The consequences of failed risk management have been in the news recently. It has got me thinking about how risk management is actually practised in organisations and projects.

Too often, risk managers become the fun police. They are brought in late in the process to complete the obligatory risk assessment, fill in the spreadsheet, and tick the box that risk management has been done.

The problem comes when that process identifies significant risks. By then, mitigating them may add cost, extend timelines, or mean that something cannot be achieved in the way originally intended. Risk management becomes a problem for the project, rather than something that helped shape it.

At its worst, this can create pressure to make the risk fit the project. Likelihood or consequence ratings get revisited until the risk becomes more palatable, providing a rationale for doing no more than the project was already prepared to do.

I would suggest flipping the approach.

Rather than bringing risk management in at the end, start project scoping and strategic planning by asking: what risks does the organisation face, and what are we trying to do about them?

The project can then become part of the mitigation of those risks. Cost, scope, capability, and timelines can be considered with that purpose in mind, rather than risk mitigations appearing late in the process as unwelcome costs or barriers to delivery.

Risk management should help determine what you do, not simply assess what you have already decided to do.

So, a question worth asking: are your risk management practices helping your organisation make better decisions, hindering them, or are they simply there because someone said they had to be?