Session Five: Risk Management Inside the Programme

Session Five: Risk Management Inside the Programme — Transformation Delivery for Financial Services

Transformation Delivery for Financial Services

A Practitioner's Course

Session Five

Risk Management Inside the Programme

Why programme risk registers so often exist for governance rather than management, and how benefits realisation extends risk management beyond go-live

Session Five: Risk Management Inside the Programme

In large organisations, programme risk management is often weaker than the governance pack suggests. Risk registers can run to dozens of entries, with static ratings and mitigating actions that remain permanently in progress. That creates the appearance of risk management without the reality. This session is about closing that gap at the level of an individual programme, not repeating the enterprise risk framework a bank already operates.

The risk register that exists for audit

A risk register updated on a schedule, populated by people who do not own the risks it lists, and signed off by a committee that does not read it closely, is a familiar pattern. The register used for governance reporting should also be the register that captures the programme's real exposures and is argued over by the people accountable for managing them. In many programmes, those are still two different documents.

Effective risk management focuses on the risks that matter: the risks that could compromise the programme's ability to deliver its objectives. Those risks need clear ownership, credible mitigating actions, and an honest assessment of whether the mitigation is working. A register with forty entries and no distinction between a programme-threatening risk and a minor irritant is not helping anyone make a decision.

Why honest escalation is hard

The escalation of risk is a particular challenge, and the difficulty runs in both directions. Programme managers are sometimes reluctant to escalate because they fear being seen as unable to manage their own delivery. Sponsors sometimes do not want to hear about risk because it creates pressure to act. Both dynamics produce programmes in which the senior tier does not know about problems until they have become crises.

Good governance creates an environment where honest risk escalation is expected and valued, not discouraged. That is partly a structural question, addressed in Session Two, and partly a cultural one: an organisation that treats an amber status as a personal failure by the programme manager will get exactly the reporting behaviour that incentive produces. Session Seven returns to this dynamic in more depth, because the same forces that suppress honest risk escalation also shape what does and does not make it into a status report.

Dependencies are risks

Dependencies are one of the most important and most poorly managed aspects of programme delivery. A dependency on a technology team, a regulatory decision, a third-party provider, or another programme in the portfolio is a risk in its own right. It needs to be identified, owned, tracked and actively managed. Dependencies found late, or listed but not managed, are among the most common causes of programme delay. They are usually foreseeable if dependency mapping is treated as part of planning, rather than as an afterthought once the plan is already agreed.

Benefits realisation as risk management

The benefits case is what justifies a programme, representing the value the organisation expects in return for the investment of time, money, and organisational disruption. In practice, benefits realisation is one of the most consistently neglected aspects of programme delivery, in part because benefits are often defined in terms too vague to measure: an efficiency improvement expressed as a percentage estimate rather than a specific cost reduction, a customer experience improvement with no baseline, a regulatory outcome treated as binary rather than measurable.

Benefits should be defined at the outset in terms that can actually be measured, with a baseline established before the programme begins and a measurement approach agreed. The benefits owner, typically a business leader rather than the programme manager, should be accountable for realising those benefits after delivery, and governance should continue to track them after programme closure, not only during delivery. Some form of post-programme review, at six and twelve months, is a minimum expectation for programmes of significant scale. A governance structure that disbands at go-live cannot capture whether the expected benefits were actually delivered, which means the organisation loses the single most useful piece of feedback available to improve the next programme.

Knowing when to stop

One of the hardest decisions in programme delivery is recognising when a programme should be stopped or fundamentally restructured. The sunk cost effect is powerful. The investment already made creates pressure to continue, even when the evidence suggests the programme will not deliver the expected value. Boards and sponsors that remain engaged with the business case throughout delivery, as described in Session Two, are better placed to make this call. They can assess whether the programme still makes sense in light of what is now known. They can then restructure scope, accept a regulatory consequence in exchange for more time, or stop the programme altogether. The ability to stop is as much a mark of delivery capability as the ability to deliver.

Jurisdiction equivalents

Programme-level risk discipline sits inside the wider enterprise risk management framework a regulated institution operates. Prudential and capital change tends to sharpen board attention on programme risk because the underlying capital and reporting requirements are themselves risk-sensitive. New Zealand and Australian institutions face equivalent pressure through their own prudential frameworks and supervisory expectations, administered respectively by the Reserve Bank of New Zealand and the Australian Prudential Regulation Authority, even where the specific rules diverge from the UK position.

Coming up in Session Six

Session Six covers framework and methodology: why methodology debates distract from the real question, the different shapes of delivery work found in a regulated organisation, and how to choose deliberately rather than by default. Continue to Session Six.

Further reading and resources

Prudential capital implementation materials. Current policy statements and supervisory materials from prudential regulators are useful examples of the kind of capital, reporting and governance change that sharpens programme risk attention. Available from the relevant regulator websites.

Delivering Transformation in Financial Services. The published Ārai Tika guide with a fuller treatment of programme risk, dependency management, and benefits realisation. Available at araitika.com.

Enterprise Risk Management in Practice. The published Ārai Tika article addressing enterprise-wide risk discipline, a useful companion for readers wanting the institution-level picture behind this session's programme-level focus. Available at araitika.com.

Ārai Tika