Avoiding tripping over the hurdles of risk

In life, it is extremely easy to forget what is important to you as a Risk Manager, may not be important to others. In addition, not only do we sometimes forget what is important, we confuse what is urgent with what is important. For those of you familiar with the “7 Habits” this will sound extremely familiar.

Showing resilience and efficiency requires the Risk Manager to be concious of the distinction between importance and urgency.

Too often Risk Managers get caught up in what is considered urgent, thereby neglecting what is important and not actually delivering true businsss value.

In this respect it is often assumed that the Risk Manager should be the first person to know and take responsibility when an issue or event arises.  They will lead the way by ensuring that everyone is aware of their responsibilities and their actions.  In addition, they will be the gatekeeper of ensuring the event or issue is managed through the process, and make key decisions.

Unfortunately if your Risk Manager is doing this then he or she is actually not helping the business manage risk but rather becoming part of the problem.  Why do we say this?

The role of the Risk Manager is not to manage your risk for you but rather to provide the platforms, spaces and thoughts to make risk management a critical component of running a successful business.  Effectively, the role of the Risk Manager is to coach and train you not to trip over the hurdles but rather jump all of the hurdles without hitting them.  But when you do happen to knock one and have an issue or event, that it does not see you or your business completely fail but rather manage through the small trip with resilience and efficiency.

This then allows the Risk Manager to focus on the next 20, 30, 50, 100 or 1,000 hurdles that may be in front of your business, and provide you with the information to better help you leap those hurdles with efficiency and effectiveness.

So, pay attention Risk Managers to the choices of importance and urgency of what you are focusing on as your true goal should be to help your business achieve ultimate business success through each employees ownership and responsibility of risk management.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.