There are systems whose shutdown is immediately noticeable. Production control, for example. Or payroll. When it comes to risk management, things are different in some companies: You could pull the plug on the server, bury the risk lists in a decommissioned SharePoint site, and set all the status indicators to dark gray. Nothing would happen for weeks. Probably for months. Only shortly before the next audit would someone nervously ask where the current risk matrix had actually gone.
This is the uncomfortably simple stress test for any risk management system: What specific decisions would be made worse if it no longer existed tomorrow? Would investments be prioritized differently? Would financing be adjusted? Would supply chains be made more robust, insurance limits changed, or emergency measures triggered sooner?
If the answer is an awkward silence, then it is not a relevant management system. In that case, it is merely a ritualized data collection exercise with an annual presentation deadline. It produces reports, heat maps, lists of measures, and the reassuring feeling that risks have been properly documented. Unfortunately, however, they have no real impact. At least this spares the company the effort of having to make unpleasant decisions.
Risk accounting is not the same as corporate management
Many systems function like accounting without a balance sheet: Hundreds of individual risks are collected, labeled with probability of occurrence and potential loss, and then sorted into red, yellow, and green categories. Sales reports a potential loss of a customer, IT reports a server outage, purchasing reports a delayed delivery, and the legal department reports some new regulation. Often, these aren't even risks, but merely threats or causes. A server failure is initially a threat—it only becomes a risk relevant to management control through its potential impact on production capacity, revenue, earnings, and liquidity. Anyone who doesn't understand this difference confuses a weather warning with the economic damage caused by the storm. In the end, the company or government agency—assuming they even deal with risks at all—ends up with an impressively long list and surprisingly little insight.
It is particularly noteworthy that many risks are still assessed using qualitative "voodoo" approaches: "high," "medium," "low," supplemented by gut feelings, color-coded logic, and a pinch of expert opinion. Such assessments may look neat in a PowerPoint presentation, but they have no relevance whatsoever to management decisions. They show neither how risks interact nor what impact they have on earnings, liquidity, and financing—and certainly not whether the company's risk-bearing capacity is sufficient.
After all, management does not make decisions based on "Risk 147b, probability medium, impact high." It makes decisions about liquidity, earnings, investments, capacity, financing, market position, and strategic options. Anyone who fails to translate risks into this decision-maker's language shouldn't be surprised if the executive board—at best—nods politely and then moves on to the next item on the agenda.
From an IT Outage to an Earnings Warning
Let's take a manufacturing company as an example. The central system for production planning and materials control goes down following a cyberattack. Traditional risk accounting reports: "IT outage, probability: occasional, impact: high." This is about as useful as a weather forecast that says "it will be wet at some point."
The scenario only becomes relevant to decision-making once the chain of effects becomes clear: Without production control, multiple production lines come to a standstill. Work-in-progress cannot be allocated, materials cannot be scheduled, and delivery dates cannot be confirmed. After two days, backlogs begin to accumulate; after five days, there are no products ready for shipment. Revenue is delayed or lost, fixed costs continue to accrue, contractual penalties loom, and customers may switch to a more reliable competitor. A technical incident turns into an operational disruption; the operational disruption becomes a burden on revenue, liquidity, and operating profit.
Now is the time to decide: How much can a redundant system cost? What restart time is economically necessary? Which manual emergency processes must function? What level of insurance coverage is reasonable? Or are there alternative and more sensible measures than insurance? And at what threshold is the crisis management team activated? That is precisely where risk management begins. Everything before that is "risk accounting."
Geopolitics? Apparently, someone else was in charge
For years, many companies treated geopolitical risks like bad weather on another continent: unpleasant, but presumably not relevant to business. The government was often hardly any better. Dependencies on individual countries, suppliers, raw materials, trade routes, or technologies were not viewed as strategic vulnerabilities, but rather as a sign of efficient procurement. The main thing was that it be cheap, just-in-time, and with as little inventory as possible. Resilience was considered a cost factor—until the bill came due.
A blocked sea route, sanctions, an export ban, or a military conflict are not isolated "procurement risks." They extend transit times, create shortages of intermediate goods, drive up prices, increase working capital requirements, and, in the worst case, bring entire production programs to a standstill. Anyone who breaks these effects down into purchasing, logistics, production, sales, and finance ends up with five neatly managed individual risks—and overlooks the one scenario that actually threatens the business model.
The crucial question, therefore, is not: "Has the procurement department recorded the risk in the system?" It is: "What happens to sales, margins, liquidity, and delivery capacity if the critical raw material is unavailable for twelve weeks?" Only then does geopolitical "folklore" become a robust basis for decision-making. And only then can one assess whether inventory levels, alternative suppliers, technical substitutions, price pass-throughs, or changes in capacity make economic sense.
While risk management counts crumbs, the business model goes up in smoke
Companies rarely face existential difficulties because travel expenses were exceeded by three percent, a regional branch was understaffed for two weeks, or a single receivable went unpaid. They run into trouble because they fail to keep up with technological upheavals, ignore customer needs, build dangerous dependencies, underestimate new competitors, or defend outdated business models to the bitter end. Strategic missteps, a lack of adaptability, and fundamental shifts in the market and demand are regularly the actual drivers of crises. It's no different for nations.
Yet in the risk management report, the world often still looks surprisingly reassuring. While a new technology lowers barriers to market entry, digital platforms take over customer access, and the company's own product gradually becomes obsolete, the organization conscientiously discusses travel expenses, minor bad debt losses, and local staff absences. The business model is already going up in flames—but the risk report is dominated by 237 properly assessed smoldering embers.
Strategic risks do not disappear from the reports because no one can identify them. They disappear because they are inconvenient. They do not fit into any single department, cannot be assigned to a clear "risk owner," and cannot be resolved with an additional work instruction or another checkbox. Above all, they force decisions: Do products need to be discontinued, technologies replaced, supply chains rebuilt, markets exited, or significant investments made? It is precisely at this point that, in many places, the courage of risk management ends and the management of the "non-risky" begins.
In the process, a second fundamental mistake is often made: Risk management is understood exclusively as the management of potential losses. It focuses on "downside risk," lists potential dangers, and then searches for as many reasons as possible why something might not work. Opportunities, positive surprises, and strategic potential—the "upside risk"—are, by contrast, barely considered. It's as if the sole task of risk management were to guide the company as safely as possible into irrelevance.
This one-sided approach is particularly absurd when it comes to strategic issues and innovation projects. A new technology can threaten the existing business model—but at the same time, it can open up new markets, lower costs, improve products, and unlock significant growth potential. An innovation project can fail and destroy capital. Above all, however, it is intended to create a competitive advantage, increase margins, or enable access to new customers. Anyone who merely lists risks, cuts budgets, and points to uncertainties has failed to understand the issue. They are not engaging in risk management, but rather in the organized rejection of opportunities.
Decision-oriented risk management must therefore consider both sides: What can go wrong, and what can we gain? What range of possible outcomes is realistic? What conditions must be met for the opportunities to materialize? Which decision increases the expected benefit without overstretching the company's risk-bearing capacity? And which option offers an attractive ratio between potential loss and potential gain?
A small operational risk, on the other hand, is remarkably low-maintenance. It has a person in charge, a specific action, a deadline, and—ideally—a "green" status after three months. This generates activity, report pages, and the pleasant feeling of having the situation under control. Whether this activity has any impact on the company's future viability is another question—and one that is often not particularly popular.
Effective risk management would therefore have to look precisely where things get uncomfortable yet simultaneously interesting from a business perspective: Which technological developments could devalue our value proposition—and which could radically improve it? Which changes in customer behavior could destroy our margins—and which ones open up new revenue potential? Which competitor could bypass our value chain—and where could we ourselves bypass someone else's value chain? Which assumption underlying our business model absolutely must not be wrong—and which new assumption could give us a strategic advantage?
Those who merely catalog risks but ignore opportunities are no more engaged in strategic risk management than those who completely ignore disruptive developments. Both approaches amount to risk accounting: fully documented, neatly categorized, and either completely caught off guard when a crisis strikes—or just as surprised when a competitor seizes an opportunity that you yourself had prudently ruled out.
Just switch it off—and see if anyone even notices
Effective risk management must therefore focus less on collecting data and more on distilling it. It must model chains of impact, make interdependencies visible, and translate scenarios into impacts on earnings, liquidity, and enterprise value. It must show which decision today makes the company more resilient and what that costs. And it must have the courage to prioritize ten scenarios critical to the company's survival over five hundred carefully tracked minor risks or threats.
Effective risk management does not need to collect more and more risks, but rather condense the few truly relevant scenarios in such a way that decisions can be derived from them. It must model chains of impact, make dependencies and interactions visible, and show how a scenario affects earnings, liquidity, financing, supply capability, and enterprise value. Above all, it must answer which decision makes the company more resilient today, how much that decision costs, and to what extent it actually reduces risk.
This requires the courage to prioritize ten scenarios critical to the company's survival over five hundred meticulously maintained minor reports. A risk management system that records every malfunctioning air conditioner but fails to robustly analyze the potential loss of a sales market, a technological disruption, or the failure of critical production systems has missed its mark. It produces data, but no insight. It documents activity, but not any impact on decision-making.
The crucial question, therefore, is not whether all risks were reported on time, all forms were filled out, and the traffic-light colors were set correctly. The crucial question is: Which specific management decision was actually changed or improved as a result of the information provided by risk management? Was an investment adjusted, a supply chain made more robust, financing secured early on, or a strategic misstep corrected in time? If there is no answer to this, a surprisingly simple test can help: The risk management system is temporarily shut down. No risk reports, no traffic-light matrices, no quarterly queries, and no endless lists of measures. Then you wait to see what happens.
Does management miss the information? Are there suddenly no reliable scenarios for investment, financing, or strategic decisions? Are critical developments no longer identified in a timely manner? If so, the system clearly had value. If, on the other hand, no one notices anything, all decisions continue as before, and the only thing that stands out is that some employees suddenly have more time, the diagnosis is clear: The system was not a management tool, but an administrative ritual.
Risk management systems that are not relevant to management should not be optimized, expanded, or equipped with a new dashboard. They should be shut down. Because an ineffective system doesn't just tie up resources—it creates the dangerous illusion that risks are under control simply because they've been documented somewhere.




