The widening gap between risks and the ability to manage them
Just 30% of CROs and CFOs feel their risk management is mature or robust, the AICPA finds.
• 3 min read
Dealing with ever-changing risks has become the norm for finance executives.
Workiva CFO Barbara Larson put it this way at the company’s Amplify conference in Las Vegas last week: “Since Covid, volatility really stopped being just an event. It’s something that’s become the baseline,” and it affects everything in the CFO’s remit, including “reporting, planning, [and] decision-making.”
However, business leaders indicate a “growing disconnect” between an increasingly unpredictable risk landscape and their “ability to manage those risks strategically,” according to the latest AICPA State of Risk Oversight report.
Drawing on a survey of 331 CROs, CFOs, and other senior executives in the second quarter, the report said roughly seven in 10 (69%) indicated the volume and complexity of risks either “mostly” or “extensively” increased over the last five years. That was up from 61% in last year’s survey.
Yet, just 30% of respondents described their level of risk-management oversight as “mature” or “robust,” down slightly from 32% last year. Two in five respondents indicated their risk-management oversight maturity as “evolving.”
Most organizations still don’t see risk management as a strategic tool, researchers noted. Just 11% of respondents believed risk management “mostly” or “extensively” provides them a competitive advantage.
“Risk insights are inconsistently incorporated into strategic planning, capital allocation, and board discussions, and relatively few organizations formally articulate risk appetite,” according to the AICPA report.
Pressure points. Some organizations reported increased pressure from stakeholders for more information on enterprise risks. More than a quarter (28%) of respondents said external parties are “mostly” or “extensively” putting more pressure on such information. That percentage was even higher for respondents from large organizations (35%) and public companies (33%).
Some survey respondents also noted that they’re being asked for more “senior executive involvement in risk oversight.” Nearly four in 10 (38%) said their audit committees were “mostly” or “extensively” asking for it, and 31% indicated the ask was coming from other board committees.
“Many organizations acknowledge that enhancements [to risk oversight] are still needed—particularly in areas such as business continuity and crisis management, indicating that practices have not fully kept pace with stakeholder demands.”
CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
About the author
Alex Zank
Alex Zank is a reporter with CFO Brew who covers risk management and regulatory compliance topics. Prior to CFO Brew, he covered the property/casualty insurance industry.
CFO Brew helps finance pros navigate their roles with insights into risk management, compliance, and strategy through our newsletter, virtual events, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.