Risk Management and Accountability: Why Public Sector Risk Frameworks Often Miss the Point
Enterprise risk management frameworks have proliferated across the public sector. Most of them are technically sound and practically useless. The reason is almost always the same.
The adoption of enterprise risk management (ERM) frameworks across the Canadian public sector over the past two decades has been, by most measures, a success story of policy diffusion. Treasury Board guidance, departmental risk profiles, risk registers, and risk appetite statements are now standard features of the public sector management landscape. The frameworks exist. The question is whether they work.
The evidence is mixed, at best. Risk registers are maintained. Risk ratings are assigned. Risk mitigation strategies are documented. And then, with remarkable frequency, the risks that actually materialize are not the ones that appeared on the register — or they appeared on the register but were rated low, or they were rated high but the mitigation strategies were never resourced.
The core problem is that most public sector risk frameworks are designed to satisfy accountability requirements rather than to inform decisions. A risk register that is updated annually for the departmental plan is not a risk management tool. It is a compliance artifact. The distinction is not subtle, but it is frequently overlooked.
Effective risk management in the public sector requires two things that compliance-oriented frameworks rarely provide: genuine integration with decision-making processes, and honest assessment of the risks that are most politically uncomfortable to acknowledge. The second is the harder problem. Organizations face real incentives to understate reputational and political risks — the very risks that are most consequential in a public accountability environment.
The organizations that manage risk well tend to treat their risk frameworks as living analytical tools rather than periodic reporting requirements. They update risk assessments when circumstances change, not when the reporting cycle requires it. They discuss risk explicitly in senior leadership forums. And they have developed the organizational candour to name the risks that are genuinely threatening — including the ones that implicate leadership decisions.
Related Insights
