Edit Content

ABOUT

The 4th Edition of G[P]RC Summit, hosted by Corporater, is the world’s largest summit on GPRC: GRC integrated with Performance and Strategy – bringing together C-level executives, GRC experts, and industry and academia professionals from across the world to share insights, innovative solutions, and best practices needed to drive organisational success and resilience in an increasingly complex and interconnected business environment. This year’s summit will be centred around the theme of “Driving Success: Integrating GRC with Strategy Execution in a Hyperconnected World"

G[P]RC Summit is an exclusive, invitation-only, two-day event hosted in Dubai, UAE from 26 — 27 August 2026, in Johannesburg from 10 — 11 November 2026, in Riyadh, KSA from 26 — 27 January 2027.

Contact us

Host Partner

Risk & Strategy: A Marriage Made in Heaven — Or Are They Still Living Separate Lives?

In theory, risk and strategy should be inseparable. One defines the organisation’s direction, while the other helps ensure that direction is sustainable, resilient, informed, and able to withstand uncertainty. Together, they should form one of the most important strategic partnerships within any enterprise.

Yet in many organisations today, risk and strategy continue to operate as though they are still living separate lives.

In my view, risk and strategy should absolutely work together — but they should not become one and the same. As in any successful marriage, both must remain aligned while preserving their own independence, objectivity, and integrity.

Strategy should not compromise the independence of risk management, and risk management should not dictate strategy. Both functions should operate independently — yet collaboratively — challenging, informing, and strengthening one another without imposing on or undermining each other’s roles. Another important issue organisations should carefully consider is the growing tendency in some institutions for strategy functions to gradually absorb or assume risk-management responsibilities, under the belief that strategic capability alone is sufficient to manage enterprise risk. In reality, while strategy and risk must work closely together, they should never become substitutes for one another.

Strategy teams are designed to drive growth, transformation, competitiveness, and strategic ambition. Risk management, however, requires a distinct set of competencies, methodologies, perspectives, governance disciplines, and capabilities for independent challenge that extend far beyond strategic planning alone.

The ability to identify, assess, quantify, challenge, monitor, and continuously evaluate enterprise-wide risk exposure requires specialised expertise and an independent mindset that should not be diluted within broader strategic or commercial objectives.

When risk management loses its independence or becomes fully absorbed into strategy functions, organisations may unintentionally weaken objective challenge, reduce governance effectiveness, create blind spots, and increase the likelihood of overly optimistic decision-making.

The strongest organisations are therefore not those where strategy replaces risk management — but those where both functions operate independently, respectfully challenge one another, and collectively support leadership in making informed, balanced, and sustainable decisions. Ultimately, leadership — particularly the CEO, executive management, and the Board — must remain the final decision-makers, balancing growth, opportunity, resilience, sustainability, and risk appetite. The CEO plays a critical role in ensuring that such practices are implemented within the organisation. This is where organisational culture is defined and respected.

However, one of the most common weaknesses I continue to observe across organisations is that risk functions are often not sufficiently informed, consulted, or engaged early enough in key strategic and operational decisions.

Too frequently:

  • strategic shifts occur without timely risk involvement,
  • management changes priorities or execution approaches without adequate risk consultation,
  • short-term strategic decisions evolve rapidly outside formal risk discussions,
  • and risk teams only become aware of critical developments after implementation has already begun

By that stage, valuable opportunities for informed challenge, scenario analysis, mitigation planning, strategy reshaping, resilience assessment, and strategic optimisation may already have been missed. This is not because organisations intentionally exclude risk. Rather, many leadership teams continue to perceive risk management primarily as:

  • a control function,
  • a compliance requirement,
  • or in some cases, a potential “showstopper.”

As a result, when management reaches critical crossroads involving:

  • expansion,
  • transformation,
  • major investments,
  • acquisitions,
  • restructuring,
  • partnerships,
  • technology change,
  • or accelerated growth initiatives,

Risk is often consulted too late — or not sufficiently at all. In reality, mature risk management should never exist simply to prevent ‘risk-taking’. The purpose of effective risk management is not to eliminate risk entirely. It is to enable informed, balanced, intelligent, and sustainable risk-taking. Organisations cannot grow, innovate, transform, or create value without taking risks. The role of risk management is therefore not to stop progress, but to help organisations:

  • understand risk and opportunity,
  • quantify exposure,
  • evaluate alternatives,
  • strengthen resilience,
  • anticipate consequences,
  • and make better-informed decisions.

In many ways, risk management should act as a strategic enabler rather than a strategic obstacle.

If risk only says “no,” it is not truly contributing to enterprise success. Likewise, if management avoids risk because it fears challenge or delay, the organisation loses an important layer of strategic intelligence and decision support.

This raises numerous important questions that organisations rarely ask themselves openly:

  • Why is risk management often absent from key executive and Board discussions?
  • Why are Chief Risk Officers (CRO) not consistently invited into strategic management conversations early enough?
  • Why do some Boards engage extensively with finance, strategy, operations, and audit – yet interact only minimally with the CRO unless there is a crisis, regulatory issue, or formal risk report presentation?
  • And perhaps more importantly: Why do some Boards and executives still hesitate to openly challenge, question, or engage the CRO as part of strategic decision-making discussions?

The reality is that in many organisations, the CRO remains structurally present — but strategically underutilised. Risk management is sometimes viewed as a reporting layer rather than a strategic intelligence function capable of contributing to:

  • strategic foresight,
  • resilience planning,
  • investment decision-making,
  • operational sustainability,
  • scenario analysis,
  • and long-term value protection.

When risk management is excluded from strategic discussions, organisations may unintentionally weaken:

  • decision quality,
  • resilience visibility,
  • strategic challenge,
  • governance effectiveness,
  • and enterprise preparedness.

The healthiest organisations are those where:

  • management actively seeks independent risk perspectives,
  • the CRO is viewed as a trusted strategic advisor rather than an obstacle. the CEO should have close relationships with the CRO and can hold deep discussions in confidence.
  • Boards openly engage with risk leadership, such engagement should not limited to the board committee.
  • constructive challenge is encouraged,
  • and risk-informed decision-making becomes embedded across the enterprise.

In truly mature organisations, risk-based thinking becomes visible across:

  • strategic planning,
  • investment decisions,
  • operational processes,
  • governance frameworks,
  • Board and management papers,
  • transformation initiatives,
  • capital allocation,
  • Human capital management (HCM),
  • performance management,
  • and executive decision-making.

Risk management should not exist in isolation within risk registers, committees, or reporting packs. It should become part of how the organisation thinks, governs, prioritises, and operates every day.

At Aquilae Consulting LLC, we believe organisations increasingly require integrated governance models in which strategy, risk intelligence, operational resilience, and executive decision-making operate in alignment — while preserving the independence and objectivity necessary for effective governance. The objective is not simply risk mitigation.

The objective is informed decision-making, sustainable growth, operational resilience, and long-term value creation. Perhaps the real question organisations should ask themselves today is not whether they have both a strategy function and a risk function. But whether both are genuinely working together — independently yet collaboratively — to build long-term enterprise success. Are risk and strategy truly aligned in your organisation? Or are they still living separate lives?

At Aquilae Consulting LLC, we also recognise that many organisations continue to navigate important questions about the evolving roles of risk management, Board engagement, strategic alignment, and risk-informed decision-making.

As part of our advisory services, the firm offers exclusive online “Majlis”1 sessions designed for Boards, executive management, risk leaders, and strategic decision- makers. These sessions aim to provide a deeper practical and strategic understanding of how organisations can build dynamic, forward-looking risk management functions that support:

  • better decision-making,
  • stronger governance,
  • strategic resilience,
  • intelligent risk-taking,
  • operational sustainability,
  • and long-term value creation.

The objective is to move risk management beyond traditional reporting and compliance frameworks toward becoming a trusted strategic partner within the enterprise.

About the Author:

Susan Daniel

CEO, Aquilae Consulting LLC, UAE