Risk Management Is Not About Eliminating Risk: Using ISO 31000 to Make Better Decisions
- John C. Blackshire, Jr.

- Aug 22
- 8 min read
Risk Management Overview (ISO 31000) — September 15 and November 10, 2026
Every organization manages risk.
The question is whether it manages risk systematically, consistently and intelligently.
Executives make strategic decisions. Managers approve investments. Auditors assess controls. Organizations introduce new technology, hire employees, select vendors, enter markets and respond to regulatory requirements.
Every one of those activities involves uncertainty.
The purpose of risk management is not to eliminate that uncertainty. Organizations that eliminate all risk would probably eliminate most opportunities as well.
The objective is to understand uncertainty well enough to make better decisions.
That is the focus of Corporate Compliance Seminars' Risk Management Overview (ISO 31000), a 2-CPE program introducing professionals to the principles, framework and risk-management process contained in ISO 31000. The program addresses risk identification, assessment, treatment and monitoring while connecting risk management with organizational objectives, governance and resilience.
Upcoming sessions are:
Tuesday, September 15, 2026
Tuesday, November 10, 2026
Start With Objectives, Not Risks
Organizations sometimes begin risk assessments by asking:
“What are our risks?”
That sounds reasonable, but there is a better starting point:
“What are we trying to accomplish?”
Risk only makes sense in relation to objectives.
Suppose an organization has an objective to implement a new ERP system by January 1.
Now meaningful risk questions emerge:
What could prevent successful implementation?
What assumptions are we making?
Where are the greatest uncertainties?
What could cause cost overruns?
Could data conversion fail?
Are employees adequately trained?
Could cybersecurity weaknesses be introduced?
What happens if implementation is delayed?
The relationship becomes:
Objective
→ Uncertainty
→ Risk
→ Assessment
→ Response
→ Monitoring
That is a much stronger approach than developing a generic list of risks disconnected from what the organization is trying to achieve.
CCS's ISO 31000 program specifically emphasizes aligning risk-management practices with organizational goals and integrating risk management into strategic planning.
Risk Is Not Just Something Bad Happening
Risk management is frequently reduced to identifying bad things that might happen.
Cyberattack.
Fraud.
Regulatory violation.
System failure.
Employee turnover.
Supply-chain disruption.
Those certainly deserve attention.
But effective risk management is broader.
Organizations operate in an environment of uncertainty, and that uncertainty can affect objectives in different ways.
A new technology could fail.
It could also create substantial competitive advantage.
Entering a new market could generate losses.
It could also create significant growth.
Risk management should therefore help decision-makers understand both threats and opportunities.
CCS specifically describes ISO 31000 as helping organizations address evolving risks and opportunities while strengthening organizational resilience.
Risk Identification Is Only the Beginning
Many organizations believe they have an ERM program because they maintain a risk register.
A spreadsheet containing 75 risks is not necessarily enterprise risk management.
It is a list.
The real work begins after the risks have been identified.
For each significant risk, management needs to understand:
What causes the risk?
How likely is it?
What would the impact be?
How quickly could it affect us?
What controls already exist?
How effective are those controls?
What is the remaining risk?
Is that level of risk acceptable?
Who owns the risk?
What additional action is necessary?
CCS's program therefore moves beyond identification to risk assessment, treatment and monitoring.
Inherent Risk and Residual Risk Matter
Auditors and risk professionals should distinguish between the risk that exists before considering controls and the risk remaining afterward.
Consider the simple model:
Inherent Risk
↓
Controls and Risk Responses
↓
Residual Risk
Management should understand both.
Suppose a significant cyberattack could produce catastrophic consequences.
The organization implements:
Multi-factor authentication
Network segmentation
Endpoint protection
Security monitoring
Employee awareness training
Incident response
Backup and recovery controls
Those controls may substantially reduce the risk.
But they probably do not eliminate it.
The important management question becomes:
Is the residual risk within the level the organization is willing and able to accept?
That is where risk management becomes a management decision rather than merely a risk department exercise.
Someone Must Own the Risk
One of the most important questions in risk management is remarkably simple:
Who owns this risk?
The answer should not automatically be:
“Internal Audit.”
Internal Audit does not own management's risks.
Nor should the Chief Risk Officer become the owner of every organizational risk simply because that individual coordinates the ERM process.
Operational management owns operational risks.
Financial management owns financial risks.
Information technology management owns technology risks.
Executive management ultimately owns the risks associated with achieving organizational objectives.
Internal Audit can provide independent assurance concerning how effectively those risks are being managed.
That distinction protects accountability.
Risk Management Should Be Embedded in Decision-Making
CCS emphasizes integrating risk management into organizational culture and strategic planning rather than treating it as an isolated compliance activity.
That is important.
An organization should not perform its annual risk assessment in January, update a spreadsheet, present it to the board and forget about it until next January.
Risk management should appear when management considers:
Strategic Planning
Capital Investments
Acquisitions
New Technology
Artificial Intelligence
Major Projects
New Vendors
Outsourcing
Cybersecurity
New Products
Regulatory Changes
Organizational Restructuring
The practical question should become:
“What risks and opportunities should we understand before making this decision?”
That is a risk-aware organization.
A Risk Matrix Is a Tool, Not the Risk Assessment
Many organizations use a traditional matrix:
Likelihood × Impact = Risk Rating
There is nothing inherently wrong with that.
The problem occurs when the matrix becomes the entire risk-management process.
A risk rated High still needs analysis.
Why is it high?
What causes it?
How quickly could it occur?
What controls exist?
Are those controls effective?
Who owns the response?
What indicators would tell management that exposure is increasing?
What would happen if several risks occurred simultaneously?
A red square on a heat map is not risk management.
It is a communication device.
hink About Risk Velocity
Likelihood and impact are important, but they don't tell the entire story.
Consider two risks.
Both have a potentially significant financial impact.
Risk A might develop gradually over 18 months.
Risk B could produce severe consequences in 30 minutes.
Management's ability to respond is completely different.
That introduces the concept of risk velocity:
How quickly could the risk affect the organization once it begins to occur?
Cybersecurity incidents, liquidity crises, social-media events and certain regulatory matters can develop rapidly.
Management needs to understand not just how bad something could be, but how quickly it could become bad.
Think About Risk Inter-dependencies
Risks rarely operate independently.
A cyberattack might create:
Operational Risk
Financial Risk
Regulatory Risk
Legal Risk
Reputational Risk
A staffing shortage might create:
Operational Risk
Control Risk
Fraud Risk
Compliance Risk
Customer-Service Risk
This is one reason enterprise risk management needs an enterprise perspective.
Individual departments can understand their own risks while nobody recognizes how those risks interact across the organization.
Internal Auditors Have an Important Role
CCS specifically identifies auditors and assurance professionals among the intended audience for its ISO 31000 program.
That makes sense.
Risk assessment drives Internal Audit planning.
The auditor should understand:
What are management's objectives?
What could prevent those objectives from being achieved?
Which risks does management consider most significant?
How were those risks assessed?
What controls address them?
What residual risk remains?
What does management monitor?
Where does independent assurance exist?
Those questions can then influence the annual audit plan.
A risk-based audit plan should not simply be:
Last year's audit plan + different dates.
It should respond to the organization's current and emerging risk profile.
Internal Audit Should Challenge Management's Risk Assessment
Internal Audit should not automatically accept management's risk register as complete.
Suppose management identifies cybersecurity as a high risk.
Good.
But what about:
Management override?
Third-party concentration?
Artificial intelligence?
Succession planning?
Liquidity?
Regulatory change?
Data quality?
Fraud?
Corporate culture?
Business continuity?
The Internal Auditor can provide significant value by identifying blind spots.
One useful question is:
“What risk could materially affect this organization that management is currently underestimating?”
Another:
“What assumptions in our strategic plan would create significant problems if they prove wrong?”
Those are risk-management questions worth asking.
AI Creates Both Risk and Opportunity
Artificial intelligence provides an excellent modern example of ISO 31000 thinking.
Organizations can approach AI as a threat:
Data leakage.
Hallucinations.
Cybersecurity.
Bias.
Regulatory exposure.
Poor decisions.
Those risks are real.
But AI also creates opportunities:
Improved productivity.
Better analytics.
Fraud detection.
Faster research.
Automated processes.
Improved decision support.
The risk-management objective should not automatically be:
“Prevent employees from using AI.”
A more sophisticated question is:
“How can we obtain the benefits of AI while keeping the associated risks within acceptable boundaries?”
That is risk management.
Risk Treatment Requires Choices
Once management understands a risk, it has options.
Depending on the circumstances, management might:
Avoid the activity creating the risk.
Reduce the likelihood or impact through controls.
Transfer or share portions of the exposure.
Accept the remaining risk.
The correct response depends upon the organization's objectives, resources, risk appetite and circumstances.
That is why risk management should not automatically produce more controls.
Sometimes another control is appropriate.
Sometimes insurance is appropriate.
Sometimes redesigning the process is appropriate.
Sometimes discontinuing the activity is appropriate.
And sometimes management should knowingly accept the risk.
The key is that the decision should be informed and deliberate.
Monitoring Closes the Loop
Risk management cannot end when management selects a response.
The environment changes.
New competitors appear.
Technology changes.
Employees leave.
Regulations change.
Control effectiveness deteriorates.
New threats emerge.
The CCS program therefore includes monitoring as part of the ISO 31000 risk-management process.
Management should develop Key Risk Indicators (KRIs) where appropriate.
A KRI should help answer:
Is our exposure changing?
For example, depending upon the risk, management might monitor:
Employee turnover
Customer complaints
Cybersecurity incidents
Past-due receivables
Liquidity measures
Control exceptions
Vendor concentration
Regulatory findings
System downtime
The objective is to identify meaningful changes before they become surprises.
Risk Management Is a Governance Issue
CCS emphasizes that ISO 31000 can strengthen governance by aligning risk management with organizational priorities and values.
Boards and Audit Committees therefore have an important oversight role.
They should understand:
What are our most significant risks?
Which risks are increasing?
Which risks exceed tolerance?
What assumptions concern management?
What emerging risks are not yet fully understood?
Where are controls weakest?
What does Internal Audit believe?
nd perhaps:
“What could materially damage this organization that isn't currently receiving enough management attention?”
Risk oversight should produce discussion—not simply approval of a heat map.
Who Should Attend?
CCS designed Risk Management Overview (ISO 31000) for professionals seeking to strengthen their risk-management capabilities, including risk-management professionals, auditors and assurance professionals, and strategic leaders.
The program is classified at the Basic level, requires no prerequisites or advance preparation, and provides 2 NASBA-approved CPE credits in Auditing. It is delivered as a Group Internet-Based program from 1:00 p.m. to 3:00 p.m. Central Time.
Two Opportunities to Attend in 2026
Corporate Compliance Seminars offers two upcoming presentations particularly well timed for year-end and 2027 planning:
Tuesday, September 15, 2026
The September session provides an opportunity to strengthen risk-management knowledge as organizations begin developing budgets, strategies, risk assessments and audit plans for the coming year.
Tuesday, November 10, 2026
The November session is especially relevant for organizations finalizing their 2027 enterprise risk assessments and Internal Audit plans.
Before approving next year's audit plan, Audit Committees should be able to answer:
Does the Internal Audit plan actually address the risks that matter most to achieving our organization's objectives?
ISO 31000 provides a useful framework for having that discussion.
The Bottom Line: Risk Management Should Improve Decisions
The objective of enterprise risk management should not be producing:
More spreadsheets.
More heat maps.
More risk registers.
More committee meetings.
More compliance documentation.
The objective should be better decisions.
A useful risk-management process connects:
Objectives
→ Uncertainty
→ Risk Identification
→ Risk Assessment
→ Risk Treatment
→ Ownership
→ Monitoring
→ Decision-Making
→ Organizational Resilience
That is why ISO 31000 matters.
It provides organizations with a structured way to think about uncertainty while keeping the focus where it belongs: achieving objectives and making informed decisions. CCS's program specifically emphasizes ISO 31000's principles, framework and process and their application to risk identification, assessment, treatment and monitoring.
Corporate Compliance Seminars' Risk Management Overview (ISO 31000) on September 15 and November 10, 2026 provides a focused two-hour introduction to putting those concepts into practice.
Comments