operational risk Archives -

Why Risk Management Frameworks Are Failing — And How to Fix Them

Most organisations have risk management frameworks. Very few have risk management frameworks that actually work under operational pressure. The gap between the two is where regulatory penalties, reputational damage, and business disruption live.

In 2026, enterprise risk management is facing a perfect storm: increasingly complex multi-jurisdictional regulatory requirements, faster-moving threat landscapes, and boards demanding more granular visibility into risk exposure than ever before. Against this backdrop, compliance programmes built on legacy structures — outdated policies, siloed risk functions, and reactive mindsets — are simply no longer adequate.

At Baretzky & Partners LLP, we deliver comprehensive risk management programmes designed to identify, assess, and mitigate enterprise-wide exposures — from operational and regulatory risk through to reputational and cyber risk — across 116 countries. Our certified practitioners design bespoke compliance frameworks aligned with ISO 31000, COSO ERM, and sector-specific regulatory requirements, combining deep jurisdictional knowledge with practical implementation experience.

The Four Pillars of Effective Enterprise Risk Management

Effective enterprise risk management is not a single programme — it is an integrated system of interconnected capabilities. Organisations that treat risk management as a box-ticking exercise will find their frameworks failing precisely when they are most needed. Those that build genuine capability across four core areas are positioned to manage risk proactively, demonstrate compliance effectively, and recover rapidly when disruptions occur.

1. Enterprise Risk Framework Design

The foundation of effective risk management is a properly designed risk architecture. This means more than a risk register — it encompasses governance structures, risk appetite statements, escalation protocols, and board-level reporting frameworks that give senior leadership genuine visibility into risk exposure.

Critical components include risk appetite and tolerance frameworks that translate abstract board-level risk tolerance into operational parameters; three lines of defence models that clearly delineate the responsibilities of business functions, risk and compliance, and internal audit; and governance structure design that ensures risk ownership is clearly assigned and accountability mechanisms are functioning.

Without this architectural foundation, even the most sophisticated risk identification processes will generate insights that cannot be effectively acted upon.

2. Compliance Programme Development

Compliance programmes must be built for the regulatory environment organisations actually face — not the one that existed when the programme was last updated. In 2026, this means addressing a dramatically expanded regulatory landscape covering GDPR, DORA (Digital Operational Resilience Act), the EU AI Act, ESG disclosure requirements, and continued expansion of AML and sanctions obligations.

Effective compliance programme development starts with regulatory gap analysis — a systematic assessment of where the organisation’s current policies and procedures fall short of applicable requirements. From this foundation, policy and procedure drafting, cross-jurisdictional mapping, and compliance training programmes can be built on a solid evidential basis rather than assumption.

PCI security compliance, GDPR and data protection obligations, and sector-specific requirements all demand specific attention. Multi-jurisdictional organisations face the additional challenge of reconciling conflicting regulatory requirements — an area where specialist advisory is particularly valuable.

3. Operational and Third-Party Risk Assessment

Some of the most significant risk exposures facing organisations in 2026 are not internal — they sit in the supply chain, in third-party relationships, and in the complex ecosystem of vendors, partners, and counterparties that modern businesses depend on.

Comprehensive operational risk assessment covers internal process vulnerabilities, technology dependencies, and human factors. Third-party due diligence extends this assessment to the organisation’s external relationships — identifying where concentration risk, compliance gaps, or integrity issues in the supply chain could create exposure.

Business continuity planning completes this picture, ensuring that when disruptions occur — whether from operational failures, cyber incidents, regulatory actions, or external shocks — the organisation has tested, credible plans to maintain critical functions and recover effectively.

4. Regulatory Response and Remediation

No compliance programme is perfect, and regulatory inquiries, enforcement actions, and compliance gaps are an inevitable feature of operating in complex regulated environments. When they occur, the quality of the response is as important as the underlying compliance posture.

Effective regulatory response requires rapid assessment of the scope of the issue, transparent and well-structured communication with regulators, and a credible remediation programme that addresses root causes rather than symptoms. Our team supports organisations through regulatory inquiries and enforcement actions — providing regulator liaison expertise, remediation programme management, and the specialist advisory needed to minimise exposure and restore compliance standing as efficiently as possible.

ISO 31000 and COSO ERM: The International Standards Framework

Two frameworks dominate enterprise risk management practice internationally: ISO 31000 and the COSO Enterprise Risk Management Framework. Understanding both — and knowing when to apply which — is fundamental to building programmes that satisfy regulatory expectations while delivering genuine operational value.

ISO 31000:2018 provides principles and guidelines for risk management applicable to any organisation, regardless of sector or size. Its strength is its universality and its focus on integrating risk management into organisational processes and decision-making at every level. For organisations seeking a risk management standard that is recognised globally and applicable across jurisdictions, ISO 31000 is the benchmark.

The COSO ERM Framework (2017 update) integrates enterprise risk management with strategy and performance, emphasising the connection between risk appetite and strategic objectives. Its five components — governance and culture, strategy and objective-setting, performance, review and revision, and information, communication and reporting — provide a structured approach particularly suited to larger organisations with complex governance structures.

Our practitioners are experienced in both frameworks and advise on their application based on organisational context, regulatory requirements, and existing risk infrastructure.

The DORA Challenge: Digital Operational Resilience in Financial Services

For organisations in the financial services sector, the Digital Operational Resilience Act (DORA) represents the most significant new compliance obligation of the current regulatory cycle. In force since January 2025, DORA requires financial entities — including banks, investment firms, insurance companies, and crypto-asset service providers — to implement comprehensive digital operational resilience frameworks covering ICT risk management, incident reporting, operational resilience testing, and third-party ICT risk management.

DORA’s requirements are prescriptive and demanding. ICT risk management frameworks must be documented, tested, and subject to independent review. Significant ICT-related incidents must be reported to competent authorities within defined timeframes. Digital operational resilience testing — including advanced threat-led penetration testing for significant institutions — must be conducted on a regular basis.

Third-party ICT risk management under DORA is particularly significant, as it extends compliance obligations beyond the regulated firm to its critical third-party service providers — creating a new dimension of supply chain risk management that many organisations are still working to address.

Building a Risk Culture That Sustains Compliance

Technical compliance frameworks are necessary but insufficient. Organisations that sustain genuine compliance over time are those that have built a risk culture — where risk awareness is embedded in decision-making at every level, where escalation of concerns is encouraged rather than discouraged, and where the tone from the top communicates genuine commitment to compliance rather than performative adherence.

Building this culture requires more than training programmes, although training is an important component. It requires governance structures that give risk and compliance genuine authority, incentive frameworks that do not reward short-term performance at the expense of risk management, and leadership that models the behaviours it expects from the organisation.

Our risk management advisory includes assessment of organisational risk culture — identifying where cultural barriers to effective risk management exist and advising on the interventions needed to address them.

When to Engage a Risk Management Specialist

Organisations typically engage specialist risk management advisory in several circumstances: when facing a new regulatory requirement that existing capabilities cannot address; when a regulatory inquiry or enforcement action has identified compliance gaps; when entering new markets or jurisdictions that require unfamiliar compliance frameworks; or when an internal review has identified that the existing risk programme is not functioning as intended.

In all of these situations, early engagement is advantageous. The earlier specialist advisory is engaged, the more options are available — whether that means building a compliance programme before a regulatory deadline, engaging proactively with a regulator before an inquiry becomes adversarial, or addressing a compliance gap before it escalates into an enforcement issue.

Baretzky & Partners: Risk Management Across 116 Countries

Our risk management practice combines global reach with local expertise. With coverage across 116 countries and 25+ years of experience in enterprise risk management, our certified practitioners deliver programmes that are not only technically sound but practically implementable in the jurisdictions and sectors where our clients operate.

We work with organisations across financial services, professional services, technology, energy, and government sectors — designing and implementing risk frameworks that meet regulatory requirements while delivering genuine operational value.

Contact Baretzky & Partners LLP to request a risk assessment or discuss your compliance programme needs. Initial consultations are strictly confidential, and our team can deliver a remediation roadmap within days of engagement.

Baretzky & Partners LLP provides strategic risk mitigation, legal affairs and crisis mitigation, and international information policy and compliance specialist counsel. We do not provide litigation services. All investigative services are provided by our European offices only.