the evaluation of responses to government mandates, shareholder demands and changing markets in a cost-effective and sustainable manner. He assists companies in integrating risk and risk management with strategy setting and performance management. Jim has been appointed to the NACD Directorship 100 list from 2012 to 2018.

Related Posts

news roundup bundled papers

Executive & GCs at Odds Over Legal’s Business Contributions

by Staff and Wire Reports
April 17, 2026

And why aren’t all boards talking about AI?

news roundup_june 14 2024

US Regulatory Fines Plummet in 2025

by Staff and Wire Reports
March 19, 2026

Majority of orgs report breach involving AI

vintage board of directors

Audit Committees: Resilient or Reactive?

by Pat Niemann
March 10, 2026

From scenario analysis to portfolio resilience reviews, the audit committee’s role in 2026 looks considerably different than the one most...

rhinos in brush

Back to Basics: 14 Risk Oversight Rules You Know (But May Be Ignoring)

by Jim DeLoach
February 23, 2026

Cognitive bias, concentration risk and third-party dependencies haven't disappeared just because we have advanced digital tools to identify patterns and...

Next Post
ai policy concept collage

Effective AI Policy Is Not a Crock-Pot; You Can’t Just Set It and Forget It

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2026 Corporate Compliance Insights