Risk Management

New Risk Owner in 60 Days: What to Fix Before the Register Becomes a False Promise

A risk owner is not the person who updates a register. The role is to make sure material exposure has a clear decision path, an operating control, and evidence that the control still works when conditions change.

By 7 min read

Key takeaways

  1. 01A risk owner owns the decision path around a material exposure, not merely the risk-register entry.
  2. 02The first 60 days should clarify decision boundaries, map control ownership, and test controls in ordinary work.
  3. 03Escalation is useful only when people know who can decide, how quickly a response is required, and what happens when a control is unavailable.
  4. 04Findings should close only after the changed operating condition has been verified, not when an action is assigned.
  5. 05Andreza Araujo's experience across more than 250 cultural transformation projects reinforces the need to connect stated expectations with visible decisions and field evidence.

A newly appointed risk owner often receives a spreadsheet, a review calendar, and a request to "keep the register current." That handover looks orderly, yet it can leave the most important question unanswered: who has the authority to change the work when the exposure is no longer acceptable?

The first 60 days should not be spent polishing risk descriptions. They should establish whether each material risk has an accountable decision-maker, a defined control, a trigger for escalation, and evidence from the operation. Without those elements, the register records management intent while the exposure continues to move.

What does a risk owner actually own?

A risk owner owns the quality of the decision path around an exposure. That responsibility is broader than maintaining a row in a risk register, because the owner must know what could cause serious harm, which controls are expected to prevent it, who performs those controls, and what happens when the evidence is weak.

The role does not mean that one manager personally performs every control. A maintenance leader may own an isolation process, a production supervisor may own a shift-level verification, and an engineering manager may own a design barrier. The risk owner connects those responsibilities and makes sure that unresolved gaps cannot disappear between departments.

James Reason's work on latent failures remains useful here because a visible event often reflects decisions made earlier in design, planning, procurement, staffing, or supervision. A risk owner therefore looks upstream, where the conditions for failure are created, rather than treating the final task deviation as the whole problem.

Before starting, define the exposure and the decision boundary

Start by selecting the exposure that deserves the first 60-day review. Choose a risk that can affect people seriously, crosses organizational boundaries, or has repeatedly survived previous action plans. Do not choose it because its register entry is old or because the last audit mentioned it.

Write the exposure in operational language. "Process safety risk" is too broad to guide a decision. "Loss of containment during temporary transfer when the normal isolation point is unavailable" gives the team something that can be observed, challenged, and controlled.

Then define the decision boundary. State what the organization will not accept without additional control, who can authorize a temporary deviation, which conditions require work to stop, and who must be informed when the exposure changes. A clear boundary is more useful than a risk score whose meaning differs from one department to another.

The article Risk Criteria Explained offers a useful companion for this step because it separates the criteria leaders set from the ratings people later enter in a system.

First week: map the people who can change the risk

During the first week, interview the people who plan, authorize, execute, supervise, maintain, and review the work. Ask each person which decision they can make when the control is unavailable, what evidence they trust, and where they believe responsibility changes hands.

Listen for mismatches. A supervisor may be held responsible for a safe start but lack authority to delay production. An engineer may own the design standard while operations owns the temporary workaround. A contractor may perform the task while the client controls access, sequencing, and emergency response.

Record those interfaces in a simple owner map. The map should show the risk owner, control owners, verification owner, escalation recipient, and decision-maker for a temporary change. If one role appears in every box, the arrangement may be convenient on paper but fragile in practice.

Review the barrier-owner map process when the exposure involves several preventive or mitigating barriers. The purpose is not to create another chart. It is to expose the handoffs that allow a weak control to remain unchallenged.

Days 8 to 30: test whether controls exist in ordinary work

In the second phase, move from descriptions to demonstrations. Select the controls that matter most for the exposure and ask the responsible people to show how those controls work during a normal shift, a workload increase, a staffing change, or a temporary deviation.

Check four things for each control. First, the control must be specific enough that two supervisors can recognize the same acceptable condition. Second, someone must have the time, competence, equipment, and authority to perform it. Third, the control must leave evidence that a reviewer can inspect without relying on memory. Fourth, the response to a failed check must be defined before pressure arrives.

A signed procedure is not proof that the control works. Neither is a training record, an audit score, or a risk rating that has remained unchanged for several review cycles. Ask what the worker sees, what the supervisor decides, and what the system records when the control is challenged.

When the exposure includes a temporary workaround, compare the documented arrangement with the practical conditions that make the workaround last. The review of temporary deviations helps the risk owner look for informal extensions, missing review dates, and controls that became normal without a formal decision.

Days 31 to 45: make escalation usable under pressure

Many risk systems describe escalation as if sending an email were the same as changing a decision. It is not. A usable escalation path tells the person who found the problem what to do next, how quickly a response is required, and what happens if the decision-maker is unavailable.

Run a short scenario with the team. Remove one critical control, introduce a production delay, or change the work sequence. Ask who can pause the task, who can approve an alternative, which evidence is required, and how the decision reaches the next shift.

Pay attention to silence. If people can identify the risk but cannot identify the person who will respond, the system has detection without control. If everyone can escalate but nobody can decide, the organization has created a queue rather than a safeguard.

The risk-escalation review is relevant here because it examines the ways a serious exposure can be softened as it moves through layers of review.

Days 46 to 60: convert findings into accountable decisions

By the final phase, the risk owner should be able to show which controls are effective, which are uncertain, and which require a decision beyond the current operating team. Do not close findings because an action has been assigned. Close them when the changed condition has been verified.

Each open item needs a named decision owner, a due date that reflects the exposure rather than administrative convenience, an interim protection where necessary, and evidence that will demonstrate completion. When the organization accepts residual risk, record the basis for that acceptance, its duration, and the condition that will trigger a new review.

Use a decision log for choices that alter the control arrangement. The safety decision log guide can help preserve the reasoning, assumptions, dissent, and follow-up date that a risk register usually compresses into one sentence.

Common mistakes made by new risk owners

The first mistake is treating the register as the work. A clean register can coexist with unclear authority, weak verification, and controls that exist only during audits.

The second mistake is accepting the risk score as a conclusion. A score is a communication device, not evidence that a barrier is available, independent, and effective under the conditions that matter.

The third mistake is assigning every gap to the EHS team. EHS can facilitate analysis and challenge assumptions, but the operating leader who controls the work must own the decision that changes exposure.

The fourth mistake is asking for more actions when the existing decision rights are unclear. More actions create movement in the tracker. They do not necessarily create a safer operating condition.

What should the risk owner show at the first 60-day review?

The review should be short enough for leaders to understand and specific enough for operators to challenge. Show the selected exposure, the decision boundary, the owner map, the critical controls, the evidence sampled, the failed or uncertain controls, and the decisions that remain open.

Separate three statements that are often blended together. "The procedure exists" describes documentation. "The control was performed" describes an event. "The control prevented or limited the exposure under relevant conditions" describes effectiveness. The third statement requires stronger evidence than the first two.

Across more than 250 cultural transformation projects supported by Andreza Araujo, the practical distinction remains important: responsibility becomes credible when leaders can connect a stated expectation with a visible decision and a verifiable condition at the point of work. That is the standard a new risk owner should bring to the first review.

Frequently asked questions about becoming a risk owner

Is a risk owner the same as the person who maintains the risk register? No. The register custodian manages information quality and review workflow, while the risk owner remains accountable for the decision path, control ownership, escalation, and evidence around a material exposure.

How should a new risk owner choose the first risk to review? Choose an exposure with serious potential consequences, multiple interfaces, repeated unresolved actions, or a control that depends on temporary arrangements. The first review should reveal how the system operates, not merely confirm that records exist.

What evidence shows that a control is working? Evidence depends on the control, but it should show that the expected condition was present, the responsible person could perform the control, exceptions were handled, and the arrangement remained effective under relevant operating pressure.

Can EHS own the risk for an operating department? EHS can own specific technical or assurance responsibilities, but an operating risk should remain connected to the leader who controls the work, resources, priorities, and decision rights that shape the exposure.

What should happen when the risk owner lacks authority? Escalate the authority gap as a risk condition. The organization should either give the role the necessary decision rights, appoint a person who has them, or formally accept the exposure with a documented basis and review trigger.

Topics risk-management risk-owner risk-register decision-rights critical-controls field-verification ehs-manager leadership

Frequently asked questions

Is a risk owner the same as the person who maintains the risk register?
No. The register custodian manages information quality and review workflow, while the risk owner remains accountable for the decision path, control ownership, escalation, and evidence around a material exposure.
How should a new risk owner choose the first risk to review?
Choose an exposure with serious potential consequences, multiple interfaces, repeated unresolved actions, or a control that depends on temporary arrangements. The first review should reveal how the system operates, not merely confirm that records exist.
What evidence shows that a control is working?
Evidence depends on the control, but it should show that the expected condition was present, the responsible person could perform the control, exceptions were handled, and the arrangement remained effective under relevant operating pressure.
Can EHS own the risk for an operating department?
EHS can own specific technical or assurance responsibilities, but an operating risk should remain connected to the leader who controls the work, resources, priorities, and decision rights that shape the exposure.
What should happen when the risk owner lacks authority?
Escalate the authority gap as a risk condition. The organization should either give the role the necessary decision rights, appoint a person who has them, or formally accept the exposure with a documented basis and review trigger.

About the author

Andreza Araújo

Safety Culture Expert | Senior EHS Executive

Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.

  • Civil & Safety Engineer (Unicamp)
  • M.A. Environmental Diplomacy (University of Geneva)
  • Sustainability Cert (IMD Switzerland)
  • People Management & Coaching (Ohio University)
  • UN Paris speaker representative for Brazil
  • ILO Turin speaker
  • LinkedIn Top Voice
  • Indra Nooyi PepsiCo CEO recognition (2x)

Documentaries

Watch Andreza's documentaries

Three productions on safety culture, organizational failure and the human lessons behind major disasters.

Podcasts

Listen to Andreza's podcasts

She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.

Summarize with AI