top of page
The Risk of Control Obsolescence
One of the lesser discussed challenges in enterprise risk management is that controls can become obsolete without becoming obviously ineffective. A control may continue to operate exactly as designed while the risk environment around it has fundamentally changed. Consider an organization whose cybersecurity controls were designed around human-generated threats. The controls may include authentication, access reviews, phishing awareness and periodic vulnerability assessments.

Michael G. Bradshaw, CPA
Aug 132 min read
Â
Â
Â
4th Party Risk: Effective Visibility
Organizations increasingly depend on third parties for technology, logistics, professional services, data processing and critical infrastructure. Consequently, third-party risk management has become an established component of enterprise risk management. Yet a less visible problem is emerging: fourth-party risk. A fourth party is a supplier or service provider upon which an organization's direct vendor depends. The organization may have a sophisticated due-diligence process f

Michael G. Bradshaw, CPA
Aug 111 min read
Â
Â
Â
Risk Velocity & Decision Latency
Traditional enterprise risk management tends to organize risk around two familiar dimensions: likelihood and impact. These remain useful, but they are increasingly insufficient for organizations operating in environments where conditions can change faster than management processes can respond. A third dimension, risk velocity, probably deserves greater attention. This is the speed at which a risk can move from an emerging condition to a material business consequence. Consider

Michael G. Bradshaw, CPA
Aug 111 min read
Â
Â
Â
bottom of page