Six Questions Every Board Should Ask About Risk

Boards are rarely short of risk information. Papers get circulated, registers get tabled, and heat maps appear. What is often missing is a way to test whether any of it reflects the business as it is now.

The difficulty is that risk reporting tends to be produced by the same people whose work it describes. That is not a criticism — they are the ones who know — but it means the reporting inherits their assumptions. A board's contribution is not to know the risks better than management does. It is to ask the questions that surface what the reporting cannot show about itself.

These six do most of that work. They are deliberately blunt, and the useful signal is often in how easily they are answered rather than in the answer itself.

1. "Who owns this risk, by name?"

Not which department. Which person.

Risks owned by a function are, in practice, owned by nobody. When something falls between two teams — and the risks that matter usually do — a departmental owner gives everyone a reason to assume it sits elsewhere.

What the answer tells you. A confident name means someone is accountable and probably engaged. Hesitation, or a job title instead of a person, usually means the risk is being tracked rather than managed. Watch also for one name appearing against a large share of the register: that is a capacity problem waiting to become an incident.

2. "What has changed since we last discussed this?"

Ratings that never move are the most common symptom of a register being maintained rather than used.

Businesses change constantly — new customers, new suppliers, new systems, new markets. If the risk profile has not moved in a year while the business has, the assessment is almost certainly stale.

What the answer tells you. Specific changes, with reasons, indicate live reassessment. "No change" across the board, repeatedly, means the review has become a formality. It is worth asking what would have to happen for a rating to move — if nobody can answer, the rating is not really a measurement.

3. "What are we most dependent on that we cannot easily replace?"

This question deliberately avoids the word risk, because it tends to produce a different and more honest list.

Dependency accumulates without anyone deciding on it. A supplier who was one of three becomes the only one. A system adopted for one team ends up carrying several critical processes. A person becomes the only one who knows how something works.

What the answer tells you. If the answer is quick and specific, someone has mapped the dependencies. If it takes a while, they have not — and unmapped dependencies are where disruption usually enters. This is closely related to the operational risks that build up quietly as a business grows.

4. "What would have to happen for this to reach us sooner?"

Boards usually hear about problems at a scheduled meeting or once they are severe. Neither timing is chosen; both are defaults.

The question tests whether escalation thresholds exist and are agreed in advance. Without them, escalation becomes a judgement made under pressure by someone who may be personally exposed to the outcome — the least reliable conditions possible.

What the answer tells you. A clear threshold ("if X exceeds Y, it comes to the board within a week") means the path is designed. "We'd let you know" means it depends on someone's judgement in a bad moment.

5. "Which of these risks have we decided to accept?"

Not every risk should be mitigated. Some are uneconomic to address, and accepting them is a legitimate, often correct decision.

The problem is accepting one without knowing you have. Risks get accepted by default — through inaction, cost, or simply never being decided on — and the board is frequently unaware that a decision was made at all.

What the answer tells you. A board that can name its accepted risks is exercising oversight. If the answer is "none", either the register is unrealistically optimistic or acceptance is happening silently. Asking explicitly converts a default into a decision, which is most of what governance is.

6. "What is not on this list?"

The most valuable question, and the one most likely to be met with silence.

Every risk process has blind spots. Registers are built from what people already recognise, and reporting formats reward risks that fit the format. Emerging risks, cross-functional risks and risks that would embarrass someone to raise are all systematically under-represented.

What the answer tells you. Useful responses sound uncertain: "we've wondered about X", "we don't have a good handle on Y". A crisp "nothing" is rarely accurate and usually means the question has not been given room. Asking it consistently, without penalising the answer, is what makes it productive over time.

Using them well

A few things make the difference between these being useful and being theatre.

Ask them of the same risks over time. The pattern across meetings is more informative than any single answer. Ownership that keeps shifting, or ratings that never move, tells you something no individual response will.

Treat difficulty answering as the finding. The point is not to catch anyone out. If question three takes ten minutes, the gap is in dependency mapping, and that is actionable.

Do not accept the register as the answer. All six ask about things a register typically does not record: whether ownership is real, what changed and why, what was consciously accepted, and what is missing.

Governance expectations around board risk oversight vary by entity type and sector in India, and confirming what applies to your organisation is worth doing before designing reporting around it.

{{ADD SOURCE: Indian corporate governance requirements on board-level risk oversight by entity type}}

If the answers are uncomfortable

That is usually the useful outcome. Most boards asking these for the first time find at least one they cannot answer well, and that gap is more valuable than a set of confident responses that were never tested.

Where the difficulty is structural — no register, no thresholds, no dependency map — the fix is a framework rather than better questions. Our enterprise risk management work covers exactly that, and our approach sets out how we get there without producing something nobody maintains. If you want a quick, private read on where you stand first, the free two-minute risk health check covers ownership, reporting, dependency and review.

To talk any of this through, book a consultation — no obligation.

KEEP READING

Related Insights

Enterprise Risk

Building a Risk Register Your Team Will Actually Use

A register fails when it is built as a record rather than a tool. Here is how to structure one that survives contact with a busy team — and what to leave out.

7 min read