Risk management can sound like something designed for large companies with risk departments, compliance teams and endless spreadsheets.
For a small business, it can feel rather different.
You might be managing risk while running the business, serving customers, managing employees, dealing with suppliers, keeping the finances moving and trying to think about what comes next.
There probably isn’t a risk manager sitting in the next office waiting to update the risk register.
That doesn’t mean risk management isn’t relevant. In fact, the opposite is often true.
The smaller the business, the more exposed it can be to individual people, critical suppliers, technology failures, cash-flow problems, regulatory changes and decisions that haven’t been properly challenged.
The question is not whether your business has risks.
It does.
The more useful question is whether you understand the risks that matter, whether you know how well they are controlled and whether your business can continue to operate when something doesn’t go according to plan.
That is where practical risk management comes in.
Risk isn’t just about things going wrong
One of the problems with traditional approaches to risk is that risk can become synonymous with threats.
Something might go wrong.
Someone might make a mistake.
A supplier might fail.
A system might go down.
A regulation might change.
Those things matter, but risk management is broader than simply making a list of everything that could go wrong.
Uncertainty is unavoidable. You cannot predict everything that will happen to your business, and trying to do so can become an exercise in false confidence.
A more useful approach is to build the capability to respond when circumstances change.
That means understanding what matters to your business, recognising the things that could affect it, knowing how well you are protected and making deliberate decisions about where to focus your attention.
The aim isn’t to eliminate risk. That isn’t possible.
The aim is to manage it intelligently so that you can respond more effectively when something unexpected happens.
Start with the business, not the risk register
One of the simplest changes you can make to your approach to risk management is to stop starting with risks.
Start with the business. What are you trying to achieve? What activities are essential to achieving those objectives? Which customers, people, suppliers, systems, processes or resources are particularly important? What would have to happen for you to be unable to deliver what matters?
This is the thinking behind the first stage of the TRAPS framework in Strategic Risk.
T = Targets
Before you can manage risk, you need to understand what you are protecting. That means identifying your business objectives and considering your risk appetite, or how much uncertainty you are prepared to accept in pursuit of those objectives.
Without that context, risk identification can quickly become a long list of things that might happen without any clear idea of which ones actually matter. For example, a business might list:
- cyber attack
- loss of a key employee
- supplier failure
- regulatory change
- economic uncertainty
- data breach
- equipment failure
All of these could potentially matter. But which one could prevent the business from achieving its most important objectives?
That is a much more useful question.
Identify what could prevent those targets being achieved
Once you know what you are trying to protect, you can identify the risks that could get in the way.
R = Risks
The book looks at a range of areas where risks can arise, including people, health and safety, supply chain, legislation, finance and technology. It also considers the importance of looking beyond the risks that are already on your radar and paying attention to emerging threats and changes in the external environment.
This is particularly important for smaller businesses because dependencies can be hidden. For example, perhaps one person holds most of the knowledge about a key client. Perhaps one supplier provides something that would be extremely difficult to replace. Perhaps the business owner is the only person who knows how a critical process works. Perhaps important information is stored in an individual’s inbox rather than somewhere the wider business can access it. None of these necessarily looks like a dramatic risk on a normal working day.
They become risks when something changes.
The key-person dependency is a good example. If a business depends heavily on one person and that person becomes unavailable, the issue isn’t simply that someone is off sick or leaves.
The question is what happens to the business as a result.
Can customers still be served? Can decisions still be made? Can someone else access the information they need? Can the work continue without the business owner stepping in?
Risk management starts to become much more useful when you ask questions like these.
Analyse the controls you already have
Identifying a risk is only the beginning. The next question is what you already have in place to manage it.
That is the A in TRAPS: Analyse.
This means looking at your existing controls and asking whether they actually provide the protection you think they do.
And this is where there is an important distinction between having a control and having an effective control. A business may have a policy. It may have a procedure. It may have insurance. It may have backups. It may have a contract with a supplier. It may have completed a training programme.
Those things can all be useful. But the existence of a document, system or process doesn’t automatically mean the underlying risk is controlled. A policy that nobody follows is not much of a control. A backup that has never been restored is an assumption. A supplier contingency plan that has never been tested may look reassuring until the supplier actually fails. A training programme that employees completed two years ago may not tell you much about what they do today.
This is why assurance matters.
The book describes governance and assurance as complementary. A risk register tells you what you think the risks are. Assurance helps you understand whether your response is actually working.
For a small business, this doesn’t need to mean creating a huge assurance programme. It could simply mean asking better questions.
- What evidence do we have that this control works?
- When did we last test it?
- Who is responsible for it?
- What happens if it fails?
- What has changed since we put it in place?
Those questions can reveal much more than another review of a risk register.
Don’t confuse a policy with a control
This deserves particular attention because it is one of the easiest traps to fall into. Writing something down can create the feeling that the risk has been dealt with. It hasn’t necessarily. A policy tells people what should happen. A control is what actually helps prevent, detect or respond to something happening. There is nothing wrong with policies. They can be an important part of a control environment and can provide consistency and assurance. But compliance should not be confused with effective risk management.
As my book puts it, a certificate or policy may provide assurance without guaranteeing that the underlying risk is controlled.
So instead of asking:
“Do we have a policy?”
ask:
“What does this policy actually control?”
And then:
“How do we know?”
That small change in questioning can make a significant difference.
You cannot fix everything at once
Once you’ve identified your risks and looked at your controls, you will probably find gaps. This is where many businesses get stuck. There are too many things to fix.
Cyber security could be better.
Business continuity could be better.
Supplier management could be better.
Documentation could be better.
Training could be better.
The temptation is to create a huge action plan and try to tackle everything. That usually isn’t sustainable.
The fourth stage of TRAPS is therefore P = Prioritise.
The principle is simple: you cannot fix everything at once. Trying to do so can actually result in doing very little. Instead, prioritisation helps you decide where attention will make the biggest difference. That might mean addressing a critical dependency. It might mean improving a control that currently provides little protection. It might mean documenting something that currently exists only in someone’s head. It might mean addressing a risk that could seriously affect your ability to operate.
The objective isn’t to produce the longest possible list of improvements. It is to make meaningful progress on the things that matter most.
Resilience goes beyond business continuity
Business continuity is an important part of risk management, but resilience is broader.
A continuity plan might tell you what to do if a particular disruption occurs.
Resilience is about the wider capability of the business to prepare, adapt, respond and recover when circumstances change.
That distinction matters because you cannot write a plan for every possible future event.
You can, however, understand your critical activities, dependencies and vulnerabilities and build the capability to respond.
Consider a critical supplier.
You might have a contingency plan that says you will use another supplier if the first one fails.
But have you checked whether the alternative supplier actually has capacity?
Have you considered how long it would take to switch?
Would customers be affected?
Would your costs increase?
Who would make the decision?
What information would they need?
That is where risk management moves from documentation into practical resilience.
The book’s approach is deliberately about helping businesses understand their real position rather than the position they hope they are in.
Make risk management part of how the business operates
The final stage of TRAPS is S = Systemise.
This is where the work becomes part of the way the business operates rather than another project that gets completed and forgotten.
A risk framework that exists only in the business owner’s head isn’t particularly useful.
Neither is one sitting in a folder that nobody opens.
The purpose of systemising is to embed what you’ve learned into the way the business works.
That might include:
- documenting important processes
- assigning ownership
- incorporating risk into decision-making
- reviewing important assumptions
- monitoring changes
- testing important controls
- learning from incidents and near misses
- revisiting risks as the business changes
This doesn’t mean creating bureaucracy for its own sake.
In fact, the TRAPS framework was specifically designed to be practical for business owners without dedicated risk teams or specialist departments. It is qualitative rather than dependent on complex quantitative analysis.
The aim is to make risk management usable.
So where should a small business start?
If you feel that your business could be more resilient but you don’t know where to begin, don’t start by building a 50-page risk register.
Start with five questions.
- What are we trying to achieve?
Identify the objectives that really matter.
- What could stop us achieving them?
Think about people, suppliers, technology, finance, regulation, customers, processes and external changes.
- What do we already have in place?
Identify the controls, processes and safeguards that are supposed to manage those risks.
- How confident are we that they work?
Look for evidence. Test important controls rather than simply assuming they work.
- What should we address first?
Don’t try to fix everything. Focus your time and resources where they will make the greatest difference.
That is essentially the logic behind TRAPS. Each stage builds on the previous one. The result isn’t a promise that nothing will go wrong.
It is a clearer understanding of the business, its dependencies and its vulnerabilities, together with a practical way to decide what to do about them.
Risk management should help you run the business
For a small business, good risk management shouldn’t be an administrative exercise sitting alongside the real work.
It should support the real work.
It should help you make decisions.
It should help you understand where the business is vulnerable.
It should help you challenge assumptions.
It should help you prepare for disruption without pretending you can predict exactly what will happen.
And perhaps most importantly, it should help reduce the amount of the business that exists only in the owner’s head.
Risk will always be part of running a business.
The objective isn’t to remove it.
It is to understand it well enough to make better decisions, respond when circumstances change and build a business that doesn’t depend on everything going according to plan.
That is the thinking behind Strategic Risk: The TRAPS Framework for Better Business Decisions.
If you want to explore the framework in more detail, Strategic Risk: The TRAPS Framework for Better Business Decisions takes each stage of TRAPS further, including risk identification, people risk, supply chains, regulatory compliance, controls, business continuity, prioritisation and systemising risk management.
Want to take a more practical approach to risk management?
Strategic Risk is available now on Amazon.
If you’re a business owner who wants to understand where your business is vulnerable, make better decisions and build greater resilience without turning risk management into a full-time job, this is where I’d start.
Recent Comments