The smoke alarm works perfectly. It is wired, tested, and certified. It sounds on schedule. And the room is on fire, and no one moves, because everyone is busy logging that the alarm performed exactly as designed. This is the strange place our sector has arrived at. We have built risk management so thorough that managing the risk has become the larger risk. Not because anyone set out to fail the people we serve, but because a system built to protect them slowly learned to protect us instead.
This is not a complaint about caution. Caution is right. Stewardship is real, fraud is real, and harm done in our name is a debt we carry for years. The argument is narrower and harder. Somewhere in the layering of safeguards, the question quietly changed. We stopped asking what protects the family at the door and started asking what protects the organization in the audit. Both wear the same word. Only one of them is the job.
When avoiding error becomes the only goal
Watch what a mature risk function rewards, and the pattern shows itself. A delayed program rarely triggers a finding. A fast decision that goes wrong almost always does. So we add the clearance, the second sign-off, the extra assessment, each one defensible on its own. Stacked together they produce an organization where the safest move is to slow down, qualify everything, and make sure the file is clean if anyone ever asks. We have made inaction feel responsible and judgment feel reckless. That is not a failure of the people inside the system. It is the system working exactly as we wired it, toward an outcome few of us would choose on purpose.
The cost lands where it always lands. A risk avoided at headquarters often reappears as a risk absorbed in the field, by a team waiting on an approval that the calendar has already overtaken. The person on the other end does not experience our diligence as protection. They experience it as time they did not have.
Pushing the danger downhill
There is a second move, quieter and more uncomfortable. When risk cannot be eliminated, it tends to be relocated, and it tends to flow toward whoever has the least power to refuse it. The closer an actor sits to the crisis, the more real risk they carry and the less of the decision they hold. We pass down the compliance burden, the reporting load, the security exposure, and the demand to prove themselves clean again and again, while keeping the authority and the funding that would let them manage any of it. This is rarely anyone’s intent. It is the residue of a chain built so that formal risk concentrates wherever the agreement was signed, and control follows it upstream. We have quietly arranged things so that the institutions most exposed to the actual hazard are the ones we trust with the least room to handle it.
Risk does not disappear when we manage it well. It moves, and it moves toward whoever has the least power to say no.
Building a risk function that serves the work
The fix is not less rigor. It is rigor pointed at the right target. Three moves make it concrete, and none of them require new technology or a softer conscience.
First, give delay a cost the way error already has one. Put a visible clock on decisions of consequence and a named person accountable for the time they take, not only for whether they went wrong. When lateness carries a name the way a misspent line item does, the calculation changes. A risk register that counts the harm of moving too slowly, beside the harm of moving wrongly, is simply a more honest register.
Second, separate stewardship from control, because we have let them fuse. Protecting funds well does not require pre-deciding every operational choice from a distance. We can hold accountability for money tightly while placing the judgment about how to spend it close to the people who can see the ground. Write the reallocation thresholds and decision rights into the agreement itself, so flexibility is a rule agreed in advance rather than a favor granted under pressure. Stewardship is a duty. Control at a distance is a habit, and habits can be redesigned.
Third, carry risk together instead of sending it downhill. Joint risk registers, shared due diligence so a partner vetted once is recognized by many rather than re-proving themselves to each, security costs funded for local actors rather than assumed away, and a contingency line that accepts in advance that some reasonable decisions will not work out. Shared risk is what makes shared authority affordable. It is also the difference between a partner and a subcontractor we have left holding the exposure.
None of this asks us to stop managing risk. It asks us to remember what the management was for. A safeguard that protects the institution while the people it serves wait, or carry the danger we declined, is not managing risk. It has become the risk. We built that system, carefully and with good intentions, and that is the most hopeful thing about it. What we built, we can wire differently. The test of a risk function is not how clean the file looks after the fact. It is whether, when the room fills with smoke, anyone is still free to move.