← University
Building an Enterprise Risk Framework
0 of 6

A regional non-profit organization in southern Alberta that provides employment training and supportive housing services has operated for 22 years, growing from a small charitable initiative into an organization with an annual operating budget of $4.8 million, 47 full-time staff, and 3 service locations across 2 municipalities. The organization holds service contracts with 2 provincial ministries, receives funding from 4 corporate donors and a community foundation, and maintains a portfolio of 6 residential properties that house program participants. Its board of directors consists of 9 volunteer members drawn from the local business, legal, and social services communities.

During a board governance review conducted in response to concerns raised by the organization's external auditor, directors discovered that risk management across the organization existed in disconnected pockets with no coordinating structure. The finance team maintained a spreadsheet tracking accounts receivable aging and cash flow projections. The housing program manager kept an informal log of building maintenance issues and tenant complaints. The human resources coordinator had developed a checklist for workplace safety incidents. The information technology contractor who visited twice monthly had flagged cybersecurity vulnerabilities in 3 separate reports over 18 months without receiving a formal response from management. None of these activities connected to one another, to the organization's strategic plan, or to regular board deliberations.

The governance review also revealed that 2 of the organization's ministry contracts contained new provisions requiring funded agencies to demonstrate formalized risk management practices by the next contract renewal period, now 14 months away. The board chair, a retired manufacturing executive, recalled that the company where she had spent her career had implemented an enterprise risk management framework after a supply chain crisis, but she was uncertain how such an approach would translate to a non-profit context with different stakeholders, funding structures, and accountability relationships.

The executive director, who had led the organization for 8 years, acknowledged that risk conversations tended to arise only after problems materialized rather than through any systematic anticipation. A recent incident illustrated the point: a data breach affecting 340 client records had prompted a reactive scramble rather than an execution of pre-established protocols, because no such protocols existed. Staff members in different departments had responded based on their own judgment, with inconsistent messaging to affected clients and no clear escalation path to the board.

The board directed the executive director to develop a proposal for implementing an enterprise-wide approach to risk management, with attention to available frameworks, governance structures, resource requirements, and the cultural changes necessary to embed risk awareness throughout the organization.

Building a Risk-Aware Culture: The Human Dimension of Enterprise Risk

Risk management, at its core, is not a technical discipline but a human one. While the previous lessons in this course have examined the structural and procedural elements of enterprise risk frameworks, the mechanics of identification, assessment, mitigation, and monitoring, this final lesson turns to what determines whether any framework actually works in practice: the people who must understand it, believe in it, and live it every day. An enterprise risk framework exists only on paper until it becomes embedded in the beliefs, behaviours, and decisions of everyone within an organization. This human dimension represents both the greatest challenge and the greatest opportunity in risk management, because even the most sophisticated framework will fail if the organizational culture resists it, ignores it, or treats it as someone else's responsibility.

The concept of risk-aware culture has gained significant attention in Canadian regulatory and professional standards over the past decade. The Canadian Securities Administrators, through National Instrument 52-109 on Certification of Disclosure in Issuers' Annual and Interim Filings, as of the date of authorship, requires that certifying officers establish and maintain disclosure controls and internal control over financial reporting, obligations that cannot be met without embedding risk awareness throughout an organization's financial reporting chain. Similarly, the Office of the Superintendent of Financial Institutions has emphasized in its Corporate Governance Guideline that federally regulated financial institutions must foster a risk culture that supports adherence to established risk appetite and policies. While these specific requirements apply to publicly traded issuers and regulated financial institutions respectively, the underlying principle resonates across all organizational types: risk management effectiveness depends fundamentally on how people think about and respond to risk in their daily work.

A risk-aware culture is one in which employees at every level understand that managing risk is part of their job, feel comfortable raising concerns about potential risks without fear of reprisal, and possess the knowledge and authority to make appropriate risk decisions within their spheres of responsibility. This definition immediately reveals why building such a culture is challenging. It requires alignment across multiple dimensions: individual attitudes, team dynamics, management behaviours, organizational policies, incentive structures, and communication practices. Each of these dimensions can either reinforce or undermine the others. An organization that publicly celebrates risk awareness while privately punishing those who raise uncomfortable concerns will quickly find that employees learn to keep quiet regardless of what the formal policies say.

The foundation of risk-aware culture lies in what organizational psychologists call psychological safety, the belief that one can speak up with questions, concerns, or mistakes without being humiliated or punished. Canadian workplaces have increasingly recognized the importance of this concept, particularly following amendments to occupational health and safety legislation across provinces that now require employers to address workplace psychological hazards alongside physical ones. In British Columbia, Alberta, Saskatchewan, Manitoba, Ontario, and most other common law provinces, occupational health and safety statutes have been amended in recent years to explicitly include mental health and psychological safety within the scope of employer duties. Quebec's approach, shaped by its civil law tradition under the Act respecting occupational health and safety and provisions of the Civil Code of Quebec relating to employer obligations, similarly encompasses psychological dimensions of workplace safety, though the legislative framework differs in structure and interpretation. The practical implication is that fostering an environment where employees feel safe to identify and report risks is not merely good management practice but increasingly a legal expectation across Canadian jurisdictions.

Understanding how risk culture operates in practice requires examining how organizations actually make decisions under conditions of uncertainty. Every organization faces a continuous stream of situations where employees must choose between competing priorities, often without explicit guidance from formal policies. A project manager deciding whether to delay a deliverable to address a newly discovered quality concern, a sales representative considering whether to disclose a product limitation that might cost a sale, a maintenance technician choosing between a quick fix and a thorough repair, these daily decisions collectively determine an organization's actual risk posture far more than any written framework. The question for organizational leaders is what influences these decisions when no one is watching.

Research consistently shows that employees take their cues primarily from what they observe in leadership behaviour and what they see being rewarded or punished within the organization. Formal policies matter, but they matter less than the informal signals that leaders send through their actions, their questions, their allocation of attention, and their responses to problems. When leaders consistently ask about risks alongside results, when they respond to bad news with curiosity rather than anger, when they publicly acknowledge their own mistakes and uncertainties, they create conditions in which risk awareness can flourish. Conversely, when leaders focus exclusively on short-term results, when they shoot the messenger who brings unwelcome information, when they project an image of infallibility, they teach employees that risk awareness is dangerous to one's career regardless of what the risk management policy might say.

The challenge is particularly acute in organizations where strong performance pressure exists alongside significant risk exposure. Resource extraction operations in Alberta and British Columbia, construction projects in Ontario and Quebec, healthcare delivery across all provinces, these sectors combine demanding productivity targets with the potential for serious harm if risks are not properly managed. Employees in these environments often face implicit or explicit pressure to cut corners, skip steps, or ignore warning signs in order to meet deadlines or budgets. Building a risk-aware culture in such contexts requires more than exhortation; it requires fundamentally aligning incentive structures, performance metrics, and management practices with the organization's stated commitment to risk management.

Consider the situation faced by a medium-sized environmental consulting firm based in Calgary with projects across Western Canada. The firm had grown rapidly over a five-year period, expanding from eighteen employees to nearly seventy while taking on increasingly complex remediation and assessment projects for clients in the oil and gas sector. The partners prided themselves on their technical excellence and had invested significantly in staff training, quality management systems, and professional development. They had also developed a comprehensive enterprise risk framework that identified professional liability, regulatory compliance, project execution, and environmental safety as key risk categories, with detailed policies and procedures for each. On paper, the firm appeared to have a mature approach to risk management.

In practice, however, the firm's culture had evolved in ways that undermined its risk framework. The rapid growth had created intense competition for advancement among mid-level staff, with project profitability serving as the primary metric for performance evaluation and bonus allocation. Senior associates who delivered projects under budget and ahead of schedule received promotions and public recognition at firm meetings. Those whose projects ran over budget or behind schedule, regardless of the reason, found themselves passed over and sometimes quietly managed out. The message employees received was clear: deliver results, whatever it takes.

This dynamic created predictable problems. Junior staff felt unable to push back when clients made scope changes without corresponding budget adjustments. Site supervisors underreported the time required for safety documentation because it made their projects look less efficient. Field technicians occasionally skipped sampling protocols that seemed redundant, reasoning that the client would never know and that meeting the deadline was what really mattered. Senior associates, aware of at least some of these shortcuts, tacitly tolerated them because confronting the behaviour would have required acknowledging problems they would then own. The risk framework's provisions for quality control and safety compliance existed in the firm's management system, but they had become dead letters.

The problems came to light in late February 2024 when a regulatory audit by the Alberta Energy Regulator identified significant deficiencies in the documentation and sampling procedures for a major remediation project the firm had completed the previous year. The client, a major pipeline operator, immediately suspended all work with the firm pending investigation. Three other clients followed suit within days. The Alberta Energy Regulator opened a broader investigation into the firm's practices across multiple projects. The professional regulatory bodies governing the engineers and geoscientists employed by the firm requested explanations that could lead to disciplinary proceedings. Insurance counsel advised that coverage for the emerging claims was uncertain given the nature of the alleged deficiencies.

What followed was a painful eighteen-month period during which the firm lost approximately forty percent of its workforce, replaced two of its four partners, settled claims totalling more than $1.8 million in excess of insurance coverage, and faced professional discipline proceedings that resulted in practice restrictions for several individuals. The direct financial impact was severe, but the reputational damage proved even more consequential. Several long-standing client relationships proved impossible to rebuild. Recruiting became difficult as word spread within the industry. The firm's most talented employees, those with the strongest external options, left for competitors perceived as more professionally rigorous.

The implications of this scenario extend far beyond the specifics of environmental consulting. The firm had not failed for lack of a risk framework. Its framework was detailed, professionally prepared, and covered all the relevant risk categories. The failure occurred because the framework existed separately from the culture that actually drove behaviour. The incentive structure rewarded short-term results without regard to how those results were achieved. Leadership behaviours reinforced this emphasis on results while paying only superficial attention to process compliance. Employees rationally concluded that the real expectations differed from the written expectations and adapted their behaviour accordingly. The risk framework became a ceremonial document rather than a living guide to practice.

The scenario also illustrates how risk culture problems tend to remain hidden until a triggering event brings them into view. The concerning behaviours had developed gradually over several years, normalized through repetition and mutual tolerance. No single decision seemed catastrophic at the moment it was made. The cumulative effect, however, was to create an organization operating far outside its stated risk appetite without any of its leaders fully appreciating this reality. The regulatory audit served as the triggering event, but it could just as easily have been a serious environmental incident, a whistleblower complaint, or a client's internal audit. The underlying vulnerability existed regardless of which specific event exposed it.

Building a genuinely risk-aware culture requires attention to several interconnected elements that reinforce each other when properly aligned. The first element is clarity of expectations, ensuring that employees understand what the organization expects of them regarding risk management in terms specific enough to guide actual decisions. Generic statements that employees should act prudently or exercise good judgment provide little practical guidance. More useful are explicit statements about acceptable and unacceptable practices, decision-making authority at different levels, required escalation pathways for particular types of concerns, and the circumstances under which schedule or budget considerations should yield to risk management considerations.

The second element involves alignment of incentives and performance management with stated risk expectations. Organizations must examine whether their reward structures, promotion criteria, performance metrics, and management practices actually reinforce the risk behaviours they claim to value. This examination often reveals uncomfortable misalignments. A non-profit organization that claims to value careful stewardship of donor funds while rewarding program managers primarily for growth and visibility should not be surprised when program managers take risks with donor funds to achieve growth. A construction company that claims to prioritize safety while paying bonuses based on project completion time should not be surprised when supervisors pressure crews to work in unsafe conditions. Aligning incentives with risk expectations requires genuine willingness to reward risk-aware behaviour even when it costs short-term results.

The third element concerns leadership behaviour and tone. Employees observe leaders closely and calibrate their own behaviour based on what they see. Leaders who wish to build risk-aware cultures must model the behaviours they seek, which means asking about risks as routinely as asking about results, responding to problems with genuine curiosity about causes rather than blame, acknowledging uncertainty and mistakes in their own decisions, and visibly participating in risk management activities rather than delegating them entirely. This modelling function cannot be outsourced or performed insincerely. Employees are skilled at detecting the difference between leaders who genuinely care about risk management and those who merely perform concern for appearance.

The fourth element involves creating effective channels for risk information to flow through the organization. Formal reporting systems matter, but informal communication patterns often matter more. Employees must believe that raising concerns will be taken seriously and will not damage their careers. They must see evidence that concerns raised by others have been addressed appropriately. They must trust that confidential concerns will remain confidential. Building this belief requires consistent action over time. Organizations that want employees to report concerns must demonstrate through repeated experience that doing so is safe and effective.

The fifth element addresses training and capability building. Risk-aware behaviour requires not only willingness but ability. Employees need to understand the specific risks relevant to their roles, the organization's approach to managing those risks, their authority and responsibility within that approach, and the practical skills needed to identify, assess, and respond to risks they encounter. This training must be ongoing rather than one-time, role-specific rather than generic, and integrated with operational practices rather than treated as a separate compliance exercise.

The sixth element concerns organizational learning, the processes by which organizations identify lessons from experience and incorporate them into improved practices. Near-misses, incidents, audit findings, complaints, and other risk events provide valuable information about vulnerabilities in risk management systems. Organizations that effectively capture and analyse this information, share lessons across units, and modify practices accordingly strengthen their risk management over time. Organizations that treat each event as an isolated incident, fail to look for patterns, or resist changing established practices in light of new information remain vulnerable to recurring problems.

Practical application of these principles begins with honest assessment of current culture. Leaders should ask themselves and trusted colleagues a series of probing questions. When was the last time an employee raised a concern that prevented a significant problem? If such instances are rare, why might that be? What happens to people who bring bad news? What do the organization's actual reward and promotion patterns reveal about what is truly valued? Do managers at all levels actively participate in risk management activities, or is this function siloed in a compliance or quality department? Do employees believe that stated policies reflect genuine expectations, or do they perceive a gap between formal requirements and real expectations?

Gathering this information requires multiple approaches. Formal employee surveys can provide useful data if designed thoughtfully and if employees trust that responses are genuinely anonymous. Focus groups and skip-level conversations can surface concerns that might not emerge through formal channels. Exit interviews with departing employees often yield candid assessments that current employees hesitate to provide. External perspectives, from auditors, consultants, board members, or trusted advisors, can identify blind spots that internal observers miss. The goal is to develop an accurate picture of how risk management actually functions in the organization, not merely how it is supposed to function according to formal documentation.

Once assessment reveals gaps between current culture and desired culture, leaders face the challenging work of culture change. This work is inherently long-term. Culture reflects deeply embedded patterns of belief and behaviour that developed over years and will not transform quickly regardless of leadership intent. Sustainable culture change requires consistent effort sustained over multiple years, patience with incremental progress, and resistance to declaring premature victory. Organizations that announce cultural transformations and then move on to other priorities typically find that old patterns reassert themselves once attention wanes.

Effective culture change efforts combine symbolic actions with substantive changes to systems and practices. Symbolic actions, such as leadership statements, revised value statements, recognition ceremonies, and visible executive participation in risk activities, signal priorities and begin shifting perceptions. Substantive changes, such as modified incentive structures, revised performance metrics, new reporting channels, and altered promotion criteria, reshape the practical calculations employees make when deciding how to behave. Neither symbolic nor substantive actions alone typically produce lasting change. Symbols without substance breed cynicism. Substance without symbols fails to engage emotion and identity. The combination, consistently maintained over time, creates the conditions for genuine cultural evolution.

Organizations should also consider how to sustain risk-aware culture during periods of stress. Economic downturns, competitive pressures, leadership transitions, and organizational crises all tend to pressure risk standards. The temptation to cut corners increases when resources are scarce and stakes are high. Yet these moments of stress are precisely when risk awareness matters most. Organizations that maintain their risk disciplines during difficult periods often emerge stronger, while those that sacrifice standards for short-term survival frequently create problems that prove more damaging than the original stressor. Building resilience into risk culture means preparing for these stress tests, discussing in advance how the organization will maintain standards under pressure, and creating accountability mechanisms that function even when attention is divided.

The human dimension of enterprise risk ultimately determines whether risk management adds value or merely adds bureaucracy. Organizations that successfully embed risk awareness into their cultures gain genuine competitive advantage: they identify threats earlier, respond more effectively when problems arise, maintain stakeholder trust through demonstrated reliability, and avoid the catastrophic failures that can destroy years of organizational progress. The investment in culture building pays returns not through any single dramatic event but through the accumulation of countless better decisions made by employees who understand risk, feel empowered to manage it, and believe their organization genuinely values their doing so. This cultural foundation, invisible in organizational charts and policy manuals, represents the essential human infrastructure on which all other risk management depends.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options