No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

The Hardest Risk to Avoid

by James Bone
November 7, 2014
in Risk
The Hardest Risk to Avoid

What is the hardest risk to avoid?  The risk you didn’t anticipate.  The answer may seem obvious, after the fact, however most firms seldom analyze why.  What is not so obvious are the decisions leading up to the risk event.  It is human nature to assume that we understand risk and will avoid it just in time.  Yet, time and again we are surprised.

Somewhere along the way, a consultant categorized risks into awareness buckets of “Knowns,” “Known Unknowns” and “Unknown Unknowns.”  Unfortunately, categories of risk do not protect us from the effects of a risk occurrence.  Senior executives do not like surprises and, more importantly, they expect risk professionals to detect and prevent them before they occur!

Let’s examine whether these events are really “Unknown Unknowns” or, quite simply, the avoidance of decision making that could have minimized or contained the risk.  Cognitive research suggests that blind spots in decision making account for up to 90 percent of large operational risks across all organizations.  Very few firms take the time to re-examine failed decisions, fearing where the truth may lead.

More frequently than not, an executive is quoted as saying, “in hindsight, we should have done X, Y or Z,” once the extent of the damage has been revealed.   A huge amount of resources are spent to “correct” the problem and the blame is inevitably assigned with a vow to never repeat that mistake again.

What Can We Learn?

The failure to closely examine where decision making led to blind spots is an opportunity lost to learn valuable lessons and to lead by example.  Mistakes are inevitable and most result in small errors of judgment with little impact.  Strategic errors of judgment may be costly, but they are extremely informative.  Even worse, when firms refuse to examine their decision-making processes, they are doomed to repeat them, resulting in potentially catastrophic results.

Some believe financial service firms exhibit this blindside.   After being bailed out during the “Great Recession” by the U.S. government, the level of risk taking in markets has reached new heights.  The opportunity to lead by example and re-examine bad behavior has been lost in the rush to gain market share and profit from increasingly risky new products.  Yet financial service firms are not the only example!

Firms large and small have largely ignored warnings to build more robust Internet security to protect customer data.  Today, the news is littered with examples of breaches in data security.   These public notices do not capture the magnitude of the problem, however, since most are not fully disclosed, leading to millions of dollars in losses to hackers from around the world.

Decision risk may be the most costly risk of all!

Cognitive Risk Management: A More Enlightened Approach

Let’s be clear.  Risks cannot be completely avoided, nor can we prevent firms from making costly mistakes.  It is equally important to shatter the myth, or expectation, of the risk professional having supernatural abilities to “see around corners” to detect and prevent risks before they happen.  We don’t live and work in protective bubbles built from risk frameworks, processes and internal controls.  Internal controls are important, but they do not operate in a vacuum absent individual judgment.

Strong risk management is a derivative of good judgment.

An interesting observation should be noted here: COSO Enterprise Risk; Basel I,II, and III; ISO 3000 and Federal Sentencing Guidelines all make reference to human behavior, but none suggest effective approaches to address or detect deviations from expected behavior.  Regulatory agencies and external auditors note the importance of decision risk, but remain silent on remedies for detecting, correcting and preventing change in [expected] management behavior.

The traditional tools in use today are not effective for mitigating the hardest risk to avoid.

Today’s risk professional must consider looking to the behavioral sciences to address this most pervasive risk common to every organization.

Making decisions under uncertain conditions.

What makes this risk more complicated is that it is transitory in nature.  Meaning that decision making becomes more complicated as the certainty of outcomes become harder to predict.  In other words, how does flawed decision making morph into bad behavior?

The intent is not to solve these problems, but to suggest new approaches to detect these subtle changes and put processes in place to mitigate the impact of both behaviors.  Let’s call this a Behavior Risk Heat Map for now.  Collectively, these measures would provide a “gut check” for the Board and senior executives.  These measures need not be formally documented, but could be the basis for a discussion to build consensus.

Considerations for Building a Cognitive Risk Framework:

  • We tend to underestimate the downside of new risks – plan accordingly.
  • All humans use “heuristics and biases” to make decisions – understand where limits to intuition may lead to blind spots.
  • Conventional wisdom leads to the illusion of understanding – do your homework thoroughly and accurately.
  • The halo effect created by group think often leads to the illusion of consensus – disagree smartly.
  • “Less is more” – complex strategies and products are often fiction disguised as “the next big thing” – ask a 9-year old if they understand it.
  • “Jumping to conclusions” should be reserved for competitive sports.  Run simulations before committing to a full implementation.
  • And lastly, we all tend to seek short cuts and substitute “mediocre” for “better” solutions.  Don’t assume the easy answer is the correct one to pursue.

Keep in mind that the hardest risk to avoid is the one that you did not anticipate so ask yourself – What am I missing?

It might make the difference between success and failure.


Previous Post

Cash Flow, Working Capital and Strategic Planning Top List of Priorities for CFOs in 2015, According to New Study from Protiviti and Financial Executives Research Foundation

Next Post

Anti-Corruption Enforcement in Brazil Heats Up Against Individuals

James Bone

James Bone

James Bone’s career has spanned 29 years of management, financial services and regulatory compliance risk experience with Frito-Lay, Inc., Abbot Labs, Merrill Lynch, and Fidelity Investments. James founded Global Compliance Associates, LLC and TheGRCBlueBook in 2009 to consult with global professional services firms, private equity investors, and risk and compliance professionals seeking insights in governance, risk and compliance (“GRC”) leading practices and best in class vendors. James is a frequent speaker at industry conferences and contributing writer for Compliance Week and Corporate Compliance Insights and serves as faculty presenter and independent consultant for several global consulting firms specializing in governance, risk and compliance, IT compliance and the GRC vendor market. James created TheGRCBlueBook.com to provide risk and compliance professionals with transparency into the GRC vendor marketplace by creating a forum for writing reviews on GRC products and sharing success stories on the risk practices that are most effective. James is currently attending Harvard Extension School for a Master of Arts in Management with an emphasis in accounting and finance. James received an honorary PhD in Letters from Drury University in Springfield, Missouri and is a member of the Breech Business School Hall of Fame as well as the Missouri Sports Hall of Fame. Having graduated from the Boston University Graduate School of Education, James received his M.Ed. in Management and Organizational Design in 1997 and a Bachelor of Arts in Business Administration from Drury University in 1980.  

Related Posts

news roundup data grungy

DEI, Immigration Regulations Lead List of Employers’ Concerns

by Staff and Wire Reports
May 9, 2025

Half of fraud driven by AI; finserv firms cite tech risks in ’25

GFT Canada Update

GFT Expands AI Compliance Suite for Canadian Credit Unions

by Corporate Compliance Insights
May 8, 2025

Digital transformation company GFT has expanded its compliance suite to help Canadian credit unions combat payment scams and identity theft...

AxiomGRC Launch

Business Resilience Platform Axiom GRC Enters Global Market

by Corporate Compliance Insights
May 8, 2025

A business resilience platform called Axiom GRC has launched in the UK, backed by £500 million private equity investment from...

MyCOI Launch

myCOI Launches AI-Powered Insurance Compliance Platform

by Corporate Compliance Insights
May 8, 2025

Insuretech provider myCOI has launched illumend, an AI-powered platform designed to manage third-party insurance compliance and certificate of insurance processing....

Next Post
Anti-Corruption Enforcement in Brazil Heats Up Against Individuals

Anti-Corruption Enforcement in Brazil Heats Up Against Individuals

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights