Articles | Cases

Uncovering the hidden cost and impact of risk management failure
By Randy Boss, CRM, MWCA, SHRM-SCP


Risk management is a necessary process that businesses and organizations undertake to identify, assess, and mitigate risks that can potentially harm their operations, assets, or reputation. Risk management's goal is to minimize the likelihood and impact of adverse events. But despite the best intentions, it can fail. Here are the reasons behind risk management failures and their consequences.


Failure to IDENTIFY

The first step in risk management is identifying potential risks that could impact a business because you can't manage what you do not know. This step involves reviewing business processes, the external environment, and other factors that could put operations at risk. A business must identify internal and external dangers, such as financial risks, natural disasters, cybersecurity threats, and market competition. As insurance and risk advisors, we can assist in using different methods to identify risk, such as checklists, employee interviews, walkarounds, industry experts, looking at past incident and near-miss reports, and conducting job safety analyses (or similar task evaluation processes). I recently conducted a walkthrough and discovered an opening in a mezzanine without a gate or safety chain. During a round of employee risk interviews, somebody noted that some employees were overriding safety features to speed up machines to add to their piece work pay.


Failure to ANALYZE

The second step in risk management is to analyze data. Failure to do so can have serious consequences that can negatively impact a business in several ways. With data analysis, companies may clearly understand the risks they face, making it easier to develop effective strategies to mitigate or manage those risks. For example, a business that needs to analyze safety records may be able to establish effective safety policies and procedures to prevent workplace accidents. Failure to analyze data can also increase a business's exposure to liability. With data analysis, companies may be aware of compliance risks related to legal and regulatory requirements. These gaps in compliance can lead to violations that can result in fines, penalties, and legal action.


Failure to CONTROL

The third step in risk management is controlling risk. This is critical to the success and sustainability of any business. Each step builds to the next, so failure to correctly identify and analyze efforts leads to a "shot in the dark" control strategy. An effective control strategy protects a business's finances from potential risks. It minimizes legal and regulatory risk, improves business continuity, and protects the company's reputation to support growth and expansion.

For example, implementing financial controls can prevent fraud and financial mismanagement, thus reducing the risk of financial losses. It's essential to recognize that an insurance policy cannot cover all risks and that risk control protects the ability to get insurance at an affordable rate.


Failure to FINANCE

The fourth step of risk management is financing risk, often with insurance policies. Another method often overlooked is to transfer risk by contract. This method is used frequently between owners, general contractors, and sub-contractors in the construction industry. The problem is that many businesses stop with the insurance and don't protect themselves in ways insurance can't. No amount of insurance can replace an injured worker's ability to provide for their family if injured or killed on the job. Businesses often need to be more accurate when insuring their operations. Things to avoid include underestimating the value of their business assets, failing to review and update insurance policies, not understanding the scope of their coverage, and not considering specialized coverage.


Failure to MONITOR

Monitoring risk management results is essential for ensuring that the risk management process is effective and that the business is protected from potential risks. By monitoring risk management, a company can identify potential gaps in risk management strategies, evaluate the effectiveness of risk management strategies, adapt to changing risk, demonstrate compliance, and make informed business decisions.

The consequences of risk management failures can be significant and costly, resulting in:

Reasons behind Risk Management Failures

Risk management is just excellent management. Failure results in fines and other regulatory or legal action, elevated employee turnover, customer dissatisfaction, negative or damaged reputation, missed opportunities, product, or project failure, decreased market share, profit, financial loss, and even business failure. The lesson I've learned over my career is that effective risk management is both science and art. All the knowledge in the world means nothing until it is applied.

Randy Boss is a Certified Risk Architect at Ottawa Kent in Jenison, MI. He is a Master WorkComp Advisor (MWCA).