Former Co-op head of risk and governance Stefan Gershater explains why risk teams need to stop leading with registers, controls and heat maps, and start with the business objectives they are trying to protect.

When Stefan Gershater began looking for an integrated risk management system at The Co-operative Group, his starting point was not risk.

It was value.

IMG_3728

Speaking at Risk-!n in Zurich, the former head of risk and governance at The Co-operative Group said risk teams often lose influence because they begin with the language of their own function, rather than the priorities of the business.

For Gershater, the purpose of risk management is not to populate a register, but to help leaders make better decisions about value creation and value protection.

“I never realised I was interested in risk. I was always interested in getting stuff done,” he said.

That shaped the way he approached the project. Instead of buying a traditional risk system, Gershater wanted a platform that could support better decisions by linking risks to objectives, outcomes and business value.

“It very quickly changed from a risk system to a decision support system,” he said. “How do we take better decisions faster? That was my starting point.”

The challenge: learning the business’ language

Gershater said he is sceptical of many governance, risk and compliance systems because they start in the wrong place. Too often, he argued, tools and frameworks are built around risks, controls and assurance, rather than the objectives the organisation is trying to achieve.

“The first column in your metadata should be objective, output, value,” he said.

The Co-operative Group’s senior leaders were focused on business outcomes, not risk terminology, and Gershater said risk practitioners need to recognise that most executives are not interested in being trained to speak that language.

“Why am I spending months and months of my life trying to train somebody to speak in the language of risks, controls and assurance when they really don’t care, they really aren’t interested about that,” he said. “What they’re interested in is creating new products, creating new services, going into new geographies, selling more profitably.”

That meant the risk team had to change its own approach first. Gershater said he told his team every conversation had to begin with the objective, not the risk.

“I said: ’Every conversation that you have, you are going to start with the objective. If I hear you start a conversation with ’what are your risks?’ I will make you take a personal day to go and think about what you’ve done’,” he said.

The approach: make risk useful to the business

The breakthrough came when Gershater positioned the risk team as part of the business leader’s extended team. He said the conversation with business heads became easier once risk was framed around helping them achieve their own goals.

“What was easy was talking to the MD of the food business,” he said. “I genuinely said, I want to help you get your bonus.”

That opened a different kind of discussion. Rather than asking leaders to fill in a risk register, Gershater asked what they were trying to achieve and then explained how risk management could support those objectives.

He gave the example of looking at transformation portfolios and end-to-end processes, including areas where the business was leaving value on the table. In one case, he referenced a source-to-pay process through which hundreds of millions of pounds moved each week.

Gershater argued that once risk teams can show how they support better capital allocation, more resilient processes or improved operational performance, they become more relevant to business leaders.

The lesson: the hard part is culture, not implementation

Gershater evaluated 14 platforms before ultimately choosing Corporater, but said the technology was not the most difficult part. The harder task was convincing the business, changing the way the risk team spoke, and finding a provider willing to support his approach.

“It took nearly two years to convince the business. It took nine months to implement. So the convincing is the hard bit and the culture is the hard bit,” he said. “How to talk the language of the business and not make them talk your risk language was the hardest thing I’ve ever done in my career, but it was probably one of the successes that I’m most proud of.”

He also warned against treating technology as the whole answer. Gershater said he is sceptical of many AI use cases in risk analysis and would rather see vendors focus on the fundamentals.

“I would far rather that software vendors worked on the fundamentals of their solutions… or being able to at least discuss value as a innate and native factor… rather than jumping to AI,” he said.

For Gershater, the next opportunity for risk practitioners is not simply automation, but a better understanding of causality: how one event leads to another, and how external risks translate into internal impacts and strategic consequences.

But ultimately, he argued that the value of risk management depends on where the conversation starts. If the starting point is a register, the function is likely to remain process-led. If the starting point is how the business creates value, risk practitioners have a better chance of influencing decisions before they are made.