David Tattam, co-founder of Protecht, recently gave one of his final presentations after 27 years spent sharpening one idea: intelligent risk-taking is an asset.
His message at the Gartner Enterprise Risk, Audit & Compliance Conference 2026, hosted Sept. 15-16 in Grapevine, Texas, was a challenge to risk leaders to consider the role their function plays in the organization. Does risk management primarily document and constrain activity? Or does it give people the knowledge they need to make better decisions?
In David’s terms, are you the Department of No or the Department of Know?
Two departments
The Department of No stops things. The Department of Know understands risk well enough to help the organization proceed with confidence.
Much of what passes for risk management can drift toward what Dan North called “risk management theatre:” registers, heat maps and reports that demonstrate activity without materially informing decisions.
David’s argument is that the value of risk management should be measured by what happens next. Does the information change a decision? Does it prompt action? Does it help someone understand uncertainty well enough to pursue an objective?
If it does, risk management becomes an enabler.
A risk is not its consequence
David illustrates the distinction with a story from his own life. Years ago, he was considering taking up hang gliding. When asked about the risk, his initial answer was simple: dying. A friend pointed out that dying was a consequence, not the risk itself.
The actual risks included things such as equipment failure, misjudged conditions and inadequate training. Those risks had causes. And if the causes could be understood, they could be controlled.
Using bow tie analysis, David eventually developed a 44-point control checklist that brought the risk within his appetite. He went on to fly for 15 years.
The lesson extends well beyond hang gliding. Understanding the consequence tells you what you are trying to avoid. Understanding the risk, its causes and the effectiveness of your controls gives you information you can use.
Once David understood the risk, he could say yes.
Two tests for every decision.
David's decision rule is simple:
-
Can I? Is the risk within appetite? If it is not, decline or add controls until it is.
-
Should I? Does the reward exceed the risk? Proceed only if it does.
Risk functions can become overly focused on the first question and stop at a negative answer. Yet bringing risk within appetite only tells us whether an activity is permissible. It does not tell us whether it is worth doing.
That second question reconnects risk management with the reason the organization is taking risk in the first place.
Risk management is outcome management.
ISO 31000 defines risk as the effect of uncertainty on objectives, and that effect can be positive or negative.
David takes that definition seriously.
If risk is about uncertainty affecting objectives, risk management needs to begin with those objectives. From there, organizations can consider the operating model and strategic initiatives required to achieve them, followed by the uncertainty that could affect those outcomes.
In that sense, David argues that risk management is really outcome management. It starts with objectives, moves to the operating model and strategic projects that deliver them, and only then identifies the risks that could derail either. A function organized this way is seen by the front line as helping it achieve its goals.
That changes the relationship between the risk function and the front line. Risk management becomes part of helping people achieve what the organization set out to accomplish.
From risk data to risk intelligence.
For GRC to support those decisions, David argues that its information needs three characteristics.
It must be comprehensive, bringing together the risks and activities that matter.
It must be connected, using common taxonomies and relationships so individual pieces of data can become meaningful intelligence.
And it must be continuous, because information that was accurate when an assessment was completed may no longer describe the risk when a decision has to be made.
This is where the distinction between risk data and risk intelligence becomes important.
More information does not automatically create better decisions. The value comes from knowing something relevant that you did not know before, while there is still time to act on it.
That is also central to what we mean at Protecht by Risk in Motion. Risk changes as controls change, incidents occur, business conditions evolve and new information emerges. GRC needs to keep that picture current enough to support the next decision.
Third-party risk puts the idea to the test.
In the same Gartner session, VISO TRUST co-founder Paul Valente applied these principles to third-party risk management. (About Protecht and VISO TRUST.)
Third-party risk makes the challenge particularly visible. Vendor ecosystems change. New evidence emerges. Exposure evolves over the course of a relationship.
A thorough assessment has limited value if the information it produces arrives too late or no longer represents the vendor when the business needs to make a decision.
AI-enabled analysis, current evidence and continuous monitoring can help make that knowledge available sooner and keep it current as conditions change.
The purpose is bigger than completing an assessment. It is reducing uncertainty so someone can make a better-informed decision about the third party.
That is the Department of Know in practice.
Risk information has to move at the speed of the decision.
The same principle applies across enterprise risk.
An incident can change a risk profile. A control can deteriorate. A KRI can cross an appetite threshold. A new vendor can introduce an exposure that connects cyber risk with operational, compliance or strategic risk.
Each produces another piece of information. Its value depends on whether the organization can connect it to the broader risk picture and put it in front of the people who can act.
Risk management therefore has to do more than record what has happened. It should help monitor the outcomes of previous decisions, identify when circumstances have changed and provide the intelligence needed for the next one.
That is how the risk function earns its place in the decision-making process.
Four questions for risk leaders.
David closed with a self-assessment that every risk leader should run:
- Is risk management valued in your organization?
-
Is it linked directly to objectives?
-
Is it timely, or merely historical?
-
Does it prompt and change decisions?
The last question may be the most important.
If risk information does not influence what the organization does, David would argue that much of the activity risks becoming risk management theatre.
The answer is unlikely to be another report.
It is better risk knowledge: comprehensive enough to see the whole picture, connected enough to understand what it means, and current enough to act on it.
That is how a risk function moves from the Department of No to the Department of Know.
With thanks to David Tattam for nearly three decades of making risk management clearer for the rest of us.
Continue exploring:
Risk in Motion: A Guide to Continuous Risk Management
Risk Appetite For Dummies, co-authored by David Tattam with Wiley publishing.
The CRO's Guide to Risk Management Success
Read more insights on risk management by David Tattam.
