top of page

Risk Velocity & Decision Latency

Traditional enterprise risk management tends to organize risk around two familiar

dimensions: likelihood and impact. These remain useful, but they are increasingly insufficient for organizations operating in environments where conditions can change faster than management processes can respond. A third dimension, risk velocity, probably deserves greater attention. This is the speed at which a risk can move from an emerging condition to a material business consequence.


Consider two risks with identical likelihood and impact ratings. One may take three years to materialize, while the other could significantly disrupt operations within 72 hours. Treating them identically creates a false sense of equivalence. The real management question becomes: How much time does the organization have to detect, decide and respond?


This introduces a valuable ERM concept: decision latency. Organizations should assess not only whether controls exist, but whether information reaches the appropriate decision-maker quickly enough for those controls to matter. For boards and executives, this means key risk indicators (KRIs) should increasingly incorporate indicators such as escalation time, response capacity, dependency concentration and time-to-impact. The internal audit function can further add value by testing whether escalation mechanisms actually operate within the timeframes assumed by management.


The implication is significant. A risk register describes exposure; it does not necessarily demonstrate readiness. The mature question is therefore not simply “What could go wrong?” but “How quickly could it matter, and are we capable of responding before it does?”


That distinction can fundamentally change how organizations prioritize risk, allocate resources and design resilience.

Recent Posts

See All
The Risk of Control Obsolescence

One of the lesser discussed challenges in enterprise risk management is that controls can become obsolete without becoming obviously ineffective. A control may continue to operate exactly as designed

 
 
 
4th Party Risk: Effective Visibility

Organizations increasingly depend on third parties for technology, logistics, professional services, data processing and critical infrastructure. Consequently, third-party risk management has become a

 
 
 

Comments


bottom of page