Select Page

“Certitude is not the test of certainty. We have been cocksure of many things that were not so.” – Oliver Wendell Holmes Jr., “Natural Law”, Harvard Law Review, Volume 32, 1918

 

The board pack looked the way it always looks after a clean compliance review. Every policy signed off. Every register updated. The auditor’s letter as tidy as it had ever been.

Risk beyond compliance rarely gets a mention in a meeting like that. There’s a sense of lightness that settles once a clean audit result lands, and this meeting had it. The agenda moved on quickly afterwards, to the sales pipeline and a cash flow question, with the unspoken sense that risk had, for this quarter at least, been dealt with. Nobody in the room seemed to think there was anything more to ask.

There was, though, a concern that stayed with me afterwards. It had nothing to do with anything the audit had failed to check. It was something that sits outside the file everyone had just closed, waiting for someone to remember it was never in there to begin with.

 

Why compliance became the language everyone reaches for

It isn’t hard to see why compliance becomes the working answer to “how do we manage risk” in a growing business. It’s the kind of risk governance work that can be handed to somebody, a company secretary, the finance team, an external auditor, or outside adviser. There are requirements to interpret, documents to maintain and deadlines that make it clear when something is complete. The work may be demanding, but the business can see who is doing it and whether it has been done.

That visibility matters. Compliance failures have serious legal, financial and reputational consequences, and an established business cannot afford to treat them casually. Good compliance management also creates discipline beyond the audit itself. Records improve, responsibilities become clearer and practices that were once informal become more dependable.

The difficulty begins when this visible, assignable work becomes the organisation’s working definition of risk governance. A founder can delegate the schedule and receive a report. Strategic risk doesn’t behave the same way. It tends to stay with whoever actually holds authority in the business, and in a founder-led company that’s usually one person, who is rarely the one filling in the compliance schedule.

I’ve sat with founders who could walk a new board member through the compliance folder with real pride, tab by tab, and then go quiet, just for a moment, when asked what happens to the risks that never made it into that folder at all. That folder is the easy part of managing risk. Risk beyond compliance is what’s left once it’s closed.

The decision-making load that sits with one person for too long rarely shows up in a compliance file, because nothing in the file was built to look for it. It was built to check whether the things everyone already agreed mattered had been done, not to ask what else might matter and hasn’t yet been documented.

 

What the checklist was never built to catch

A compliance process starts from something that already exists: an obligation, a rule, a standard someone else wrote down. It can tell you whether a required thing was done, whether a control operated as intended, whether the evidence is on file and the exceptions were logged. Those are legitimate questions, and getting them right matters. A missed regulatory filing or an undocumented safety control has real legal, financial and reputational consequences, and no leadership team should be casual about that.

What a compliance process cannot ordinarily tell you is whether the assumptions supporting the business are still sound. A company may be fully compliant and still hold real customer concentration risk, with most of its profit dependent on one customer. Its contracts can be valid while the business holds an equally real key person risk, the commercial relationship depending almost entirely on the founder. Every delegated authority can be documented even though the senior team still waits for one person before making decisions that matter. None of these fail a compliance test, because none of them were ever part of what the test measures.

I’ve watched a due diligence process where the compliance file was spotless and the buyer’s own advisors found the real strategic risk exposure within a day, simply because they were looking somewhere the internal audit never had reason to.

That does not make the audit less valuable. It shows the limit of the assurance it can offer. The risk widens when the organisation forgets that limit and treats evidence of correct process as evidence of protection. ISO 31000 places risk management within governance, strategy, planning, reporting, policies, values and culture, rather than treating it as the concern of a compliance function alone.

 

When the register becomes the conversation

Back in the boardroom, something similar happens. A risk register exists to support judgement, but it can gradually start to stand in for it. Once the recognised risks have been rated, given an owner and a status colour, the meeting tends to organise itself around whether those entries have moved. Red edges towards amber. Amber stays under review. Whoever owns each line reports on the agreed actions. It’s an orderly way to spend twenty minutes, and the board can see, clearly, that risk is being attended to.

A genuine risk conversation doesn’t behave nearly as tidily. It might start with a hesitation about a customer relationship, or a sense that the leadership team is operationally excellent but strategically thin, or a feeling that the market is shifting in a way none of the current reports quite capture. None of that fits neatly into an existing category, and it’s not easy to minute, either – they have no agreed rating and may not have an obvious owner.

So, the meeting often returns to the register, where the risks are specific enough to discuss properly. Nothing improper has happened. The board has simply moved back to information it knows how to handle.

What I’ve noticed isn’t that the register contains bad information. It’s that its very completeness can make a meeting feel finished, at exactly the point where genuine board oversight would still be asking what hasn’t been written down at all.

 

The false confidence of a clean pass

Passing an audit doesn’t only fail to catch the risks that matter most. It can actively dull the appetite to go looking for them, because a clean compliance outcome gets read, at board level, as a broader verdict on the health of the business, rather than the narrower thing it actually is. It’s a fair description of what risk beyond compliance actually looks like: exposure that never once fails a test. That’s the same sense of lightness we saw at the opening of this piece, seen again from a little further back.

A board may spend ten minutes noting a successful review and then move quickly past a question about whether the business model still holds. The two subjects are unrelated on paper. In the meeting, however, the first has already created a mood of confidence around the second.

Harvard Law School’s governance forum made a related point earlier this year: board risk oversight, they argue, is increasingly expected to move beyond compliance and traditional oversight into something closer to genuine strategic stewardship. It’s a requirement that turns up, in one form or another, in company law and governance codes across most of the jurisdictions I’ve looked at. That shift is easier to agree with in principle than to notice happening, or not happening, in the room you’re actually sitting in.

 

Where the real risk conversation actually lives, and why it’s unwritten

Strategic risk ownership in a founder-led business tends to sit with the founder by default rather than by any decision anyone actually made. There’s no line for it in a job description, no mention of it in a set of committee terms of reference. It’s the risk equivalent of a task everyone assumes is somebody’s job, right up until the moment it turns out to have been nobody’s.

Compliance risk has an owner because regulation or convention requires one. Strategic risk has an owner only if someone has, without anyone ever overtly doing so, taken it on, and that arrangement is invisible on paper in a way the compliance file never is.

It’s a step back from the risk ownership gap I’ve written about before, which looked at risks that were known but never assigned. The prior question is whether a compliance-led picture of risk ever gave those exposures the chance to be recognised as needing an owner in the first place. I asked a founder once, directly, whose job it had been to see a particular problem coming. The pause before he answered told me most of what I needed to know.

 

The audit that was never the question

Back in that first boardroom, the mood has settled a little. The audit result still stands. The required processes were followed, the controls did what they were designed to do, and there’s a fair amount of genuine reassurance to be taken from that.

But the meeting has already moved on to the pipeline, and the risks most capable of altering where this business ends up may still be sitting outside the documents that produced that morning’s relief. The most exposed business isn’t necessarily the one that failed an audit. It may be the one that has passed every audit for years, and has slowly stopped noticing the difference between evidence that its controls worked and evidence that it was actually protected.

So, back to the meeting, where the paperwork is all in order. The certificate proves the process worked. It was never going to prove the business was protected. That’s the whole shape of risk beyond compliance, and it’s still sitting there once the meeting ends. Perhaps the question worth sitting with isn’t whether the business complied. It’s whether anyone in that room is still looking for the risks the compliance process was never built to find.

 

If you enjoyed this article you can subscribe here to receive future articles.

—   

risk beyond compliance, compliance risk, compliance management, business resilience, customer concentration risk, strategic risk exposure, key person risk, board risk oversight, risk accountability, founder dependency, Structural Authority, Governance & Operating Design, #BusinessFitness,

0 Comments

Leave a Reply

Join My Business Tips Newsletter

Subscribe for news and tips on making the best of your business.

 

13 + 7 =

Contact

Phone

 

Email

 

 

Discover more from Business Fitness

Subscribe now to keep reading and get access to the full archive.

Continue reading