Managing Complex System Risk

At Red Strokes Consulting we believe in looking at enduring challenges in new and different ways to provide innovative solutions that work. We believe relying on outdated methodologies, originally designed for simple systems yet applied to increasingly more complex systems, is an exercise in futility.

The risk management approaches that dominate businesses and board rooms simply do not respect what is needed to actually manage risk in a modern environment defined by complexity and uncertainty.

Modern operating environments need an approach that respects contemporary business complexity, but aids in transparency, visibility and decision making at all levels. Complex system risk management is our solution.

How is our model different?

Our approach to managing risk in complex systems is different to the prevailing guesswork methodologies applied across business. And it is significantly more effective in providing insights into performance, identifying weaknesses in the management system, and supporting effective decision making. We look to the parts of the management system that already exist, or perhaps don’t yet exist, to apply system control and in doing so, suppress the chances of the undesired risk event from happening.

If we set up a business management system to achieve success, it stands to reason any risk to achieving that outcome will come from, or be a result of, the management system controls not performing to expectations. Our approach seeks to understand, measure and optimise the performance of the management system controls rather than add more steps for busy people to manage.

Risk is everywhere. Risk does not go away. It is important to manage the environment that leads to the most critical undesirable outcome, or risk event, as a priority. We work with clients to identify the core risk events that businesses are looking to manage and help to understand how the management system is structured and performing to provide the confidence that the risk event can be avoided.

Likelihood and consequence are not metrics. In fact, they are guesses. Risk ratings offer nothing more than a way to colour code the outcome of those guesses. We implement ways to assess, measure and report on the existence, health and performance of the existing management system controls to provide defencible metrics that enable confidence and decision making.

Our approach is built on the foundations of known concepts to create a unique approach that is effective and simple to manage.

Using knowledge of system engineering, we rely on the management control system as the basis for risk suppression, measurement and transparency. Where the control system fails, we look to identify and fix the failure, not add controls to the system.

To manage a system, we only need to identify and focus on the control or controls whose ineffectiveness may increase the chance of a risk event happening, either because the control doesn’t exist, is not effective or is not being used.

A basic visualisation of the relationship between risk sources, risk events, consequences and controls enables simplified management of the system, rather than individual risk line items.

Understanding that complex systems cannot be defined by known cause and effect relationships means we can categorise and apply better techniques to manage risk in a contemporary business environment. Applying the lessons from the Cynefin Framework (Snowden), we can start to manage beyond simple cause and effect relationships.

Download our
Complex System Risk Management Playbook

We know industries are wedded to the old ways of risk management, primarily because there are precious few alternate options. We know moving away from the norm is scary and you probably need more information. So we developed this playbook to walk you through a little more detail on the theories, methodology and application.

Reach out if you want to shift to manage your system to suppress risk impact, rather than simply admire risks.