Objectless Risk Management: Why 90% of Corporate Risk Systems Fail
The Foundation: What Risk Actually Is
Risk is the potential for negative consequences arising from completed — and therefore past — “incorrect” actions. Not an abstraction. Not a “possible event.” But precisely the consequence of a specific managerial decision made in the past.
From this follows a rigid conclusion: objectless risk management does not exist.
It is impossible to effectively manage “potential” without measuring, collecting, and systematizing what is being done “incorrectly.” This is where the absolute hopelessness of most risk management projects lies — regardless of what they “stand on”: mathematical forecasting, machine learning, neural networks, or fashionable frameworks.
There is no universal approach. All these tools are meaningless if reproduced without connection to deep domain knowledge. Typically, “risk experts” do not know the nuances of activity at the execution level. And only the executor can assess risks — and only they decide whether to take the risk or not.
The Luxury of an Error Management System
Is it worth spending time and capital on building a system of potential errors?
Before answering, one must understand: is there a primary system of correct actions? Is it implemented? Does it work?
The “luxury” of creating an error management system and preliminary assessment of consequences can only be afforded by those who have a clearly established system of correct actions. Otherwise, risk management is an attempt to implement the idea of “how to make everything work, but without consequences for anything.” This is always the shadow side. Sometimes — an attempt to deal with something that is solved in a completely different way.
Four Levels of Risk Management Application
Risk management is not a universal tool. It is a discipline applied at different levels of processes, with different objectives and different depths.
Level 1. Pre-Investment Identification: To Enter or Not to Enter the Project
This is the level of the Go / No-Go decision. Here, risk management performs the function of a filter:
- Does the asset match the investor’s strategy?
- What hidden liabilities may emerge after the deal closes?
- What is the real jurisdictional, tax, and reputational burden?
- Are there non-obvious risks of counterparties, beneficiaries, or the regulatory environment?
At this level, risk management is capital protection against entering a dangerous asset. Its result is not a report, but a decision: “we enter / we do not enter / we enter under condition X.”
Level 2. Project Development Stage: Preventing Cash Gaps and Structural Failures
Here, risk management works as an engineering discipline:
- Have all cash flow stages been accounted for until the project reaches self-sufficiency?
- Will the attraction of debt capital lead to a shortage of working capital in 6–12 months?
- Does the financing structure match the real dynamics of the project?
- Are there buffers for delays in permits, logistics, or construction?
At this level, risk management is preventing a situation where the project is technically successful but financially dead.
Level 3. Investment Period: Operational Asset Management
After entering the project, risk management becomes a daily operational function:
- Monitoring deviations from the business plan.
- Controlling the fulfillment of obligations by counterparties.
- Managing currency, interest rate, and commodity risks.
- Responding to changes in the regulatory environment.
Here, risk management is keeping the project within the boundaries of the targeted return.
Level 4. Exit from Investment
At the exit stage, risk management addresses:
- How to minimize the tax consequences of the sale.
- How to avoid disclosure of deal terms before closing.
- How to protect reputation and assets from the buyer’s post-closing claims.
- How to structure the transfer of rights and obligations.
Here, risk management is protecting the result of all previous work.
Global Risk Management Models
International practice has several established models. Each is a product of its own legal, economic, and cultural environment.
Model | Country / Region | Scope of Application |
COSO ERM (Enterprise Risk Management — Integrated Framework) | USA, global | Corporate governance, public companies |
ISO 31000:2018 | International standard (EU, Australia, Asia, Middle East) | Universal standard for any organization |
Basel III / Basel IV | Global (Basel Committee) | Banking sector, credit and market risk management |
Solvency II | European Union | Insurance industry |
PMI PMBOK — Risk Management | USA, global | Project management |
M_oR (Management of Risk) | United Kingdom (AXELOS) | Public sector, infrastructure projects |
FAIR (Factor Analysis of Information Risk) | USA | Cyber risks, information security |
NIST RMF | USA | Public sector, critical infrastructure, IT |
FERMA Standards | European Union | Corporate risk management in the EU |
ICH Q9 (Quality Risk Management) | Global (FDA, EMA) | Pharmaceuticals, biotechnology |
Orange Book / HM Treasury Guidelines | United Kingdom | Public sector risk management |
None of these models is “universal.” Each works only in connection with deep domain knowledge and the maturity of the primary system of correct actions within the organization.
The Key Principle
Risk management is not a separate function. It is a mirror of business maturity.
If a company does not have a clear system of correct actions — no risk model will save it. It will only create an illusion of control, behind which real damage will accumulate.
Conversely, where the primary system of processes is built, risk management becomes a precise tool for protecting capital, reputation, and business value.
Scope of Application
Risk management is applied where there is:
- An investment decision (entry / exit / restructuring).
- Project activity (construction, development, product launch).
- Operational activity with a high cost of error.
- Attraction of debt or equity capital.
- Entry into new markets and jurisdictions.
The goal of any risk management is not “to avoid everything.” The goal is to make risks conscious, measurable, and manageable.
Conclusion
Objectless risk management is impossible. But subject-based risk management is one of the most expensive and in-demand competencies in modern business.
Companies that build risk management not as a “report for the board of directors,” but as a decision-making tool at every level of processes, gain a sustainable competitive advantage. They do not avoid risks — they choose which ones to take, and they do so consciously.
ALLTERRA GROUP
Expert support for investment and operational projects. Risk identification at the start. Deal structuring. Risk management at all stages of the project life cycle.

