Risk owners need authority over the consequence
You cannot own a risk you have no power to do anything about.
Assigning a risk to somebody who cannot fund the fix, change the process or accept the outcome produces a name in a spreadsheet and no action. It is one of the most common defects in a risk register, and it is why registers stagnate: the owner is not the decision-maker.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Risk acceptance spends organisational toleranceSigned, and spent
- Control effectiveness is separate from control existenceTicked, and still empty
- Risk aggregation can reveal concentrationAll on one leg
