Every medium and large organisation should have a corporate risk register.
It’s one of the most important governance documents an organisation produces. It records the strategic, operational, financial, compliance and reputational risks that could prevent the organisation achieving its objectives, identifies who owns those risks, what controls are in place and how they will be monitored.
Done properly, a risk register is an invaluable leadership tool.
It encourages organisations to think ahead rather than react afterwards. It supports decision-making, helps prioritise resources and provides a structured way of reviewing whether significant risks remain acceptable.
So, this article isn’t suggesting risk registers are ineffective.
Far from it.
The question I want to explore is this:
What if your biggest organisational risk isn’t actually on it?
Not because your risk register is poorly written.
Not because the process is flawed.
But because the greatest threats to an organisation often begin long before they can be described as a single risk.
They begin with leadership behaviours.
Management systems.
Organisational culture.
Assumptions.
And the gradual gap between what leaders believe is happening and what is actually happening.
Risks…and the Conditions That Create Them
Look at almost any corporate risk register and you’ll find familiar themes.
Unclear risk profile.
Loss of key people.
Organisational growth.
Insurance risk.
Business continuity failure.
Reputational damage.
Health and Safety failures.
Cyber security breach.
These are all legitimate organisational risks and absolutely deserve their place on the register.
But from experience something often sits behind them.
Conditions.
Conditions that develop over weeks, months or even years before anyone recognises them as risks.
Managers who stop challenging poor practice because they’re overwhelmed.
Procedures that no longer reflect how work is actually carried out in reality.
Supervisors signing paperwork they’ve never observed in practice.
Teams developing workarounds because the documented process simply doesn’t work.
Employees deciding it’s easier to stay quiet than raise concerns.
None of these would normally appear as individual entries on a corporate risk register.
Yet they are often the very conditions that allow the recorded risks to materialise.
A risk register records what could happen.
Leadership also needs to understand why it might.
Where Management Systems Really Matter
Every organisation has management systems.
Some are highly sophisticated.
Others are relatively simple.
Either way, their purpose is the same.
To ensure work is carried out consistently, safely and effectively.
Unfortunately, too many organisations mistake documentation for implementation.
A new policy is approved.
A procedure is uploaded to SharePoint.
A risk assessment is signed.
An emergency plan is circulated.
And that’s considered job done. Except it isn’t.
A management system only starts with documentation.
The real test comes afterwards.
Was it communicated?
Did the people affected understand it?
Were they appropriately trained?
Was the procedure tested before implementation?
Has anyone observed it being used?
Has anyone confirmed it actually reflects how work is carried out today?
Is leadership receiving meaningful assurance that the controls are operating as intended?
Because if the answer to those questions is no, then the organisation doesn’t have an effective management system.
It has documentation.
There is an important difference.
Documents don’t manage risk. People using well-designed management systems do.
False Assurance Is a Risk in Its Own Right
One of the greatest dangers for any leadership team isn’t a lack of information.
It’s receiving information that creates false confidence.
Throughout my career I’ve reviewed organisations with shelves full of policies, comprehensive procedures and beautifully written risk assessments.
Everything on the surface appears compliant.
Until we spent time reviewing the work.
The documented process wasn’t being followed.
Sometimes because staff had never been properly briefed.
Sometimes because operational pressures had changed the way work was done.
Sometimes because the procedure had never been tested before being introduced.
And sometimes because employees had developed a safer or more practical way of working, but nobody had updated the documentation.
The paperwork is never deliberately misleading.
It just stops reflecting reality.
That’s a management system issue.
Not a paperwork issue.
Organisations Don’t Experience Risk in Silos
One of the biggest lessons I’ve learned over the years is that organisational risks rarely belong to one department.
Consider a manager experiencing prolonged stress and burnout.
Initially, it appears to be a wellbeing issue.
But look more closely.
Decision-making begins to suffer.
Safety conversations become less frequent.
Training quality declines.
Employees become disengaged.
Absence increases.
Capability concerns emerge.
Near misses go unreported.
Customer service deteriorates.
Insurance claims become more likely.
Productivity falls.
Financial performance follows.
What started as an occupational health issue has become an HR issue, a leadership issue, a health and safety issue, an insurance issue and ultimately a commercial issue.
This is why organisations shouldn’t manage these disciplines in isolation.
They are all contributing to the same outcome: Leadership confidence.
The Question Every Leader Should Ask
When working with leadership teams, I rarely begin by asking:
“What’s your biggest risk?”
Too generic, too obvious.
Instead, I ask something much more revealing.
How do you know what’s really happening in your organisation when you’re not there?
How do you know your risk assessments reflect reality?
How do you know managers are leading consistently?
How do you know training has changed behaviour rather than just produced certificates?
How do you know people feel confident raising concerns?
How do you know your policies are being followed rather than stored on SharePoint and forgotten?
How do you know the information reaching you is an accurate reflection of operational reality?
Those questions usually tell me far more about organisational resilience than any individual risk score on a dashboard.
Because leadership assurance isn’t built through assumptions.
It’s built through evidence.
Looking Beyond the Register
Corporate risk registers remain one of the most valuable governance tools available to organisations.
But they shouldn’t become the only lens through which leaders view risk.
Good leaders understand that every risk on the register has underlying causes.
Their role isn’t simply to monitor the consequences.
It’s to understand the organisational conditions that allow those consequences to develop.
That means continually testing management systems.
Observing work.
Listening to employees.
Reviewing trends.
Seeking independent assurance.
Challenging assumptions.
Most importantly, remaining curious.
Because leadership isn’t about knowing everything.
It’s about asking better questions.
Every organisation has risks.
The strongest organisations don’t pretend otherwise.
What they do differently is continually test whether their management systems are working as intended.
They don’t place their confidence in paperwork.
They place it in evidence.
Because leadership isn’t about hoping your systems work.
It’s about knowing they do.
One Question for Leaders
If you looked beyond your corporate risk register today, what organisational conditions concern you most, and what evidence do you have that your management systems are preventing them from becoming tomorrow’s biggest risks?
Next week…
Risk assessments are among the most relied upon documents in any organisation, yet many bear little resemblance to the work they are intended to control. Next week, we’ll explore why the most expensive risk assessments are often the ones nobody values, and how leaders can gain confidence that they’re describing operational reality rather than just recording good intentions.






