Devensa Advisory
Get started

What Happens When Risk Ownership Isn't Assigned

Firms without board-level risk visibility are 20% more likely to face major risk events. See what happens when a risk register lists departments instead of names.

Devensa Advisory 3 min read
Risk register with four owner rows. Three list a department and one lists a named person, J. Alvarez.

Firms without board-level visibility into enterprise risk were 20% more likely to suffer six or more critical risk events than firms with that visibility in place.1 That's not a scare number pulled from a vendor deck. It's the measured gap between companies where risk reaches the board continuously and companies where it reaches the board once a year, if at all, and ownership is the variable sitting underneath it.

Most risk registers have an owner field. Most of those fields say “IT” or “Finance” or “Operations.” A department isn't accountable for anything. A named person is. When a risk's owner is a function instead of a face, the mitigation plan stalls, because nobody individually has to explain at the next review why it hasn't moved.

The Register That Never Gets Revisited

I've seen this pattern often enough to call it what it is: risk ownership assigned at registration time and never revisited. The risk gets logged, scored, and shelved. Eighteen months later the business has doubled in size, moved half its infrastructure to a new vendor, and the score on paper hasn't changed, because nothing in the process forced anyone to ask whether it should.

Three Lines of Defense, One Usually Empty

The Three Lines of Defense model exists specifically to solve this, and it's more useful than most people give it credit for. First line: the business functions that own and manage risk day to day. Second line: risk and compliance, setting policy and challenging the first line's calls. Third line: internal audit, checking that the first two are actually doing what they report. When ownership is unassigned, you can usually trace it to one of the three lines being staffed on paper but empty in practice, most often the second.

A Heat Map Is Not a Fix

A heat map won't fix this. Red, yellow, green looks decisive in a board deck and it's decoration if the register underneath it doesn't have a name attached to every open item. Assign risks to people, not departments, and require a closure date or an active update on every open item, quarterly at minimum. That's not a sophisticated fix. It's just the one most companies skip.

Frequently asked questions

How often should a risk register actually be reviewed?

Quarterly at minimum for anything open, and immediately after a material change to the business, a new vendor, a new market, a restructuring.

Can one person own too many risks?

Yes, and it's a common failure mode. If someone owns fifteen open risks, ownership has become a formality again, just with a name attached instead of a department.

What's the difference between a risk owner and a risk sponsor?

The owner is accountable for the day-to-day mitigation work. The sponsor is the executive who ensures the owner has the resources and authority to actually do it.

If your board asked for the current owner of your top five risks today, how many names would actually come back?

Sources

  1. Forrester, The State Of Enterprise Risk Management, 2025, cited via Secureframe. https://secureframe.com/blog/risk-management-statistics

Originally published on the Devensa blog.

Keep reading

All insights →
Risk Management

Five Signs Your Risk Register Is a Filing Cabinet, Not a Tool

Firms without board-level risk visibility are 20% more likely to face major risk events. See the five signs a risk register has stopped being a tool.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Put a name next to every gap.

A Current State Assessment scores where you are across the six domains and sequences what comes next, with owners attached.

Get started Explore Risk Management