Managing Risks to Success

Risk Management Is Not a Register. It Is How Organisations Stay Ready.

A good risk register can be useful. It can bring structure, consistency and visibility to a set of risks that might otherwise sit in different teams, documents and conversations. But a risk register is not the same as risk management, and one of the quiet dangers for organisations is that the presence of a well-maintained register can sometimes create a stronger sense of control than the evidence supports.

Risk management

The real test is not whether risks have been captured, scored and reviewed. The real test is whether the organisation understands what could affect its ability to achieve its objectives, whether the assumptions behind those objectives are still valid, whether controls are working as intended, and whether leaders are receiving the right information early enough to act.

That distinction is becoming more important. Boards, Audit and Risk Committees, executive teams and internal audit leaders are being asked to provide more confidence over increasingly complex environments. Regulatory expectations are moving in the same direction. The UK Corporate Governance Code 2024 places a stronger focus on risk management and internal controls, with Provision 29 requiring boards to monitor the effectiveness of the risk management and internal control framework and, from reporting periods beginning on or after 1 January 2026, to make a declaration on the effectiveness of material controls. The Companies Act 2006 also requires strategic reports to include a description of the principal risks and uncertainties facing the company, which means risk is not just an internal governance exercise, but part of how an organisation explains its position, prospects and preparedness.

The Financial Reporting Council’s 2025 review of corporate governance reporting gives a useful indication of how listed companies are responding. In a sample of 100 companies, including FTSE 100, FTSE 250 and Small Cap organisations, more than half mentioned the new Provision 29 requirements and many provided further detail on how they were preparing. The same review found that 85% of companies included cybersecurity as a principal risk, with a further 12% covering it within operational principal risks, and 66% highlighting board-level oversight of cyber risk. That does not mean all organisations are mature in the way they manage risk, but it does show where the market is heading: towards clearer accountability, better evidence and more active board-level challenge.

The cyber figures reinforce why this matters. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses reported experiencing a cyber security breach or attack in the previous 12 months, rising to 69% for large businesses and 65% for medium businesses. Phishing remained the most common type of breach or attack, experienced by 38% of businesses. The same survey also reported an increase in businesses saying a breach or attack led to loss of revenue or share value, from 2% in 2024/2025 to 5% in 2025/2026, and reputational damage, from 1% to 3%.

Cyber is often discussed as a specialist technology risk, but in practice it tests the whole risk management system. It tests whether the organisation understands its critical services, whether third-party dependencies are visible, whether controls are monitored, whether incident plans have been rehearsed, whether decision-makers know what they would do under pressure, and whether assurance activity is focused on the areas where failure would matter most.

As Donna Littlechild, Co-Founder of Littlechild & Haley, puts it:

“The strongest risk conversations are rarely the ones that produce the longest register. They are the ones that reveal where the organisation is relying on assumptions, informal workarounds or controls that have not been tested under real pressure. Good risk management should help leaders see the organisation more clearly, including the parts that are working well, the parts that are under strain, and the parts where confidence is based more on habit than evidence.”

This is where risk management starts to become more like detective work. The point is not to look for failure for its own sake, or to make organisations more cautious than they need to be. The point is to follow the evidence, ask better questions and understand whether the organisation is truly prepared for the risks that could affect its success.

One helpful shift is to move from a static risk conversation to a readiness conversation.

Traditional risk questionStronger readiness questionEvidence worth looking for
What are our top risks?What could most affect our ability to achieve our objectives?Link between strategic priorities, risk themes, operational dependencies and board reporting.
Have we got controls in place?Do we know whether the controls are designed well, operating consistently and still relevant?Control testing, exception reporting, management attestations, internal audit work and evidence of remediation.
When was the risk last reviewed?What has changed since the risk was last reviewed?Horizon scanning, regulatory updates, market changes, supplier changes, cyber intelligence and operational incidents.
Who owns the risk?Does the owner have the authority, information and capacity to manage it?Clear accountability, escalation routes, decision rights, reporting lines and committee oversight.
What is the current score?What assumptions sit behind that score, and have they been challenged?Scenario analysis, stress testing, near-miss data, lessons learned and independent assurance.
What happens if the risk materialises?How quickly would we know, respond and recover?Detective controls, incident response plans, communications protocols, resilience testing and lessons from exercises.

This is also where preventative and detective controls need to be understood properly. Preventative controls are there to reduce the likelihood of something going wrong. Detective controls are there to identify when something has gone wrong, or when the conditions for failure are beginning to emerge. Organisations often give more attention to the former because they feel more reassuring, but in fast-moving environments, detective controls can be just as important. They tell leaders whether reality is drifting away from the plan.

That matters because many serious issues do not arrive as a single dramatic event. They build gradually. A supplier starts missing service levels. Manual workarounds become normal. A system upgrade is delayed. A control owner leaves. Reporting packs continue to show green, but the confidence behind them has weakened. None of these things may look significant in isolation, but together they can change the risk profile of a programme, a service or a business unit.

The FCA’s operational resilience framework makes a related point for financial services firms. Firms in scope have been required to identify important business services, set impact tolerances and complete mapping and testing so they can remain within those tolerances. The emphasis is not simply on whether a firm has policies, but whether it understands the people, processes, technology, facilities, information and third parties needed to keep important services operating during disruption. That is a useful mindset beyond financial services as well, because it moves the conversation from “do we have a process?” to “can we continue to deliver what matters when conditions are difficult?”

Risk internal;audit

The direction of travel in cyber regulation is similar. The UK’s Cyber Security and Resilience Bill, which is intended to reform and add to the existing Network and Information Systems Regulations, points towards a stronger focus on resilience, supply chain dependencies, data centres, managed service providers and incident reporting. Even where organisations are not directly in scope, the message is clear: digital dependency, cyber exposure and third-party risk are now part of mainstream governance.

Paul Haley, Co-Founder of Littlechild & Haley, says:

“Risk management has to be close enough to the organisation to understand how things actually work, but independent enough to challenge whether the evidence supports the level of confidence being reported. That balance is important. If risk management becomes too theoretical, it loses the operational detail that matters; if it becomes too embedded in day-to-day delivery, it can lose the objectivity needed to ask whether the organisation is genuinely ready.”

For internal audit and assurance teams, this creates an opportunity to add real value. Assurance should not simply confirm whether a process exists or whether a control is documented. It should help the organisation understand whether risks are being managed in practice, whether controls remain proportionate, whether leadership information is reliable, and whether there are early signals that something important is changing.

This is particularly important in organisations that are growing, transforming or operating under high scrutiny. In those environments, risk can move quickly. A strategy that made sense six months ago may now rely on outdated assumptions. A control that worked in a smaller organisation may not scale. A cyber risk that once sat with IT may now have implications for finance, operations, customer trust, legal duties and reputation. A programme that appears to be on track may still be carrying unresolved dependencies that will only become visible late in delivery.

The better question, therefore, is not “is the risk register up to date?” It is “does our risk management approach help us make better decisions?”

That means looking at how risks are identified, how assumptions are challenged, how controls are tested, how issues are escalated, how cyber and operational resilience are integrated, and how boards and committees receive assurance. It also means recognising that good risk management is not designed to slow organisations down. Done well, it gives leaders more confidence to act, because they understand the risks they are taking, the controls they are relying on and the conditions that need to hold true for success.

Risk management is not a compliance document. It is not a quarterly refresh. It is not a list of red, amber and green boxes. It is a way of seeing the organisation honestly, testing whether confidence is justified, and helping leaders prepare for what may come next.

In that sense, the most mature organisations are not those that claim to have eliminated risk. They are the ones that know which risks matter, understand where their controls are strong or weak, and are willing to keep asking whether the evidence still supports the story they are telling themselves.

Risk readiness

References / sources

  1. Financial Reporting Council, UK Corporate Governance Code 2024.
  2. Financial Reporting Council, Annual Review of Corporate Governance Reporting 2025.
  3. Financial Reporting Council, Provision 29 Mythbuster.
  4. UK Government, Cyber Security Breaches Survey 2025/2026.
  5. Financial Conduct Authority, Operational resilience: insights and observations one year on.
  6. UK Government, Cyber Security and Resilience Bill: Summary of the Bill.
  7. UK legislation, Companies Act 2006, section 414C.

Paul Haley

Co-Founder

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Integer sagittis sodales nibh, at pharetra magna rhoncus vitae. In semper quis ligula non rhoncus.

Duis pharetra sem ultrices ultrices vestibulum. Donec imperdiet tempus ligula, quis semper massa pulvinar ut. Etiam id viverra eros, vitae vestibulum lectus. Morbi lacinia elit eu massa bibendum tristique in vitae lorem. Curabitur dignissim tempus quam sit amet tempor. Nullam pellentesque, urna non eleifend pretium, quam orci pharetra leo, et vulputate mi ligula vel massa. 

Paul Haley

Co-Founder

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Integer sagittis sodales nibh, at pharetra magna rhoncus vitae. In semper quis ligula non rhoncus.

Duis pharetra sem ultrices ultrices vestibulum. Donec imperdiet tempus ligula, quis semper massa pulvinar ut. Etiam id viverra eros, vitae vestibulum lectus. Morbi lacinia elit eu massa bibendum tristique in vitae lorem. Curabitur dignissim tempus quam sit amet tempor. Nullam pellentesque, urna non eleifend pretium, quam orci pharetra leo, et vulputate mi ligula vel massa.