CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Compliance

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Bank of Queensland

Peter Deans, Chief Risk Officer

Grabbing the Tiger by the Tail-Taking Charge of Enterprise Risks

As the world we live and work in becomes more complex and interconnected, the number of risks facing business managers and executives appears to be increasing exponentially. Irrespective of whether an executive is in an information technology, operations, or front line business role the list of risks that must be identified and assessed can feel daunting. For discreet functions and activities the number and types of risks can often be more manageable. Irrespective of the number and nature of risks to be managed, calls for a structured approach to risk identification and assessment.

In a prior era, the management of risks was very much an intuitive activity–with executives and managers left to manage risks as they saw fit. Often key business risks were not even identified or fully understood. Today however the scale and breath of business activities—particularly the increased use of technology and third parties requires a more structured and sophisticated approach to the management of risks.

Across many industries and businesses, an Enterprise Risk Management approach has been widely used to better understand and manage business risks. The adoption of ERM as an embedded business activity has significantly improved in recent years. This approach usually involves:

• Establishment of risk registers across business units, functions, and specific activities
• Periodic workshops being undertaken to identify key business risks
• Rating of key business risks using a consistent methodology–usually rating the likelihood and severity of particularly risk event(s) occurring
• Development of action plans for risks identified as posing an unacceptable business risk, if not mitigated, and
• Periodic assessments of controls in place to ensure that controllable business risks do not unexpectedly materialise.

Much of the focus of an ERM approach is on existing, known business risks or operational risks. This is the correct approach. The imperative is to focus on business risks or events that can disrupt a key business activity and/ or have an adverse financial impact. These can include events such as technology or power outages, supply chain disruption, operations or process failures, and weather events that disrupt business activities. Breach of regulatory requirements is an important category of risks that can also be captured in an ERM system.

Confidence in The Overall Resilience of an Organisation Can Often Lead to a Superior Value Being Assigned To That Organisation By Equity Investors


Implementation of an effective ERM framework will ensure that each key risk is appropriately assessed and documented. The outcomes of the risk assessments can, in turn, form the basis of Business Continuity Planning (BCP). This will build organisational resilience and assists avoid reputational damage for failing to identify and mitigate known business risks.

Many regulated businesses – such as those in the banking, transport, and infrastructure and energy industries-are required to have clearly documented ERM and BCP processes in place. In addition, audit firms are increasing looking at risk management frameworks and controls as part of their ongoing audit processes.

There is sound business reason to have documented ERM and BCP processes in place even if not formally required however. A deep understanding of the risk profile of all aspects of an organisation can assist and identify material risk issues or gaps that can adversely impact on its financial performance, regulatory compliance, customer experience, and reputation. This will in the long run improve financial performance. In addition, confidence in the overall resilience of an organisation can often lead to a superior value being assigned to that organisation by equity investors.

Challenges will exist in being able to accurately assess the likelihood and impact in many risk categories. Cyber security is a good example of this and perhaps the most topical risk category in recent times. How do you assess the likelihood of a cyber event taking place, what type of cyber issue will you have and what will be its impact? It is true that it is difficult to answer these questions definitively. Using the ERM approach, the first steps of understanding an organisation’s cyber risk profile will be a series of workshops to develop a baseline assessment (using external expertise if necessary). This will in turn guide the organisation’s assessment of the likelihood of cyber risk events occurring.

Similarly, business operating models that involve the use of third parties for specific parts of the value chain should follow the ERM approach to understand the business risks of these arrangements. Often risk assessments have either never been done or only done as part of an initial due diligence or approval process for an outsourcing or supply arrangement. What happens if a key supplier or outsourcing business part has a business disruption, elects not to renew a contract or ceases operations due to financial difficulty? Supplier or third party outsourcing contracts usually enable periodic reviews to be undertaken of the contracted party and its performance. These provisions provide an opportunity to gain a deeper understanding of the risk profile of outsourced activity and the contracted third party. This is particularly common in IT and business process outsourcing. Cloud computing arrangements should also be assessed in the same manner.

The frequency of risk reviews and management reporting of the overall risk profile will vary from organisation to organisation. The most effective ERM frameworks will require ongoing monitoring of risks–with the onus on risk owners (the role or function within an organisation that owns a particular risk)–to document and promptly report any material change in a risk category. Periodic management reporting of risk profiles can be monthly, quarterly or half yearly depending on the size, complexity and maturity of an organisation. A comprehensive, pan-organisational review of all risks should be undertaken at least annually.

More mature and sophisticated ERM frameworks will see the assessment of strategic business risks incorporated into the ERM process. This will look at the potential impact of medium to longer term trends on an organisation’s overall business profile. These can include demographic, technology, competition, social, and other changes that may pose a longer term threat to the sustainability and financial performance of the organisation. This is very much a top down exercise that is usually undertaken as part of the strategic planning process.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://compliance.cioapplicationseurope.com/leadership-perspective/grabbing-the-tiger-by-the-tailtaking-charge-of-enterprise-risks-nid-393.html