r/riskmanager

Interested in moving into risk management. What should I prioritize?

I have a background working with the NFIP and currently work in insurance claims. I’m interested in eventually moving into risk management and would appreciate some advice from people already working in the field.

I’m currently working toward my AINS designation and am considering getting my P&C license next. After that, I’ve been looking at the ARM designation, but I’m open to other suggestions.

For someone with my background, what would you prioritize over the next year or two to make the transition into risk management? Are there particular designations, skills, or types of roles I should be targeting to help bridge the gap from claims into risk?

reddit.com
u/Due-Midnight-1320 — 4 days ago

Do you have an opinion on Organisational risk visibility?

Ever feel like you’re only allowed to see 10% of the actual risk picture? Or maybe you ONLY need that 10%?

I'm researching how risk information actually flows (or gets intentionally hidden) across organisations. This 100% anonymous survey digs into silos, restricted access, and the danger of not knowing what the team next door is dealing with.

I love to hear your feedback for an academic paper I'm writing

u/a-calculated-risk — 6 days ago
▲ 1 r/riskmanager+1 crossposts

Does your governance connect the organisation, or simply govern each function?

I've been exploring organisational silos over the past few weeks, and one question keeps emerging:

If organisations need specialist functions, how do we ensure those functions still operate as one enterprise?

Removing silos isn't realistic. Specialisation creates expertise, accountability and scale.

The governance challenge is making sure those boundaries don't also become boundaries for information, ownership and decision-making.

This becomes particularly important when outcomes cross several functions. Putting multiple functional reports into the same board pack may create visibility, but it doesn't necessarily create a coherent enterprise view.

I've explored this through three forms of connectivity: information, accountability and decisions.

I'd be interested in how others approach this.

What mechanisms in your organisation genuinely connect functional perspectives before enterprise decisions are made?

u/Aevitium — 7 days ago

How to analyze operational risks/develop operational risk management methodology

We have a methodology for information security risk management but none for operational risks management. I have less than a month to adapt our current methodology to also include operational risks. Is that feasible?

I have no idea how to start with operational risks management. I know that it should be done for processes and services but I have very limited knowledge of the company's processes and services. Information security has been a little easier bc we can use catalogues of threats and vulnerabilities from iso 27000 that we apply to assets. But I can't find anything similar for operational risks and I don't know what to do. Is it supposed to be scenario based analysis rather than asset based analyis, as it is done for information security risks?

Also I know the general steps of risk identification, analysis (impact probability and evaluation), treatment (transfer, reeducation, avoidance, acceptance) and monitoring. For me the biggest challenge is identification I suppose - actually coming up with the risks for the processes. Are there any resources that can help to formulate scenarios or something like that?

If anyone can give me some guidance, any help would be hugely appreciated. I am extremely stressed and struggling a lot.

Edit: thanks a lot for the suggestions. I will use them as much as I can. I have one more week to write the methodology. It seems management either wants trash or has no idea what's going on. I don't have a lot of experience but this sounds unreasonable to me.

reddit.com
u/majima1234 — 8 days ago

Risk mgmt is a lie?

I love risk mgmt BUT how much value really brings? I worked for highly regulated and tech, for reference, and I feel risk mgmt is the mean to nothing. Trapped between the low hanging fruit of isolated and atomic issues, in general, with low impact vs glorified macro risk categories that are reading tea leaves. Is anybody proud pf any risk they managed or fully remediated (aka reduced) that you feel proud about?

reddit.com
u/Flat-Primary-255 — 11 days ago

Career switch into ERM…

Currently I work as an EHS Manager for a manufacturing company. Have been in a manger role the last 3 years and have been in EHS for 8 years. I like EHS because I like the mitigation/control side but lately I have been contemplating if it’s what I want to do for the rest of my career (30 years old). I have a Masters in Safety/Security/and Emergency Management and am currently studying for my CSP. But I’ve been reading up on ERM lately and have been wondering if it is a logical switch and how might I go about it? I’ve even been looking into some graduate programs but kind of iffy on that. Any thoughts/advice is greatly appreciated.

Also - currently making 135k a year with a 10% bonus… if I were to make a switch, what might that look like initially from a compensation perspective.

reddit.com
u/Buckeyes4431 — 8 days ago