Questions to Ask About Risk Management
These questions to ask about risk management are for a board member, an executive or a manager who has just been handed responsibility for risk, to put to the people who run it: the risk officer, the senior team or a project lead. They follow the order a review tends to take: the top risks and who owns them, how risks are found and scored, how much risk the organization has agreed to take, the controls and how they are tested, who oversees it all and what reaches the board, and what happens when something goes wrong, insurance and continuity plans included. A project lead can answer a shorter version of each group for the project alone.
Want questions from the whole vault instead? Try the random question generator.
The questions
Each question, and why to ask it
Top risks
What are the five biggest risks to this organization right now?
Why ask it
Ask for them in order, and put the same question to two or three senior people separately. Matching lists give you a shared view to work from. Where they differ, you have the first thing to talk about, and it is usually worth more than anything on the register.
Who owns each of the top risks, by name?
Why ask it
An owner is one person with the authority to spend money or change a process, not a committee or a department. Check with a couple of the people named that they know the risk is theirs. A risk owned by 'management' in general tends to be watched by nobody in particular.
Which of the top risks has gotten worse since the last review, and why?
Why ask it
Direction matters as much as the rating. A risk that moved from moderate toward high in one quarter deserves more time than one that has sat at high, well managed, for years. If nothing has moved either way, the next thing to ask is when anyone last looked at the ratings properly.
What came onto the risk register in the past year, and what came off?
Why ask it
Entries should arrive and leave as the organization changes. For anything removed, the detail that matters is whether the risk went away, was accepted, or simply stopped being reported. If the list reads the same as last year's, ask who opened it between the two reviews.
Which risks could end the organization, as opposed to giving it a bad year?
Why ask it
Most entries on a register cost money or time. A few threaten the license to operate, the cash to keep going or the trust of the people served. Those few need a plan even when they are unlikely, because a low score is little comfort if the one time is the last.
Which of our risks are common to the whole sector, and which are particular to us?
Why ask it
Sector-wide risks come with help: peers, trade bodies and insurers have usually seen them before. The ones particular to you, such as one customer who provides a large share of income or one site that everything runs through, are the ones nobody outside will warn you about.
Which two risks would make each other worse if they landed in the same quarter?
Why ask it
Registers list risks one line at a time, and trouble rarely arrives that way. A key supplier failing during a cash squeeze is a different event from either alone. If nobody has thought about pairs, pick one and talk it through for ten minutes.
What worries you that is not on the register?
Why ask it
Registers hold what can be defended in a meeting, and a risk officer's unease often has not reached that stage. Give the question a pause. Whatever comes out is a candidate for the next review, and the reason it was left off is worth hearing too.
On this project, what is most likely to make it late, over budget or short of what was promised?
Why ask it
This is the version for a project lead. Ask which of the three they would bet on, and the date by which they will know. A project risk log that lists only outside causes, such as suppliers and approvals, is leaving out the team's own estimates and capacity.
Finding and scoring
How are risks identified here: who is asked, and how often?
Why ask it
A workshop of senior managers finds the risks senior managers already know about. The people who take complaints, run the sites or fix the systems see different ones, so press on when they were last asked and what the last full sweep turned up that was new.
How do you pick up risks that are new or still taking shape?
Why ask it
A change in regulation, a new technology or a shift among suppliers can matter long before it fits a line on the register. Someone should be named as watching for these and able to tell you the last one that was added. If the only mechanism is the annual review, a new risk can sit unnoticed for most of a year.
Which of our risks sit with suppliers and other outside parties, and how much can we see of them?
Why ask it
Handing work to another firm does not hand over the consequences when it fails. Get the names of the suppliers that could stop you operating, and what you would know about trouble there before it reached you. What you can require of a supplier depends on the contract, so ask what yours say.
Where do cyber and data security risks sit on the register, and who outside the technology team understands them?
Why ask it
These are often scored by the people who run the systems and reported in terms few others can question. Ask for the top one put as a business event: which service stops, for how long, and whose information is exposed. Duties to report a data breach depend on the country and sector, so check which ones bind you.
Which assumptions is this year's plan built on, and which one would hurt most if it proved wrong?
Why ask it
Strategic risk hides in assumptions: a price that holds, a contract that renews, a hiring rate. For each one named, ask who would notice it going wrong and how early. If nobody is tracking it, put it on the register with an owner before you move on.
How is a risk scored, and what does each score mean in money, time or harm?
Why ask it
Many organizations rate likelihood and impact on a scale of one to five and multiply the two. That only works if someone has written down what a four is, such as a loss above a stated amount or an outage longer than a stated time. Ask to see the definitions, because without them one manager's high is another's medium.
Who sets the score: the owner of the risk, or someone independent of it?
Why ask it
Owners have a reason to score their own risks kindly, since a red rating brings questions and extra work. Find out who challenges the ratings, and ask for the last time one was raised over the owner's objection.
Are the ratings on the register shown before or after the controls we have in place?
Why ask it
A register often shows both: the risk as it would be with nothing done, and as it stands with controls working. A risk that is green only after controls depends entirely on those controls, so ask which ones account for the difference. Those are the ones to see tested.
Which rating on the register are you least sure of?
Why ask it
Some scores rest on good data and others on a guess made in a workshop. The ones the risk lead doubts are where a second opinion or some real figures would help most. Total confidence in every line is the answer to worry about.
How quickly could each top risk hit us, and how much warning would we get?
Why ask it
Scoring grids often leave out speed. Skills draining out of a team or equipment wearing down can be watched and slowed, while a payment fraud or a system failure gives no notice and needs a response ready beforehand. Two risks with the same score can call for opposite kinds of preparation.
Appetite
How much risk are we prepared to take in pursuit of our goals, and where is that written down?
Why ask it
The written version is usually called a risk appetite statement. Ask for it, along with the date it was approved and by whom. One that declares a low appetite for everything cannot guide a decision, because every worthwhile choice carries some risk.
Where are we deliberately taking more risk because the reward justifies it?
Why ask it
Risk management is not only about avoiding things. A new market, a large investment or a fast launch is a risk chosen on purpose. If nobody can name one, either the organization is more cautious than it believes or risks are being taken without anyone saying so.
Which risks are outside our appetite today, and what is the date for bringing each one back inside?
Why ask it
A short list with dates is the healthy answer. Where a risk has sat outside appetite for a year with no plan, it has been accepted in practice, and someone should be able to say who agreed to that. If nothing is ever outside appetite, the limits may be set too loosely to bite.
What limits turn the appetite into something a manager can act on?
Why ask it
Words such as cautious or open mean little on a Tuesday afternoon. Limits do: a ceiling on reliance on one customer, a floor for cash, a maximum tolerable outage. Ask what happens when one is breached, and when that last occurred.
Can you give me a recent decision where the stated appetite changed the outcome?
Why ask it
A deal made smaller, a launch delayed or a supplier dropped shows the statement is in use. If nobody can think of an example from the past year, the document may be read only when it is up for renewal. The question then becomes who is expected to consult it, and at which point in a decision.
How is risk weighed when a new project, product or major contract comes up for approval?
Why ask it
A risk section written by the sponsor of a proposal is advocacy. Someone without a stake should review it, and a recent proposal that was changed or stopped as a result is the evidence that they do. If there is none, the review may be a formality.
Who can accept a risk on the organization's behalf, and up to what size?
Why ask it
Risks are often accepted quietly by whoever happens to be closest. A written threshold, above which the decision moves up a level, makes that harder. Ask to see the last few risks that were formally accepted and who signed each one.
Do the managers making everyday decisions know what the appetite is?
Why ask it
Put this one to a middle manager, not to the risk officer. If they cannot say what is off limits in their own area, the appetite exists in board papers only. A one-page version in plain words for each department is a reasonable thing to ask for.
Controls
For each top risk, what is the main control, and who operates it?
Why ask it
You want one control per risk in plain words: a second sign-off on payments, a nightly backup, a monthly inspection. If the reply is the name of a policy, ask what a person actually does, and how often. A policy describes an intention, and a control is an action someone takes.
For each top risk, have we chosen to avoid it, reduce it, pass it to someone else or live with it?
Why ask it
Those four choices cover most of what can be done with a risk, and each top risk should have one on record. Living with a risk is a fair answer when it comes with a name and a date. Passing it on, through insurance or a contract, deserves a second look at how much of it comes back if the other party cannot pay.
How do you know the controls work, and when was each key one last tested?
Why ask it
Tested means someone other than the person who operates the control looked at evidence that it happened. Get the date, the tester and the result for each key control. Until someone has checked, you are trusting that it works, however sensible it looks on paper.
Which controls depend on one person remembering to do something?
Why ask it
Manual checks tend to slip during holidays, staff changes and the busiest weeks, which is when they matter. For each one named, ask who covers when that person is away and whether the step could be built into a system.
Which controls failed or were bypassed in the past year, and what happened next?
Why ask it
In an organization of any size, an answer of none more often means failures are not recorded than that there were none. Follow up by asking how someone would report a control that did not work, and whether the last person who did was thanked.
Who looks at risk and controls independently of the managers who run them, and what do they leave out?
Why ask it
Larger organizations may have internal audit, and smaller ones may rely on an outside reviewer or a board member with the right background. Whoever it is, get their plan for the year and look for the gaps. A top risk that no independent person has examined in two years is the place to send them next.
How many actions from audits and risk reviews are open, and how many are past their due date?
Why ask it
Overdue actions are a plain measure of whether risk work turns into change. Ask about the oldest one and what is holding it up. When a due date has been moved three times, treat the risk behind it as accepted and ask who agreed.
What early warning measures do you track for the top risks, and at what level does someone act?
Why ask it
These are often called key risk indicators: overdue maintenance, turnover in a critical team, late supplier deliveries, complaints of one kind. Each needs a level at which somebody has to act, so ask for the last time one crossed its line and what was done.
Where are we over-controlled, spending effort on checks that no longer earn their keep?
Why ask it
Controls tend to be added after an incident and rarely taken away. Ask which one uses the most staff time and what would happen if it stopped. Time freed there can go to a top risk whose cover is thin, which makes this a question operational managers are glad to hear.
Oversight
Who is accountable for risk management as a whole, and what is everyone else's part in it?
Why ask it
Titles vary: a chief risk officer, a finance director who carries it alongside the accounts, or the chief executive in a small organization. Whoever it is should be able to say what they do themselves and what stays with the managers who run the work. If the reply is that risk is everyone's job, ask who would be answering for it after a serious failure.
What does the board see on risk, how often, and who writes it?
Why ask it
Ask for the most recent report and read it as a director would. A page that shows the top risks, which way each is moving and what is needed from the board does more than a forty-row grid of colored squares. If risk owners write their own entries, check who edits them.
Which committee or person oversees risk on the board's behalf, and what falls outside their remit?
Why ask it
An audit committee often takes the financial risks, and safety, technology, people and strategy can fall between committees. Ask for the terms of reference and check each top risk against them. How oversight is divided varies with the size and sector of the organization, so ask how it is done there.
Do we follow a published standard or framework for managing risk, and where do we depart from it?
Why ask it
ISO 31000 and the COSO enterprise risk framework are two that organizations commonly name. Following one is rarely the point by itself: what you want is the gap between what the framework describes and what happens here, and whether that gap was chosen. Some regulators and funders expect a particular one, so check whether yours do.
How does a serious risk get from the front line to the top, and how long does it take?
Why ask it
Have them trace a real one: who noticed, who they told, and the day an executive first heard. If the route runs through a quarterly cycle, ask what the fast lane is and whether anyone below senior level knows it exists.
What would you bring to the board the same day, without waiting for the next meeting?
Why ask it
Triggers are best agreed in a calm month: a serious injury, a loss of personal data, contact from a regulator, a loss above a stated amount. Without a list, the call is made under pressure by the person with the most reason to wait and see.
What did the last risk report leave out or soften?
Why ask it
Summaries compress. On a heat map, a risk that could close the organization and one that would dent a quarter can share a square. Ask what was cut from the final draft and whether any rating changed between the risk team's version and the one the board received.
Is it safe here to bring bad news or admit a mistake?
Why ask it
One person's word is not enough here, so ask when someone junior last raised a problem and what became of them. A route for concerns that goes around the line manager matters too. Rules on protected reporting differ by country, so check what applies where you are.
Does the risk function have the people, the access and the standing to challenge senior managers?
Why ask it
Three things show it: who the head of risk reports to, whether they can speak to the board or its committee without executives present, and what happened the last time they disagreed with one. Some sectors set rules on this, so ask what applies to yours.
What have regulators, insurers, lenders or auditors said about how we manage risk?
Why ask it
Outsiders see many organizations, and their comments are a comparison you do not have to pay extra for. Ask for the latest letters or reports and whether each point raised has been closed. Which bodies have a say depends on your country and sector.
With more budget for risk, what would you do first, and what would you stop doing either way?
Why ask it
The first half shows where the risk lead thinks the cover is thinnest. The second shows which activities they regard as box ticking. Both are worth taking to whoever sets the budget, with the top risks beside them.
If it goes wrong
What were the most significant incidents and near misses of the past year?
Why ask it
Ask for both kinds. A near miss often has the same causes as an incident, with luck making the difference, so it is a cheap way to learn. A long list of incidents beside an empty list of near misses suggests the close calls are not being reported.
What did we change after the last serious incident, and how do we know the change held?
Why ask it
Reminding staff of the procedure is the weakest outcome a review can have. Look for an altered system, an added check or a different staffing pattern, and for the person who went back some months later to confirm it was still in place.
Was the last serious incident on the risk register before it happened?
Why ask it
If it was, either the score or the control was wrong, and you can ask which. If it was not, the way risks are found has a blind spot, and other things may be sitting in it. Both answers point to the part of the process that needs fixing.
Which of our risks are insured, which are not, and what do the policies exclude?
Why ask it
A policy may pay part of the cost of an event and still leave you with the deductible, the downtime and the lost customers. Have the broker or whoever manages the policies set the main limits and exclusions beside the top risks. Cover differs from one policy to the next, so the answer has to come from your own documents.
What is the largest loss we could absorb without outside help?
Why ask it
The figure feeds two decisions: how large a deductible to carry, and which risks are too big to keep. The finance lead should be able to say how it was worked out from cash and reserves, and when. If nobody has a number, working one out is a good first action.
If our main site, system or supplier were unavailable tomorrow morning, what would the first 24 hours look like?
Why ask it
Ask for it as a walk-through: who gets the first call, where people work, what customers are told and by whom. Hesitation over those basics suggests the plan lives in a document nobody has opened. Try it with a different scenario for each of the three.
When was the continuity plan last tested, and what did the test show?
Why ask it
A two-hour exercise where the senior team talks through a scenario counts, and usually finds a good deal. Ask what broke. A test that found nothing was probably too gentle, and an out-of-date contact list is the kind of thing a real one turns up.
Which activities have to be back within hours, which can wait days, and who decided?
Why ask it
The order of recovery is a business decision, so it should come from the people who run the services and not from the technology team alone. Compare the times written in the plan with the times achieved in the last test or real outage.
Who leads in a crisis, who speaks for us, and who steps in if they cannot be reached?
Why ask it
You are after names, deputies and a way to reach them out of hours that does not depend on the system that may be down. Ask whether that group has ever practiced together, because people who meet for the first time during the event can lose the first hours to working out who decides.
Which people hold knowledge or relationships we could not replace quickly?
Why ask it
It is easier to ask about roles than about a person sitting in the room. For each role named, the follow-ups are what is written down, who could cover for a month, and whether a successor has been thought about. In a small organization the answer is often the founder or whoever keeps the books.
How to question the people who run risk
Practical guidance for the conversation itself
Before the conversation
Read the register and the last board report first
Ask for the current risk register, the appetite statement if one exists and the most recent risk report to the board, and read them before you meet anyone. Half the questions under Top risks and Finding and scoring can then start from a line on the page: 'This one is rated moderate. What would make it high?' gets further than asking for a general account of how scoring works.
Match each group to the person who knows
Top risks and Appetite belong with the chief executive or the senior team, because those are choices only they can make. Finding and scoring and Controls go to the risk officer or whoever keeps the register, and to the managers who own individual risks. Oversight is for the chair, the committee that looks after risk and the head of risk. If it goes wrong is for operations, the finance lead and whoever deals with the insurance broker. A project lead can answer a cut-down version of every group for the project alone.
Plan for about ten questions in an hour
Each of these opens a follow-up or two, so an hour tends to cover about ten. For a first meeting, take the opening two from each group and leave the rest for a second sitting. A new board member can spread the groups over a year of meetings, one group each time risk is on the agenda.
Say why you are asking
Risk questions from a director or a new boss can sound like an inspection. A sentence up front helps: you are trying to understand how risk is handled so you can support it, not to grade anyone. People who feel examined give the tidy answer, and the tidy answer is the one you already have in the report.
Running the conversation
Ask for the document, then for the example
Nearly every question here has two layers. The first is whether something exists: an owner, a scoring scale, an appetite statement, a continuity plan. The second is whether it has been used: the decision it changed, the test it went through, the day it was last opened. Get the first quickly and spend the time on the second.
Follow one risk from end to end
Choose one of the top risks and take it through every group: who owns it, how it was scored, the control that brings the score down, when that control was tested, what the board was told and whether there has been an incident or a near miss. One risk traced all the way shows how the whole system works. Twenty risks skimmed show only that a register exists.
Put the same question to more than one person
The top five risks, the appetite and the first call in a crisis are worth asking of the risk officer, an executive and a manager closer to the work, separately. You are not trying to catch anyone out. The differences between the three answers show where the organization has not yet made up its mind.
Turn ratings into plain terms
High, amber and four out of five are shorthand. Each time one comes up, ask what it would mean in money lost, days out of action or people harmed, and how likely the person thinks it is in the next year or two. If they cannot translate it, the rating was probably agreed by feel, which is useful to know before you rely on it.
What strong and weak answers sound like
Names, dates and amounts
A strong answer has a person, a date and a figure in it: who owns the risk, when the control was last tested, how large a loss would trigger a call to the chair. An answer made of process words, such as framework, methodology or embedded, may be accurate and still tell you nothing about whether the work is done. Ask for one name or one date and see whether it comes.
A register where nothing moves
Organizations change every quarter, so ratings, owners and entries should change too. A register with the same risks at the same scores as a year ago, each with the comment 'no change', has usually become a document produced for the meeting. The remedy is small: ask at each review what moved and why, and the people preparing it will start looking.
Everything rated green
A page of green can mean the organization is well run. It can also mean that owners score their own risks, that nobody challenges them or that red ratings are unwelcome. Ask which rating was most argued over and who argued. If no rating has ever been disputed, the color is telling you about the culture more than about the risks.
Bad news that arrives early
The best sign of all is a risk officer or manager who volunteers a problem before you find it: a control that failed, an action that is overdue, a near miss last month. Thank them plainly and ask what they need. How the first piece of unwelcome news is received decides how much of it you will hear afterwards.
Traps for the person asking
Taking the paperwork for the management
A register, a heat map and a policy are records of risk management, and it is possible to have all three and manage very little. The questions under Controls and If it goes wrong are the check: what a person does, when it was tested, what changed after the last incident. If time is short, cut the questions about documents before you cut those.
Asking only the risk function
The risk officer coordinates and challenges. The risks themselves belong to the managers who run the operations, the money and the projects. If every answer comes from the risk team, you are hearing a summary. Put at least a few questions straight to a risk owner, with the risk officer in the room if that is more comfortable.
Treating every risk as something to remove
An organization that takes no risk does nothing new. The aim of these questions is to see that risks are chosen knowingly, sized against what the organization can absorb and watched, and that includes finding places where it could afford to take more. A director who only ever asks for more controls will, in time, be told less.
Stopping at the answer
A good conversation about risk ends with two or three actions, each with an owner and a date, and a note of when you will ask again. Write them down before you leave and bring the same list to the next review. Managers work out quickly whether a board member's questions are followed up, and prepare accordingly.