The Comfort of the Register: How Risk Management Became a Ritual

Essay·Giovanni Leonardi·June 2002·14 min read

A register records that a risk was considered; it does nothing to ensure the risk was managed, and the gap between those two verbs is where programmes are lost.

Executive Summary

The risk register has become the most diligently maintained document in the modern programme, and one of the least consequential. It is opened each month, its columns filled, its scores recomputed, its owner reassured — and then it is closed again, having changed nothing. This essay asks why, and refuses the comfortable answer that the fault lies with lazy or unskilled people. The reduction of risk management to a clerical ritual is not a lapse in diligence; it is the predictable output of three structural forces.

The first is the register’s quiet reinvention as a legal artefact — a record built to demonstrate that risk was considered, rather than a tool built to ensure it is managed. The second is the seductive completeness of the list: enumeration feels like control, and a full register feels like a safe programme, even when the two have nothing to do with one another. The third, and most corrosive, is the separation of logging from deciding — the people who maintain the register rarely hold the authority to act on what it holds, and the people who hold that authority rarely read it.

Against the backdrop of the corporate failures now dominating every boardroom, the reflex is to respond with more process: more registers, more scoring, more attestation. This essay makes the opposite case. What the great failures exposed was not an absence of risk documentation but an abundance of it sitting alongside an absence of risk thinking. The remedy is not a better form. It is the return of judgement to a discipline that has been slowly, and comfortably, drained of it.

A document that changes nothing

Picture the monthly programme board. Risk is item four on the agenda, after finance and before dependencies. The register on the screen runs to forty-one open lines. Each has a probability, an impact, a score derived by multiplying the two, a red-amber-green status, a named owner, a mitigating action and a review date. The programme manager walks the board through the reds. There are six. Two of them have been red since February. Nobody in the room is surprised that they are still red, and nobody proposes to do anything about them that has not already been proposed and not done. The item takes eleven minutes. The board moves on to dependencies.

The register is complete. It is current. It is, in the only sense that matters, inert. It has absorbed perhaps two days of someone’s effort this month — collating updates, chasing owners, recalculating scores — and it has altered no decision, redirected no money, and changed no plan. Everyone present would agree, if pressed, that this is not what risk management is for. And yet next month it will happen again, in almost the same words, and the month after that.

The honest question is not how did these people become so careless — they are not careless; they are often the most conscientious people on the programme. The honest question is what is this ritual actually for, because it is plainly for something. A practice this stable, this widely reproduced, and this resistant to reform is not an accident. It is doing work. It is simply not doing the work its name advertises.

The register becomes a shield

The first structural force is the oldest, and in the climate of 2002 it is intensifying by the week. The register has become, above all else, evidence.

Watch what a risk log is asked to prove when a programme goes wrong. The first question from any review, any audit, any inquiry, is not did you manage the risk but did you know about it. A named risk on a dated register, with an owner and a mitigating action, answers that question in the affirmative. It establishes that the risk was seen, recorded, and — the register implies — attended to. It converts a failure of management into a failure of luck. We identified it. We had a mitigation. It materialised anyway. The register is the paper that stands between a manager and the accusation of negligence.

This is not cynicism; it is a rational response to how organisations assign blame. And it has become sharper in the past year than at any point I can recall. The collapses that have dominated the financial press since the autumn, and the reforms now being drafted on both sides of the Atlantic in their wake, have made one lesson brutally clear to every director: the gravest sin is no longer to have taken a bad risk but to be found not to have known. The guidance that followed Cadbury and, more pointedly, Turnbull already asked boards to demonstrate a sound system of internal control. The instinct that guidance produces, under pressure, is documentary. If the board must be able to show it has a system, then the system must produce show-able artefacts. The register is the most show-able artefact there is.

So the register’s centre of gravity shifts. Its purpose migrates, quietly and without anyone deciding it, from helping us act to proving we looked. Once that migration happens, every incentive that shapes the document points away from usefulness. A risk written to be defensible is written differently from a risk written to be managed. It is written to be complete rather than sharp, to be owned rather than resolved, to be reviewed rather than closed. Completeness, ownership and review are precisely the properties an auditor checks. They are not the properties that stop a risk from sinking a programme.

A risk written to be defensible is written to be complete, owned and reviewed. A risk written to be managed is written to be sharp, urgent and closable. The two documents look alike and behave nothing alike — and under the pressure of the moment, organisations are quietly choosing the first.

The seduction of the complete list

The second force is quieter and, because it feels like virtue, harder to see. It is the false comfort of enumeration.

There is a deep and largely unexamined belief in the transformation world that to list a thing is to have a degree of control over it. A full register — forty-one risks, none missed, each scored — produces a genuine feeling of safety in the people who own it. The feeling is not irrational. It reflects real effort and real coverage. But it rests on a confusion between two utterly different achievements: knowing what might go wrong, and being able to do anything about it. The register delivers the first and is routinely mistaken for the second.

Enumeration also imposes a false democracy on risk. A register lays out forty-one lines of equal visual weight, each with a score between one and twenty-five. The scoring system implies that these things are commensurable — that a fifteen is a fifteen wherever it appears, and that the six reds are the six things to worry about. But the risks that actually kill programmes are frequently the ones that score badly on this scale, because the scale rewards what is easy to articulate. The catastrophic risk is often the one nobody can write in a single line: the slow erosion of sponsorship, the quiet drift of the business case away from anything the organisation still wants, the accumulating fatigue of a team that has been at emergency pitch for a year. These do not have a clean probability or a clean impact. They do not fit the columns. So they are not on the register, or they are on it in a form so vague that they are unownable and therefore unmanaged. The register’s completeness is an illusion produced by only counting the risks that fit its shape.

There is a worked version of this worth stating plainly. Take a programme that logs twelve reds over its life and closes eleven of them through diligent mitigation. On the register, that is a 92 per cent record — an unarguable success. But suppose the one that was never on the register at all, because it could not be scored, was the withdrawal of the executive sponsor in month nine. That single unlogged risk determines the entire outcome. The register reports a triumph. The programme is dead. Nothing in the document is false; the document is simply measuring the wrong thing, and measuring it with great precision.

The wall between logging and deciding

The third force is the most damaging, and it is almost entirely structural. In most organisations the people who maintain the risk register and the people who can act on its contents are not the same people, do not sit in the same meetings, and do not share the same incentives.

The register is typically kept by the programme office — a coordinator, an analyst, a support function. These are capable people doing necessary work, but their authority is to collate, not to decide. When a risk needs money, a change of scope, a hard conversation with a sponsor, or a decision to stop, that action lives two or three levels up, with people who did not write the entry, were not in the workshop where it was raised, and encounter it only as item four on a monthly board. The register crosses this wall as a summary — a RAG status and a one-line action — and almost everything that would make it actionable is left behind on the other side. The texture, the urgency, the why-this-matters-now, does not survive the compression.

So the discipline splits in two. On one side, logging: careful, continuous, and disconnected from power. On the other, deciding: powerful, intermittent, and disconnected from the detail. The register is the object passed between them, and it is optimised for neither. It is too coarse to drive a decision and too laborious to be merely a record. It falls into the gap, and in that gap it becomes ritual — a thing done because it must be done, by people who cannot act, for people who will not read.

This is why exhortation never fixes it. Every few months someone senior declares that the organisation must “take risk seriously” and the register grows a new column. But the problem was never the form. The problem is that the form spans a structural divide it was never designed to cross, and no amount of additional columns will teach a summary to carry judgement across a wall.

The objection worth taking seriously

The strongest case against this argument deserves to be met directly, not waved away. It runs like this: registers may be ritualistic, but the ritual is protective. In a world where risk is genuinely uncertain, the disciplined habit of writing risks down, reviewing them monthly and assigning owners is exactly the kind of dull, repeatable practice that catches the occasional real thing. Abandon the ritual in the name of “judgement” and you get something worse — risk management by charisma, where whatever the loudest person fears this week gets attention and everything else is forgotten. The register, on this view, is a deliberately unexciting safety net, and its very tedium is the point.

This is a serious argument and it is partly right. The discipline of writing things down does catch real risks, and unstructured judgement is genuinely dangerous — it is swayed by recency, seniority and volume. A programme run purely on intuition would be worse than one run on a register. If the choice were ritual or nothing, ritual would win.

But that is not the choice, and presenting it as such is how the ritual defends itself. The alternative to a ritualised register is not the abolition of the register; it is a register wired back into decision-making. The habit of enumeration can be kept — it is cheap and occasionally valuable — while the three forces that hollow it out are deliberately reversed. Keep the list; stop treating it as evidence. Keep the scoring; stop believing the score tells you what matters. Keep the office that maintains it; stop letting the wall between logging and deciding stand. The register is not the enemy. Mistaking the register for the management of risk is the enemy, and it is possible to keep the first while refusing the second.

What risk thinking would actually restore

If the register is not the answer, what is? Not a new template — the field has enough templates. What has to be restored is a set of habits that the ritual has crowded out.

  • Fewer risks, held harder. A programme that genuinely manages six risks it can influence is safer than one that logs forty it cannot. The discipline is subtraction: which of these do we actually own, and which are we merely recording so that no one can say we did not know? The recorded-but-unownable risks are not risk management; they are insurance against blame, and they should be named as such and moved off the register that drives decisions.
  • The un-scoreable risks, forced into words. The risks that kill programmes resist the columns. The remedy is not to exclude them but to abandon the columns when they do not fit. A single paragraph of plain prose about the state of sponsorship, updated honestly each month, does more real risk work than twenty scored lines. If it cannot be scored, write the sentence anyway.
  • The wall, deliberately breached. The person who logs a serious risk and the person who can act on it must, at least occasionally, be in the same room while the risk is still live — not reading a compressed summary a month later. The single most useful reform available to most programmes is not a better register but a standing route by which a real risk reaches a real decision-maker without passing through the flattening machinery of the monthly board.
  • A different question at the board. The board should stop asking “is the register up to date” and start asking “what have we changed this month because of something on it”. The first question can always be answered yes, and answering it teaches everyone that yes is the goal. The second can often only be answered nothing, and the discomfort of that answer is the beginning of the discipline’s recovery.

“Stop asking whether the register is up to date. Start asking what you changed because of it. The first question can always be answered; the second usually cannot — and the silence is the lesson.”

The moment we are in

It would be easy to read the events of the past year as a call for more control, and much of the response now taking shape will read them exactly that way. The reforms being drafted will demand more attestation, more documented internal control, more evidence that risk was considered. Some of that is necessary. But there is a real danger, visible already, that organisations answer a crisis of thinking with a surplus of documenting — that they meet the exposure of hollow governance by building more of the very artefacts that were hollow.

The great failures were not short of risk registers. They were rich in process and poor in judgement, thick with committees and thin with courage, and their documents were, in many cases, immaculate. That is the warning that matters. A discipline can be fully staffed, fully templated and fully audited, and still not be happening at all. The register is not where risk is managed. It is, at best, where risk is remembered. The work — the noticing, the weighing, the deciding, the acting — happens in the judgement of people who are willing to look at an inconvenient truth and change something. No form has ever done that work, and in a year when everyone is reaching for a better form, that is the thing most worth saying aloud.


More from Transformation