Part of the series Leading Through Turbulence.
What separates the companies a crisis surprises from the companies a crisis merely tests?
The reputation of risk management deserves an honest hearing first, because it is poor and often earned. In many organisations the risk register is a spreadsheet that wakes twice a year, shortly before the audit, receives some fresh dates and returns to its sleep. The matrix on page four of the board pack has shown the same traffic lights for three years. Treated this way, risk management is paperwork about misfortune, and executives are right to give it little time.
Sailors run the discipline differently, and they compress it into one of the oldest rules of seamanship: reef when you first think of it. The sail is shortened while shortening it is still easy, on a suspicion, before the weather makes the argument. The work happens ahead of the storm, which is precisely the point of it. Earlier articles in this series built the watch that reads the weather and the craft of deciding when the sky stays unclear. This article covers the discipline that keeps the boat out of trouble in the first place, and ready for the trouble that comes anyway: the structured look at what could go wrong, what it would cost, and what is done about it before anyone is wet.

Figure 1. The whole system on one page. A risk named, priced, treated and owned is a risk that has lost most of its power to surprise.
The work itself
Stripped of its jargon, risk management is a structured conversation about the current situation, held before the situation forces one. The internal side of the ledger covers the state of the business: liquidity, key people, concentration on customers and suppliers, the age of the technology, the health of the order book. The external side covers the world the business floats in: markets, regulation, interest rates, geopolitics, and the dependencies the previous articles taught the organisation to scan. For each material risk, the conversation produces four things: an estimate of how likely it is, an estimate of what it would cost, the preventive measures that make it less likely, and the mitigating measures that make it survivable once it occurs. Each risk gets a named owner and a review date, and the whole exercise repeats on a rhythm.
The structure of that conversation is well settled. ISO 31000, the international standard, describes the loop of identifying, analysing, evaluating and treating risks inside a defined context, with communication and review wrapped around it. Robert Kaplan and Anette Mikes added the most useful sorting logic in their Harvard Business Review framework: preventable risks from inside the organisation deserve rules and controls, strategy risks are taken deliberately in pursuit of return and deserve open discussion, and external risks lie beyond influence and deserve scenario work. The categories matter because each one asks for a different treatment, and because the second category makes an often forgotten point in plain sight. Some risks are supposed to be taken. Frank Knight drew the underlying line a century ago in Risk, Uncertainty and Profit: risk is measurable and can be priced, while genuine uncertainty is neither, and profit is the reward for facing what cannot be insured. The list and the matrix work on the first kind. The second kind is met with the buffers and the decision craft of the earlier articles.
What this means for you
- Hold the structured conversation on a fixed rhythm, and refuse to let the audit calendar own it.
- Sort every risk into preventable, strategic or external, and treat each category on its own terms.
- Give every material risk a named owner, two kinds of measures and a review date.
The matrix
The risk matrix is the most familiar picture in the discipline: probability on one axis, impact on the other, and a colour field from green to red that turns a list into a landscape. Used honestly, it does two jobs well. It forces an explicit estimate where vague worry lived before, and it concentrates the attention of a leadership team on the upper right corner, where likelihood and damage meet.
The tool’s weakness deserves naming, because pretending it away is itself a risk. Tony Cox showed in his much-cited paper What’s Wrong with Risk Matrices? that ordinal scales compress very different risks into the same cell, that colour boundaries are arbitrary, and that a matrix can rank a worse risk below a milder one. The conclusion for practice is moderation rather than abandonment. The matrix is a triage and conversation tool, and it earns its place as one. For the few risks that reach the red zone, the organisation moves beyond the colours and works with numbers: expected loss, scenario calculations, and the cost of the countermeasures against the damage they prevent. Colour for the many, arithmetic for the few.

Figure 2. The landscape view. The matrix earns its keep as a triage and conversation tool, and the red corner earns real arithmetic.
What this means for you
- Use the matrix to force explicit estimates and to focus the room on the red corner.
- Quantify the red-zone risks individually, in money and scenarios, beyond the colour code.
- Revisit the plotted positions on every review, because risks drift while registers sleep.
The two dividends
The return on all this structure arrives in two forms, and both arrive precisely when the weather turns. The first dividend is recognition speed. An organisation that has thought about a risk recognises its early form, because the pattern is already in the building. The scanning from earlier in this series tells a leadership team that something is moving. The risk work tells it what that movement means, because the scenario has a name, an owner and a file. The second dividend is immediate capability. Where a plan exists, the first days of a crisis are execution instead of improvisation, and the leadership decides from a prepared position with the calm that preparation buys. The crisis still costs, but it costs the planned amount, and it meets a team that knows its first three moves.
Both dividends were on public display in the spring of 2000, in the most instructive risk case European industry has produced. On 17 March, lightning caused a ten-minute fire in a Philips semiconductor plant in Albuquerque. The flames were out before the fire brigade arrived, and nobody was hurt, but smoke and sprinkler dust contaminated millions of radio-frequency chips in the clean rooms. Philips estimated a week of lost production and informed its two largest customers for those chips, Nokia and Ericsson, both of which were preparing new phone generations.
Nokia’s system reacted before Nokia’s executives did. The company tracked incoming component flows on a near daily rhythm, and the anomaly surfaced within days. Nokia treated the one-week estimate as a scenario rather than a promise, put the case on executive agendas, sent people to the plant, locked up alternative capacity at other suppliers across the world and re-engineered chips so that other fabs could produce them. When the week became months, Nokia’s production barely stumbled, and its profits rose that year. Ericsson took the estimate at face value. The first report reached a middle manager and travelled no further, the escalation arrived weeks late, and by the time the company sought alternative capacity, Nokia had bought it. Ericsson put its losses at around 400 million dollars, reported a 16 billion kronor loss in its handset division for the year, and folded its phone business into a joint venture soon after. One fire, two systems, and the difference was made before the lightning struck.
For an owner or an entrepreneur, the same structure pays a third dividend on top. A written risk picture turns risk appetite into an actual decision. Resources are placed deliberately, the risks taken are taken on purpose and at a known price, and the risks declined are declined consciously. That is the difference between running a risk and being run by one.
What this means for you
- Treat supplier estimates, and all comforting first reports, as scenarios to test rather than promises to file.
- Make sure bad news travels upwards faster than good news, and reward the messenger.
- Decide your risk appetite in writing, so that the risks you carry are the ones you chose.
Four answers to any risk
Once a risk is named and priced, the treatment menu is short. Every risk response in every framework comes down to four moves, with a fifth for the risks that point upwards.
The first answer is avoidance: the activity is changed or dropped so the risk disappears, as when a business declines a customer whose payment behaviour would dominate its receivables, or exits a market whose legal ground keeps shifting. The second is reduction, the workhorse of the list: preventive measures cut the probability, mitigating measures cut the damage, and Nokia’s multi-sourcing is the textbook case of a mitigation that was worth a decade of its cost. The third is transfer: insurance, hedging and contract design move the financial consequence to a party paid to carry it, which is why currency exposure lives in forwards and why force-majeure and liability clauses are risk instruments in legal dress. The fourth is acceptance, the honest residual: the risk is carried knowingly, with a margin sized to it. Roald Amundsen remains the standard-bearer of disciplined acceptance. He could avoid neither weather nor ice on the way to the South Pole, so he carried supplies at multiples of the calculated need and marked his depots for miles across the line of march, while Scott ran on thin margins and paid the full price. Jim Collins and Morten Hansen later measured the same behaviour in companies and called it productive paranoia: the leaders who win in turbulence carry buffers that look excessive in calm years and turn out to be the price of survival.
The fifth answer applies to positive risks, and David Hillson has spent a career reminding the discipline that opportunity is risk with a plus sign. The same logic that prepares for a supplier failure can prepare for a demand surge: capacity options, prepared hiring pipelines, and financing lines agreed before they are needed. A company that plans only its downsides will be surprised by its upsides, and surprise is expensive in both directions.

Figure 3. The whole treatment menu. Four answers to any threat, a fifth for the risks that point upwards.
What this means for you
- Choose one of the five answers explicitly for every material risk, because an unchosen answer is acceptance by accident.
- Size the buffers on accepted risks deliberately, and defend them in good years.
- Plan the upside scenarios with the same discipline, so that opportunity meets prepared capacity.
Who sits at the table
Risk management fails most often as an organisational question, and the failure pattern is always the same: everyone in general is responsible, so nobody in particular is. The remedy is a small set of named roles, and the Three Lines Model of the Institute of Internal Auditors describes the accepted division of labour.
Owners and the supervisory board set the frame. They decide the risk appetite, the amount and kind of risk the company is in business to take, and they oversee whether management stays inside it. Management owns the risks and the system: the executive level answers for the whole picture, and each material risk has one named risk owner who answers for its measures. A coordinator, in larger organisations a risk manager or the controller, runs the process, keeps the list honest and the rhythm alive, and consolidates the picture for board and supervisory board. Internal audit, where it exists, gives independent assurance that the system works as described rather than as hoped. And the wider organisation is the sensor network, which only functions where reporting a risk is treated as a contribution. Ericsson’s fire report died in the middle layer of exactly this network. Nokia’s survived because the escalation path was short, known and used.

Figure 4. Nobody in particular is the enemy. The roles that make a risk system real, after the Three Lines Model of the IIA.
What this means for you
- Put the risk appetite where it belongs, with the owners and the supervisory board, in one written sentence per risk class.
- Name one risk owner per material risk, and let the coordinator run the process instead of owning the risks.
- Shorten the path a bad report travels, and check it occasionally with a real case.
What the law expects
Company law in this legal space treats parts of this craft as a duty. What follows is an orientation for Germany and Austria, without any claim to completeness, and it is no substitute for legal advice in the individual case.
In Germany, the anchor stands in stock corporation law. Section 91 of the Aktiengesetz, covered in an earlier article of this series, obliges the management board to run a monitoring system that recognises developments endangering the company’s existence early. Since 2021 the StaRUG extends the core of that duty well beyond the stock corporation: the managing directors of every entity with limited liability, the GmbH included, must continuously monitor for developments that could endanger the company as a going concern, take countermeasures when they appear, and report to the supervisory organs where such organs exist. Alongside the systems duty runs a reporting duty. Under section 90 of the Aktiengesetz the management board reports to the supervisory board on intended policy, profitability and the course of business on a fixed rhythm, and immediately on important occasions. The annual management report adds public disclosure: section 289 of the Handelsgesetzbuch requires a description of the expected development with its material opportunities and risks. Where an audit committee exists, section 107 of the Aktiengesetz assigns it the monitoring of the effectiveness of the internal control system, the risk management system and the internal audit function.
Austrian law runs parallel. Under section 81 of the Aktiengesetz the management board owes the supervisory board an annual report on fundamental questions of future business policy, quarterly reports on the course of business, and immediate special reports on important occasions, expressly including circumstances significant for the company’s profitability or liquidity. Section 82 of the same act obliges the board to run an accounting system and an internal control system that meet the requirements of the company, and section 22 of the GmbH-Gesetz places the equivalent duty on the managing directors of the GmbH. The management report under section 243 of the Unternehmensgesetzbuch must describe the material risks and uncertainties the company faces, and for companies with an audit committee, section 92 of the Aktiengesetz includes the monitoring of the effectiveness of the internal control and risk management systems among its tasks.
Read together, the statutes describe the article so far: a system that watches, a list that names, owners who answer, and reports that reach the supervisory level at a defined rhythm and immediately when it matters. The law, once again, codifies the craft.
What this means for you
- Check which duties reach your legal form, because the German early-warning duty now covers every limited-liability entity.
- Align the internal reporting rhythm with the statutory one, so that one system serves both.
- Document the system and its reviews, because in any later dispute the file is the evidence that the duty was met.
What a smaller company should still do
None of this requires a risk department, and the law no longer treats it as a large-company subject either, since the German early-warning duty applies to every GmbH. The owner-managed company runs the same discipline at one page of scale.
An afternoon each quarter produces and refreshes the one-page list: the ten risks that matter, each with a probability, a damage estimate, its measures and a name. The matrix is drawn on the same page, and the red corner gets an hour of real arithmetic. The two dividends weigh more at small scale, since thin buffers shorten the time a surprised company survives, and the third dividend weighs most of all, because in an owner-managed business the risk appetite and the owner’s private exposure are the same number. The Nokia lesson costs nothing to copy: know your critical dependencies, decide today what you would do if the most important one failed tomorrow, and make sure the person who hears of it first knows who to call.
What this means for you
- Keep the whole system on one page, refreshed each quarter, with ten risks and ten names.
- Spend the real analysis on the red corner and on your single most critical dependency.
- Write down your risk appetite as the owner, because your balance sheet is the buffer.
Why the reef comes first
So, what separates the companies a crisis surprises from the companies a crisis merely tests?
The separation is made in calm weather. A company that holds the structured conversation knows its situation before events ask. A company that sorts and prices its risks spends its attention where the damage would be, and takes the risks it takes on purpose. A company that has chosen a treatment for every material risk begins a crisis with execution instead of shock, and a company that has named its owners and shortened its reporting paths hears the lightning while the other side is still reading the first reassuring estimate. A company that knows what the law expects has its duties and its evidence in the same file. And a company that plans its upsides greets the good surprise with prepared capacity.
None of this removes the storm. The fire in Albuquerque was the same event for both companies: the same ten minutes, the same supplier, the same missing chips. The outcomes parted because of what the event found on arrival. The discipline decides what the storm finds when it arrives, and that is the quiet meaning of the old rule. Reefing early is what optimism looks like when it has done its homework.
The prepared company also grows differently in rough weather, because crises reprice entire markets and reward whoever kept the capacity to act. Growing through a crisis is a craft of its own, and the next article in this series takes it up.
Further reading
Main Literature
- ISO 31000: Risk management, Guidelines, International Organization for Standardization (2018)
- Robert S. Kaplan & Anette Mikes: Managing Risks: A New Framework, Harvard Business Review (2012)
- Frank H. Knight: Risk, Uncertainty and Profit, Houghton Mifflin (1921)
- Louis Anthony Cox: What’s Wrong with Risk Matrices?, Risk Analysis (2008)
- David Hillson: Effective Opportunity Management for Projects, Marcel Dekker (2004)
Cases and evidence
- Almar Latour: Trial by Fire: A Blaze in Albuquerque Sets Off Major Crisis for Cell-Phone Giants, The Wall Street Journal (29 January 2001)
- Jan Husdal: Ericsson versus Nokia, the now classic case of supply chain disruption, husdal.com (2008)
- Yossi Sheffi: The Resilient Enterprise: Overcoming Vulnerability for Competitive Advantage, MIT Press (2005)
- Jim Collins & Morten T. Hansen: Great by Choice, Harper Business (2011)
- Daniel Kahneman & Dan Lovallo: Delusions of Success: How Optimism Undermines Executives’ Decisions, Harvard Business Review (2003)
Roles and governance
- The Institute of Internal Auditors: The IIA’s Three Lines Model, Position Paper (2020)
Law (orientation, no completeness, no legal advice)
- Aktiengesetz, Sections 90, 91 and 107, Germany
- StaRUG, Section 1: crisis early recognition and crisis management, Germany (in force since 2021)
- Handelsgesetzbuch, Section 289: management report, Germany
- Aktiengesetz, Sections 81, 82 and 92, Austria
- GmbH-Gesetz, Section 22, Austria
- Unternehmensgesetzbuch, Section 243: management report, Austria

