Risk aggregation can reveal concentration
Ten moderate risks that all depend on the same supplier are not ten moderate risks.
Registers list items separately, which conceals common dependencies. Aggregating by what they have in common, the same provider, the same platform, the same credential, frequently reveals a concentration nobody has assessed because no single entry looked serious enough.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Risk acceptance spends organisational toleranceSigned, and spent
- Control effectiveness is separate from control existenceTicked, and still empty
- Risk owners need authority over the consequenceThe name, not the lever
