Beyond reporting lines: rethinking risk and resilience

Beyond reporting lines: rethinking risk and resilience

Beyond Reporting Lines: Rethinking Risk and Resilience

Over the past 12 months there has been an interesting trend across a number of the UK’s largest organisations: risk and resilience functions traditionally found within Finance, are being aligned to General Counsel teams.

There are understandable reasons for this. Regulatory expectations continue to grow. Boards are under increasing scrutiny. Operational resilience, cyber risk, governance, compliance and legal obligations are more interconnected.

However, the focus on reporting lines overlooks a more important challenge: the need to create an integrated and human-centred lens on uncertainty, resilience, performance and decision-making.

Risk has historically found its home within Finance because the CFO was considered to be owner of the controls agenda, aligned to the external audit. While legal teams focused on regulatory obligations, resilience functions evolved separately to grapple with operational disruption, cyber threats and business continuity.

An explanation of this shift may be Provision 29 of the UK Corporate Governance Code. The Code is widening the lens of internal control, together with associated narrative reporting and disclosures in the Annual Report. This broader stewardship responsibility has historically sat within the orbit of the Company Secretariat and Legal teams. This does not mean that risk and resilience “belong” in Legal, but it helps explain why some organisations are looking to legal and governance functions to help frame and communicate the board-level story around control, accountability and assurance.

It also reflects an expansion of the General Counsel’s role. In many organisations, the GC is no longer viewed only as the organisation’s senior legal adviser, but as a broader counsel to the directors on governance, regulation, reputation, ethics, stakeholder expectations and enterprise judgement. The GC’s vantage point can be valuable: not because legal advice is a substitute for risk management, operational resilience or assurance, but because the GC often sits at the intersection of strategy and board obligations and accountability.

Boards are being asked to oversee increasingly complex and interconnected challenges. Cyber incidents become operational failures. Operational failures become regulatory events. Regulatory events become reputational issues. Culture influences risk-taking behaviour. Technology introduces new opportunities and new uncertainties. AI is accelerating both the volume of information available and the speed at which decisions must be made.

None of these challenges fit neatly within a single function. The real challenge is not organisational ownership, but organisational integration. Directors need a joined-up view of strategy, risk, resilience, performance and culture to make informed decisions in an increasingly complex environment. This is objective-centric risk management.

Too often, strategy, risk, resilience, compliance, performance and assurance are reported through separate channels. Directors receive extensive reporting, often from highly capable teams. Yet directors still say they struggle to see how the pieces fit together. The result is plenty of information but insufficient insight.

When risk reports within Finance, the result can be to over-index on controls and reporting. When it sits within Legal, there is a risk of over-indexing on compliance and regulatory obligations. Neither of these perspectives are wrong. But without integration meaningful change is unlikely.

Leading organisations are those that focus less on ownership and more on integration. They seek to connect strategic objectives, risk, resilience, performance, culture and decision-making into a coherent whole.  This is where good governance is heading. Not towards another organisational reshuffle, but towards a model where directors receive a joined-up view of what matters most, written in the language of the directors, focused on strategic objectives, and empowering decisions that need to be made.

The future of governance is not about finding the perfect home for risk and resilience, it’s about ensuring that risk, resilience, legal, compliance, internal audit, strategy and performance collectively contribute to one thing: better decisions.

AUTHORS.

EMMA PRICE & MICHAEL LUCAS.

Share on
Related Posts