Mark Elbadramany

Concentration, Reversibility, Detection: Three Questions for Any Risk on the Agenda

A person's hands hold a smartphone displaying colorful candlestick trading charts in front of a blurred monitor showing similar financial graphs.
A person's hands hold a smartphone displaying colorful candlestick trading charts in front of a blurred monitor showing similar financial graphs.

Most risk discussions I have sat through end with a colour. The item is amber. It was amber last quarter. Someone notes that it may go green by year end, the minutes record that the board reviewed it, and we move on. The colour has done no work at all. It is a summary of two guesses — likelihood and impact — dressed up as an output, and it tells a director nothing about what to do next.

I have come to rely on three questions instead, and I ask them of every item, whether it is a cyber exposure, a customer concentration, a key-person dependency or a regulatory filing. How concentrated is this? How reversible is it? How quickly would we know? Board risk oversight gets sharper the moment the conversation moves off probability and onto those three. The habit came from sitting on both company boards and non-profit ones — I chair Berkeley Florida, the Cal alumni community here in the state — and noticing that the same three questions worked in rooms with wildly different budgets and stakes.

Why the heat map fails a director

Likelihood and impact are the wrong axes for a board, not because they are useless but because management is already better at them than we are. The operating team knows the base rates. They know how often the system has gone down, how often a customer has churned, how a similar filing was handled last time. If the board's contribution is to second-guess an estimate the executives are closer to, we are adding friction rather than judgement.

There is a second problem. A heat map treats each row as independent. Real risk is rarely independent. The same weather event that closes your facilities also depresses demand in the market you serve, delays your receivables, and distracts the two people who would otherwise be running the response. On a grid those appear as four amber squares. In reality they are one red one.

So the three questions are deliberately chosen to be things a board can answer better than management can, because they are structural rather than predictive. You do not need to know how likely something is to know how far it would travel, how hard it would be to undo, and how long it would sit undiscovered.

Concentration: what else is attached to this?

Concentration is not size. A large exposure that is genuinely isolated is a manageable problem. A modest exposure that touches six other things is not. The useful question is not "how big is this?" but "what else fails when this does?"

Customer concentration is the version everyone can see, and even that is usually understated. Boards look at the largest account by revenue and stop there. The harder look is at shared fate: three customers who look independent on the schedule but sell into the same end market, buy through the same channel, or are financed by the same lender. I have argued elsewhere that choosing which customers not to serve is one of the few decisions that changes a company's risk profile permanently, and concentration is exactly why. The composition of the revenue base is a governance question, not just a commercial one.

The same test applies well beyond customers. One person who holds an undocumented system. One bank relationship. One certification that gates the whole product line. One geography that carries operations and demand at once. My practical version of this question, and I ask management to answer it directly, is: name the single failure that would put a mark against the most lines of our risk register. That answer is almost never the item currently coloured red. It is usually something that sounds mundane — a vendor, a login, a person's judgement — precisely because it is embedded everywhere rather than concentrated anywhere visible.

Reversibility: what does it cost to undo?

The second question separates decisions the company can walk back from decisions it cannot. This is the one that most changes how a board allocates its own attention, because it argues for spending time on low-probability items that heat maps quietly demote.

A cheaply reversible risk should be taken quickly and delegated fully. If we can try something, see the result, and unwind it within a quarter for a known cost, the board's job is to make sure the unwinding is genuinely available — not to debate the trial. Where boards add value is at the one-way doors: acquisitions, long leases, the abandonment of a product line, the release of a public commitment, an irreversible change to the capital structure. Those deserve disproportionate time even when everyone agrees the downside is unlikely, because the price of being wrong is not paid in money, it is paid in optionality.

Two things about reversibility are easy to miss. The first is that it decays. A decision that could be reversed in month one often cannot be in month twelve, once systems, staffing and customer expectations have set around it. So the honest question is not "is this reversible?" but "for how long, and what is the last moment we could still change course?" Put a date on it and the item becomes governable.

The second is that reversibility is asymmetric across categories. Money lost can be re-earned. Trust cannot be re-earned on the same schedule. Reputational damage and damage to the standing of a brand in search results and public conversation do not unwind at the rate the finance team assumes, and they rarely unwind on the same trajectory they arrived. Treating a reputational exposure as if it were a cash exposure of equivalent size is one of the more common errors I see in enterprise risk management frameworks.

Detection: how long would this sit unnoticed?

The third question is the one I have grown most insistent about, because detection lag is what converts a manageable problem into a crisis. Nearly every governance failure I can think of shares a structure: the underlying event was survivable, and the delay between the event and anyone senior knowing about it was not.

Some risks announce themselves. A lawsuit arrives. A customer resigns the account in writing. Those need less board attention than their severity suggests, because the alarm is built in. The dangerous items are the quiet ones — margin drift, a control that stopped being performed, a security intrusion, a culture problem in a division nobody visits, an accounting treatment that made sense once. Each of these can run for a long time while every report still reads normal.

So I ask for the shortest honest description of the detection mechanism. If the answer is "management would tell us," that is reporting, not detection. Reporting depends on someone noticing, interpreting, and choosing to escalate news that reflects on their own performance. Real detection is independent of that person: a threshold that trips, a reconciliation someone else performs, a customer conversation a director has directly, an external review on a schedule nobody controls internally. This is also why so much of the work happens outside the meeting itself — I have written before about what a board actually does between the meetings, and building independent lines of sight is most of it.

There is a limit worth respecting. Detection that fires constantly gets ignored, and a board that demands an alert for everything will be told about nothing. The goal is a small number of tripwires set where the three questions overlap.

Reading the three together

Individually the questions are useful. Together they rank the register. The item that is concentrated, irreversible and slow to detect is the one that ends organisations, and it very often sits mid-table in amber because its probability looks modest. The item that is isolated, cheap to undo and immediately visible can be handed to management with a note, however alarming it looks.

That second direction matters as much as the first. Most boards do not suffer from missing risks so much as from spending their scarce hours on the ones already well handled. Applying the framework in reverse gives you permission to stop discussing things — and permission to stop is rarer, and more valuable, than another item added to the watch list.

The framework also travels. It works on a small non-profit board with no committee structure, and it works in a company where the audit committee has done the detailed work already. That portability is the point of keeping it to three questions rather than thirty. A director who cannot hold the framework in their head will not use it under pressure, and pressure is the only time it matters.

The questions you keep asking

Before I accept a board seat I ask to observe a meeting, and part of what I am listening for is whether questions like these get asked at all — or whether the room accepts colours as answers. It tells you more about the governance culture than any charter document will. A board that habitually asks what else is attached, what it costs to undo, and how long it would sit unnoticed is a board that has decided its job is judgement rather than review. The same instinct shows up in chairing something you do not run, where the only real authority you have is the quality of the questions you keep putting on the table.

None of this requires a new framework document, a consultant, or another quarterly template. It requires three questions asked consistently enough that management starts answering them before we ask. That is the version of risk oversight worth having: not a register we review, but a set of habits that make us harder to surprise.