top of page
Search

Risk Management Is Not About Eliminating Risk: Using ISO 31000 to Make Better Decisions

Aug 22
8 min read

Risk Management Overview (ISO 31000) — September 15 and November 10, 2026


Every organization manages risk.


The question is whether it manages risk systematically, consistently and intelligently.


Executives make strategic decisions. Managers approve investments. Auditors assess controls. Organizations introduce new technology, hire employees, select vendors, enter markets and respond to regulatory requirements.


Every one of those activities involves uncertainty.


The purpose of risk management is not to eliminate that uncertainty. Organizations that eliminate all risk would probably eliminate most opportunities as well.


The objective is to understand uncertainty well enough to make better decisions.


That is the focus of Corporate Compliance Seminars' Risk Management Overview (ISO 31000), a 2-CPE program introducing professionals to the principles, framework and risk-management process contained in ISO 31000. The program addresses risk identification, assessment, treatment and monitoring while connecting risk management with organizational objectives, governance and resilience.


Upcoming sessions are:

  • Tuesday, September 15, 2026

  • Tuesday, November 10, 2026



Start With Objectives, Not Risks


Organizations sometimes begin risk assessments by asking:

“What are our risks?”

That sounds reasonable, but there is a better starting point:

“What are we trying to accomplish?”

Risk only makes sense in relation to objectives.


Suppose an organization has an objective to implement a new ERP system by January 1.


Now meaningful risk questions emerge:

  • What could prevent successful implementation?

  • What assumptions are we making?

  • Where are the greatest uncertainties?

  • What could cause cost overruns?

  • Could data conversion fail?

  • Are employees adequately trained?

  • Could cybersecurity weaknesses be introduced?

  • What happens if implementation is delayed?


The relationship becomes:


Objective

Uncertainty

Risk

Assessment

Response

Monitoring


That is a much stronger approach than developing a generic list of risks disconnected from what the organization is trying to achieve.


CCS's ISO 31000 program specifically emphasizes aligning risk-management practices with organizational goals and integrating risk management into strategic planning.


Risk Is Not Just Something Bad Happening

Risk management is frequently reduced to identifying bad things that might happen.

  • Cyberattack.

  • Fraud.

  • Regulatory violation.

  • System failure.

  • Employee turnover.

  • Supply-chain disruption.


Those certainly deserve attention.


But effective risk management is broader.


Organizations operate in an environment of uncertainty, and that uncertainty can affect objectives in different ways.


A new technology could fail.


It could also create substantial competitive advantage.


Entering a new market could generate losses.


It could also create significant growth.


Risk management should therefore help decision-makers understand both threats and opportunities.


CCS specifically describes ISO 31000 as helping organizations address evolving risks and opportunities while strengthening organizational resilience.


Risk Identification Is Only the Beginning

Many organizations believe they have an ERM program because they maintain a risk register.


A spreadsheet containing 75 risks is not necessarily enterprise risk management.


It is a list.


The real work begins after the risks have been identified.


For each significant risk, management needs to understand:

  • What causes the risk?

  • How likely is it?

  • What would the impact be?

  • How quickly could it affect us?

  • What controls already exist?

  • How effective are those controls?

  • What is the remaining risk?

  • Is that level of risk acceptable?

  • Who owns the risk?

  • What additional action is necessary?


CCS's program therefore moves beyond identification to risk assessment, treatment and monitoring.


Inherent Risk and Residual Risk Matter

Auditors and risk professionals should distinguish between the risk that exists before considering controls and the risk remaining afterward.


Consider the simple model:


Inherent Risk

Controls and Risk Responses

Residual Risk


Management should understand both.


Suppose a significant cyberattack could produce catastrophic consequences.


The organization implements:

  • Multi-factor authentication

  • Network segmentation

  • Endpoint protection

  • Security monitoring

  • Employee awareness training

  • Incident response

  • Backup and recovery controls


Those controls may substantially reduce the risk.


But they probably do not eliminate it.


The important management question becomes:

Is the residual risk within the level the organization is willing and able to accept?

That is where risk management becomes a management decision rather than merely a risk department exercise.


Someone Must Own the Risk

One of the most important questions in risk management is remarkably simple:

Who owns this risk?

The answer should not automatically be:

“Internal Audit.”

Internal Audit does not own management's risks.


Nor should the Chief Risk Officer become the owner of every organizational risk simply because that individual coordinates the ERM process.


Operational management owns operational risks.


Financial management owns financial risks.


Information technology management owns technology risks.


Executive management ultimately owns the risks associated with achieving organizational objectives.


Internal Audit can provide independent assurance concerning how effectively those risks are being managed.


That distinction protects accountability.


Risk Management Should Be Embedded in Decision-Making

CCS emphasizes integrating risk management into organizational culture and strategic planning rather than treating it as an isolated compliance activity.


That is important.


An organization should not perform its annual risk assessment in January, update a spreadsheet, present it to the board and forget about it until next January.


Risk management should appear when management considers:

  • Strategic Planning

  • Capital Investments

  • Acquisitions

  • New Technology

  • Artificial Intelligence

  • Major Projects

  • New Vendors

  • Outsourcing

  • Cybersecurity

  • New Products

  • Regulatory Changes

  • Organizational Restructuring


The practical question should become:

“What risks and opportunities should we understand before making this decision?”

That is a risk-aware organization.


A Risk Matrix Is a Tool, Not the Risk Assessment

Many organizations use a traditional matrix:


Likelihood × Impact = Risk Rating


There is nothing inherently wrong with that.


The problem occurs when the matrix becomes the entire risk-management process.


A risk rated High still needs analysis.


Why is it high?


What causes it?


How quickly could it occur?


What controls exist?


Are those controls effective?


Who owns the response?


What indicators would tell management that exposure is increasing?


What would happen if several risks occurred simultaneously?


A red square on a heat map is not risk management.


It is a communication device.


hink About Risk Velocity

Likelihood and impact are important, but they don't tell the entire story.


Consider two risks.


Both have a potentially significant financial impact.


Risk A might develop gradually over 18 months.


Risk B could produce severe consequences in 30 minutes.


Management's ability to respond is completely different.


That introduces the concept of risk velocity:

How quickly could the risk affect the organization once it begins to occur?

Cybersecurity incidents, liquidity crises, social-media events and certain regulatory matters can develop rapidly.


Management needs to understand not just how bad something could be, but how quickly it could become bad.


Think About Risk Inter-dependencies

Risks rarely operate independently.


A cyberattack might create:


Operational Risk


Financial Risk


Regulatory Risk


Legal Risk


Reputational Risk

A staffing shortage might create:

Operational Risk


Control Risk


Fraud Risk


Compliance Risk


Customer-Service Risk


This is one reason enterprise risk management needs an enterprise perspective.


Individual departments can understand their own risks while nobody recognizes how those risks interact across the organization.


Internal Auditors Have an Important Role

CCS specifically identifies auditors and assurance professionals among the intended audience for its ISO 31000 program.


That makes sense.


Risk assessment drives Internal Audit planning.


The auditor should understand:

What are management's objectives?
What could prevent those objectives from being achieved?
Which risks does management consider most significant?
How were those risks assessed?
What controls address them?
What residual risk remains?
What does management monitor?
Where does independent assurance exist?

Those questions can then influence the annual audit plan.


A risk-based audit plan should not simply be:

Last year's audit plan + different dates.

It should respond to the organization's current and emerging risk profile.


Internal Audit Should Challenge Management's Risk Assessment

Internal Audit should not automatically accept management's risk register as complete.


Suppose management identifies cybersecurity as a high risk.


Good.


But what about:

  • Management override?

  • Third-party concentration?

  • Artificial intelligence?

  • Succession planning?

  • Liquidity?

  • Regulatory change?

  • Data quality?

  • Fraud?

  • Corporate culture?

  • Business continuity?


The Internal Auditor can provide significant value by identifying blind spots.


One useful question is:

“What risk could materially affect this organization that management is currently underestimating?”

Another:

“What assumptions in our strategic plan would create significant problems if they prove wrong?”

Those are risk-management questions worth asking.


AI Creates Both Risk and Opportunity

Artificial intelligence provides an excellent modern example of ISO 31000 thinking.


Organizations can approach AI as a threat:


Data leakage.


Hallucinations.


Cybersecurity.


Bias.


Regulatory exposure.


Poor decisions.


Those risks are real.


But AI also creates opportunities:

  • Improved productivity.

  • Better analytics.

  • Fraud detection.

  • Faster research.

  • Automated processes.

  • Improved decision support.


The risk-management objective should not automatically be:

“Prevent employees from using AI.”

A more sophisticated question is:

“How can we obtain the benefits of AI while keeping the associated risks within acceptable boundaries?”

That is risk management.


Risk Treatment Requires Choices

Once management understands a risk, it has options.


Depending on the circumstances, management might:


  • Avoid the activity creating the risk.


  • Reduce the likelihood or impact through controls.


  • Transfer or share portions of the exposure.


  • Accept the remaining risk.


The correct response depends upon the organization's objectives, resources, risk appetite and circumstances.


That is why risk management should not automatically produce more controls.


Sometimes another control is appropriate.


Sometimes insurance is appropriate.


Sometimes redesigning the process is appropriate.


Sometimes discontinuing the activity is appropriate.


And sometimes management should knowingly accept the risk.


The key is that the decision should be informed and deliberate.


Monitoring Closes the Loop

Risk management cannot end when management selects a response.


The environment changes.


New competitors appear.


Technology changes.


Employees leave.


Regulations change.


Control effectiveness deteriorates.


New threats emerge.


The CCS program therefore includes monitoring as part of the ISO 31000 risk-management process.


Management should develop Key Risk Indicators (KRIs) where appropriate.


A KRI should help answer:

Is our exposure changing?

For example, depending upon the risk, management might monitor:

  • Employee turnover

  • Customer complaints

  • Cybersecurity incidents

  • Past-due receivables

  • Liquidity measures

  • Control exceptions

  • Vendor concentration

  • Regulatory findings

  • System downtime


The objective is to identify meaningful changes before they become surprises.


Risk Management Is a Governance Issue

CCS emphasizes that ISO 31000 can strengthen governance by aligning risk management with organizational priorities and values.


Boards and Audit Committees therefore have an important oversight role.


They should understand:

  • What are our most significant risks?

  • Which risks are increasing?

  • Which risks exceed tolerance?

  • What assumptions concern management?

  • What emerging risks are not yet fully understood?

  • Where are controls weakest?

  • What does Internal Audit believe?


nd perhaps:

“What could materially damage this organization that isn't currently receiving enough management attention?”

Risk oversight should produce discussion—not simply approval of a heat map.


Who Should Attend?

CCS designed Risk Management Overview (ISO 31000) for professionals seeking to strengthen their risk-management capabilities, including risk-management professionals, auditors and assurance professionals, and strategic leaders.


The program is classified at the Basic level, requires no prerequisites or advance preparation, and provides 2 NASBA-approved CPE credits in Auditing. It is delivered as a Group Internet-Based program from 1:00 p.m. to 3:00 p.m. Central Time.


Two Opportunities to Attend in 2026

Corporate Compliance Seminars offers two upcoming presentations particularly well timed for year-end and 2027 planning:


Tuesday, September 15, 2026

The September session provides an opportunity to strengthen risk-management knowledge as organizations begin developing budgets, strategies, risk assessments and audit plans for the coming year.


Tuesday, November 10, 2026

The November session is especially relevant for organizations finalizing their 2027 enterprise risk assessments and Internal Audit plans.


Before approving next year's audit plan, Audit Committees should be able to answer:

Does the Internal Audit plan actually address the risks that matter most to achieving our organization's objectives?

ISO 31000 provides a useful framework for having that discussion.


The Bottom Line: Risk Management Should Improve Decisions

The objective of enterprise risk management should not be producing:

  • More spreadsheets.

  • More heat maps.

  • More risk registers.

  • More committee meetings.

  • More compliance documentation.

  • The objective should be better decisions.


A useful risk-management process connects:


Objectives

Uncertainty

Risk Identification

Risk Assessment

Risk Treatment

Ownership

Monitoring

Decision-Making

Organizational Resilience


That is why ISO 31000 matters.


It provides organizations with a structured way to think about uncertainty while keeping the focus where it belongs: achieving objectives and making informed decisions. CCS's program specifically emphasizes ISO 31000's principles, framework and process and their application to risk identification, assessment, treatment and monitoring.


Corporate Compliance Seminars' Risk Management Overview (ISO 31000) on September 15 and November 10, 2026 provides a focused two-hour introduction to putting those concepts into practice.


 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page