No Risk Regulation

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

What if there was no risk regulation?  What if your organization did not have a risk department, nor had any mandatory risk reporting?  What would change?

Ironically it is quite possible that your organization’s risk management would get better.  I have written before quite extensively on risk homeostasis, but to bring it down to earth and out of the fancy terms, consider crossing by either jaywalking in between intersections or crossing at the crossing signal at the intersection.  In which situation are you paying the most attention?  In which situation are you more risk aware?  In which situation are you more risk “alive”?

In his popular book David and Goliath, author Malcolm Gladwell talks about the “inverted U” effect.  The inverted U effect is when adding an element (in our context risk management) has an initial benefit.  However, adding more of the effect starts to have diminishing gains and then adding more starts to produce negative effects.  Too much is often worse than none at all.

A trivial example is ice cream.  Having a half scoop of ice cream is better than just having a quarter scoop.  Likewise having a full scoop is better than half a scoop.  However, having to eat 50 scoops of ice cream is likely to make you very sick and wishing you had never even heard of ice cream.

So I ask again; What if there was no risk regulation?  What if your organization did not have a risk department, nor had any mandatory risk reporting?  What would change?  Has your organization gone past the point of the inverted U?

Abundance and Paucity

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

Sometimes when I sit down to write blogs I have an abundance of decent ideas to try out and see how they look on the written page.  Other times, like now, I have a paucity of ideas.  That I guess is one of the artifacts of being a living, thinking human.

The abundance / paucity cycle however also seems to apply to organizations.  Sometimes they have an abundance of ideas and the challenge of management is to try and prioritize which projects will be pursed and which ideas will have to survive a waiting time if they are ever to see the light of day.  Other times there is a paucity of ideas and the troops are generally marched off to an offsite to develop inspiration that sometimes produces results, but more often produces a wasted 72 hours for all involved.

So what’s the deal with your risk department?  If you have an abundance of ideas, how do you go about prioritizing them.  If you have a paucity, how do you generate new ideas?  Or do you simply think that all the good ideas for risk management have already been thought of?

Passion 2

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

In a previous blog I wrote about the desirability of passion for risk management over simply knowledge and intelligence about risk management.  I briefly argued that risk managers who are passionate about risk management tend to be more effective than those who simply know a lot about risk management.

I believe there are many reasons for this – enough that would fill a book.  However, one that readily comes to mind is that passion is contagious, while knowledge and intelligence is not.  A passion for risk management (or anything else for that matter) tends to circulate and catch on.  When others outside the risk management function become passionate about risk management then risk management is almost certain to be effective.  After all, one of the current risk catch phrases is that “risk management is everyone’s job”.  That statement is totally vacuous if there is not a positive culture around risk management.  A positive culture starts with passion, while knowledge frequently kills the culture.  (What was your favorite subject in school – was it the one where the teacher was passionate or simply knowledgeable about the subject?)

Passion 1

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

In my life I have been very fortunate to be around many very intelligent people and many people who are very passionate about their profession.  Passion and intelligence are not mutually exclusive, nor are they substitutes for each other.  You can be quite passionate about something, yet somewhat ignorant of it.  Likewise you can be quite intelligent or knowledgeable about a field yet have little or no obvious passion for it.

What I have noticed however is that people who are passionate about something also tend to be the most effective in it.  The same cannot be said for intelligence or knowledge.  Possessing intelligence or knowledge, while desirable, does not automatically make one effective.

In my experience this also holds for risk managers.  Those risk managers who are passionate about risk management tend to be the most effective.  Those who are simply the most intelligent or knowledgeable tend to be quite ineffective (again in my experience).  Ironically though, those who are the most passionate also become the most practically intelligent and the most practicably knowledgeable.  Hmmmm…  Maybe it is practical knowledge and practical intelligence that I should be blogging about.  For now, I’ll stick to passion as the key ingredient.

AI

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

Lots of jokes have been made about AI (Artificial Intelligence); Artificial Ignorance and Artificial Imbecility are two that readily come to mind.  AI is a tool, and a very useful tool at that – in my opinion.  However, AI does not replace the human factor.  AI does not understand the human factor.  AI cannot (almost by definition) deal with the paradigm shifts caused by the human factor – namely human creativity.  Likewise, AI is not so good at dealing with or predicting seemingly random human stupidity.

The point that the good risk manager remembers is that virtually all risk is human in nature.  Humans are real.  Humans are not artificial (okay, some reality TV stars – and former reality TV stars – are very artificial).  While AI is a very helpful risk management tool and a complement to human wisdom and intuition, ultimately you need humans to understand and manage humans.  Risk is human, and so ultimately the final word in risk management should be human as well.AI

Thermometer or Thermostat

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

In his book Tribes, writer Seth Godin asks the simple question of whether you are a thermometer or a thermostat?  It’s a great question.  One measures temperature, and one is used to regulate or modify the temperature.  How would you classify risk management at your organization?  Does it measure risk, or does it regulate / modify risk?  Is your risk management a thermometer or a thermostat?

In Theory

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

In theory ….  When you hear someone say that, you almost expect a “but” is coming very soon.  In theory, a lot of things are true, but in practice, or from experience, we know that they are not true.  Theory and experience are two very different things; a point that should never be forgotten.

How much of risk management is based on theory, and how much of it is based on experience?  How much of risk management theory do we assume is based on experience?  Perhaps more importantly, how much of it is based on relevant experience

The sad truth is that much of what currently passes for best practice in risk management is based on theory, not experience, nor even wisdom for that matter.  As a researcher, I am not knocking theory per se, but theory needs to be respected and understood and utilized for what it is, and as well for what it is not.

In theory, theory is great.  In practice, I will choose wisdom, critical thinking and experience.

Marsha Marsha Marsha

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

There is a lot to mock about The Brady Show, but if you were raised in the seventies you probably viewed most of the episodes more than once.  (If you have never seen the show, then you really didn’t miss much except a lot of homey corniness, bad and constantly changing hairstyles and an earworm of an opening jingle.)

For those of you who have seen the show, you probably remember the episode where Jan was jealous of her sister and screamed out “Marsha! Marsha! Marsha!” to highlight the fact that everything in the Brady household seemed to revolve around her older sister Marsha.[1]

If you are a risk manager of a certain level of experience and competence you are likely to exclaim in a similar fashion and with a similar level of envy and exasperation “Data! Data! Data!”.

Jan’s parents, like all good parents, loved each of their children through thick and thin.  However, in any complex situation there are times when things are “thick” and times when things are “thin”.  Just as one child is not superior to another child, one form of risk management is not exclusively nor inherently better than another.

Risk management by data has its place, but it should not be to the exclusion of all other methods of assessing and responding to risk.  Just as a parent does not want to be seen as catering to the needs of one child to the exclusion of the other children, risk management should not focus exclusively on risk control by data metrics.  There is a case to be made that some of the most important aspects of risk management are not measurable – even conceptually.

[1] For those of you who are wondering, or those who want to go back in time, here is the “Marsha, Marsha Marsha” clip on YouTube  https://www.youtube.com/watch?v=-yZHveWFvqM

Riskless?

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

If asked, most managers will tell you that the goal of risk management is to reduce risk.  Ok – that is pretty simple.  However, what does it actually mean, and what are the logical consequences of this simple statement?

If the goal is to reduce risk, then reducing risk to zero presumably would be ideal.  However what does a riskless organization look like?  How successful would a riskless organization be?  What future would a riskless organization look like?  Would you like to work for a riskless organization?

I fully realize that I am employing the trick of taking an argument to its extremes, and I am also aware of many of the traps of doing so.   However in this case I think there is a strong case to be made to consider what exactly the consequences of a riskless organization would be – particularly as that seems to be the objective of many regulators.

A few quick observations of a riskless organization would be one that would be run by a computer – for without risk, there is no need to manage anything.  A second observation is an organization that would never implement anything or create anything new.  A third observation is that a riskless organization would be the riskiest of all as it would be existing in an island by itself in our inherently risky world that would quickly overtake it and crush it.

The goal of risk management should not be to eliminate risk, but to take on smart risks and to take on smart risks in an intelligent way.  Risk is not to be avoided, risk is to be embraced – albeit properly.

Reactions or Decisions?

By Rick Nason, PhD, CFA
Partner, RSD Solutions Inc.

Follow Rick Nason on Twitter
Follow RSD Solutions on Twitter

Winston Churchill said that, “Fear is a reaction.  Courage is a decision.”  Much of what passes for risk management is undeniably fear based.  It unfortunately is not based on a proactive basis of making courageous decisions about moving forward.

As I have written many times, risk management should not be about preventing bad things happening, but instead risk management should be about how we can do things better so as to take advantage of uncertainty – that is managing so as to increase the possibility and magnitude of good events happening while mitigating the probability and severity of bad things happening.  If fear is the basis of risk management, not only is it missing half of the equation, but it is also simply just reacting to the last crisis, and not allowing the organization to intelligently go forward.

Ultimately it comes down to if your risk management is fearfully reacting or courageously deciding.