Chapter SixBuilding a Risk Culture

The test in the real world is how competent the organization’s risk management practices are, and the degree to which [an organization is] instilling risk management behaviors into its culture and management’s decision-making [process]. In short, how mature is the company’s enterprise risk management program and how thorough are its practices at all levels of the organization?

—Risk & Insurance Management Society (RIMS), 2009

When one ponders how an organizational culture is changed, it is important to keep these few words in mind: “Culture change is hard, slow, and subject to frequent relapse.”1 The reality of this statement is designed not to discourage, but rather to equip one with the knowledge and ...

Get Enterprise Risk Management: A Guide for Government Professionals now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.