Compliance and Risk Management

Violation does not create a whole new type of risk. It simply reopens the risk that the policy itself was in the first place seeking to address – that you could have avoided (or at least limited) re-exposing yourself to by complying with the law, regulation or policy in the first place. Compliance is hugely important, and quite simply essential to your being allowed to exist; it is about doing the right things now, and adhering to what you have agreed to obey … but inventing a whole phraseology and pseudo-function around compliance risk (and meaning it to be the risk of non-compliance)? Cease and desist please. The risk of not taking medicine when you have the headache is simply the headache itself and it’s not going away soon, worse becoming larger. We don’t need new terminology to define it anew. Take the medicine. Be aware (continually) of what you need to follow and adhere. And just follow and adhere. Yes, I understand those dashboard and yet more toolkits give you this sense of comfort. But speak to risk, and help you manage it? No, they don’t.

Meanwhile, we show no signs of getting the overall point. Regulators were significantly embarrassed through the last crisis, realizing as they then (finally, correctly) did, that the hubris and excess of financial services can and will threaten the world. Their own eventual appreciation of the issues that come from correlations and concentrations, has by now been sharpened to absolute disgust and sheer paranoia. Can you really blame them? Isn’t it but natural, however uncomfortable and seemingly business-unfriendly it is, that they will come at markets and players now with a sense of don’t-trust-and-will-verify and will then ask you what if you and we are wrong again.

That’s my real problem with innovative risk-creation and system-selling and showcases full of black-boxed-frameworks. I believe that the misguided schools of Compliance Risk and Legal Risk and GRC are together conjuring up this great escape mechanism for risk-takers who do not want to, or cannot, understand and deal with the underlying risks. They are designed for and help perpetuate this school of box-checkers trying to postulate adherence to regulation, paying lip-sympathy to systematized approaches to control, and getting an obsessive hold over form, with not a prayer on substance. Technology does not manage risk, it enables it, and very much so especially with the phenomenal ability we all have today to harness data for all it is worth. But the voodoo part (the parrot picking the risk-card from the native astrologer) is not Risk Management … not least of the differences being that Risk Management is about forming forward-looking views on risk and how to manage it within one’s appetite, how to earn an optimal return against such risks, how to be able to define “the unusual, the unintended and the unacceptable”, and how to survive for the benefit of the employee, the shareholder, the customer, and the market at large. Not playing catch-up games with fancy boxes and arrows and colors.

Call me old-school. But if one of these Compliance Risk or Legal Risk or Regulatory Risk gurus ever finds and deals with a Risk on time and effectively, do give me a shout. I might have by then actually started making my own “Risk Risk” consulting. And do send a hat over, for I would have already eaten mine!