Select Page

“…the rule by Nobody is not no-rule, and where all are equally powerless we have a tyranny without a tyrant.” – Hannah Arendt, On Violence (1970)

 

A leadership team sits down to a board pack that looks exactly like the one from the month before. The risk is there, in the same paragraph, almost the same words – customer concentration, say, or the fact that one person still signs off everything that matters. Nobody’s surprised by it, and nobody’s particularly alarmed, because they’ve had this conversation before, and it felt, at the time, like it was resolved. It wasn’t. What’s sitting in that pack isn’t really a risk without an owner – it’s a risk ownership gap, and the room moves on to the sales pipeline without anyone paying that issue any more attention.

This is not a room of people who dropped the ball. If anything, they’re the ones paying closest attention.

 

The satisfaction of having named something

Putting a risk into words for the first time often gives a feeling of relief. The sense of unease that’s been sitting somewhere in the background of a leadership team’s thinking gets a label, and the label gives people language for something they’d only half-articulated. It lets everyone in the room feel more at ease than they did a week ago, more comfortable about the state of the business, more in control of a thing that had previously felt a little vague.

That thing that had been hovering in the background now has a phrase attached to it. Customer concentration. Founder dependency. Margin pressure. Leadership depth. Ageing systems. Weak succession. Over-reliance on a single supplier. A sales pipeline that looks larger than it really is because too much of it depends on the same few relationships.

That relief isn’t false, and it isn’t naive. Naming something does matter – it’s usually the first sign that a leadership team has stopped avoiding an uncomfortable subject. The trouble starts when the naming becomes the achievement in itself. A business can become genuinely fluent at describing its own exposure. It can talk about customer concentration, or founder dependency, or a management layer that’s been stretched two roles too thin, with real clarity and even a certain confidence. The conversation can sound mature, sophisticated, even.

I’ve seen versions of this in growing businesses that are otherwise well run, where the business underneath that conversation often remains almost exactly as exposed as it was before anyone said a word.

The risk register gets more detailed. The colour coding gets more precise. The language the leadership team uses to describe its own vulnerabilities improves, cycle after cycle. None of that is nothing. But it’s worth noticing how easily it can happen without the underlying exposure moving at all – where the comfort of recognition can become slightly misleading.

 

The comfort of board papers

Seeing a difficult matter properly captured in the board papers is almost reassuring. Once it’s there, in black and white, everyone in the room can point to it as evidence that the business isn’t ignoring the problem. It becomes a kind of institutional memory – proof of awareness, sometimes proof of real concern. What it doesn’t prove, and what it was never designed to prove, is movement.

The risk sits alongside the financials, the operational update, the pipeline report, without disturbing any of them. It’s visible. It just isn’t forceful, and is easily crowded out by urgent matters which can often take precedence over the important ones. A leadership team can discuss an exposure with real seriousness for twenty minutes and then move to the next item on the agenda without anyone having asked, out loud, whose job just got harder because of what was said.

That’s not evasion, as naming a risk costs nothing – no reallocated time, no reshuffled budget, no conversation with someone about the fact that their role is about to change, or be added to. Deciding what to do about it costs all three. It would be strange if the conversation weren’t more comfortable than the decision that’s supposed to follow it.

Corporate Compliance Insights put a version of this plainly not long ago, in a piece on board risk reporting, noting that directors should not just have a risk on the page – they should have assurance that someone actually owns it. That’s a fair description of the gap between a well-worded risk note and genuine risk accountability. A well-compiled board pack can carry a risk for a surprisingly long time. But at some point the issue has to leave the paper and land on someone’s desk, or it simply repeats itself, quarter after quarter, with only the date at the top of the document changing.

The conversation may be serious, but seriousness does not turn awareness into ownership – an unassigned risk stays exactly that, however seriously it’s discussed.

 

“We’re aware of it” as a stopping point

There’s a phrase that I’ve heard frequently from leadership teams, usually said with complete sincerity: we’re aware of it. It isn’t a dodge – most of the time, the team genuinely is aware. The issue has genuinely been discussed. Nobody in the room is pretending the exposure doesn’t exist. And yet the sentence has a strange finality to it – it closes the subject, at least for the time-being, and it lets everyone feel realistic and honest while conveniently avoiding the next, more uncomfortable question: whose responsibility changes because of this?

The mechanics of how that happens are usually unremarkable, which is part of why they’re so easy to miss. A risk starts life as its own item on the agenda, gets discussed properly for a meeting or two, and then just folds itself into “operations update,” where it sits as a sub-bullet rather than a subject in its own right.

Someone asks, in passing, who owns this – and the question trails off, unanswered, with nobody circling back to it. A founder says succession is on the radar, and it is, in the sense that everyone’s aware of it, though no successor is actually being developed. A management team agrees, without much disagreement, that customer concentration is a real concern, yet the sales focus for the next quarter looks exactly like the sales focus for the last one, with the largest customers receiving the most attention, the familiar relationships continuing to shape the pipeline. The difficult work of building a broader, more balanced customer base remains desirable, but not quite urgent.

None of this happens because anyone decided it should. That’s what makes it worth noticing, and why unassigned risk is so persistent in founder-led businesses. Not because the founder or leadership team lacks intelligence, but because the business has learned to hold certain issues collectively without translating them into altered responsibility. The risk remains shared at the level of conversation and unowned at the level of work.

The risk ownership gap sits there, between those two levels.

It is rarely dramatic. Nobody announces that the risk will be ignored. Nobody formally decides that the business will continue to be exposed, or that long-term value will be impacted. The issue simply fails to become specific enough to inconvenience anyone.

 

Fluent, but not protected

Most risks that matter to a business aren’t hard to see. They’re hard to act on, because acting on them has consequences inside the business that talking about them never does. Naming customer concentration is one sentence. Changing how the business sells, and to whom, is a different undertaking entirely. Naming founder dependency takes a moment’s honesty. Moving real authority away from the founder takes rather longer, and it’s rarely comfortable for anyone involved, least of all the founder.

The businesses most articulate about their own exposure aren’t necessarily the best protected against it – if anything, fluency can start to stand in for genuine protection, at least in a leadership team’s own sense of itself. It’s a strange substitution, but not an unusual one. The conversation about a risk can stay intelligent, shared, and relatively safe. The decision that would follow it tends to inconvenience someone specific: it might need capital nobody had earmarked, expose a capability gap someone would rather not have named out loud, or ask a senior person to give up authority they still feel is theirs by right.

I’ve sat in rooms where a founder can recite the business’s three biggest risks fluently, unprompted, in a first conversation with an advisor – and where none of the three has actually moved in eighteen months. The board agrees, more or less unanimously, that a second layer of leadership is overdue, and the founder still chairs every meeting where anything of consequence gets decided. The margin pressure is real, and everyone can describe exactly where it’s coming from, but nobody wants to be the one to reopen pricing with a customer they’ve had for a decade.

Strategic risk is uncomfortable precisely because acting on it tends to disturb something inside the business that currently works, or appears to work. A concentrated customer base may be dangerous, but it may also be profitable and familiar. Founder dependency may limit future value, but it may also be the reason the business survived difficult years. A thin leadership layer may constrain scale, but hiring senior people introduces its own risk. Business resilience is not built by pretending these trade-offs are simple.

Long-term value isn’t protected by how well a business can describe its own fragility. It’s protected by whether the conversation is ever allowed to change who holds the authority, the resource, or the priority that the risk actually requires. A well-run business that has apparently stopped noticing its own strategic drift can look, from the outside, exactly like one that’s on top of things.

 

The moment it becomes somebody’s

What separates the businesses that actually move on a risk from the ones that keep discussing it usually isn’t more insight, and it isn’t a better framework. It’s a good deal simpler than that, and a lot less dramatic than most people expect. There’s rarely a transformation programme attached to it; instead the risk simply stops floating above the organisation as a shared concern and becomes, in some ordinary and almost unremarkable way, part of someone’s actual work.

A customer concentration risk becomes part of the sales director’s mandate rather than a recurring line in the board pack. Founder dependency becomes something that shows up in how meetings are run and who’s allowed to make which calls, rather than a familiar worry that resurfaces every year-end. Margin fragility becomes part of a commercial review with teeth, rather than a note in the finance pack that everyone nods at.

In each case, someone’s calendar changes. Someone’s measured on it now. Someone, at some point, says something as small as I’ll take this – and the room shifts slightly, almost without anyone remarking on it, because the risk has just changed hands from everyone to somebody. It’s the kind of shift that would be easy to miss if you weren’t watching for it, which is probably why it gets missed so often. Decisions that lose momentum tend to lose it at exactly this point – not for lack of agreement, but for lack of a single name attached to what happens next.

The shift from shared concern to personal responsibility is often the point at which the business starts building real business resilience, protecting long-term value in a more serious way. Not because the risk has disappeared. It usually has not. But because the risk is no longer allowed to exist only as a well-understood vulnerability. It has entered the operating life of the business.

There’s a useful connection here with the hidden cost of being the final decision point. Risks that remain close to the founder often remain unresolved not because the founder lacks ability, but because everything significant still has to pass through the same narrow channel. The business sees the exposure, but the person best placed to release it is also the person most embedded in it. That is a hard pattern to change.

It is also why structure matters, but not as a diagram. The issue is not whether the organisation chart looks clean or whether the governance process is formally correct, but whether real authority exists in the places where the risk has to be worked on. A board can discuss leadership depth every quarter. A founder can agree every time. A senior team can nod in recognition. But if nobody has the authority to develop, test, and trust the next layer of leadership, the discussion remains suspended above the business, and the risk belongs to everyone in conversation but nobody in practice.

In businesses that handle this better, responsibility tends to become visible in small ways before it becomes impressive in large ways. Someone starts returning to the issue without being reminded. A recurring concern stops appearing only as commentary and starts appearing in how work is allocated. A leader brings back evidence that something has changed, even if only slightly. The business begins to look different because the risk has started to touch actual work.

 

The risk with a name, but no owner

The board pack often looks different after this. Not because the format has changed, but because the reader sees it differently. The same paragraph may still be there. The same exposure may still exist. Customer concentration may still be too high. Founder dependency may still be uncomfortable. Margin may still be thinner than anyone would like. Leadership depth may still take longer to build than the business hoped. A risk that is still being worked can look, on paper, exactly like one that is simply being repeated. One has an owner, even if the work is incomplete. The other has language.

The board pack from the opening of this piece is probably still sitting in someone’s inbox, largely unchanged, waiting for the next cycle. The risk in it has a title, a paragraph, perhaps a colour rating. It’s been discussed properly, more than once, by people who take it seriously. And it may, for all of that, remain practically unnamed – because nobody’s actual responsibility has changed as a result of it being there.

It’s worth going back through your own version of that document, not to audit it, but simply to notice. Which of the risks in it currently belong to somebody. And which ones everyone has simply, sincerely, agreed are real.

 

If you enjoyed this article you can subscribe here to receive future articles.

—   

 

risk ownership gap, strategic risk, business resilience, risk accountability, board risk, unassigned risk, long-term value, risk register, founder dependency, Strategic Value Direction, #BusinessFitness,

0 Comments

Leave a Reply

Join My Business Tips Newsletter

Subscribe for news and tips on making the best of your business.

 

10 + 8 =

Contact

Phone

 

Email

 

 

Discover more from Business Fitness

Subscribe now to keep reading and get access to the full archive.

Continue reading