top of page

Does Risk Management Create Its Own Work?

Writer: Julien Haye
Julien Haye
1 day ago
13 min read
Hero image for an Aevitium article titled “Does Risk Management Create Its Own Work?”, showing growing stacks of documents and reports representing the accumulation of controls, remediation, assurance and risk management workload.

Risk management responds to change. An incident, control weakness, regulatory requirement or assurance finding can require new controls, monitoring, remediation or oversight. Each response may be appropriate to the conditions that created it.


Those conditions do not remain static.


Business volumes increase. Processes and technology change. Strategic remediation progresses or stalls. Risks evolve. Other controls are introduced. Yet the original response can remain embedded in the risk operating model long after the circumstances surrounding it have changed.


The first article in this series explored how Risk Demand accumulates as legitimate requirements converge and layer around business activity. The second examined the administrative workload that this creates across the organisation.


This article considers what happens next: once risk-management activity enters the operating model, what determines whether it changes or ever leaves?


The answer extends beyond control effectiveness. Accountability, organisational memory, assurance, regulatory scrutiny and the way organisations govern previous decisions can all influence whether an intervention continues.


Effective risk management therefore requires more than the ability to respond. It also requires the ability to revisit those responses as circumstances change, determining whether they should continue, adapt, consolidate, be replaced or retire.


Article series:


Executive Takeaways


For readers scanning rather than reading in full, five insights frame the argument:

  1. Risk responses can outlive the conditions that justified them.

    Controls, monitoring and governance introduced for a particular incident, weakness or risk can become embedded in the operating model even as business volumes, processes, technology and risks change.

  2. Existing risk activity needs active reassessment.

    A control that remains in place is not necessarily still the most appropriate response. Effective risk management revisits the assumptions, purpose and outcomes behind existing interventions as circumstances evolve.

  3. Adding risk activity is often easier than changing or removing it.

    Accountability, organisational memory, audit and regulatory scrutiny can increase the burden of proof for changing an established response, particularly where a subsequent failure could expose the earlier decision to challenge.

  4. Control ownership should include lifecycle ownership.

    Organisations may know who operates a control without clearly assigning responsibility and authority for determining whether it should continue, adapt, consolidate, be replaced or retire.

  5. Effective control depends on outcomes, not permanence.

    Mature risk operating models can preserve controls that remain effective while changing those that no longer fit their purpose or operating conditions. The objective is not fewer controls, but a control environment that continues to be proportionate, understandable and effective.


The Risk Management Feedback Loop


Risk-management interventions are usually introduced in response to identifiable conditions. A control addresses a weakness. Enhanced monitoring provides additional oversight. A tactical solution manages exposure while a more permanent change is developed.


Once implemented, these responses become part of the risk operating model. Responsibilities are assigned, processes adapt and governance incorporates the new activity. What began as a response to a particular set of circumstances becomes part of how the organisation operates.


The conditions surrounding that response can then change. Business volumes grow, processes evolve, technology changes, other controls are introduced or the original risk develops differently than expected. The intervention may still be effective, but the assumptions that supported its original design may no longer be the same.


This creates a different type of feedback loop. Risk management responds to changing conditions, but its own responses also become part of the environment that future risk decisions must consider.


Without deliberate reassessment, yesterday's response can remain embedded in today's operating model because it exists, rather than because the organisation has confirmed that it remains the most appropriate response.


Effective risk management therefore needs to revisit its own interventions as deliberately as it introduces them.


How Risk Responses Become Embedded


Risk responses can become permanent features of the operating model surprisingly quickly. Once a new control, policy, monitoring requirement or governance process is implemented, responsibilities are assigned, procedures change, systems may be configured and assurance expectations develop around it.


Over time, the activity becomes part of normal operations. Its original trigger can become less visible, particularly as people change roles and organisational knowledge fades. What remains is the requirement itself.


McKinsey found that some midsize and large banks had accumulated thousands of risk and compliance policies, with individual policies generating dozens of downstream procedures affecting processes and controls. Its work also identified institutions that reduced policy populations by as much as 30% while improving the quality of those retained.


Accumulation does not mean that the individual requirements were unnecessary when introduced. The more important question is whether the organisation continues to understand why they exist and whether they remain appropriate as circumstances change.


This becomes particularly important for responses introduced after incidents, regulatory findings or periods of heightened concern. Once incorporated into policies, systems, controls and assurance programmes, removing or changing them can require coordination across several parts of the organisation.


A risk response therefore develops its own organisational footprint. The longer it remains embedded, the easier it can become to treat its existence as evidence of its continuing necessity rather than reassessing the conditions that originally justified it.



See how structure, accountability, Risk Demand and capability combine to make risk management work in practice.


Risk management operating model infographic showing how strategy, objectives, risk appetite and decisions connect to governance, roles, organisational structure, processes, people, technology and Risk Demand.

When Assurance Creates More Assurance


Assurance provides independent challenge over whether risks are being managed effectively and controls are operating as intended. Its findings can also change the future scope of risk management.


A review that identifies a control weakness may lead to remediation, additional monitoring or new controls. Once implemented, those measures become part of the control environment. Some will require future testing or assurance to confirm that they remain effective.


This creates a compounding effect. Assurance examines the existing control environment, while its findings can contribute to expanding the population that future assurance must consider.


The effect can extend beyond the original finding. New controls may introduce dependencies, ownership requirements or monitoring that subsequently require their own oversight.


Effective assurance therefore considers both the weakness being addressed and how the response changes the wider control environment. Closing a finding can increase the scope of what the organisation subsequently needs to govern and assure.


Why Risk Management Adds More Easily Than It Removes


Risk management has clear triggers for adding activity. An incident can lead to a new control. A finding can generate additional monitoring. Regulatory change may require new reporting or governance. Emerging risks can bring new assessments and oversight.


Removing existing activity follows a different dynamic. A control may have operated for years without another incident. Determining whether that reflects the control's effectiveness, changes in the underlying risk or other factors is rarely straightforward.


Accountability reinforces this asymmetry. Introducing a control after a failure has a documented rationale. It also demonstrates that the organisation has responded. Retiring it later requires someone to conclude that the control is no longer needed, can be replaced or no longer justifies the resources it consumes.


The consequences are also easier to attribute in one direction. When a control remains and no failure occurs, its contribution may be difficult to isolate. The recurring cost of retention is usually dispersed across teams through operation, monitoring, evidence, testing and assurance. When a control is removed and a related failure subsequently occurs, the earlier decision becomes highly visible.


Internal Audit, external assurance and regulatory scrutiny can reinforce this dynamic. Removing a control may require management to demonstrate why the decision was appropriate and what evidence supported it. If a related failure occurs later, that decision can become a natural focus of retrospective challenge. Retaining an additional control rarely creates the same visible point of accountability.


This creates a psychological as well as governance incentive for retention. The organisational cost of keeping unnecessary activity can remain diffuse, while the perceived accountability for removing it can be concentrated on the person or committee that approved the decision.


Organisational memory can reinforce that effect. A control introduced after a significant incident may retain importance because of the event associated with it, even when the underlying risk, operating conditions or surrounding controls have changed.


Activities can therefore remain part of the risk operating model because continued operation is easier to justify than removal.


The burden of proof for adding risk activity and removing it is rarely symmetrical.


Effective risk governance therefore needs an explicit mechanism for reviewing whether controls, monitoring, reporting and oversight continue to serve the purpose for which they were introduced. It also needs to make legitimate retirement a normal governance decision, supported by evidence and clear authority, rather than an exceptional decision that an individual must defend.


Infographic showing why risk management activity is easier to add than remove, using an unbalanced scale to illustrate clear triggers for adding controls versus the higher burden of proof and accountability required to retire them.

When Temporary Responses Become Permanent


Risk responses are often introduced for a defined period or purpose. Enhanced reporting may support oversight after an incident. Additional monitoring can provide assurance while remediation is underway. A new control may address a specific weakness, while a governance forum may coordinate a major programme.


Over time, these activities can become part of business as usual. Reports remain in governance packs. Monitoring continues after remediation closes. Controls stay in the control library. Programme forums become recurring meetings.


Continued use may be appropriate. The important governance discipline is ensuring that retention reflects a deliberate decision based on the activity's current purpose and value.


Without that review, temporary responses can become permanent simply because they have become embedded in the operating model. The original trigger may have disappeared while the resulting workload remains.


Organisations can look for signs that temporary measures have become embedded without deliberate review:

  • Reports that continue after the event that created them

  • Enhanced monitoring with no defined end point

  • Controls whose original rationale is difficult to establish

  • Recurring forums with no clear decision purpose

  • Remediation arrangements that remain after the underlying issue has closed


Age alone does not make an activity unnecessary. The stronger signal is loss of connection between the activity, its original purpose and the outcome it now supports.


Temporary risk activity needs an explicit point at which the organisation decides whether to retain, change, consolidate or retire it.


Case Study: When a Tactical Control Outlives Its Design


The following illustrative example demonstrates how a temporary response can silently degrade when its operational boundaries are left unmonitored.


A financial institution identifies that a customer process can produce incorrect outcomes in certain circumstances. While the underlying system is being redesigned, it introduces a tactical control. A daily report flags transactions meeting specified criteria, and an operations team reviews each case before completion.


At implementation, the process handles around 1,500 transactions a day, generating approximately 40 exceptions for manual review. The team can comfortably review up to 60 cases a day. Testing confirms that the control is operating effectively, and the issue is closed while the strategic system change remains on the transformation roadmap.


The strategic change is subsequently delayed. Over the next two years, transaction volumes increase to 3,500 a day and additional products begin using the same process. Exception volumes regularly exceed 90 cases a day, but the control design, staffing and review criteria remain unchanged.


Eventually, the backlog results in exceptions being cleared without timely review. Several incorrect transactions reach customers, resulting in customer remediation, complaints and the reopening of the original control issue.

The tactical control had worked as designed. The operating conditions around it had changed beyond the capacity for which it was designed.


The failure started earlier than the incident. Increasing exception volumes were evidence that the assumptions supporting the control were changing.


Tactical controls can address an immediate exposure, but they also create continuing Risk Demand. They require people to operate them, capacity to absorb the workload, monitoring to confirm they remain effective and oversight to respond when conditions change. If strategic remediation is delayed, that additional workload can become a permanent part of the operating model while the underlying weakness remains.


Organisations therefore need to monitor both the effectiveness and continuing cost of tactical controls, including whether volumes, capacity, processes or dependencies have changed since they were introduced. Strategic remediation should remain visible until the underlying weakness has been addressed.


A tactical solution can reduce today's risk while creating tomorrow's workload.


Who Owns the Decision to Change What Already Exists?


Risk activities usually have identifiable owners. Controls have control owners. Reports have producers. Issues have accountable executives. Policies have designated owners.


Ownership of the activity does not always mean ownership of its continued necessity.


A control owner may be responsible for operating a control effectively without having the authority to remove it. Risk may oversee the control environment without owning the underlying business process. Internal Audit can challenge effectiveness but does not manage the control. A regulatory requirement may have been translated into several internal activities without any single person retaining visibility of the original rationale.


This can leave an important governance gap. Everyone may be accountable for performing their part of the existing process, while nobody is clearly accountable for determining whether the process should still exist in its current form.


The problem becomes more difficult when a risk response crosses organisational boundaries. Changing one control may affect policies, systems, reporting, assurance plans or regulatory commitments elsewhere. The decision therefore requires more than an individual control owner deciding that an activity no longer adds value.


Clear lifecycle ownership can address this. Significant risk interventions should have an identifiable purpose, decision authority and basis for future review. Where circumstances change, someone must have both the responsibility and authority to initiate that reassessment and bring the appropriate functions into the decision.


Owning a risk activity should include responsibility for questioning whether it remains the right activity.


More Controls Are Not the Same as Better Control


New controls are often introduced for good reasons. They may address a specific weakness, respond to an incident, strengthen regulatory compliance or reduce exposure to an emerging risk. Their value depends on the outcomes they improve, not simply their presence in the control environment.


As controls accumulate, the organisation has more to understand, operate, maintain, monitor and assure. Control owners need to know how controls work and interact. Management and Risk need visibility of performance, while assurance needs to determine where testing and challenge remain necessary.


Documentation and evidence can demonstrate that these activities have taken place, but they do not by themselves establish control effectiveness. Formal management systems such as ISO 27001 illustrate this distinction: documented information supports governance and assurance, while effectiveness ultimately depends on whether the controls achieve their intended security outcomes.


Controls can also introduce new risks. Manual reviews can create capacity constraints and human error. Additional approvals can create bottlenecks. Automated controls introduce technology and data dependencies. Complex control processes can encourage workarounds. These effects can themselves generate further monitoring, controls or remediation.


Organisations therefore need to assess both individual controls and whether the overall control environment remains proportionate, understandable and manageable. Additional controls may be entirely justified, including where they increase workload. Their value should be assessed against the outcomes they improve, the continuing Risk Demand they create and any new risks or dependencies they introduce.


Effective control is an outcome, not a control count.


Infographic showing how additional risk controls can increase complexity across a business activity, creating ongoing demands on people, technology, data, management and assurance, while potentially introducing capacity constraints, bottlenecks, human error, dependencies and workarounds.

Create a Discipline of Subtraction


Risk frameworks need mechanisms for reviewing existing activity as deliberately as they introduce new requirements. This starts when the activity is created, not several years later when complexity or cost becomes a concern.



For significant new controls, monitoring, reporting or governance, four questions can establish that discipline:

  • Purpose: What problem is this addressing?

  • Outcome: What should change if it works?

  • Demand: What continuing activity and resources will it require?

  • Review: When, or under what conditions, should its continued need and effectiveness be reconsidered?

The subsequent review should reflect how circumstances have evolved. Activity may continue, change, consolidate or retire. A tactical control may need strengthening, replacing with a strategic solution or removing once its original purpose has been fulfilled.


This also creates a useful management measure: What did we add to the risk operating model this year, and what did we remove?


The aim is not numerical balance. Regulatory change, growth or emerging risks may legitimately require significant additions. The discipline lies in making review and subtraction part of normal governance.


Subtraction should be an established capability of the risk operating model, not an exceptional exercise triggered by cost pressure or transformation.


I would make the board questions test the governance implications of recursive Risk Demand, rather than repeat the article's operational detail.


Five Questions Board Directors Should Ask


1. Do we know which significant risk responses were designed for particular conditions?

Controls, monitoring, reporting and governance may have been introduced following incidents, regulatory findings or periods of heightened risk. Boards should seek confidence that management can identify the purpose and assumptions behind significant interventions, particularly where they have become embedded in normal operations.


2. Who is accountable for determining whether existing risk activity should change?

Operating a control is different from deciding whether it remains the right control. Boards should understand whether significant risk interventions have clear lifecycle ownership and whether someone has the authority to initiate reassessment as circumstances change.


3. How do we know existing controls remain effective as operating conditions change?

Controls designed around particular volumes, processes, systems or risks may remain for years. Governance should provide visibility of whether their underlying assumptions remain valid and whether tactical responses continue to operate effectively.


4. Can management demonstrate that the overall control environment remains proportionate and manageable?

Individual controls may each have a valid purpose while collectively creating complexity, dependencies and additional risks. Boards should look beyond control counts and assurance completion to whether the overall environment continues to deliver the intended outcomes.


5. What have we continued, changed, consolidated, replaced or retired?

Risk activity needs a lifecycle. The objective is not to achieve a particular level of removal, but to demonstrate that existing interventions are deliberately reassessed rather than continuing indefinitely because they have become part of the operating model.



Explore how Aevitium connects risk strategy, governance, capabilities and decision-making through its Integrated Risk Management Framework™.


Integrated Risk Management visual illustrating the connection between strategy, governance, accountability and decision-making through Aevitium’s integrated risk framework.


Conclusion: Risk Responses Need a Lifecycle


Risk management must respond to incidents, regulatory change, emerging risks and control weaknesses. Those responses can remain part of the operating model long after the circumstances that shaped them have changed.


The challenge is not simply accumulation. It is ensuring that existing risk activity continues to reflect the risks, operating conditions and outcomes it was designed to address.


That requires clear lifecycle ownership, deliberate reassessment and the authority to change established responses. Accountability, organisational memory and potential audit or regulatory challenge can make this difficult, particularly when retaining an existing activity appears easier to defend than changing it.


Mature risk management therefore needs to revisit its own interventions with the same discipline it applies when introducing them. Controls, monitoring, reporting and assurance should continue where they remain appropriate, and adapt, consolidate, be replaced or retire where circumstances require it.


Risk management is designed to respond to change. An effective risk operating model ensures its own responses can change too.


About the Author: Julien Haye


Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.


 


Frequently Asked Questions


What is lifecycle management for risk controls?

Lifecycle management ensures that controls are reviewed throughout their use, not only when they are introduced or tested. It considers whether their original purpose remains relevant, whether operating conditions have changed and whether the control should continue, adapt, consolidate, be replaced or retire.


How often should organisations review existing risk controls?

Review frequency should reflect the nature and materiality of the risk and control. Reviews may also be triggered by significant changes in transaction volumes, technology, business processes, regulation, incidents or dependencies. Controls designed for temporary or changing conditions may require more frequent reassessment.


What is the difference between tactical and strategic remediation?

Tactical remediation manages an immediate exposure, often while a more sustainable solution is developed. Strategic remediation addresses the underlying process, system or operating-model weakness. Where tactical measures remain for extended periods, organisations should monitor their effectiveness, capacity and continuing resource requirements.


Who should be responsible for reviewing whether a risk control is still needed?

Responsibility will depend on the organisation and control, but operating ownership alone may not be sufficient. The review may require input from the business, Risk, Compliance, Technology or assurance functions, particularly where changing a control affects other processes or regulatory commitments. Governance should make clear who has authority to initiate and approve the reassessment.


What evidence should support the retirement or replacement of a risk control?

The decision should consider the control's original purpose, changes in the underlying risk, performance and incident information, alternative controls, dependencies and the consequences of removal or replacement. The rationale and approval should be documented so the organisation can demonstrate that the change was a deliberate, evidence-based risk decision.

 
 
bottom of page