
By Monika Amukoto
As you went through the previous articles, much of the content may have sounded familiar. In fact, you may have found yourself agreeing with many of the concepts discussed, as they are not entirely new.
However, the real question is what effective risk management looks like on a day-to-day, monthly, quarterly, or annual basis within an organisation.
There are a few simple tests organisations can apply to determine whether risk management is genuinely embedded in the business or merely documented.
1. Is there a clear link between your strategic objectives and risk mitigation actions?
Take your organisation’s strategic plan and place it alongside its risk register or risk management plan. If you operate below executive level, do the same with your departmental plan.
If you are part of a team, compare your team’s objectives with the risks that could affect their delivery.
Then ask yourself:
Can you clearly link your strategic objectives to the material risks and corresponding mitigation actions?
If the answer is no, you may have two perfectly sound documents that are functioning independently of one another.
I experienced this firsthand during the development of a local company’s strategic plan. Although the strategic plan was well put together and aligned with the organisation’s goals, it didn’t consider the risks that could impact its success.
To remedy this, and rather than simply inserting a risk section in the strategic plan, I engaged the Executive Committee to challenge and evaluate each proposed strategic action through a risk lens.
What quickly became apparent was that several strategic initiatives were advancing without adequate consideration of the material risks that could undermine their successful execution.
A strategy may be comprehensive yet still be highly exposed to execution risks. When an organisation identifies an existential or material risk during its risk assessment process, that risk should not remain confined to the risk register.
It should be reflected in strategic priorities, resource allocation, budgeting decisions, and execution planning. When risks are treated separately from strategy, organisations create the illusion of preparedness while leaving themselves vulnerable to execution.
2. What happens when risks are raised?
Think about your recent executive committee, management, or team meetings. When someone highlighted a risk or challenged a proposed decision, what was the response? Was it curiosity and a willingness to understand the issue, or pressure to move ahead regardless?
Risk culture becomes most visible in moments when risks are raised and decisions are challenged. To assess the strength of your organisation’s risk culture, consider the following questions:
Can employees question risk exposures and raise concerns without fear of being labelled negative or difficult?
When uncomfortable risks are raised, are individuals thanked for highlighting them, or questioned for doing so? Are difficult conversations encouraged, or do people tend to tell management what they believe management wants to hear?
Do leaders openly acknowledge when decisions have not worked as intended, and are mistakes examined as opportunities for learning rather than occasions for assigning blame?
Equally important, do employees escalate risks early, or wait until problems become unavoidable? When was the last time a significant decision was changed because a risk was identified? Perhaps the most revealing question of all is this: are there known risks that go unreported because people believe raising them will make no difference?
The lesson is simple: Effective risk management is not about explaining failures after they occur; it is about influencing decisions early enough to improve the likelihood of success.
*Monika Amukoto is a Strategy, Governance, Risk and Compliance professional with expertise in helping organisations strengthen governance, manage risk and execute strategy effectively.








