Chapter 6: Risk Oversight — Beyond the Register, Into the Room

What Good Looks Like — a board-level guide to governance done well

Every board has a risk register. Very few boards have a risk conversation. The register is a document. Oversight is what happens when directors sit round a table and decide whether they're comfortable with the risks the organisation is carrying.

Chapter 5 looked at how the information a board sees shapes what it does. The risk register is the clearest example. It arrives every quarter, it looks thorough, and it can quietly replace the thinking it was meant to support.

Why the register gives false comfort

Most risk registers are built in good faith. They still tend to fail in the same few ways.

Scores settle. A risk is rated 16 when it's first added, and two years later it's still 16, because nobody has a reason to change it. The number stops describing the risk and starts describing the habit.

Controls are listed, not tested. "Policy in place", "training delivered", "monitored at committee". Each one sounds like protection. None of them tells the board whether the control actually works.

Mitigations are intentions. "Review of staffing model underway" can sit on a register for a year. It reads as action. Often it's a plan to have a plan.

The register only holds what someone has already thought of. The risks that hurt organisations most are frequently the ones nobody wrote down, or the ones that were written down at the wrong size.

And red, amber and green do a lot of quiet work. A board that sees mostly amber tends to relax. Amber means a risk the organisation hasn't brought under control.

What a good risk conversation sounds like

The difference is easier to hear than to describe. A weak conversation goes something like this.

"Risk 7, agency staffing, remains at 16. Controls are in place and the action plan is on track. Any questions?"

"No, thank you. Next item."

A better one sounds more like this.

"Risk 7 has been at 16 for five quarters. What would have to happen for it to move, up or down?"

"Honestly, the score hasn't been reviewed properly since we set it."

"Then let's not rely on it. Which control would fail first if two senior nurses left in the same month? And how would we know before a patient did?"

The second conversation does three things the first doesn't. It treats the score as a claim to test, not a fact. It asks how controls fail, not whether they exist. And it brings the risk back to the people it would harm.

Good risk questions tend to share that shape. What's changed since we last looked? What are we assuming? What's the worst credible outcome, not the average one? What risk are we carrying that isn't on this list? And are we comfortable, as a board, with where this sits against our appetite?

What it looks like when it fails

Carillion collapsed into liquidation in January 2018. The joint report of the Work and Pensions and BEIS Committees opened with a blunt verdict: "Carillion's rise and spectacular fall was a story of recklessness, hubris and greed."

The committees were clear about the board's part in it. Non-executives, they wrote, "have a particularly vital role in challenging risk management and strategy and should act as a bulwark against reckless executives. Carillion's NEDs were, however, unable to provide any remotely convincing evidence of their effective impact." On the board's awareness of shareholder concerns about debt and the pension deficit, the report found that "the board minutes, however, show little sign of these positions being properly challenged".

When the senior independent director was asked whether the board should have been asking more probing questions, his answer, even with hindsight, was "perhaps". The papers existed. The risks were known. What was missing was the conversation.

Where to start

None of this means throwing the register away. It means using it to start the conversation, not to finish it.

Spend board time on a few risks, properly. Pick the three or four risks that would hurt most, and discuss them in depth each meeting. Let the committee work through the rest.

Ask what's changed. Any score that hasn't moved in a year should be challenged. Either the risk is stable and you can say why, or nobody's looking.

Test one control a quarter. Choose a control the register relies on and ask for evidence it works: an audit, a spot check, a walk-round. "Policy in place" isn't evidence.

Ask for the risk that isn't there. Once a year, ask executives and front-line leaders what keeps them awake that isn't on the register. Add what you hear.

Agree your appetite, then use it. A board that has said how much risk it will accept in safety, finance and reputation can judge each risk against that. Without it, every discussion starts from scratch.

Next
Next

Chapter 5: Information — What the Board Sees Shapes What the Board Does