Do your leaders actually care about risk management?


Leadership buy-in means acting on what risk management uncovers, not just having a process for it.
A pitch built on numbers survives leadership far better than one built on instinct.
Buy-in only lasts when risk becomes part of how the company already works, with a named owner and a regular check-in, not something leadership only remembers during a crisis.
Time is of the essence when disaster strikes. Most leaders wait for the full picture before acting, but by then, the damage is already done.
In 1982, seven people in the Chicago area died after someone laced common medicinal capsules with cyanide. A full investigation was launched, but with no time to waste, the company behind the product pulled 31 million bottles off shelves nationwide, losing over $100 million..
That decision came from the top and fast. And it's still taught in business schools today as the standard for how leadership should respond when risk turns real. More often, when something goes wrong, the story afterward is about how long leadership knew and did nothing.
So why don't more leaders step in like this?
Most leaders don't reject risk management outright. They just don't treat it as urgent as they should.
Risks can contribute to the bottom line of most organizations, and if repeated, they could hit really hard. Which is why leadership really needs to step in and invest in risk management.
Research from the American Institute of Certified Public Accountants (AICPA) AICPA and NC State University's 2025 State of Risk Oversight report found that only 35% of organizations have a comprehensive enterprise risk management process in place, meaning most companies still don't have one system covering risk across the whole organization. Meanwhile, 32% would call their overall risk oversight strong and solid.
The research also found that only 10% of organizations say their risk process is mostly a strategic advantage, and just 1% say it's extensively one. That's the gap leadership is missing out on. Most companies have a risk process. Very few have one that actually changes a decision.
According to Mark S. Beasley, director of NC State University's Enterprise Risk Management Initiative, a few reasons keep showing up:

4 reasons leaders struggle with risk management
Overconfidence: Leaders think talking about risk occasionally is the same as actually managing it.
Resistance to negative conversations: Risk discussions feel discouraging, so they get avoided in favor of more optimistic conversations.
Seeing risk as competing with priorities: Leaders see risk management as competing against growth for time and budget.
Leaders don’t want to hear “no”: Leaders resist pushback on their plans, especially when it comes from someone lower than them.
None of these reasons are really about risk itself. Rather, they're about where leaders choose to spend their attention, and what happens when risk management doesn't compete well for it.
When persuading a higher up, you have to think like one. A pitch built on instinct rarely survives contact with leadership, but a pitch built on numbers usually does.
The fastest way to get an executive's attention is to connect risk directly to something they already care about, like revenue, valuation, or a strategic goal. A risk management program that only tracks incidents just shows what already went wrong. On the other hand, one that tracks avoided losses shows how much the company is saving.
Estimate what inaction costs. Some of that cost is financial, some of it isn't. How much would downtime actually cost? What's the safety risk to employees if this goes unmanaged? Factor in regulatory exposure and reputational impact too. Giving leadership a concrete estimate, even a rough one, gives them something real to weigh against the cost of the program.
Leaders love data. A chart showing "risk exposure decreased 15%" means little on its own. A short before-and-after narrative helps. Showing what nearly went wrong and what changed once it was caught, gives that same chart a reason to matter. The story is what makes the leadership team remember the number after the meeting ends.
Simplify risk management and compliance with our centralized platform, designed to integrate and automate processes for optimal governance.
A single successful pitch to leadership doesn't create lasting buy-in. It creates a temporary spike in attention that goes away once the next priority shows up. Buy-in only sticks when risk becomes part of how the company already works, not something leadership only remembers during a crisis.
Many boards only revisit risk when something forces the conversation, and it's rarely clear who even owns what gets flagged. Checking in regularly, and assigning a named owner and deadline to every risk, keeps risk visible before it becomes a problem. Digital tools can handle both, tracking risk in real time and keeping ownership visible so nothing stalls.
SSP, one of the largest food and beverage providers across Australian travel locations, uses SafetyCulture to spot compliance gaps it couldn't see before. Now, compliance went from 60% to nearly 100%.
We can change our safety culture through SafetyCulture. We’ve experienced firsthand what happens when we hone in on the quality of our inspections.
Important notice
The information contained in this article is general in nature and you should consider whether the information is appropriate to your specific needs. Legal and other matters referred to in this article are based on our interpretation of laws existing at the time and should not be relied on in place of professional advice. We are not responsible for the content of any site owned by a third party that may be linked to this article. SafetyCulture disclaims all liability (except for any liability which by law cannot be excluded) for any error, inaccuracy, or omission from the information contained in this article, any site linked to this article, and any loss or damage suffered by any person directly or indirectly through relying on this information.