Preconceived Notions and Risk Management

A recent conversation reminded me of something uncomfortable—but important. Experience, which we often wear as a badge of credibility and honour, can quietly become a barrier to new thinking. Which got me thinking.

In risk management, experience is invaluable. It sharpens judgment, builds pattern recognition, and helps us anticipate issues before they materialize. But it also comes with a hidden cost: the tendency to rely on preconceived ideas. When we’ve “seen it before,” we may stop truly seeing what’s in front of us. Do we really see the forest and not the trees?

That’s the pitfall.

Preconceived notions are efficient. They help us move quickly. But they can also lead us to filter out new information that doesn’t fit our existing mental models. In a field like risk management—where emerging risks rarely look exactly like past ones—that can be a significant vulnerability.

So the question becomes: how do we demonstrate, both to ourselves and to others, that we are open to new ideas?

First, it starts with awareness. Recognizing that experience can create blind spots is not a weakness; it’s a strength. The most effective risk managers are not those who assume they know, but those who continuously test what they think they know.

Second, it requires intentional curiosity. That means asking more questions than making statements. Instead of framing a situation through the lens of “this looks like X,” we can shift to “what might I be missing here?” or “how is this different from what I’ve seen before?” These small changes in approach create space for new insights.

Third, we need to actively invite challenge. In many organizations, especially those with strong hierarchies or experienced leadership, dissenting views can be unintentionally discouraged. As risk professionals, we should do the opposite—encourage alternative perspectives and reward thoughtful pushback. It’s often in those moments of constructive tension that the most valuable insights emerge.

Fourth, we can demonstrate openness through process. This might include structured decision-making frameworks that require consideration of multiple scenarios, or post-mortem reviews that explicitly examine where assumptions may have influenced outcomes. When openness is built into the process, it becomes less dependent on individual mindset.

Finally, humility plays a critical role. Experience should give us confidence, but not certainty. The risks that matter most are often the ones that don’t fit neatly into our past experiences. Being willing to say “I don’t know” or “this may be different” signals both credibility and adaptability.

For those of us in risk management, this is more than a personal development exercise—it’s a professional obligation. Markets evolve. Regulations change. Organizational dynamics shift. If we approach these changes with rigid expectations, we risk becoming part of the problem rather than part of the solution.

The irony is that true expertise is not about having all the answers. It’s about knowing how to question your own answers. Experience should be a foundation, not a filter. The challenge—and the opportunity—is to use what we know without being limited by it.

Why Post

The idea behind postings on this platform is to ask questions. Also, hopefully provide ideas, concepts or thoughts that highlight the challenges facing risk and compliance managers in the corporate governance structure. These postings are based on my personal experience, the experiences of others, and developing my understanding of the many leadership challenges, through publications and literature.

It’s my desire to help close the perceived negative gaps between corporate governance and risk/compliance management. There are ways and means to enhance the relationship, which I’ve focused on for several years. Direct message me for additional information on how to create a collaborative governance environment

Lending Your Reputation as a Compliance Officer

Recently, I received notice of a registrant that admitted to supervision failures and paid a significant regulatory fine. It prompted me to revisit an experience from a few years ago — an interview process that, in hindsight, reinforced one of the most important lessons for any compliance or risk professional: we do not just take jobs; we lend our reputations.

Before the interview, I did what any compliance officer should do — due diligence. Public records showed the company had experienced consequential regulatory issues. There had been scrutiny, restrictions, and reputational bruising. Still, I believed in keeping an open mind. Companies can learn. Governance can mature. Culture can evolve.

The interview itself went well — at least on the surface. There was good back-and-forth between the owner and members of the Board of Directors. The discussion was candid and energetic. From a professional standpoint, it felt productive.

Then I asked one of my favourite questions: “What are your thoughts on the regulators?”

Their tone shifted immediately with their response becoming defensive — even hostile. Their comments raged from “Regulators this, ” “Regulators that, ”“Why are they picking on us?” or “Why won’t they just leave us alone?”

Conspicuously absent was a different question: “What do we need to do to get out from under this scrutiny?” That was the tell.

A firm’s attitude toward its regulator says more about its governance culture than any policy manual ever will. In Canada, whether you are dealing with the Ontario Securities Commission or another securities authority, regulatory oversight is not personal — it is structural. If leadership views supervision and compliance as an external nuisance rather than an internal responsibility, the Chief Compliance Officer inherits an almost impossible mandate.

I decided to ask what I consider the ultimate governance question to the interviewees:

“If I take the role, and my professional recommendation is that the business should close or materially restructure or put it’s self up for sale, how would you respond?

The answer told me everything I needed to know. I did not get the job, and I was grateful.

Fast forward to today. The company ultimately faced significant regulatory consequences and was forced to sell to another firm. The outcome was not surprising. Culture, when left unchecked, eventually compounds.

This experience reinforced a principle I share often with fellow compliance and risk professionals: We rent our reputation to the firms that hire us.

Yes, the relationship is employer–employee. But the marketplace sees more than that. Future boards, CEOs, and hiring committees look at where you served. They ask:

  • What kind of firm was it?
  • What was its regulatory standing?
  • What happened under your watch?

Of course, each situation is unique. Talented compliance officers often join firms precisely because they need remediation and strengthening. Turnarounds are real, and success stories exist. But there is a difference between joining a firm committed to reform and joining one that views compliance as an afterthought.

As an employer or board member, I would inevitably ask: Why did this compliance officer align themselves with that firm?

Fair or not, reputations transfer.

Over the years, we have seen a multitude of firms sanctioned, fined, restricted, or placed under terms and conditions. In every case, governance culture played a role. Fines are rarely just about technical breaches; they often reflect systemic supervision failures.

For compliance officers, the risk is not only legal or operational — it is reputational.

Your name becomes attached to the firm’s trajectory. If the firm improves, your credibility strengthens. If it collapses under regulatory pressure, your professional narrative becomes more complicated.

So before accepting a role, consider:

  • Does leadership respect regulatory oversight?
  • Is the Board genuinely engaged in governance?
  • Are you being hired to build a culture of compliance — or to absorb regulatory friction?
  • If you made a hard but necessary recommendation, would it be heard?

Compliance is not just about policies, procedures, and reporting lines. It is about judgment — including the judgment to decide where you place your professional capital.

Reputations in financial services still matter. They travel faster than résumés. They shape board invitations, consulting mandates, and future executive opportunities.

The question is simple, but not always comfortable:

Are you lending your reputation to a worthy firm?

Because once you do, it’s reputation becomes part of yours.

Responsibility: Own It — Or Pass It On

 I might be showing my age here — or maybe just leaning into a bit of nostalgia — but I’ve been thinking a lot about responsibility lately. Not in a legal sense. Not in a job-description sense. But in a personal, lived-experience sense. The mainstream media headlines speak to this post.

When I was starting my career, responsibility felt straightforward in that if it was yours, you owned it. If it wasn’t, you passed it to the person who did own it. Clean lines, clear expectations, and little or no ambiguity.

Somewhere along the way, that clarity feels like it has softened.

What I’m increasingly hearing and seeing in both professional and personal contexts  is something like this:
“Yes, that was my responsibility… but the negative outcome wasn’t my fault.”

Or:
“It was out of my control.”
“There were external factors.”
“I couldn’t influence the result.”

Now, let’s be honest, sometimes those statements are true.  We operate in complex systems, markets shifts, regulations changes. Or other people make poor decisions, or technology fails. There are countless variables none of us can fully control.

But here’s the question that keeps coming back to me: If you accept responsibility, what exactly are you accepting? Is it just the authority? The title? The upside when things go well?
Or does it include the uncomfortable part — the consequences when things don’t?

To me, responsibility has always meant ownership. Not ownership of blame, necessarily — but ownership of outcome. Ownership of the response and more importantly, ownership of the fix.

In leadership roles — whether as a CEO, COO, CCO, board member, or simply as a colleague — responsibility isn’t a selective agreement. You don’t get to claim the success and distance yourself from the fallout. If the file sits on your desk, if the team reports to you, if the mandate falls under your remit, then it’s yours.

That doesn’t mean you caused the issue. It means you’re accountable for addressing it.

There’s a subtle but important difference between fault and responsibility. Fault is about cause. Responsibility is about stewardship. I’ve seen situations where something clearly wasn’t caused by the person in charge — perhaps it was inherited, systemic, or the result of someone else’s oversight — yet the leader stepped forward and said, “This sits with me. We’ll fix it.” That response builds trust. It builds credibility. It builds culture.

Conversely, when someone says, “Yes, it was my responsibility, but not my issue,” something erodes. Your teams notices, clients notice, Boards notice and over time, that gap between words and ownership creates cynicism.

Maybe this is generational. Maybe expectations around accountability are evolving, or maybe the world has simply become more complex, and people feel exposed to risks they genuinely cannot control. I can accept that as a possibility.

But I also believe that clarity around ‘responsibility’ has never mattered more — especially in governance, risk, and compliance environments. In regulated industries, responsibility cannot be diluted. If something falls within your mandate, regulators won’t be overly interested in how many contributing factors existed. They will ask: who was accountable?

That’s not meant to be harsh. It’s meant to be real.

I include myself in this reflection. It’s easy to write about responsibility. It’s harder to consistently live it. There are moments when deflecting is tempting. When explaining feels safer than owning. When saying “not my fault” seems rational.

So, I’ve had to remind myself: walk the talk.

If I speak about responsibility, I need to embody it. If I expect it from others, I need to demonstrate it first. That means accepting the uncomfortable conversations, the reputational hits and the clean-up work, however valuable lessons are learned.

Responsibility, to me, is not about perfection. It’s about posture.

It’s the posture of saying: “If it’s mine, I own it. If it’s not mine, I pass it to the right person — clearly and transparently. But once I accept it, I stand behind it.”

Perhaps that sounds old-fashioned. Perhaps it is, but I’m not convinced it’s outdated.

In fact, in a world where accountability can feel blurred, maybe returning to that simple principle is exactly what strengthens leadership and culture.

I’m genuinely curious how others see it.

Is it time we stopped asking CCOs and CROs to “stay in their lane” — and instead re-draw the map?

Are Pre-Conceived Notions About the CCO and CRO Roles Holding Back Better Governance?

I came across a social media post recently that listed the regulatory fines paid by a large Canadian bank in 2025. Included were supervisory failures, compliance breakdowns and anti-money laundering deficiencies. The total dollar amount was staggering — not because fines are new, but because many of these issues were entirely preventable.

That post stuck with me, particularly when read alongside several recent articles and papers on the evolving role of the Chief Compliance Officer (CCO) and Chief Risk Officer (CRO). While most of this research focuses on the U.S. and Europe, the themes have very clear Canadian overtones and are highly relevant given the regulatory and operational environment financial services firms are facing as we head into 2026.

One recurring question keeps surfacing for me:
Are our pre-conceived notions of what the CCO and CRO “should be” actually limiting better governance outcomes?

In most organizations, the CCO and CRO roles are treated as distinct, but in practice they are often interchangeable — particularly when it comes to second-line oversight, escalation, and board engagement. The problem isn’t the mandate itself; it’s the expectations wrapped around it.

Take the traditional “zero tolerance” approach to policy breaches. Many oversight structures are designed with the assumption that strict enforcement, rigid controls, and absolute adherence will reduce risk. Yet evidence increasingly shows the opposite. These environments often discourage early escalation, create defensive behavior, and push issues underground — resulting in larger, more costly compliance failures over time.

In other words, we may be designing governance frameworks that look strong on paper but weaken risk management in practice.

Another area where expectations are clearly shifting is DEI. Historically, DEI has been viewed as a human resources function. However, recent lawsuits against large organizations that altered or rolled back DEI programs due to political or financial pressure tell a different story. In several cases, boards were asked why they were not informed of the changes or the associated legal, reputational, and conduct risks.

That question is telling.

If changes to DEI strategy can create material legal and reputational exposure, should DEI remain solely within HR? Or is it now firmly within the oversight scope of the CCO and CRO? If boards are holding compliance and risk leaders accountable for not flagging these risks, then the expectation has already shifted — whether organizations have acknowledged it or not.

The same tension exists with technology and digital transformation. Cloud computing, data governance, cyber risk, and now AI are fundamentally reshaping financial services. Yet most CCOs and CROs did not come up through or have competent IT or data disciplines. That reality raises an uncomfortable but necessary question: how can compliance and risk leaders credibly oversee risks they were never expected to understand?

AI is a perfect example. What is the firm’s policy on AI usage? What supervisory controls exist? What level of risk tolerance has been defined — if any? Avoiding these questions because they feel “technical” is no longer defensible. Regulators and boards are already asking them.

All of this points to a broader conclusion: the CCO and CRO roles must evolve. Not incrementally, but deliberately.

Holding onto dated assumptions about what compliance and risk management should look like — narrow, reactive, enforcement-focused — may itself be a governance risk. Today’s environment requires CCOs and CROs to be translators, challengers, and strategic advisors who operate across silos, not within them.

The real question may not be whether these roles need to change, but whether organizations are willing to let go of the pre-conceived notions that are quietly holding them back.Is it time we stopped asking CCOs and CROs to “stay in their lane” — and instead re-draw the

Is now the time to ask: How Close Is Too Close?

I guess what I’m asking is should we be rethinking the CRO and CCO’s Proximity to the Front Line.

The traditional “three lines of defense” model has long provided a clear and logical framework for risk management and compliance. Tier 1 owns and manages risk, Tier 2 oversees and challenges, and Tier 3 independently assures. The structure is elegant, defensible, and regulator-friendly.

But in today’s environment—defined by geopolitical shocks, social media amplification, rapid regulatory change, and economic volatility—the question is no longer whether the model is sound. It’s whether how we operate within it remains fit for purpose.

At the heart of this discussion is a question I would ask felloe CROs and CCOs: How close should I be to the first line of defense?

Proximity to Tier 1: Independence vs. Insight

Conventional wisdom says that Tier 2 must maintain distance from Tier 1 to preserve independence. That principle still holds. However, distance should not mean detachment.

Risk and compliance failures rarely stem from a lack of policies. They arise from misunderstandings, operational pressures, cultural blind spots, or weak escalation. These are best identified not through dashboards alone, but through regular, informed engagement with the front line.

A CRO or CCO who understands how risks are actually being taken, managed, and rationalized day-to-day is better positioned to challenge effectively. Proximity enables context. Context improves judgment. And judgment is ultimately what regulators expect from senior control functions.

The key distinction is this: advising, observing, and challenging is not the same as owning or executing. Independence is preserved through clarity of accountability, not physical or intellectual distance.

What About Tier 2 and Audit?

If Tier 2 is too far from Tier 1, it risks becoming reactive—discovering issues only once they’ve crystallized. But if Tier 2 becomes too operational, it risks role confusion and diminished credibility.

The same tension exists with audit. Audit’s independence is sacrosanct, yet its effectiveness improves when it understands the real risk landscape rather than a theoretical one.

Strong CROs and CCOs act as connective tissue—ensuring insights from Tier 1 inform Tier 2 oversight and audit planning, without compromising the independence of either.

Does This Pull You Away from Your Core Duties?

Yes, increased engagement with the front line can feel like a distraction from core CCO or CRO responsibilities—regulatory interpretation, policy governance, board reporting, and supervisory interaction.

But there are tangible benefits:

  • Earlier identification of emerging risks
  • Fewer surprises escalated late
  • Stronger risk culture and credibility
  • More meaningful challenge, not just checklist oversight

In practice, time spent closer to the front line often reduces downstream remediation, regulatory friction, and reputational risk—arguably the most time-consuming outcomes of all.

The Pace of Change Demands a Different Model

The velocity of modern risk has fundamentally changed escalation dynamics. Issues can become public before they become internal. Social media can transform minor operational errors into brand-threatening events within hours. Political or regulatory shifts can invalidate existing controls overnight.

In this environment, waiting for risks to “filter up” through supervisory layers may no longer be sufficient.

This raises a critical question: should C-suite executives—particularly CROs and CCOs—be more actively engaged earlier in the risk and compliance lifecycle?

Increasingly, the answer is yes.

Is the Traditional Escalation Model Outdated?

I would say that the model itself is not outdated—but relying on it passively might be.

Escalation should still occur through defined channels, but senior leaders should not depend solely on formal reporting cycles to surface material risks. Active engagement, informal check-ins, and direct visibility into emerging issues provide a necessary complement to traditional governance structures. In effect, walk the office floor and have those informal watercooler talks.

This does not mean bypassing management layers. It means enhancing situational awareness.

A More Active C-Suite Role—Without Blurring the Lines

The future likely belongs to CROs and CCOs who are:

  • Visible, but not operational
  • Engaged, but not directive
  • Informed early, but disciplined in escalation

Being closer earlier does not undermine the three lines of defense—it strengthens them.

In a world where risks emerge faster, louder, and with greater consequence, the real risk may not be being “too close” to the front line—but being too far away, for too long.