Roger Martin, former Dean of the Rotman School, has written a fascinating and insightful article about risk management, emphasizing that a robust strategic process is the only effective way to approach it. Martin argues that, in most cases, risk management conducted by corporate boards often amounts to little more than box-ticking to comply with the Sarbanes-Oxley Act (S-OX) Section 404. This requirement, enacted after scandals like Enron and WorldCom, has become a lucrative exercise for consulting firms but provides little real value to management or investors. Instead of addressing critical risks, these efforts often generate exhaustive lists of potential risks (as seen in typical 10-K filings), which serve as "safe harbor" statements for management rather than actionable insights. A more effective way to approach risk management is by applying the Rumsfeld Risk Matrix (as illustrated in the accompanying graphic). This matrix divides risks into four quadrants: 1.Known Knowns – Risks we are aware of and understand well enough to measure and manage. 2.Known Unknowns – Risks we recognize but do not fully understand. 3.Unknown Knowns – Risks we are unconsciously aware of but fail to identify as risks. 4.Unknown Unknowns – Risks we are entirely unaware of. The ultimate goal of risk management is to increase awareness, turning unknowns into knowns, and improving precision by addressing uncertainties. This involves identifying key risks that are not fully understood, assessing their material impact and likelihood, and investing in understanding them better. It also requires implementing systems to monitor risks that might not be obvious and to uncover entirely new risks. So how is this achieved? The answer lies in a strong strategic process. A well-designed strategy explicitly considers what must be true (WWHTBT) for success and potential derailment, addressing factors such as industry dynamics, customer behavior, organizational capabilities, competitor actions, vendor dependencies, and technological advancements. By conducting thorough internal (IFE) and external (EFE) factor evaluations, along with a comprehensive SWOT analysis, organizations can identify key risk factors, enhance awareness, and improve their ability to detect unknown risks early. This article offers valuable insights and is highly recommended for anyone interested in strategic risk management. (text revised by a LLM) https://rogermartin.medium.com/risk-management-strategy-59869afd3558
- Pedro
Read on Substack