Does strong risk management necessarily lead to improved resilience?
Abstract
Major disruptive events are inevitable, yet organisations continue to experience vulnerabilities despite the widespread adoption of risk management practices. This paper examines whether the expansion of risk management frameworks has led to improved resilience or has introduced unintended complexity that limits effectiveness. In response to significant incidents, standards, regulations, and assessment processes have been developed to strengthen preparedness. These frameworks are often implemented independently, however, resulting in overlapping requirements, fragmented processes, and increased administrative burden. The accumulation of multiple programmes may therefore create inefficiencies in identifying, managing, and reporting emerging risks, while contributing to a false sense of preparedness. The paper analyses how siloed frameworks and function-specific response plans can reduce organisational effectiveness, particularly in complex incidents involving multiple risk domains. It considers how current approaches may fail to provide a coherent, enterprise-wide view of risk and response readiness. The paper argues for a more integrated approach to enterprise risk management, emphasising cross-functional coordination, consolidation of assessment activities, and improved alignment of stakeholders. A more holistic framework enables organisations to prioritise critical risks, improve decision making, and strengthen resilience in an environment of increasing uncertainty and complexity. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Diane Doering leads the global Enterprise Risk Management (ERM) programme at Takeda Pharmaceuticals. Prior to that, she led both the global ERM programme and the Information Security Governance, Risk & Compliance team at Iron Mountain. Key to Diane’s success has been her ability to understand and incorporate various risk management frameworks, such as the National Institute of Standards and Technology’s Cybersecurity Framework, with other key frameworks, including sustainability, business continuity, cyber security, and third party risk management programmes designed to address specific risks while strengthening enterprise-wide operational resilience. Diane’s career in leading enterprise risk, operational risk, and business continuity management has spanned over 20 years, and includes positions at Putnam Investments, Bank of America/ Columbia Management, and State Street Global Advisors. In 2011, she was recruited to develop and implement the Operational Risk programme, including business continuity management, for the Abu Dhabi Investment Authority. Diane is a founding member of the DRI Foundation’s Women in Business Continuity Management Committee, serving as Chair for five years. In 2020, she received the DRI Foundation’s Distinguished Service Award; in 2022, she was invited to join the DRI International Board of Directors.
Citation
Doering, Diane (2026, August 6). Does strong risk management necessarily lead to improved resilience?. In the Journal of Business Continuity & Emergency Planning, Volume 20, Issue 1. https://doi.org/10.69554/KQGA9473.Publications LLP