Defrag your strategy - risk

Your biggest risk may be your risk management. Not because you're taking too many risks but because you've separated risk from strategy.
Over the past few years, we've seen a worrying fragmentation of strategy:
Purpose becomes a marketing strapline
Values become virtue signalling, hijacked by HR
Vision becomes wishful thinking from Internal Communications
Goals get handed to Finance.
Risk disappears into a committee
Priorities get swallowed by BAU
The organisation still has all the right words. It just no longer has a coherent strategy. And when risk is separated from strategy, something particularly dangerous happens - risk becomes a compliance exercise rather than a strategic conversation.
What is risk?
Forget the 200-line risk register. The strategic question is much simpler: “What could stop us achieving what we've set out to achieve?” That's strategic risk.
It might be:
our business model becoming obsolete
AI disrupting our competitive advantage
losing a critical customer or market
being overtaken by a more agile competitor
a regulatory or geopolitical shock
failing to attract the talent we desperately need
a cyberattack that cripples the business
a supply chain that suddenly stops supplying
The point isn't to create a longer list of things that could go wrong. The point is to identify the uncertainties that could materially affect the strategy. And then decide what we're going to do about them.
The critical distinction: appetite vs capacity
This is where many organisations get confused.
Risk appetite asks: "What are we willing to risk?" Risk capacity asks:"What are we actually able to risk?" They are not the same thing. You might be willing to bet £50m on a new growth strategy. But if losing £10m would threaten your ability to operate, you don't have the capacity to take that risk.
Appetite is a choice. Capacity is a constraint. Confusing the two is how organisations get into trouble. The sweet spot is where strategic ambition, risk appetite and risk capacity line up.
How much risk are you prepared to take?
Don't start by asking: "What are our top ten risks? Start with: "What are we trying to achieve?" Then ask: "What could stop us?"
Then ask:
Which of those risks are we prepared to accept?
Which must we reduce or avoid?
Which are worth taking because they create opportunity?
If it goes wrong, can we afford the consequences?
That's a strategic risk conversation, not a compliance exercise.
Risk isn’t always the enemy
Here's another uncomfortable truth: you can't eliminate risk and still have an ambitious strategy.
Growth is risky. Innovation is risky. Entering new markets is risky. Investing ahead of demand is risky. Doing nothing is risky. In fact, the risk of doing nothing may be greater than the risk of acting. So, the question isn't: "How do we avoid risk?" It's: "Which risks are worth taking?"
For any significant risk, you have five basic choices:
Avoid – don't do it
Reduce – lower the likelihood or impact
Transfer – share it with someone else
Accept – knowingly live with it
Exploit – take more of it because the potential reward justifies the exposure
The last one is often forgotten. But sometimes risk isn't something to manage down, it's something to lean into.
What should you worry about?
Worry about the assumptions underneath your strategy:
What if customers change?
What if technology moves faster than expected?
What if your competitive advantage disappears?
What if your best people leave?
What if the market you've built your strategy around no longer exists?
The most dangerous risks are often not the ones that suddenly explode. They're the ones that quietly become true while everyone is watching something else.
Beware or ‘risk theatre’
A beautifully formatted risk dashboard doesn't mean you're managing risk. Neither does a risk committee. Or a traffic-light system. Or a 7.3 risk score. Or a 200-page risk register. These things can create the illusion of control.
The real test is much simpler: does your risk management improve the quality and speed of strategic decisions? If not, you're probably managing paperwork rather than risk.
What does good look like?
Good strategic risk management means:
Strategy – know what you're trying to achieve
Uncertainty – identify what could materially change the outcome
Risk – understand the consequences
Appetite – decide what you're willing to risk
Capacity – know what you can afford to lose
Response – decide what you'll do about it
Monitoring – watch for the signals that tell you your assumptions are changing
And above all, give people ownership and the authority to act. Because responsibility without decision rights is just accountability theatre.
The bottom line
The purpose of strategic risk management isn't to stop an organisation taking risks. It's to ensure that it takes the right risks, for the right reasons, within the boundaries of what it can afford to lose.
Risk shouldn't live in a sub-committee. It should live inside the strategy. Because the biggest risk of all isn't taking the wrong risk. It's believing you have no risk.
strategy → uncertainty → risk → appetite → capacity → response → monitoring
That's how you defrag risk. And that's how you put it back where it belongs: at the heart of strategy.
Next in the Defrag Your Strategy series is the sixth and final foundation of good strategy – implementation priorities. Previous articles in the series can be found on our Defrag you Strategy webpage.




Comments