The International Institute of Enterprise Risk Practitioners (IERP)® hosted a Tea Talk on 19 June 2026 titled “Are We Managing Risk or Just Buying Comfort?”
Key Insights
- Many organisations mistake the emotional comfort of excessive safety controls for genuine risk mitigation.
- Stacking reactive policies and software often creates an illusion of safety that bottlenecks operations without actually reducing threats.
- Effective risk management requires overriding our fear of uncertainty to build dynamic, value-driven controls that protect the business without stifling growth.
In enterprise risk management, it is easy to confuse feeling safe with actually being safe. Driven by a natural aversion to uncertainty, organisations frequently invest in cutting-edge compliance software and stack risk controls, mistaking emotional relief for risk mitigation.
To help decision-makers distinguish whether their control environments reduce the probability of loss or merely serve as expensive reassurance, the International Institute of Enterprise Risk Practitioners (IERP)® hosted a Tea Talk on 19 June 2026 titled “Are We Managing Risk or Just Buying Comfort?”
Ramesh Pillai, Chairman of the Board of Governors of the IERP®, led the session, inviting participants to reflect on whether their policies genuinely contribute to risk mitigation or simply buy peace of mind.
“When you make a critical decision to protect your business or team, what asset are you actually protecting?” he asked.
“Are you fundamentally altering the mathematical probability of a catastrophic event? Or are you simply paying a premium just to stop your hands from shaking?”
Confusing Emotional Relief with Risk Mitigation
Breaking the corporate obsession with safety nets starts with understanding a biological truth: the human brain is hardwired in a certain manner.
Ramesh explained that the brain is an evolutionary machine optimised for one primary task: immediate survival. It was designed to flee from predators, not to perform statistical analysis or macroeconomic forecasting.
When faced with unexpected market shifts, sudden client silence, or disruptive technologies, our biology does not recognise the friction as a strategic variance. Instead, the amygdala processes that uncertainty as an imminent physical threat, generating a physiological wave of cortisol and anxiety.
Because the brain detests sitting in discomfort, it demands an immediate resolution. The cognitive glitch occurs when professionals respond with the fastest available control just to feel secure. The result is a flawed approach to enterprise risk management that merely treats emotional distress rather than solving the underlying business vulnerability.
“We treat our internal emotional symptom, and we misinterpret that relief as having cured the external operational disease,” Ramesh noted.
“To build true resilience, you have to learn to override this basic biological hardwiring.”
Separating Risk Controls From Actual Security
Ramesh drew a sharp line between enterprise and operational risk management to clarify what effective risk mitigation actually looks like.
“Enterprise risk management is all about achieving organisational objectives and improving the quality of decision-making,” he shared.
“Whereas the definition of operational risk management is the risk of loss arising from inadequate or failed processes, systems, people, or other external events.”
Risk treatment should never aim to eliminate all uncertainty or avoid every possible failure. That is zero-risk bias in action, creating a mere illusion of safety. Organisations often stack compliance policies, software, and audits, mistaking this accumulation for genuine risk controls.
“An organisation can become heavily controlled without necessarily becoming safer,” Ramesh noted.
“Visible activity should never be mistaken for genuine control effectiveness.”
As such, the dichotomy between managing uncertainty and buying comfort exposed the stark difference between actual security and emotional peace of mind.
True risk management is proactive and fact-driven; it lowers the statistical probability of a negative event or drastically limits its fallout.
Conversely, buying comfort is an emotional, reactive transaction. Organisations pay an operational premium in capital, time, or agility, leaving the external hazard completely unmitigated.
When Risk Controls Become Expensive Reassurance
Often, the first few risk controls provide the most protection. However, constantly adding new ones eventually leads to diminishing returns.
Take cybersecurity as an example. An organisation might already have measures in place: multi-factor authentication, endpoint protection, Security Operations Centre monitoring, among others.
Adding another costly software tool or forcing staff to change passwords every month may not materially reduce overall exposure. Meanwhile, issues like staff skill gaps or poor governance remain unresolved.
Rather than making the business safer, these extra layers create an illusion of safety. As Ramesh explained, “At some point, each additional control may reduce only a very small amount of risk, while adding significant cost, complexity, and operational burden.”
To know if an organisation has crossed the line from value-driven enterprise risk management into expensive reassurance, decision-makers should watch for three red flags.
- The Cost-Benefit Flip: When implementing, maintaining, and auditing risk controls costs more than the actual financial impact of the threat itself
- Operational Friction: When too many approvals cause bottlenecks, delay projects, and slow the business down
- Cultural Disengagement: When complex rules frustrate employees, forcing them to find unsafe workarounds that actually increase hidden vulnerabilities
Moving From Compliance Checklists to Value-Driven Risk Governance
To establish robust risk governance, organisations must shift their approach to enterprise risk management by moving away from a traditional mindset where the default response is simply adding more controls and towards value-driven thinking.
The ideal approach evaluates which combination of controls creates the best balance between protection, cost-efficiency, and resilience.
“Risk management should support performance, agility, strategic execution, and long-term sustainability. It should not become an obstacle to them,” Ramesh shared.
To put this into practice, the Chairman of the Board of Governors of the IERP® laid seven considerations before implementing new risk controls:
- Does this control materially reduce risk?
- Is the cost of the control justified?
- Is the control sustainable?
- Does the control solve the root cause?
- Is the control a duplicate?
- Are people bypassing the existing process? Would strict enforcement be more effective than imposing a new control?
- Does the control improve resilience or only perception?
Optimising Controls in Enterprise Risk Management
Risk treatment is inherently dynamic. A control that effectively mitigated threats five years ago may no longer align with current market conditions, shifting business models, or an organisation’s evolving risk appetite.
Rather than allowing legacy policies to remain out of habit, enterprise risk management requires organisations to regularly review their risk registers and conduct risk and control self-assessments. Crucially, these must be executed using separate, dedicated templates to avoid conflating the two processes.
As Ramesh emphasised, “Organisations need to continuously evaluate effectiveness, relevance, efficiency, and unintended consequences. Controls need to evolve with strategy, operating models, and the risk landscape, not remain in place by default.”
For a smarter approach, he shared four considerations:
- Align on Priorities: Focus on critical risks, high-impact exposures, key vulnerabilities, and business critical controls.
- Invest Correctly: Invest where the value of mitigation is clear
- Avoid Control Accumulation: Avoid layering controls without strategic purpose
- Avoid Reflex Responses: Treat risk mitigation as an investment decision, not a reflex response
Key Lessons For Risk Leaders
Enterprise risk management should protect value and enhance strategic decision-making, rather than serving as an expensive coping mechanism for executive uncertainty. To build genuine operational resilience, organisations must transition from reactive compliance checklists to dynamic, value-driven governance.
Override Biological Reflexes
Recognise that mitigating internal anxiety with rapid, visible activity often provides a mere illusion of safety while leaving the actual business vulnerability completely unresolved.
Recognise Diminishing Returns
Avoid harmful accumulation of risk controls by remaining vigilant against critical red flags such as the cost-benefit flip, escalating operational friction, and widespread cultural disengagement.
Adopt Value-Driven Risk Governance
Critically evaluate whether every proposed policy materially reduces exposure, addresses the root cause, and clearly justifies its financial and operational burden.
Maintain Dynamic Treatments
Regularly conduct risk and control self-assessments using dedicated templates to ensure mitigation strategies actively evolve alongside shifting business models, changing market conditions, and an organisation’s evolving risk appetite.






















