top of page

The Hidden Administrative Burden of Risk Management

Writer: Julien Haye
Julien Haye
21 hours ago
22 min read
Hero image for The Hidden Administrative Burden of Risk Management, showing interconnected gears, documents and data networks representing the organisational workload created by risk governance, reporting and administration.

Risk management has become increasingly sophisticated.


Financial institutions have developed specialist risk disciplines, stronger governance structures, more extensive assurance and better technology. These developments have strengthened the ability to identify, monitor and respond to risk.


They have also created something less visible: an expanding layer of activity required to operate the risk management system itself.


Some of that activity sits within Risk and Compliance. Much of it does not. It is absorbed into the day-to-day workload of control owners, business teams, technology functions and managers across the organisation, making its overall scale difficult to see.


The first article in this series examined the growth of Risk Demand. This article looks inside that demand at a different question: how much organisational effort is consumed by the administration surrounding risk management?


That question is important because administrative activity rarely arrives as one large requirement. It accumulates through individually reasonable demands and becomes embedded in how organisations operate.


The result can be a substantial organisational workload that remains largely invisible when risk management is viewed through functions, headcount or budgets alone.


Article series:


Executive Takeaways

For readers scanning rather than reading in full, five insights frame the argument:

  1. Risk administration extends well beyond Risk and Compliance.

    Assessments, evidence requests, reporting, attestations, assurance and remediation create workload across control owners, business managers, technology teams and other functions. Risk and Compliance headcount therefore captures only part of the organisational effort involved.

  2. Evidence and documentation should serve a defined outcome.

    A requirement for assurance, accountability or regulatory evidence does not automatically require additional documentation. Existing operational data, workflows and records may already provide reliable evidence. The starting point should be the outcome required and the minimum evidence needed to support it.

  3. Legitimate risk processes can create substantial cumulative administration.

    Individual assessments, reviews, evidence requests and governance requirements may each be reasonable. Administrative burden emerges when multiple frameworks interact with the same product, process, third party or team without sufficient visibility of their combined effect.

  4. Technology can reduce the cost of administration without reducing its volume.

    AI can make assessments, reports, control narratives, regulatory mappings and evidence analysis significantly easier to produce. That productivity gain can also encourage greater production, shifting the constraint from creating risk information to reviewing, challenging, maintaining and acting on it.

  5. Administrative burden should be measured where it lands.

    Understanding Risk Demand requires looking beyond the activities performed by risk functions to the workload experienced by the business. The objective is not to remove governance or independent challenge, but to ensure that the administrative machinery remains proportionate to the risk outcomes it exists to support.


When Managing Risk and Administering Risk Become Different Things


A control owner is responsible for ensuring that a control operates effectively. But operating or improving the control may represent only part of the work involved.


The same control may need to be described in a risk system, supported by evidence, periodically assessed and included in management reporting. Its owner may respond to testing requests, explain exceptions, update assessments and support governance discussions. If a weakness is identified, issue management, remediation reporting and closure validation can add further activity.


In the first article in this series, I introduced Risk Demand to describe the organisational workload generated by how risks and regulatory requirements are managed, governed, evidenced and assured. I argued that this demand can accumulate across risk disciplines, through governance and assurance, and over time.


But understanding how Risk Demand grows raises another question: what are organisations actually spending that time doing?


Part of the answer lies in the administration that surrounds risk management.

Documentation provides a useful example because its necessity is often taken for granted. A control needs to be documented. An assessment needs a record. Evidence needs to be retained. A decision needs an audit trail.

But why?


Documentation is not itself a risk management outcome. Its value depends on what it enables. A record may demonstrate compliance with a specific obligation, preserve the basis for a material decision, establish accountability, support continuity or enable independent challenge and assurance. Where none of those purposes can be clearly identified, the case for producing the documentation becomes less obvious.


Even where a record is necessary, a separate risk document may not be.

A transaction history may already demonstrate that a control operated. A workflow may establish who approved a decision. Operational data may show whether a process is performing as intended. The evidence can exist because the business activity occurred, rather than because somebody subsequently documented it for risk management purposes.


The administrative burden grows when organisations create additional records around information that already exists. Evidence is extracted, reformatted, uploaded, described in an assessment and subsequently reproduced for different oversight or assurance processes. The underlying risk has not necessarily changed. Neither has the control. What has changed is the amount of activity required to demonstrate that it is being managed.


The same challenge extends beyond documentation. Reporting, testing, assessments, issue management and assurance can all serve legitimate purposes. But legitimacy of purpose does not establish that every activity surrounding them remains necessary or proportionate.


A longer control description does not make the control more effective. More evidence does not automatically provide greater assurance. Reproducing information across several assessments does not necessarily improve understanding. Another governance report does not necessarily strengthen oversight.


Nor can managing risk and administering it be separated neatly. The same information may support the operation of a control, regulatory compliance, management oversight and independent assurance. The objective should not be to eliminate administration simply because it does not directly manage the underlying risk.


The more useful challenge is to reverse the assumption.


Rather than starting with “this risk activity needs documentation”, start with “what outcome requires a reliable record?”


Then ask whether that record already exists, what additional information is genuinely required, who will use it and what it enables them to do.


That principle extends to the wider administrative component of Risk Demand. Much of it is also distributed beyond Risk and Compliance, across control owners, operations, technology, product and management.

The question at the centre of this article is therefore not whether risk administration is necessary.


It is whether organisations can explain why each administrative requirement exists, what outcome it supports and whether the effort remains proportionate to that purpose.


Infographic showing five questions for determining what risk management documentation is necessary: why a reliable record is required, whether evidence already exists, what additional record is needed, who will use it, and whether the effort is proportionate. It emphasises starting with the required outcome rather than assuming more documentation is needed.

Risk Management Has an Administrative Supply Chain


A single risk, control or regulatory obligation can generate a much wider set of administrative activities around it.


The underlying risk may first need to be assessed. A control may then be defined, assigned to an owner and recorded. Evidence may need to be retained. The control may be subject to attestation, testing, reporting and governance. If a weakness is identified, an issue may be raised, remediation actions tracked, closure evidence produced and assurance provided before the matter is considered resolved.


The surrounding activity can extend across several categories:


Define and allocate

  • risk and control assessments

  • control descriptions and ownership records

  • policies, procedures and standards

  • roles, responsibilities and approval requirements


Evidence and demonstrate

  • evidence collection and retention

  • attestations and certifications

  • supporting records and audit trails

  • regulatory or audit responses


Monitor and challenge

  • control monitoring and testing

  • exception management

  • assurance reviews

  • follow-up requests and clarification


Report and govern

  • management information and risk reporting

  • committee papers and governance updates

  • escalations and approvals

  • periodic assessments and refreshes


Remediate and close

  • issue and action tracking

  • remediation plans and progress reporting

  • closure packs and validation evidence

  • post-remediation assurance

Maintain and coordinate

  • data reconciliation between systems

  • record maintenance

  • workflow administration

  • coordination between business, Risk, Compliance and assurance teams


None of these activities is automatically unnecessary. Many support accountability, challenge, traceability, regulatory compliance or assurance.

The problem emerges when they are designed and managed independently.

An assessment process may define one set of requirements. A control framework may introduce another. Testing may require evidence in a different format. Governance may need a separate summary. Issue management may create further reporting. Assurance may then request additional information to validate what has already been produced.


Each process can look reasonable in isolation. The business experiences the combined effect.


That combined effect is the administrative footprint of risk management: the activity required to document, evidence, coordinate, report and demonstrate that risks are being managed, beyond the underlying activity that manages the risk itself.


The point is not to collapse legitimate independence between the First, Second and Third Lines. It is to understand the full chain of activity surrounding the same underlying risk or obligation, and to identify where information, evidence and administration are being recreated rather than reused.


Seen end to end, the question becomes less about whether each individual process is justified and more about whether the overall administrative effort remains proportionate to the risk management outcome it supports.


Why the Same Evidence Gets Requested More Than Once


Ask a control owner how many times they have provided the same information and the answer may be difficult to establish.


Evidence produced through the day-to-day operation of a control may subsequently be requested for an RCSA. Compliance may need it for monitoring. Operational Risk or a specialist risk team may examine the same activity. It may appear in regulatory reporting, be requested by Internal Audit and later be revisited through external assurance or regulatory review.


From the business perspective, this can feel like answering the same question repeatedly.


Sometimes it is. Sometimes the requests serve genuinely different purposes.


There is a useful parallel with roadworks. A road is resurfaced and, shortly afterwards, one utility company excavates it to complete necessary work. The road is repaired, only for another company to return later and excavate another section for a different purpose. By the time several legitimate interventions have been completed, much of the road is back to its pre-resurfaced state.


The problem is not necessarily that any individual piece of work was unnecessary. The question is why the different requirements could not have been identified, coordinated and addressed together.


Risk management can experience the same problem.


A business activity may be reviewed through its own control process, an RCSA, Compliance monitoring, Operational Risk, specialist risk functions, Internal Audit and external assurance. Different functions have different mandates, levels of independence and evidential standards. That does not automatically mean every review, test or evidence request can be combined.


But nor should those differences prevent the organisation from asking whether the activity could have been better coordinated.


Before requesting further evidence, there are therefore two questions.


  1. Does another review genuinely need to take place? 

  2. If it does, what new information or evidence does it actually require?


An additional review may address a different risk, meet a specific regulatory requirement, provide necessary independent challenge or close an identified assurance gap. Where that purpose exists, the review may be entirely appropriate. But it does not follow that the business must reproduce everything that already exists.


Existing evidence may sometimes be sufficient. In other cases, it may cover the wrong period, lack sufficient detail or reliability, or fail to address the question being examined. Additional evidence is then justified.


The opportunity is therefore broader than simply “produce once, use many times.” It is to understand the different requirements surrounding the same business activity early enough to determine what can be coordinated, what evidence can be reused and what genuinely needs to remain separate.


This is the practical consequence of the horizontal layering of Risk Demand explored in the first article. Each function can have a legitimate reason for digging. The administrative burden grows when nobody has visibility of the whole road.


That last line is one of the few places where I think carrying the analogy into the conclusion works. It is concrete enough that the reader immediately understands what horizontal layering feels like operationally, without suggesting that all risk and assurance activity should be consolidated.



See how structure, accountability, Risk Demand and capability combine to make risk management work in practice.


Risk management operating model infographic showing how strategy, objectives, risk appetite and decisions connect to governance, roles, organisational structure, processes, people, technology and Risk Demand.

The Cost of Evidence


Evidence can look inexpensive when viewed as an individual requirement. A control owner provides a screenshot, extracts a report, completes an attestation or uploads a record. The request is completed and the evidence exists.

But that is rarely the full cost.


Evidence has a lifecycle. Someone produces or retrieves it. Someone may validate that it is complete and reliable. It needs to be stored and made accessible. Someone reviews it and may challenge what it shows. Deficiencies generate questions, responses and potentially further evidence. Where a weakness is identified, someone eventually needs to demonstrate that it has been resolved.


The original evidence request can therefore create activity across several people and functions.


The cost is also not concentrated where it is easiest to measure. Risk and Compliance teams may design assessments, monitoring or testing programmes, but much of the resulting work falls on control owners and business managers. Their primary role is typically to run a process, manage a service, deliver a product or lead a team, not to administer risk frameworks.


This makes the burden less visible.


An hour spent responding to an evidence request does not appear as additional Risk headcount. Neither does the time spent locating records, explaining a control to a reviewer, resolving questions about evidence or providing further information after challenge. Individually, these demands can appear small. Across multiple controls, frameworks and assurance activities, they compete with the time available to manage the underlying business.


There is a further paradox. The effort required to demonstrate that a control is working can, in some circumstances, begin to compete with the effort required to operate and improve the control itself.

That does not make evidence unnecessary. Where evidence supports a clear regulatory, governance or assurance purpose, the organisation needs sufficient confidence that the underlying activity occurred and achieved what was intended.


But the cost of evidence should not be assessed only at the point where it is requested. It includes the activity required to produce, retrieve, validate, store, review, challenge, respond and ultimately demonstrate resolution.


Infographic showing the cost of an evidence request across six stages: producing or retrieving evidence, validation, storage and maintenance, review and challenge, response, and resolution. It highlights how a single evidence request can create work across business teams, control owners, Risk, Compliance, specialist functions, Internal Audit and records management.

When Risk Information Is Produced for the Process Rather Than the Decision


Highly regulated organisations produce significant volumes of risk information. Committee packs are prepared, management information is refreshed, attestations are completed, assessments are updated, control inventories are maintained and issues are reported through governance forums.


Much of this information has a legitimate purpose. The difficulty is that information requirements can persist long after that purpose has become unclear.


A report introduced following an incident becomes a standing agenda item. A temporary status update becomes part of the monthly committee pack. An assessment is refreshed because the framework requires an annual review, even where little has changed. Similar information appears in several governance forums because each has developed its own reporting requirements.

Over time, the organisation can become very efficient at producing information without regularly asking what that information is there to achieve.


The test should not simply be whether a report leads directly to a decision. Risk information serves several different purposes:

  • Decision information helps someone make a decision, intervene or determine a course of action.

  • Monitoring information helps establish whether risks, controls or operating conditions remain within acceptable parameters and whether intervention may be required.

  • Evidence information demonstrates that an obligation, control or required activity has been fulfilled.


Each can be necessary. But each should have an identifiable user and purpose.

This creates a relatively simple test for recurring risk information: Who uses it? For what purpose? What would change if it were not produced?


Those questions can expose requirements that have become disconnected from their original purpose. A committee may receive a report but rarely discuss it. The same management information may be reformatted for several forums without changing the underlying insight. An attestation may confirm information already available through operational systems. An assessment may be refreshed according to the calendar rather than because the underlying risk has changed.


The issue is not simply wasted time. Information production itself creates Risk Demand. Data must be collected, reconciled and validated. Commentary must be written. Reports need to be reviewed and approved. Questions generate follow-up activity. Different governance forums may require the same information to be repackaged in different ways.


There is also a decision-making consequence. More information does not necessarily create greater awareness. When governance processes accumulate reporting requirements, material changes can become harder to distinguish from routine information. Senior management and boards may receive increasingly comprehensive packs while still having limited visibility of what has actually changed, why it matters and where intervention may be required.


The objective is not less risk information. It is information with a clear purpose.


If an organisation cannot explain who uses a recurring information requirement, what purpose it serves and what would be lost if it disappeared, the requirement deserves to be challenged. Risk reporting should support governance, monitoring, accountability and decision-making, rather than become an output that the organisation continues to produce simply because the process expects it.


Issues and Actions Can Create Their Own Administrative Economy


Identifying an issue should trigger work to address the underlying problem. But it also triggers another stream of activity: the administration required to manage the issue through the organisation's remediation process.


An issue may need to be classified, its root cause documented and its severity assessed. Actions are created, owners assigned and target dates agreed. Progress is reported through governance forums. Evidence is submitted and challenged. Delays may require extension requests and further approvals. Once remediation is complete, closure evidence is assembled, reviewed and potentially subject to independent validation.


The resulting chain can be substantial:


Iceberg infographic showing the visible work of fixing a risk issue above the waterline and the larger administrative workload below it, including classification, remediation actions, ownership, reporting, evidence, challenge, extensions, closure and validation.

Much of this activity serves a legitimate purpose. Organisations need accountability for remediation, visibility of progress and confidence that material weaknesses have actually been addressed.


But there are two different forms of work taking place.


The first is the work required to fix the underlying problem: redesigning a process, correcting data, strengthening a control, changing a system, addressing a capability gap or resolving whatever condition created the issue.

The second is the work required to administer the remediation process: maintaining records, updating action statuses, preparing governance reports, responding to challenge, requesting extensions, assembling closure packs and navigating approval requirements.


These activities support one another, but they are not the same.


This becomes particularly visible when issues remain open for long periods or actions repeatedly move beyond their target dates. The organisation continues to consume capacity through reporting, challenge, governance and extensions while the underlying exposure remains unresolved. A remediation process intended to drive resolution can therefore generate continuing Risk Demand of its own.


The same problem can arise through fragmentation. One underlying weakness may produce several related issues or actions across different functions, assurance reviews or regulatory programmes. Each may then acquire its own owners, dates, reporting requirements and closure criteria. The organisation can end up administering several remediation processes around what is substantially the same underlying problem.


That makes the composition of remediation effort worth examining. How much capacity is being used to resolve the underlying problem, and how much is being used to administer the machinery surrounding its resolution?


The objective is not to weaken issue governance or make closure easier. It is to ensure that the administrative architecture supports timely and sustainable remediation rather than becoming a significant activity in its own right.


Why Technology Can Make the Administrative Layer Bigger


Technology is usually expected to reduce the administrative burden of risk management. Increasingly, AI can draft assessments, summarise issues, analyse evidence, map regulatory requirements, produce control narratives and prepare material for governance forums in a fraction of the time previously required.


The productivity opportunity is significant. But there is a less obvious consequence that risk functions should consider.


When something becomes cheaper and easier to produce, organisations may produce more of it.


Evidence from other forms of knowledge work demonstrates how substantially generative AI can lower production effort. A 2026 study of software developers found that access to generative AI increased code output by more than 50%, while completed tasks increased by 22%. Research involving 758 consultants found that those using GPT-4 completed 12.2% more tasks and worked 25.1% faster on tasks within the technology's capability frontier.


Neither study examined risk management, so they do not establish that AI will increase the volume of risk administration. They do, however, illustrate an important mechanism: technology can substantially reduce the cost of producing knowledge-work outputs and increase the amount that can be produced.


Applied to risk management, the implications are significant.


A committee paper that previously required several hours to prepare may become much easier to generate. The same applies to risk assessments, control narratives, regulatory mappings, issue summaries and evidence analysis. The immediate productivity gain is real.


But lower production costs also remove a natural constraint on volume.

Governance forums can request additional analysis because producing it appears inexpensive. Risk assessments can become more frequent or detailed. Reports can be tailored for individual audiences rather than reused. Control narratives can expand. Evidence can be analysed against more criteria. Monitoring can generate more exceptions and observations.


This resembles what economists describe as the rebound effect: efficiency improvements reduce the cost of an activity, but some of the resulting efficiency gain is offset because consumption of that activity increases. The concept does not prove that the same effect will occur in risk management, but it provides a useful lens through which to examine the adoption of AI.


The individual risk activity may therefore become cheaper while the administrative system surrounding it becomes larger.

Automation can reduce the unit cost of risk administration while increasing its total volume.

Production is also only one part of the cost. Someone may still need to review an AI-generated assessment, determine whether the analysis is reliable, challenge its conclusions and decide what action to take. Additional reports create additional information to consume. More detailed control narratives need to be maintained. More findings can generate more issues and actions. More monitoring can produce more exceptions requiring investigation.


Research involving 7,137 knowledge workers across 66 firms provides an interesting indication of this wider effect. Frequent users of an AI tool spent around 3.6 fewer hours per week on email and completed documents faster, but the technology did not significantly reduce time spent in meetings. AI improved the efficiency of particular activities without necessarily removing the wider organisational processes surrounding them.


For risk management, the bottleneck could therefore move rather than disappear: from producing information to reviewing, interpreting, challenging and acting on it.


That changes the productivity question.


Rather than asking only:

How much faster can we produce this?

Risk leaders should also ask:

Should we produce it at all? Who will consume it? What action could it trigger? And what additional Risk Demand will it create once it exists?

Used well, technology can remove repetitive administration and release capacity for judgement, challenge and management of the underlying risks. Used without discipline, it can make an already complex risk operating model capable of generating administration at far greater speed.


The real measure of AI productivity in risk management may therefore be less about how many assessments, reports or analyses can be produced and more about whether technology reduces total Risk Demand while preserving or improving the quality of risk management.


That is a substantially harder test than automation alone.


Case Study: When a 1.5 Line Review Reveals the Administrative Layer


Consider an organisation reviewing its risk operating model to determine the appropriate scope of a 1.5 Line risk function. The starting question appears relatively simple: which risk and control activities should sit within the function, what capabilities does it require, and how should responsibilities be divided between the business and the Second Line?


Mapping the activity can reveal something less obvious.


Risk and control work is often distributed much more widely across the business than the formal operating model suggests. Employees outside dedicated risk roles may operate controls, investigate exceptions and perform checks as part of running their day-to-day processes safely and effectively.


Those activities should not automatically be treated as risk administration. Many are simply part of operating the business.


But another layer can sit around them.


The same employees may be required to describe those controls in risk systems, complete assessments, retain and provide evidence, respond to testing, support assurance reviews, prepare governance information and manage actions arising from findings. The underlying control may be embedded within the business process, while the administrative activity surrounding it is generated by several different risk and governance requirements.


This makes the workload difficult to see through organisational structure alone. Counting employees in Risk, Compliance or the 1.5 Line misses much of the administrative demand falling on the business. Counting everyone who performs a control captures activity that may have existed irrespective of the risk framework.


The more useful distinction is between operating the activity that manages the risk and administering the mechanisms used to demonstrate, govern and assure it.


That distinction also changes how the 1.5 Line should be considered. Moving administrative activity into a specialist team may relieve some pressure on the business, but it does not necessarily reduce the underlying demand. Equally, leaving the activity distributed across the First Line can make its cumulative cost difficult to see.


Understanding what activity exists, why it exists and what outcome it supports therefore needs to precede decisions about where it should sit.


What begins as a question about the structure of a 1.5 Line function can reveal a much wider administrative footprint surrounding risk management.


Measure the Administrative Burden Where It Lands


The administrative cost of risk management is difficult to see from Risk and Compliance headcount alone. Much of it is absorbed elsewhere in the organisation.


Control owners retrieve and explain evidence. Business managers complete assessments and attestations. Technology teams respond to assurance requests. Subject-matter experts support reviews. Issue owners prepare updates, manage extensions and assemble closure evidence. None of this necessarily appears as a risk-management cost, even though it has been generated by the organisation's risk and governance arrangements.


Understanding the burden therefore requires looking at the experience of the business activities and people that interact with those arrangements.


A material business change provides one useful place to start. A new product, technology implementation or third-party relationship may pass through several assessments covering operational risk, compliance, financial crime, data privacy, cyber, resilience and other specialist areas. Counting each assessment tells the organisation something about the individual framework. Counting how many touch the same change reveals something different about the cumulative workload created around it.


The same principle can be applied elsewhere:

  • How many assessments touch a material business change? This can reveal where separate risk disciplines collectively create significant demand around the same activity.

  • How often is substantially similar evidence requested? Different reviews may legitimately require different evidence or independent validation, but repeated requests can also expose limited coordination between processes.

  • How much control-owner time is spent producing and explaining evidence? Assurance has a demand side as well as a delivery side. The time spent responding to reviews can be substantial without appearing in the cost of the function conducting them.

  • How many recurring reports have a clearly identified purpose and recipient? Reports introduced for a particular decision, incident or period of heightened scrutiny can continue long after the original need has changed.

  • How much remediation effort goes into fixing the issue versus administering its closure? Issue governance requires oversight and evidence, but the balance provides a useful indication of how much capacity is reaching the underlying problem.

  • How many temporary reporting requirements have become permanent? Incidents, regulatory findings and management concerns frequently create additional reporting. Without deliberate review, these requirements can accumulate over time.


These are not performance targets, and high numbers do not automatically indicate inefficiency. A complex change may appropriately require extensive specialist input. A material issue may justify substantial independent validation. Similar evidence may need to be reconsidered because the purpose, period or required level of assurance differs.


Their value is in exposing workload that conventional measures often miss.

Most risk functions can tell management how many assessments were completed, controls tested, issues closed or reports submitted. Far fewer organisations can see how much cumulative effort those activities required from the businesses subject to them.


That is where much of the hidden administrative burden of risk management sits.


These final two sections should change pace again. Section 9 can be more directive because it is the practical response to the diagnosis, while the conclusion should be short and synthesising rather than restating the whole article.


Reduce Administration Without Weakening Risk Management


Reducing administrative burden does not mean reducing governance, challenge or accountability. Many of the activities explored in this article exist for good reasons. The opportunity lies in designing them so that the organisation gets the required risk outcome without creating avoidable work around it.

Five principles provide a useful starting point.


Reuse before requesting.

Before asking the business for information or evidence, establish what already exists and whether it can satisfy the requirement. Operational systems, previous assessments, control records and other assurance activity may already contain what is needed. Where they do not, the additional requirement should be clear.


Separate evidence from activity.

Evidence demonstrates that something happened. It should not become a substitute for the underlying activity. A comprehensive control description does not make a weak control stronger, just as an extensive closure pack does not make remediation more effective. The amount of documentation should reflect what is necessary to establish confidence in the outcome.


Design around business activity.

Risk frameworks naturally organise work around their own disciplines. The business experiences their combined effect. Looking across the requirements surrounding a product, process, technology change, third party or team makes it easier to identify where assessments, evidence requests, reporting and assurance overlap or could be better coordinated.


Preserve independent challenge without reproducing work.

Effective Second and Third Line challenge depends on sufficient independence, not unnecessary duplication. Compliance, Risk and Internal Audit may need to reach their own conclusions and may require additional evidence to do so. That does not automatically require the First Line to recreate information that already exists or respond independently to requests that could have been coordinated.


Give requirements an owner and lifecycle.

Administrative requirements accumulate easily and disappear less readily. Enhanced reporting introduced after an incident, additional attestations following a regulatory finding or temporary monitoring during remediation can become permanent features of the operating model. Assigning ownership also creates responsibility for periodically determining whether the original need still exists and whether the requirement remains proportionate.


None of these principles depends on removing controls or weakening assurance. They focus instead on the architecture surrounding those activities: how information is requested, how evidence is used, how different requirements interact and whether administrative processes continue to serve the purpose for which they were created.


Reducing that friction can release capacity without reducing the quality of risk management. In some cases, it may improve it by allowing more organisational effort to reach the underlying risks, controls and decisions that the administrative machinery was designed to support.


Five Questions Board Directors Should Ask About Risk Administration


1. Do we know how much risk-management workload falls outside Risk and Compliance?

Board reporting often focuses on the resources and activities of formal risk functions. Directors should also understand the demands placed on control owners, business managers, technology teams and other functions through assessments, evidence requests, reporting, assurance and remediation.

2. Are our risk processes using existing information before asking the business to produce more?

Operational systems, control records, previous assessments and other assurance activity may already contain relevant evidence. Boards should seek confidence that additional documentation and information requests have a clear purpose rather than routinely recreating what already exists.

3. Can we see the cumulative administrative burden surrounding important business activities?

A material change, product, process or third-party relationship may interact with several risk disciplines and assurance processes. Each requirement may be appropriate individually while collectively creating significant workload. Governance should provide visibility across those requirements, not only within individual frameworks.

4. Are remediation processes directing sufficient effort towards fixing underlying problems?

Issues require classification, reporting, evidence, challenge and validation, but those activities also consume capacity. Directors should consider whether remediation governance supports timely resolution or whether excessive effort is being absorbed by administering the process surrounding it.

5. Is technology reducing total Risk Demand or simply making risk administration easier to produce?

AI and automation can accelerate assessments, reporting, evidence analysis and other administrative activities. Boards should look beyond individual productivity gains and consider whether technology is reducing the overall organisational burden or enabling greater volumes of information, monitoring and administration that must subsequently be reviewed and acted upon.



Explore how Aevitium connects risk strategy, governance, capabilities and decision-making through its Integrated Risk Management Framework™.


Integrated Risk Management visual illustrating the connection between strategy, governance, accountability and decision-making through Aevitium’s integrated risk framework.

Conclusion: Administration Should Support Risk Management, Not Become Its Output


Risk management requires reliable records, evidence, reporting and assurance where these support regulatory obligations, accountability, governance, continuity and effective challenge. But the need for those outcomes does not justify unlimited administration around them.


Throughout this article, the same pattern appears in different forms. Evidence creates work beyond the original request. Information is reproduced across governance processes. Issues generate administrative activity alongside remediation. Different risk disciplines interact with the same business activity. Technology can make administrative outputs cheaper to produce without necessarily reducing their overall volume.


Much of this work is legitimate. Its cumulative footprint is simply difficult to see because it is distributed across functions, frameworks and the business itself.


Understanding Risk Demand therefore requires more than identifying how much risk-management work exists. It requires understanding how much organisational effort goes into managing risk and how much goes into administering the mechanisms used to demonstrate that risk is being managed.


The objective is not to eliminate the second. It is to keep it proportionate to the outcomes it supports.


Administration should provide evidence of effective risk management. It should not become the primary output of risk management itself.


About the Author: Julien Haye


Managing Director of Aevitium LTD and former Chief Risk Officer with over 26 years of experience in global financial services and non-profit organisations. Known for his pragmatic, people-first approach, Julien specialises in transforming risk and compliance into strategic enablers. He is the author of The Risk Within: Cultivating Psychological Safety for Strategic Decision-Making and hosts the RiskMasters podcast, where he shares insights from risk leaders and change makers.


 


Frequently Asked Questions


What is the difference between regulatory burden and risk management administrative burden?

Regulatory burden originates from obligations imposed through legislation, regulation and supervisory expectations. Risk management administrative burden is broader and can also arise from how an organisation chooses to translate those obligations, and its own governance requirements, into internal assessments, controls, reporting, evidence, approvals and assurance. The two therefore overlap, but they are not interchangeable.


Does the FCA require firms to document every risk management activity?

There is no universal requirement to create a separate document for every risk management activity. Record-keeping requirements depend on the applicable regulatory obligation, activity and circumstances. Firms should identify what evidence must be retained and then determine the most appropriate way to provide a reliable record, including where existing systems and operational records can do so.


Can reducing risk administration create regulatory risk?

It can if required records, controls, oversight or evidence are removed without understanding their purpose. Administrative simplification should therefore distinguish between requirements necessary for regulatory compliance, accountability and assurance and additional processes that an organisation has chosen to build around them.


Who should be accountable for the cumulative burden created by risk processes?

Individual risk processes typically have clear owners, but cumulative workload can cross business, Risk, Compliance and Internal Audit boundaries. Senior management therefore needs sufficient visibility across functions to understand how separate requirements interact around the same products, processes, systems, third parties and business changes.


How should risk administration change as an organisation grows?

Growth does not necessarily require administrative activity to increase at the same rate. Greater complexity may justify additional controls, governance and assurance, while standardisation, better information reuse and technology can reduce other requirements. Periodic review helps prevent arrangements introduced at earlier stages of development from continuing automatically as the organisation changes. 

 
 
bottom of page