After spending seven years in the private sector, Reynold Anak Johnny Nagat transitioned to the Sarawak Civil Service in 2013.
Key Insights
- Transitioning from internal audit to enterprise risk management requires abandoning a retrospective compliance mindset for a forward-looking approach that aligns risk with organisational strategy.
- By reframing risk from a compliance burden into a strategic enabler, professionals can break out of operational silos and use frameworks like ISO 31000 to safely drive real-world objectives.
- Advancing into a strategic advisory role means trading the retrospective “rear-view mirror” of internal audit for a forward-looking risk mindset that actively creates value and enables others to succeed.
Reynold Anak Johnny Nagat’s career journey has not been straightforward.
“My journey has been a bit of a hybrid: one foot in audit and the other in risk management,” he shared.
Reynold built his foundation over seven years in the private sector, where internal audit roles taught him strict discipline, attention to detail, and how to read between the lines of financial operations.
Upon joining the Sarawak Civil Service in 2013, he continuously audited agencies from the very beginning of his government career. “Over time, as the service evolved, I began integrating enterprise risk management into my portfolio within the same department,” he said.
Earning his Enterprise Risk Manager (ERM®) and Sustainability Risk Manager (SRM™) certifications from the Institute of Enterprise Risk Practitioners® (IERP®) solidified this dual expertise, giving him the exact framework needed to merge audit precision with risk optimisation.
Today, as Principal Assistant Director in the Department of the Premier, Reynold oversees both compliance and risk. His mission surpasses traditional auditing; he ensures the organisation achieves its objectives safely.
Integrating Internal Audit with Enterprise Risk Management
For many practitioners, internal audit takes a rear-view mirror approach. It casts a retrospective look at past transactions or processes to find gaps and report on what went wrong.
Reynold spent his early career mastering this discipline, viewing risk strictly as a threat to avoid. “My job was to find the gaps, point out the non-compliance, and recommend controls to shut the door. Risk was negative,” he said.
However, taking on broader responsibilities within the Sarawak Civil Service shifted his perspective entirely. By integrating enterprise risk management into his work, Reynold transformed his approach from retrospective gap-finding to forward-looking advisory.
When sitting on the Tender Committee, his focus now looks beyond basic compliance. He asks a better question: Does this investment move the department closer to its strategic objectives, or does it create a future liability or asset?
“The compliance part is still there. I’m not throwing the rulebook out the window, but it’s now a baseline, not the final goal. The goal is strategic success,” he shared.
This dual expertise in internal audit and risk management allows him to protect value while actively creating it. For example, a new digital initiative carries data security risks, but it also presents a valuable opportunity to serve the public more efficiently.
Driving ISO 31000 Risk Management Adoption
Scaling this forward-looking approach across the Sarawak Civil Service meant introducing enterprise risk management based on ISO 31000 to bridge a critical gap in value preservation.
As stewards of public funds, Reynold recognised that agencies needed a clear map connecting governance frameworks to real-world outcomes. “We were often busy being efficient with paperwork but not always effective with outcomes,” he noted, aiming to equip teams to become value drivers rather than just administrators.
However, driving this cultural shift met immediate resistance. Agencies relying on legacy ISO 9001 Quality Management Systems viewed the new standard as a redundant chore.
“When I came in advocating for a structured enterprise risk management framework, it looked like duplication to them,” Reynold explained.
To overcome the hurdle of adopting ISO 31000 risk management, he deployed a dual-pronged strategy: grassroots education backed by top-down endorsement.
Before seeking formal approval, Reynold conducted over 20 awareness sessions. He reframed the conversation, clarifying that while ISO 9001 protects quality, ISO 31000 safeguards the organisation’s broader strategic objectives. Instead of fighting existing processes, Reynold showed teams how the methodologies complemented each other.
Coupled with a powerful endorsement from the State Secretary, this persistent education successfully transformed the ISO 31000 enterprise risk management framework from a perceived compliance burden into a strategic enabler.
Shaping Risk Culture in Daily Operations
Shaping a healthy risk culture in daily operations starts by bringing a forward-looking mindset into every conversation.
Reynold puts this into practice across three main areas: managing internal audits for state agencies, offering strategic risk consulting, and evaluating procurement as chair of the Committee of Tender. In every role, he pushes teams to look past the regulatory minimums and ask if their decisions actually support the organisation’s goals.
Balancing these tasks while navigating the typical waiting periods for top management decisions requires clear communication. To keep teams moving without burying them in bureaucracy, Reynold uses a layered approach tailored to what the teams need.
For urgent, real-time coordination with risk coordinators, he relies on WhatsApp to bypass slow email chains and uses shared Google Calendars for clarity on the rhythm of the week.
For operational alignment, he runs 10 to 15 minute stand-up discussions. Teams stand, state what they are working on, flag any roadblocks, and move on. This fast tempo keeps everyone on track without draining productivity.
Aside from communication, Reynold balances his workload by filtering issues through the lens of organisational objectives. Tasks that are important but not urgent are scheduled into long-term planning. Urgent but unimportant matters are delegated, while anything both urgent and important is escalated immediately.
“You can’t manage risk if you’re drowning in the day-to-day,” Reynold explained. “You have to carve out time for deep work, which is why I guard my bi-weekly strategic meetings jealously.”
These one-to-two-hour sessions give his team the space to navigate the nuances of dealing with stakeholders and their views on enterprise risk management.
“We discuss how to reframe the conversation from compliance burden to strategic enabler,” he added.
Building a Career in Enterprise Risk Management Beyond Internal Audit
For professionals looking to build a career in enterprise risk management, Reynold offered three guiding principles.
First, remain humble. In complex organisations like the Sarawak Civil Service, assuming you know everything quickly turns you into a liability.
Second, cultivate a enabling mindset. Whether assisting a junior officer or advising top management, true leadership focuses on enabling others to succeed rather than chasing personal glory.
Lastly, and the advice Reynold deemed the most important, avoid getting trapped in a single operational silo. While foundational experience in internal audit builds essential discipline, progressing into an advisory role requires actively broadening your expertise.
For example, Reynold deliberately expanded his toolkit to include enterprise risk management and sustainability, intentionally transforming his career trajectory.
“Had I stayed purely in the ‘checking’ mentality, I would have missed the opportunity to become a strategic advisor,” he said. “The more tools you have in your belt, the more valuable your counsel becomes.”
A Risk Culture That Extends Beyond the Office
Building a resilient risk culture isn’t just a 9-to-5 requirement; it becomes an ingrained mindset. For Reynold, this philosophy of keeping things simple and objective-driven extends outside the walls of the Sarawak Civil Service.
Even his hobbies reflect this perspective. An avid gardener, he finds deep fulfilment in nurturing plants from seed to harvest, where protecting crops from pests requires its own practical form of everyday risk management.
But his true passion is backwoods cooking. Preparing meals over an open fire with minimal equipment strips away the bureaucracy of daily governance, yet perfectly reinforces the core principles of enterprise risk management.
“It reminds me that even in a world of complex policies, frameworks, and risk registers, you can create something wonderful with just the basics. It all comes down to understanding the elements and staying focused on the objective” Reynold shared.






















