{"id":2059,"date":"2026-05-14T06:45:00","date_gmt":"2026-05-14T04:45:00","guid":{"rendered":"https:\/\/andresass.com\/?p=2059"},"modified":"2026-05-15T16:09:48","modified_gmt":"2026-05-15T14:09:48","slug":"risk-management-leadership","status":"publish","type":"post","link":"https:\/\/andresass.com\/en\/insights\/risk-management-leadership\/","title":{"rendered":"Managing Risks Without Paralyzing the Organization: Between Recklessness and Stagnation"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">The Excel Spreadsheet That No One Reads<\/h2>\n\n<p>In most organizations, risk management exists in one of two forms: as an Excel spreadsheet that is updated once a year and then forgotten. Or as a compliance department that works so thoroughly that innovation practically grinds to a halt. Both are dangerous, just in different ways.  <\/p>\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Good risk management does not mean avoiding all risks. It means consciously taking the right risks and consistently eliminating the wrong ones. <\/strong><\/p>\n<\/blockquote>\n\n<p>A manager I <a href=\"https:\/\/andresass.com\/en\/advisory\/\">advised<\/a> described his dilemma as follows: &#8220;Our risk management has two speeds: Either the compliance department blocks everything, or the operational areas completely ignore them and do what they want.&#8221; In practice, this meant that strategically important projects were stuck in approval loops for months, while operational risks in other areas escalated unnoticed until they landed on his desk as a crisis.<\/p>\n\n<p>The pattern is widespread: organizations invest effort in the formal documentation of risks and neglect the leadership question behind it. Which risks are acceptable? Which are not? And who decides? If these questions remain unanswered, a vacuum is created that is filled either by excessive caution or by uncontrolled risk-taking. Three levers help find the balance.     <\/p>\n\n<h2 class=\"wp-block-heading\">Lever 1: Differentiate Risks Instead of Treating Them Equally<\/h2>\n\n<p>Nassim Nicholas Taleb, author and risk analyst, distinguishes three categories: fragile systems that collapse under pressure. Robust systems that withstand pressure. And antifragile systems that grow stronger under pressure. Most organizations strive for robustness, enduring shocks. But truly successful organizations learn to emerge stronger from risks and setbacks.    <\/p>\n\n<p>The prerequisite for this is differentiation. Not every risk deserves the same level of attention. In practice, a simple distinction proves effective: Existential risks that could jeopardize the company&#8217;s substance require maximum control and avoidance. Data protection violations in regulated industries, security risks in critical infrastructures, and life-threatening financial exposures. Here, <a href=\"https:\/\/andresass.com\/en\/insights\/agile-governance\/\">governance<\/a> is not a brake, but a condition for survival. Strategic risks associated with deliberate investment or market decisions do not need to be avoided, but rather understood and managed. Every <a href=\"https:\/\/andresass.com\/en\/insights\/strategy-development-leadership\/\">strategic decision<\/a> is a calculated risk. The question is not whether risk exists, but whether it is in the right proportion to the expected benefit. Operational risks arising in day-to-day business require robust processes and clear <a href=\"https:\/\/andresass.com\/en\/insights\/responsibility-leadership-clarity\/\">responsibilities<\/a>, not committee decisions.        <\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Risk Type<\/th><th>Correct Response<\/th><th>Common Mistake<\/th><\/tr><\/thead><tbody><tr><td>Existential<\/td><td>Avoid, maximum control<\/td><td>Documented in the Excel spreadsheet, but not operationally managed<\/td><\/tr><tr><td>Strategic<\/td><td>Consciously take, actively manage<\/td><td>Talked to death by committees until the opportunity is gone<\/td><\/tr><tr><td>Operational<\/td><td>Harden processes, clarify responsibility<\/td><td>Ignored until it becomes a crisis<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p>A division head whom I supported in redesigning her risk management started with a simple sorting: Which of our documented risks are actually existential, which are strategic, and which are operational? The realization: Over eighty percent of the documented risks were operational and could have been managed through better processes and clearer <a href=\"https:\/\/andresass.com\/en\/insights\/cross-functional-collaboration-leadership\/\">responsibilities<\/a>, without a committee and without a monthly report. The remaining twenty percent deserved the full attention of management.  <\/p>\n\n<p>Those who master this differentiation can make targeted asymmetric investments in strategic risks: small, controlled experiments where the potential loss is strictly limited, but the potential learning or market gain is significant. Organizations that never take small risks unlearn how to deal with uncertainty and break down at the first major shock. This is exactly what Taleb means by antifragility: not the absence of risk, but the ability to grow stronger through calculated stress.  <\/p>\n\n<h2 class=\"wp-block-heading\">Lever 2: Factor in the Risk of Inaction<\/h2>\n\n<p>Most risk assessments have a systematic blind spot: they only evaluate the risks of action. What happens if we start this project? What can go wrong if we enter this market? What are the compliance risks of this new technology?   <\/p>\n\n<p>What is missing is the counter-question: What happens if we don&#8217;t? The risk of <a href=\"https:\/\/andresass.com\/en\/insights\/inaction-decision-leadership\/\">inaction<\/a> is not in any risk matrix. But it is often the greater risk. The competitor who introduces the technology while you are still reviewing. The market that shifts while you wait. The <a href=\"https:\/\/andresass.com\/en\/insights\/retaining-high-performers-transformation\/\">talent<\/a> that leaves because the organization is too slow. In regulated industries like the energy sector, this balance is particularly challenging: regulation demands caution, the market demands speed. Serving both simultaneously is the real leadership achievement.       <\/p>\n\n<p>For every risk assessment, demand an explicit evaluation of the risk of omission. &#8220;What does every week cost us in which we do not <a href=\"https:\/\/andresass.com\/en\/insights\/decisions-under-uncertainty-70-percent-rule\/\">decide<\/a>?&#8221; is a question that exposes risk aversion for what it often is: not caution, but a <a href=\"https:\/\/andresass.com\/en\/insights\/breaking-defensive-culture\/\">culture of hedging<\/a>. <\/p>\n\n<h2 class=\"wp-block-heading\">Lever 3: Risk Culture Instead of Risk Process<\/h2>\n\n<p>Risk management that exists only in processes and documents is ineffective. What matters is the risk culture: How does the organization actually deal with uncertainty? <\/p>\n\n<p>In a healthy risk culture, risks are openly addressed, even upwards. The bearer of bad news is heard, not punished. <a href=\"https:\/\/andresass.com\/en\/insights\/learning-from-mistakes-leadership\/\">Mistakes<\/a> in calculated risks are treated as learning experiences, not career-enders. And leadership exemplifies what it expects: it talks about its own misjudgments, admits when a risk assessment was wrong, and shows that uncertainty is not a sign of weakness. As I regularly experience in my <a href=\"https:\/\/andresass.com\/en\/profile\/\">consulting practice<\/a>: The quality of an organization&#8217;s risk management can be most reliably gauged by how quickly bad news reaches the executive level. One of the most important tasks of a manager is to actively seek out bad news. If your dashboard consistently shows only green lights, you don&#8217;t have good risk management, but a team that has learned what you want to hear.     <\/p>\n\n<p>In a toxic risk culture, the opposite happens: risks are concealed because naming them is seen as a weakness. Problems are sugarcoated until they can no longer be hidden. And the organization optimizes not for good decisions, but for hedging. You know the result: the <a href=\"https:\/\/andresass.com\/en\/insights\/leading-in-crisis\/\">crisis<\/a> that &#8220;no one saw coming,&#8221; even though the signals had been visible for months.   <\/p>\n\n<p>Build early warning systems based on people, not just metrics. Define clear escalation paths and remove the stigma from escalation. Create spaces where operational teams can name risks without fear of consequences. And regularly check: Does bad news reach you in time, or only when it&#8217;s too late?   <\/p>\n\n<h2 class=\"wp-block-heading\">Reality Check<\/h2>\n\n<p>First: Do you know the three biggest risks in your area, not the documented ones, but the actual ones? If your answer matches the risk Excel, that&#8217;s a good sign. If not, you&#8217;re trusting the wrong instrument.  <\/p>\n\n<p>Second: When was the last time you consciously took a risk because the expected benefit justified the risk? If the answer is &#8220;I can&#8217;t remember,&#8221; your organization may not be cautious, but paralyzed. <\/p>\n\n<p>Third: How quickly does bad news reach your desk? This week, ask an employee if there&#8217;s an operational risk they haven&#8217;t reported to you yet. The answer will tell you more about your risk culture than any audit report.  <\/p>\n\n<h2 class=\"wp-block-heading\">The Uncomfortable Truth<\/h2>\n\n<p>The greatest damage in organizations does not come from risks that were taken and went wrong. It comes from risks that were not seen because no one wanted to look, and from opportunities that were not seized because the <a href=\"https:\/\/andresass.com\/en\/insights\/learning-from-mistakes-leadership\/\">fear of making a mistake<\/a> was greater than the courage to decide. <\/p>\n\n<p>Risk management is not a task for compliance departments. It is a leadership attitude. And this attitude is not reflected in the quality of your risk matrix, but in the question: Do your employees dare to tell you the truth?  <\/p>\n\n<h2 class=\"wp-block-heading\">Further Insights<\/h2>\n\n<p><strong><a href=\"https:\/\/andresass.com\/en\/insights\/decisions-under-uncertainty-70-percent-rule\/\">Decisions Under Uncertainty<\/a><\/strong> \u2013 Why seventy percent certainty is almost always enough and why perfection kills decision-making.<\/p>\n\n<p><strong><a href=\"https:\/\/andresass.com\/en\/insights\/leading-in-crisis\/\">Leading in a Crisis<\/a><\/strong> \u2013 When the risk has materialized: How to set the course in the first hours.<\/p>\n\n<p>All Insights can be found in the <strong><a href=\"https:\/\/andresass.com\/en\/insights\/\">overview<\/a><\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Your risk matrix exists as an Excel file that no one reads. Or as a compliance department that blocks everything. Why risk management is a leadership task and which three levers create balance.  <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[230],"tags":[235,282,250],"class_list":["post-2059","post","type-post","status-publish","format-standard","hentry","category-insights","tag-leadership","tag-risk","tag-strategy"],"_links":{"self":[{"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/posts\/2059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/comments?post=2059"}],"version-history":[{"count":16,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/posts\/2059\/revisions"}],"predecessor-version":[{"id":2989,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/posts\/2059\/revisions\/2989"}],"wp:attachment":[{"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/media?parent=2059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/categories?post=2059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/andresass.com\/en\/wp-json\/wp\/v2\/tags?post=2059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}