How do you make the Risk teams an effective partner?

While many organizations agree on the need for specialists to manage risk in the business, very few actually focus on how to make them successful. Does your Risk team deal with fait accompli all the time or do they have a seat at the table?
The role of the risk teams and the Chief Risk Officer has evolved rapidly over the last few years. There was a time when risk management was a disjointed exercise with business units managing risks independent of each other and centralized teams such as Enterprise Risk and Internal Audit serving the senior leadership and the Board. However, over time there has been a recognition of the synergies, cost benefits and the impact that a combined Risk function can bring to the organization through standardized and consistent methods and a 360-degree view of the variety of risks faced.
As the businesses come to terms with dealing with a Risk team outside of their direct reporting line and with an independent mandate and point of view, there are also some challenges cropping up. The Risk teams are increasingly viewed as service providers to the business and many business owners tend to deal with them transactionally. The loss of control also tends to create a certain distance and the closeness that risk managers might have enjoyed earlier with business units also gets impacted. As a result, the business units might fret over the priorities of the Risk team, which may now be driven by overall risk concerns across the organization, and how well their risk partners understand their specific business model and objectives. At the same time, the Risk teams complain that risk management is no longer at the same level of priority for the business teams as before and that they always come into the picture when everything has already been decided or even executed.
A Risk team is most effective when they are not just securing the perimeter against threats but rather working in concert with the business units and leadership to help build a resilient strategy that can deal with future uncertainties. They should be helping the businesses leverage risk as a strategic advantage wherever possible (more on that in a future post). But, to do that they need to understand the business really well and need to have visibility to the working of the business – their objectives, strategy, product decisions, etc. Most of all, they need a seat at the table so that they can bring the Risk perspective during discussion and decision-making.
It is only fair for businesses to expect the Risk managers to align with the business targets and enable growth but on the flip side they also need to reciprocate with more risk awareness and consideration in their decisions. I guess a good place to start is with intentionally involving your risk partners in conversations, brainstorming and discussions and holding them accountable for active participation and inputs. Many organizations take a more structured approach through formal product reviews, audits and operational controls which are a legitimate part of the ERM framework but bigger benefits will accrue through close working relationships and a genuine say for your Risk professionals in the business matters.
