I stopped believing that risk management was about avoiding disaster

Institutional Strategy

I stopped believing risk management was about avoiding disaster

Why we choose the historical circumstance over the documented liability, and the cost of the “99% buffer.”

In , a man named Silas Thorne, a low-level clerk in the London Port Authority, kept a ledger of every rotting timber in the West India Docks. For , Thorne’s reports were impeccably drafted, bound in calfskin, and filed with a precision that bordered on the religious.

He documented the slow, aqueous rot of the foundation piles with the devotion of a hagiographer, yet not a single piece of wood was ever replaced. The authority’s charter required that any structural intervention over five pounds be preceded by a multi-departmental survey of the entire pier system, a process so prohibitively expensive and legally fraught that it was cheaper-and certainly safer for one’s career-to simply watch the wood turn to pulp and record the observation in a very expensive book.

The Quarter-Century Roll-Forward

I spent most of last Tuesday looking at a risk register entry that has been reviewed quarterly since . It concerns an unsupported servicing platform-a piece of software that effectively acts as the nervous system for a commercial lending portfolio. The entry is rated “High.”

The mitigation column, written in that peculiar, bloodless corporate dialect, describes “vendor extended support arrangements” and “enhanced monitoring.” Beside it sits the change proposal that would actually solve the problem. The proposal requires an architecture review, a third-party security assessment, a comprehensive Data Protection Impact Assessment (DPIA), and ultimately, board approval for a multi-year capital expenditure.

11

Times Rolled Forward

The risk register entry has been rolled forward eleven times, becoming a historical artifact rather than a call to action.

There is a specific, low-grade torture in watching a project buffer at 99% for . It feels exactly like that moment when a video stream freezes just as the revelation is about to be spoken; the little circle spins with a rhythmic, digital insolence, and you realize that the wait is no longer a delay, but a state of being.

99%

In the world of equipment finance, this 99% buffer is usually the governance process. We have built systems designed to scrutinize change so intensely that they accidentally create a protected sanctuary for the status quo, no matter how dangerous that status quo might be.

As a dyslexia intervention specialist, my day job involves dismantling the “invisible scripts” that people use to navigate systems not built for them. I see how students create elaborate, exhausting workarounds to avoid the risk of misreading a word in public. They would rather expend ten times the energy on a “safe” failure than risk the exposure of a “new” mistake.

Organizations do the same thing. They create a “shadow architecture” of patches and prayers because the risk of a new implementation is a documented liability, whereas the risk of doing nothing is a historical circumstance; therefore, the institution will always choose the circumstance over the liability.

The Imbalance of Scrutiny

To understand why this happens, you have to look at how a Risk Review Board actually functions, which is essentially a series of gatekeepers asking, “What could go wrong if we do this?” This is a necessary question, but it is structurally imbalanced.

When you propose a new equipment finance software solution, you are handing the board a 40-page document filled with variables. You are giving them a target.

The Target for Scrutiny

  • Data migration plan corruption
  • API integration latency
  • Vendor SOC2 fine print

The board examines the “Action” with a microscope. But the “Inaction”-the legacy platform that reached its end-of-support life when the current interns were in middle school-is not on the table for a 40-page scrutiny. It doesn’t require a submission. It doesn’t require a signature. It just is. By virtue of its existence, it is grandfathered into the institution’s comfort zone, even as it becomes a ticking clock.

Risk functions are understood as neutral assessors of options, but this is a polite fiction. Inaction is structurally privileged.

I’ve seen this play out in the equipment finance sector with agonizing regularity. A lender knows their core servicing engine is a liability. They know it can’t handle the complexity of modern operating leases or the speed of API-first origination systems. They know that every day they stay on the old box, they are accumulating technical debt that will eventually be called in by a catastrophic system failure or a regulatory audit.

New Transition

Measured in Ounces

VS

Current State

Measured in “Vibes”

The two scales of institutional risk.

Yet, when the time comes to pull the trigger on a modern platform like Lendscape, the “risk” of the transition is weighed against the “risk” of the current state using two different scales. The transition is weighed in ounces; the current state is weighed in “vibes.”

A risk is a definition that we use to describe our fear of the future, but we rarely apply the same definition to our tolerance of the present, which means we are often just using the word “risk” as a synonym for “unfamiliarity.”

This creates a paradox where the institution defeats its own purpose through correct procedure. You can have a perfectly compliant risk management framework that results in the total obsolescence of the business. You can have a file cabinet full of signed DPIAs and architecture sign-offs for projects that were never started because the process of getting the sign-off was more taxing than the problem being solved.

It’s a form of institutional dyslexia-we are so focused on decoding the individual letters of the governance requirements that we completely miss the meaning of the sentence, which is: The building is on fire.

The $50,000 Monthly Tax

I remember talking to a COO who was visibly vibrating with frustration. He had a team of twenty people manually reconciling spreadsheets because their legacy servicing platform couldn’t handle mid-term contract adjustments for a new fleet of medical equipment.

The “Operational Risk” of the manual work was astronomical-human error, fraud, fatigue-but the “Project Risk” of replacing the platform was what kept getting flagged by the compliance team.

“We are spending $50,000 a month to manage the risk of not spending $500,000.”

– COO, anonymous fleet management firm

He was watching his own version of a 99% buffer. He was Silas Thorne, documenting the rot because the cost of the survey was higher than the cost of the collapse.

Connectivity as Survival

The shift toward API-first architecture in the commercial finance world is supposed to solve this, but even the most modular, elegant software can’t fix a broken governance culture. A platform that allows for contract administration, asset tracking, and billing to scale without added headcount is only useful if the risk department allows it to be plugged in.

The beauty of a system that connects to the origination and accounting tools you already run is that it lowers the “surface area” of the change. It’s not a heart transplant; it’s a better way for the body to breathe.

And yet, the “What if?” culture treats every connection as a potential breach, forgetting that the current “disconnected” state is its own kind of breach-a breach of efficiency and a breach of the duty to remain competitive.

We need to start asking a different question at the board level. Instead of asking “What is the risk of this project?” we should be asking “What is the cost of the permission we are giving the status quo?”

Every time a risk register entry for an unsupported system is rolled forward, it should be treated as a new, active decision. It shouldn’t be a “carry-over.” It should require the same level of architectural review and board-level signature as the replacement project would.

If you want to keep the rotting timbers in the dock, you should have to sign for every splinter. If inaction required as much paperwork as action, we would see a miraculous surge in innovation.

The spreadsheet used to track the risk of the dying platform becomes the only part of the architecture that is truly immortal.

The Stolen Time

The frustration I feel when a video buffers at 99% isn’t about the technology; it’s about the stolen time. It’s about the promise of a result that is withheld by a technicality. In the corporate world, that stolen time is measured in years of lost growth and frustrated employees who eventually leave because they are tired of being the “human API” between two systems that refuse to talk to each other.

Zara S.-J. would tell you that if a student is struggling to read, you don’t give them a more detailed book about how to read; you change the method of instruction. You lower the friction. You acknowledge that the current “system” isn’t working and that the risk of staying in the dark is far greater than the risk of trying a new lens.

The institution must eventually act, or it will be acted upon by the market. The rot in Silas Thorne’s dock eventually claimed the pier, regardless of how well-documented the decay was. We can keep the calfskin ledgers, and we can keep the quarterly reviews, and we can keep the eleven-time roll-forwards.

But we shouldn’t pretend we are managing risk. We are simply documenting the slow-motion car crash of a business that forgot that the most dangerous thing you can do in a changing world is nothing at all.

Stop looking at the 99% buffer and start asking why the wheel is spinning. Is it the technology, or is it the hand on the mouse, too afraid to click “Confirm” on a future that doesn’t look like the past?