What Happens When Risk Ownership Isn't Assigned
Firms without board-level risk visibility are 20% more likely to face major risk events. See what happens when a risk register lists departments instead of names.
Firms without board-level visibility into enterprise risk were 20% more likely to suffer six or more critical risk events than firms with that visibility in place.1 That's not a scare number pulled from a vendor deck. It's the measured gap between companies where risk reaches the board continuously and companies where it reaches the board once a year, if at all, and ownership is the variable sitting underneath it.
Most risk registers have an owner field. Most of those fields say “IT” or “Finance” or “Operations.” A department isn't accountable for anything. A named person is. When a risk's owner is a function instead of a face, the mitigation plan stalls, because nobody individually has to explain at the next review why it hasn't moved.
The Register That Never Gets Revisited
I've seen this pattern often enough to call it what it is: risk ownership assigned at registration time and never revisited. The risk gets logged, scored, and shelved. Eighteen months later the business has doubled in size, moved half its infrastructure to a new vendor, and the score on paper hasn't changed, because nothing in the process forced anyone to ask whether it should.
Three Lines of Defense, One Usually Empty
The Three Lines of Defense model exists specifically to solve this, and it's more useful than most people give it credit for. First line: the business functions that own and manage risk day to day. Second line: risk and compliance, setting policy and challenging the first line's calls. Third line: internal audit, checking that the first two are actually doing what they report. When ownership is unassigned, you can usually trace it to one of the three lines being staffed on paper but empty in practice, most often the second.
A Heat Map Is Not a Fix
A heat map won't fix this. Red, yellow, green looks decisive in a board deck and it's decoration if the register underneath it doesn't have a name attached to every open item. Assign risks to people, not departments, and require a closure date or an active update on every open item, quarterly at minimum. That's not a sophisticated fix. It's just the one most companies skip.
Frequently asked questions
How often should a risk register actually be reviewed?
Quarterly at minimum for anything open, and immediately after a material change to the business, a new vendor, a new market, a restructuring.
Can one person own too many risks?
Yes, and it's a common failure mode. If someone owns fifteen open risks, ownership has become a formality again, just with a name attached instead of a department.
What's the difference between a risk owner and a risk sponsor?
The owner is accountable for the day-to-day mitigation work. The sponsor is the executive who ensures the owner has the resources and authority to actually do it.
If your board asked for the current owner of your top five risks today, how many names would actually come back?
Sources
- Forrester, The State Of Enterprise Risk Management, 2025, cited via Secureframe. https://secureframe.com/blog/risk-management-statistics
Originally published on the Devensa blog.