Risk Experts / Owning

A department cannot own a risk

Only a person can be asked what they did about it.

Registers routinely assign ownership to a function: finance, operations, IT. This is administratively convenient and it means nobody is accountable, because a function cannot be asked a question, cannot make a decision, and cannot be found not to have acted.

Named ownership changes behaviour immediately, which is why it is resisted. A person whose name appears against an entry will read it, will object if it is inaccurate, and will want the treatment to be achievable. Those three reactions are the mechanism by which a register becomes connected to the operation.

The objection is usually that ownership sits with somebody who cannot control the exposure. That is frequently true and it is information rather than a problem: a risk whose owner has no authority over its causes identifies a structural gap that the register has usefully surfaced.

Where ownership genuinely cannot be assigned, the honest response is to escalate rather than to fall back on a function name. An unownable risk is usually one that crosses boundaries, and those are the ones that materialise.

It is worth adding that ownership needs to survive the owner leaving. Registers routinely carry entries owned by people who left two years ago, which is the same condition as having no owner while looking as though ownership is assigned. A check against the current staff list, run once a year, is trivial and consistently finds several.