
Why Most Risk Registers Fail to Predict Real Risk and What Boards Should Do About It
For decades, organizations have relied on risk registers as the cornerstone of their risk management framework. Boards review them quarterly. Management updates them regularly. Internal auditors test the controls surrounding them. Yet when the next major disruption arrives, whether a war, financial crisis, cyberattack, geopolitical shock, regulatory upheaval, pandemic, or disruptive technology, the same question is often asked:
"Why didn't we see this coming?"
Throughout my internal audit career, I have often encountered risk registers that listed the same risks year after year. They rarely changed, even though the business environment was evolving rapidly. The risks were technically correct, but they had become an administrative exercise rather than a living management tool.
The problem was never the spreadsheet itself. The issue was the mindset behind developing and managing the risk register. This article explores the fundamentals of effective risk management.
Risk Management Evolution
One experience remains vivid in my memory. Several years ago, while conducting an audit review, I examined an organization's risk register. It contained all the expected risks:
- Financial risk
- Compliance risk
- Operational risk
- IT risk
- Reputational risk
Everything appeared comprehensive.
A few months later, the organization experienced a significant operational disruption that materially affected service delivery. Interestingly, the event was not entirely unforeseen.
There had been signals. Team members had raised concerns informally. Processes were becoming stretched. Certain controls were being bypassed to meet deadlines.
Management was focused on growth while operational capacity was beginning to weaken. Yet none of these warning signs appeared in the risk register. This was because the register captured risks that were already known, rather than risks that were emerging.
That brings us to the evolution of risk management. Real risks are often visible long before they become measurable. Unfortunately, traditional risk registers are designed to measure what we know, not explore what we do not know. Many risk registers capture process failures but underestimate behavioural risks.
We recently hired a psychologist in our firm. This is not the traditional route for an audit and consulting firm, but we wanted to start thinking differently about people risk by understanding what makes people feel challenged, reducing the fear of escalation, and improving our overall organizational culture.
Culture deserves greater attention in risk management. In many cases, it predicts outcomes more accurately than most dashboards. C-suite executives should not ignore human behaviour. Instead, they should regularly assess:
- Speak-up culture
- Quality of challenge
- Ethical behaviour
- Leadership tone
- Employee engagement
When culture weakens, risk typically increases.
I have been fortunate that much of my internal audit career has specialised in regulatory audits. Although these organizations are not always large or highly complex, they often adopt a pragmatic approach to risk management. Traditionally, they built their risk registers around previous incidents and regulatory requirements. More recently, driven by evolving regulatory expectations, they have started incorporating emerging risks such as geopolitical events, a situation few UAE residents would have imagined, economic uncertainty, new technologies, talent shortages, artificial intelligence, climate-related impacts, cultural shifts within organizations, and more.
Recently during my time on the Oxford Leadership Programme, we explored how these contextual forces interact and how entirely new risks can emerge from their convergence.
An important exercise is to take the risks from the risk register and map them into scenarios or structured risk themes. Many risk descriptions are so broad that they become difficult to manage. What risk registers often fail to do is think through plausible scenarios.
Boards cannot effectively challenge risks that lack specificity.
"Cyber Risk" tells us very little.
"Over-reliance on third-party cloud providers creating a potential single point of failure" tells us significantly more.
The more precise the risk statement, the more meaningful the discussion becomes. My recommendation is that organizations undertake a structured exercise to redefine each risk statement and fundamentally improve the way risk management is performed.
Traditional risk registers are designed to measure what we know, not explore what we do not know. Many capture process failures but underestimate behavioural risks. Boards often focus on whether controls exist rather than whether those controls remain effective in a changing environment.
Are Risk Scores Creating False Comfort?
One of my favourite observations comes from board meetings where a risk is rated as "Medium" or "Low." I often joke, "A risk does not know it is supposed to behave like a medium risk."
Risk ratings provide structure, but they can also create complacency. A low-probability event can still have catastrophic consequences.
Consider:
- Global pandemics
- Cyberattacks
- Black Swan events
- Supply chain collapse
- Regional conflict
Most of these were considered unlikely until they happened. More recently, boards across the UAE have had to revisit many of these assumptions. Boards should view risk scores as the starting point for discussion, not the conclusion.
Risk Management Concerns
In today's environment, quarterly risk reviews are no longer sufficient. Boards must continuously challenge assumptions and ask, "What are we missing?"
It is equally important to strengthen Internal Auditor’s strategic role. Internal Audit is uniquely positioned to identify risks before they become visible.
Internal auditors operate across departments, processes, regions, and levels of management. They often hear concerns long before those concerns appear in board papers.
In my experience, the most effective boards view Internal Audit as an enterprise risk intelligence function, rather than merely a compliance checker.
Within the Internal Audit framework, I strongly recommend scenario planning.
Baker Tilly's recent study on the Mid-Market Maze explores this concept further by presenting four possible worlds of 2035. Imagine a board discussing two critical uncertainties:
Factor 1: The pace of AI adoption (The Self-Steering Squeeze)
Factor 2: The level of regulatory intervention (The Regulatory Runway)
Combining these uncertainties creates four distinct futures:
- Rapid AI adoption with limited regulation.
- Rapid AI adoption with heavy regulation.
- Slow AI adoption with limited regulation.
- Slow AI adoption with heavy regulation.
Each scenario produces different risks, opportunities, competitors, customer expectations, and governance requirements.
A traditional risk register may contain a single line labelled "Technology Risk." Scenario analysis, however, produces four entirely different futures. That leads to a far more meaningful board discussion.
Scenario planning reveals vulnerabilities that static risk registers rarely detect.
Moreover, in our Mid-Market Maze study, we define the Goldilocks Zone, where organizations can turn potential risks into strategic advantages.
The purpose is not to predict the future perfectly. The purpose is to think differently.
The Strategic Imperative
After more than two decades in internal audit, governance, and risk management, I have learned that organizations rarely fail because they lack information. They fail because they interpret the future through the lens of the past.
Risk registers remain valuable. They help organizations identify, monitor, and manage known exposures. But the future rarely arrives in the format of a risk register.
As highlighted in our Mid-Market Maze research, the three qualities organizations need most to succeed are effective communication, the ability to lead through uncertainty, and strong problem-solving capabilities. These are the capabilities that enable organizations to respond to strategic forces long before they appear as red, amber, or green boxes in a risk register.
The role of boards is therefore not merely to oversee risk. It is to cultivate foresight.
Scenarios should be used as directional tools. Imagine watching a Christopher Nolan film such as Interstellar or, more recently, The Odyssey. We need to watch for signals, trends, and indicators that suggest which of the imagined futures the world may be moving towards. By comparing real-world developments with scenario narratives, organizations can adapt earlier and make more resilient decisions.
As one of the top audit and consulting firm in UAE and rated 8th (eighth) largest audit and consulting network globally, at Baker Tilly UAE, we work with boards, Audit Committees, CEOs and CFOs to strengthen governance frameworks, enhance IFRS compliance in the UAE, improve internal controls and support organisations through our internal audit, IT audit and governance advisory services designed to strengthen resilience, stakeholder confidence and long-term growth.