Issue 11·6 min read·Board Members  ·  C-Suite  ·  Senior Risk Leaders
This week: A risk owner is held accountable for a control failure. The control sat in a different function’s budget and reporting line. She had accountability, not authority. Why risk registers assign ownership without checking whether owners can act. The accountability-authority matrix. One ownership audit.
01THE SIGNAL

Sharp. Not sentimental.

She Was Accountable for the Failure. She Had No Authority to Prevent It.

A compliance incident at a financial services firm traced back to a control failure in the data handling process. The risk owner, a senior risk manager, was named in the postmortem. She had been listed as the owner of that risk for two years.

What the postmortem also established: the control sat within the IT function’s budget and reporting line. She had no authority to change it, upgrade it, or direct anyone to test it. She had raised concerns about its adequacy six months earlier. The concerns had been noted. Nothing had changed.

She was accountable for a risk she couldn’t manage. The ownership assignment in the register had created the appearance of accountability without giving her the means to exercise it.

The incident happened. She carried the consequence. The authority gap that made the incident possible was never named in the postmortem.

02THE PATTERN

Honest. Not accusatory.

Risk Ownership Is Assigned at the Register Level Without Checking Whether the Owner Can Act.

Risk registers are populated under pressure. Risk identification exercises are time-bound. Someone must be named as owner before the workshop closes. The nearest senior person in the relevant function gets the assignment.

What rarely gets asked: does this person have the authority to change the control, reallocate the resource, or direct the remediation if the risk materialises? In many cases, the honest answer is no. The owner has visibility. They have reporting obligations. They don’t have authority.

This is one of the most common governance failures in risk management, and one of the least discussed. Because it only becomes visible when something goes wrong and someone asks who was supposed to prevent it.

Accountability without authority isn’t governance. It’s liability without power.

The fix isn’t to remove accountability from risk owners. It’s to check, at the point of assignment, whether the owner can actually exercise it. And where they can’t, to name the authority gap explicitly and decide how to close it.

03THE MODEL

Simple. Not simplistic.

The Accountability-Authority Matrix: Three Questions Every Risk Ownership Assignment Needs.

Before a risk ownership assignment is finalised, three questions should be answered. They take five minutes to ask. The answers determine whether the assignment is real or nominal.

QUESTIONWHAT A REAL ASSIGNMENT LOOKS LIKEWHAT A NOMINAL ASSIGNMENT LOOKS LIKE
Does the owner control the primary control for this risk?Yes. The control sits within their budget and reporting line, or they have a documented authority to direct it.No. The control sits in a different function. The owner can flag concerns but cannot direct remediation.
Can the owner accept or reject the residual position?Yes. Within their defined threshold, they can decide to hold or escalate the risk without seeking approval from another function.No. Any decision to accept or change the position requires sign-off from a function they don’t report to.
Is the owner named in the escalation pathway for this risk?Yes. If the risk moves, they receive the first notification and have the authority to act before escalating upward.No. The escalation pathway routes around them, or they appear on a distribution list without a decision role.

A risk owner who fails all three questions is a nominally accountable person. They carry the name in the register. They don’t carry the authority the accountability implies. That distinction matters when the risk materialises.

04THE MOVE

Practical. Not obvious.

Audit Three Risk Ownerships for Real Authority.

Pick three material risks from your register. For each named owner, run the three questions above.

For each owner: do they control the primary control? Can they accept the residual position? Are they in the escalation pathway with decision authority? Count how many pass all three.

If all three pass, the ownership assignments are real. That’s a stronger governance position than most registers achieve.

If any fail, you’ve found nominal accountability. The next question is: who actually has the authority the owner lacks, and does that person know they have it?

05THE INVITATION

Open. Not pushy.

SELF-ASSESSMENT

The Decision Infrastructure Self-Assessment

The ownership link is one of four mapped in this assessment. It surfaces exactly the accountability-authority gap described in this issue and provides a structured diagnostic for the full governance chain.

Access here →
DIAGNOSTIC SESSION

Book a 45-Minute Decision Architecture Conversation

If the ownership audit found nominal assignments, the diagnostic session maps what real accountability looks like in your governance structure and how to convert nominal assignments to functional ones.

Book a diagnostic session →

That’s The Decision Layer for this week.

The accountability-authority gap is the governance failure that postmortems rarely name, because naming it requires acknowledging that the ownership structure was broken before the incident.

Forward this to any risk leader who has ever been listed as the owner of a risk they couldn’t actually manage. They’ll recognise the situation immediately.