The Risk Management Illusion, Part I - Why so many risk systems look complete but change so little

1 October 2026 —
The Risk Management Illusion, Part I - Why so many risk systems look complete but change so little

Some years ago, a sizeable life insurer was acquired by a banking group. A new senior management team arrived and asked each function head to explain what, exactly, their team contributed.

When my turn as CRO came, one executive asked a question that has stayed with me.

“We have underwriters who underwrite risk. We have actuaries who model it. We have Strategy and Finance. We have Security and Cyber Security. What exactly does Risk Management do that none of them already does? Aren’t all the risks covered?”

It was a fair question. Perhaps fairer than many risk professionals would like.

Insurance is one of the few industries in which almost everyone works with risk, yet risk management can still mean several different things around the same management table.

Underwriters decide what business the insurer is prepared to write, on what terms and at what price. Actuaries quantify liabilities and uncertainty. Finance manages financial performance and capital. Strategy decides where the company wants to go.

Enterprise risk management should not duplicate any of them. Its role is to connect what they see separately: how different exposures interact, which assumptions the business relies on, where concentrations are building, and what all of this means for strategic, capital and operational decisions.

The risk function is only one part of that system. It provides analysis, challenge, escalation and an enterprise-wide view. It does not own every risk in the company, and it is certainly not an underwriting department with a larger spreadsheet.

Yet companies have become remarkably good at constructing the visible architecture of risk management.

What is much less obvious is what that architecture actually changes.

How risk management turned into paperwork and a compliance ritual

Enterprise risk management developed gradually from earlier work on internal control, governance and corporate reporting.

In 1992, the Committee of Sponsoring Organizations of the Treadway Commission, better known as COSO, published its Internal Control Integrated Framework. COSO followed with the Enterprise Risk Management Integrated Framework in 2004. ISO 31000 appeared in 2009, the same year the European Union adopted the Solvency II Directive.

These developments gave companies a common vocabulary and a more systematic way to work with uncertainty.

Large accounting and consulting firms played an important role in turning those principles into practice. COSO itself commissioned PricewaterhouseCoopers to develop its 2004 ERM framework. More broadly, professional-services firms translated principles into governance models, methodologies, risk taxonomies, policies, assessments, committee structures, reporting formats and technology.

Companies needed that translation. Broad principles are difficult to use until they are converted into something people can actually work with.

But the process also favoured the parts of risk management that were easiest to standardise.

A policy can be drafted. A committee can be established. A risk appetite statement can be approved. A quarterly report can be produced.

Changing the way a management team thinks when its preferred strategy is challenged is much harder.

And there is no standard risk-management model that works equally well everywhere.

A multinational insurer, a small domestic carrier and a fast-growing regional group do not need identical systems. Effective risk management has to reflect the size of the company, its strategic objectives, geography, organisational structure and the way authority is actually distributed.

An effective system also has to reflect the organisation’s culture, and how much challenge senior management is prepared to accept.

What the frameworks were actually trying to achieve

The bureaucracy that sometimes surrounds risk management is not what the major frameworks asked for.

The standard setters noticed this themselves. In 2017 COSO rewrote its ERM framework and put strategy and performance into the title. In 2018 ISO rewrote 31000 and made integration into the organisation’s activities its first principle. Both revisions read as a correction. The first generation of frameworks had been treated as a filing system.

The revisions sharpened the language. The implementation problem remained.

Solvency II is more explicit still for European insurers. Article 44 requires an effective risk-management system integrated into the organisational structure and into decision-making.

This is not only European law. The International Association of Insurance Supervisors (IAIS) sets a comparable global supervisory expectation. ICP 16 requires the supervisor to make the insurer establish, within its risk-management system, an enterprise risk management framework for solvency purposes that identifies, measures, reports and manages risk in an ongoing and integrated manner.¹

Integrated is the operative word in all three texts. It was chosen deliberately, and it survived every revision.

The standards do not stop at the system. They name the people who are supposed to run it. ICP 8 requires the supervisor to make the insurer maintain control functions, risk management among them, with the authority and independence to be effective.² In the European Union that became hard law. Solvency II makes the risk-management function one of four key functions every insurer must have, with a named holder answerable for it.

Insurance went further than most industries. Solvency II Article 45 created the Own Risk and Solvency Assessment. ORSA was designed as the connection itself. It ties the risk profile to the business strategy and to the capital needed to carry that strategy out, looking forward rather than back.

On paper, it is exactly the right instrument.

It is far easier to establish the formal process than to build a management culture in which risk management genuinely influences decisions.

A regulator or auditor can confirm that a policy exists. A board can inspect committee minutes. A risk register can be reviewed. Reporting cycles can be checked.

It is much harder to establish whether challenge from the risk function caused management to rethink an assumption, restructure a transaction, reduce an exposure or stop a decision before significant capital was committed.

The documents may all be there. The annual review may have been completed on time. The risk report may even have achieved the rare administrative miracle of having no overdue actions.

None of this tells us whether risk management changed a decision.

Cassandra, with better administration

The problem predates the risk profession by about three thousand years.

In Greek mythology, Cassandra could see what was coming, but was cursed never to be believed. She warned the Trojans of the destruction ahead. The warning was there. Nothing changed while there was still time to change it.

That is where the myth starts to sound familiar.

I am not suggesting CROs are prophets. They are not, and a competent management team should challenge the CRO as rigorously as anyone else.

The parallel is simpler: information has little protective value if it cannot affect a decision.

So imagine Cassandra with a different instrument. A watch. It does not tell the time. It shows one number, and the number moves: how close the thing she warned about has come. And it is worn by the person who can still change the decision.

Cassandra held information that could have saved Troy. It played no part in the decision.

Many organisations have built a remarkably sophisticated version of Cassandra’s problem. A warning is identified, assessed, colour-coded, entered into a register, discussed at committee and recorded in the minutes.

The decision then goes ahead much as it would have done without any of it.

Troy, at least, had less paperwork.

The warning is there. What happens next depends on whether the organisation is still capable of acting on it. That is where Part II begins.

NOTES AND SOURCES

1.  The International Association of Insurance Supervisors (IAIS) is the global standard-setting body for insurance supervision. Its Insurance Core Principles (ICPs) are the benchmark against which national supervisors are assessed, including in international financial sector assessments. ICP 16 covers enterprise risk management for solvency purposes. iais.org/icp-online-tool

https://www.iais.org/icp-online-tool/13527-icp-16-enterprise-risk-management-for-solvency-purposes/

2.  ICP 8 covers risk management and internal controls. The wording on the authority and independence of control functions is drawn from the IAIS Application Paper on Supervision of Control Functions, June 2021. iais.org

https://www.iais.org/uploads/2022/01/210623-Application-Paper-on-Supervision-of-Control-Functions1.pdf

 

ABOUT THE AUTHOR

Elina Moshkovich is Founder of Risk University, a Board Advisor and Fractional CRO, and former Chief Risk Officer at Allianz and MetLife. She has more than 15 years of experience in senior risk and governance roles across insurance, banking and consulting. She advises boards, CEOs and senior executives on risk-management effectiveness, corporate governance and decision quality, with a particular focus on embedding risk management into strategic, capital and operational decision-making.

 

Through Risk University, she also develops executive education for insurers and financial institutions. www.RiskUni.com

11 views