Skip to content
The Sector Debrief Listen
Episode 8 · Guest conversation

Rethinking Risk Management in the Humanitarian and Development Sector

9 June 2026·55 min·with Sabrina Segal

A conversation with Sabrina Segal, Director of The Risk Collaborative, on what risk actually is once you stop treating it as compliance. Sabrina, Kim Kucinskas, Thomas Jepson-Lay, and Ali Al Mokdad work through risk as the effect of uncertainty on objectives, which means threats and opportunities, not a register of bad things that gets dusted off once a quarter for the trustees. The conversation moves from why so much of the sector still does risk as a tick-box exercise, to risk sharing instead of risk transfer (a woven rope, not a chain where the weakest, least-resourced link is the one expected to break), to using the language of risk as a Trojan horse to get localization and power-balancing into the rooms where funders actually sit. It closes on what Ali Al Mokdad calls the generational fight: clearing out the outdated governance and process so the sector can focus on the problems that matter.

RiskRisk SharingLocalization

Transcript

Every timestamp opens that moment in the video, which is the record. Spotted an error? Tell us and we will fix it.

Cold open, clips from later in the conversation

0:00

there's a tendency to repeat pattern behavior to revert back to what worked before even if it doesn't necessarily apply directly to the scenario that you're you're working with. as a because I mean even as you were talking I was thinking of like traditional risk is more linear right it's like a to b risk issues etc but what we all talk about all the time is more a more holistic view of how everything works because there's people there's all of the systems and

0:27

that's what we have to get done all those nonsense about risk management compliance processes some random things and structures we have to deal with this we have to fix it we need to focus at the big issues risk see risk we could do it with risk Who knew that risk was going to be so, you know, energizing? I did, but no,

0:55

we'd like to start with maybe a bit of an open question, see where you go with it. Um, how do you spend your days? That's like a long elaborate question right now. You know, I'm a cancer. I like long walks on the beach. No. Um, so how do I spend my day? Well, um, so thanks for having me on the show. uh longtime listener, first- time caller. Um I am uh how do I spend my day? So I am the director of an organization called the risk collaborative. It's a nonprofit initiative that is focused on supporting um all organizations in the third sector on improving their risk management approaches and thinking and methodologies and frameworks and tools and whatever you want to call it. Um, so I typically spend most of my day right here at my desk um, chatting with people um, in lots of different places about their organizations and trying to help them think a little bit differently about risk.

Um, I just had a conversation with somebody last week who was like, "We really like what you do, but we think that your approach to risk is a bit too strategic." And I wasn't sure what to do about that. So I posted on LinkedIn and the LinkedIn community has helped me figure that out. But um yeah, I do a lot of um of writing and I do a lot of workshop facilitation and I just do a lot of kind of working with teams that are a bit on the fringe of their organization. So like innovation teams or um even new business development teams to kind of try and position their organizations in a way that they think about risk differently. Um, from there then we're able to kind of jump off into how does this impact things like risk sharing concepts or localization or uh rebalancing the power, you know, all those conversations and you can do a lot of that through the lens of risk.

Um, so I also have two small kids and as I was Thomas and I were talking about earlier, I'm doing a doctorate. Um, so you know, got a lot going on.

Accused of thinking about risk too strategically

2:34

So you don't believe in sleep is what you're saying. [laughter] No, come on. Especially if you have small kids, you know this game. Like there's there's no sleep and you certainly can't get sick. So I mean, you know, what's that all about? I got um really intrigued there when you said you were accused of thinking about risk too strategically. Um and you said you responded in the post in a certain way, but behind the post, how did you feel? How did you respond? What was your reaction to that accusation?

Sabrina Segal3:03

As I said in the post, I kind of, you know, I said thank you and I and I laughed um you know, genuinely. And for me what it was it was really a great um snapshot into again how so much of the sector thinks about risk. They think about it in a very traditional um compliance way as opposed to thinking about it as strategic and how it can help organizations make better decisions. Um the type of risk approach that I take is we start with what is the organization trying to achieve. So we start with objectives and whether they're strategic objectives or a project objectives or a team objectives that's where we start and then we do the risk analysis out from there because the traditional approach is quite kind of negative.

It's all risk list you know all the horrible things that might happen and then you do this quasi math impact likelihood kind of nonsense and you come up with something that's 83 lines long and people only look at once a quarter when they have to dust it off and give it to the trustees. Um you know so it's like it's not super helpful. Um, and so I think, you know, the folks that I were was talking to originally were like, "Yeah, we want to do risk." And I started talking to them and then they were like, "Oh, no. Oh, no, no, no. This is not what we want." And it was like we they want compliance, right? They want somebody who's going to go through, look at all the regs, say, "This is exactly what we have to do.

Build me a tick box and then I can go and repeat that." That's important. It's all well and good, but that's not risk.

Expanding the definition of risk

Kim Kucinskas4:19

So, you really are expanding the definition because I mean, even as you were talking, I was thinking of like traditional risk is more linear, right? It's like a tob risk, issues, etc. But what we all talk about all the time is more a more holistic view of how everything works because there's people there's all of the systems and the way I when I was just listening to you talk I'm thinking about well what is the risk of missed opportunities

4:44

what are the risk of you know all of these different things and if we can start to balance that it becomes a lot less linear but that is uncomfortable. Yeah, I mean I think you know the definition of risk that I use is the International Standards Organization. It's ISO 31000 and I love it because it is six words. It's the effect of uncertainty on objectives. That's all it is. So, you know, uh when people are trying to fit uncertainty, which like you were saying, Kim, is very, you know, it's it's complex. I posted something on LinkedIn the other day about a double pendulum. Um if you've ever seen a double pendulum swing, it's fascinating. You can like stare at it for hours. um it follows all of the laws of physics.

It's not broken. Um it is something that you can mathematically work out. Problem is that because it has so many variables, even just in a double pendulum, it's impossible to predict. So you can explain it once it's done its thing mathematically, but you can't predict the way it's going. That's the environment that most third sector organizations work in, right? We work in complex or complicated depending on you know kind of your 2 by two quadrants that you look at environments with lots of moving parts and oh by the way we're dealing with human beings. We're not dealing with manufacturing which you know is a little bit easier to predict. Um and when you throw humans into that you know kind of you know stew and soup.

It's it's it's something that really I think is fascinating but for people who really like prediction and like stability it can be difficult for them. Like you said Kim it can be uncomfortable. So, I've got to say, so now I've never heard of that definition of risk before. And now it makes sense to me why you and I often have the conversations that we do because I'll be honest with you, I mean, Hanum works in operations and I often think of risk in the compliance bucket, but right now I'm working on this methodology that we're I'm kind of putting together that's literally about helping people bridge build the capacity to make decisions and take action when the future is uncertain. And that's exactly what you just said.

So, this is a cool methodology to help people do that. But I love how what you've said in the past, which is that risk is a very accessible entry point to this conversation because it can feel very big and scary for people, but when you go in through the entry point of risk, people are like compliance, you know, um there are real tangible uh incentives for people to have that conversation. So, if that's the entry point to a broader conversation, I mean, so be it. Yeah, and I think that it's really important now. Oh, sorry. Go ahead, Ellie.

What risk oversight means in practice

Ali Al Mokdad7:10

No, I just wanted to supplement what Kim mentioned because I also think risk management or risk oversight means different things depends on which level you are working in. If you are let's say at field level, area level, it's more around access, safety, security. You move to country level, it gets a bit more around compliance and overall let's say organizational positioning and how they would deal with local partner and how they define risk and all that. you go to HQ, it is strategic uh risks, enterprise risks, reputational risks and all kind of like different type of risks in that category. Yes, maybe the approach toward overseeing it is the risk register or risk matrix or that nice flashing Excel sheet but in the end of the day it does means different things to different people depends on where you are sitting.

Sabrina Segal7:56

So I agree with that. think that's the way that we have traditionally done it and actually if you look at some of the literature that's been coming out over the past goodness now I would say maybe five years or so um particularly when the grand bargain kicked off their workstream around risk sharing right you can see that mapped out in the data that there are different threats now I'm going to back up here a little bit when we talk about risk is a two-sided coin one side is threats but the other side is opportunities because remember if we go back to our definition the definition is the impact of uncertainty on objectives and uncert Certainty can be positive or negative, right? If you ever gambled, you know you can win big, but you can also lose big.

So when we look at threats and opportunities, depending on where you sit, you'll be looking at different threats and opportunities, right? Your funders are really focused much more on reputational risk. Your intermediary partners are really much more focused on kind of operational, legal, financial risk. And like you said, Ellie, your frontline delivery is usually most concerned about safety and security. Um, you know, they're concerned about uh participant or beneficiary selection, things like that, right? Um and so the thing is that people are looking at the same what we should be doing is we should all though have the same objective. So we should be looking at the same thing but from slightly different facets and by approaching risk this way we're actually getting a holistic view on it.

So there's an activity that I do with organizations that I do workshops with um about around objective centered risk management and we end up building it's really a systems map um but they don't know they're doing systems because if I start saying look you're doing systems thinking it'll kind of freak everybody out. So we just have fun with like colors and we turn something into, you know, kind of a big thing on a on a mural board or in person. But they start with the objective, right? And then we ask them, what's going to prevent you from achieving your objective and what's going to assist you? What's going to accelerate the achievement of your objective? Traditional risk thinking is only negative. We lose 50% of the of the picture when we only go negative.

The other thing I like to say is if you work in this sector, you can't be a pessimist, right? Only a pessimist. You've got to be somewhat of an optimist, right? You're either an optimistic optimist, you're an optimistic pessimist, you're a pessimistic optimist, but you cannot be a pessimistic pessimist and work in this space. So, if we're only asking staff to look at the negatives, we're losing, you know, half of their creativity and their problem solving and their decision-making like you were saying, Kim,

10:09

Ali and I were just messaging, was it a week ago, Ollie? And I was kind of complaining to him and I was like, it's so hard to be a pragmatic optimist these days. [laughter] Yeah. But yeah, I mean, but you're in the space because you want to make, you know, either your community or your neighborhood or your country or the broader world a better place. And we love that. That's why we're here. That's what gets us out of bed every day. You know, I'm a lawyer by training. If I was interested in money, I just would have gone to help rich people argue about things, right? But I wanted to use my powers for good instead of evil. So, here I am talking about risk with you guys.

When everyone is meant to share objectives

Thomas Jepson-Lay10:40

Um, I want to come back to what you said about objectives and everyone having the same objectives. I remember working once with someone who was doing something phenomenally innovative um and it was you know groundbreaking in terms of what the aid sector does wasn't necessarily groundbreaking in terms of technology or initiatives been done many times by other organizations in other industries but for the aid sector it was really innovative um but as a result it was really straining the control compliance mechanisms and measures that we had in place and so it was asking forcing the organization to ask so many questions about its own way of being almost. It was bordering on existential, although no one talked about it in that way. But it was certainly challenging and asking some naval gazing questions around who are we, what are we, how what do we do, um why do we have things set up in a certain way?

And what became fascinating was that a small group of people from the headquarters um took it upon themselves self-appointed uh came together as a as a group to kind of oversee the risk management of this of this initiative and their stated objective was to safeguard the interests of the organization and subsequently that came into direct conflict with the kind of objectives of this innovative approach and they were so obviously that was trying to serve people and give it was in a refugee setting and so they were trying to help refugees get a foot up on the ladder and this group came together and was very much sort of putting barriers up or it felt like the perception was that they were creating barriers for this project to proceed.

And so my question, my thought when you made these then sort of objectives, you stated it or said it in a way that kind of assumed that everyone has the same objectives when they're working. Um, and that's not always the case, especially when we talk about risk, when we come up against risk. I've personally had a an experience working in the TIGRA conflict response where we had sort of competing risks to manage here on you know whether you speak out or whether you safeguard operational access and that's going to have been a common dilemma and pragmatic approach that organizations will have faced daily um in many scenarios and increasingly so as conflicts go in a more politicized way. Um, so there's one example of where competing objectives start to speak in my example a minute ago on the on the project.

I just wonder what your thoughts were on when how risk can be conducted when you're you're talking about competing objectives.

Sabrina Segal13:24

So that goes from sort of your external and internal kind of um analysis to purely an internal analysis. And this has actually happened to me several times when I've facilitated workshops because when I do workshops, I use real objectives from the organization. I'm not going to use a hypothetical, something that people may not have any connection to. I use a real objective. But what happens every once in a while, even when I say, "Does everybody know what this objective means?" And the people that I'm talking to go, "Yeah, yeah, yeah, totally." I'll put it up on the screen and half the room's like, "Yep, totally got it." And the other half's like, "I've never seen this before. What is this talking about? I don't understand the vocabulary.

Like, where are we with this?" And it ends up being a lot more of like a therapy session than it kind of is a risk analysis session that highlights internal risks that you have whether it's with internal communications, internal governance, like whatever it is. Um, you know, it highlights things. What I found with the type of risk approaches that I take is these sit more comfortably in the strategy space than in the operation space because what you actually are trying to do is test these objective hypothesis, right? Because when you set an objective, it really is a hypothesis. If it's something that you've already done, it wouldn't be an objective, right? So it's something that you are aspiring to do. So if you actually do the risk analysis while you're developing the objective.

So while people are understanding what it means, how you're going to deliver it, what the impact is going to be, if you build the risk analysis in with that, you're bringing everybody along with you. And so I advocate for doing your risk analysis upstream when you're developing the objective um for a lot of reasons. One, again, kind of you're able to bring people along with you. they understand things and they're going to be able to position themselves, their skills, their units, their resources in a way to help achieve that objective. But another reason is because the methodology that I use is very practical. There is an element of budgeting in it. Uh once you identify your preparation elements that you are going to take in order to address the opportunities and the threats, we price those and those need to then be put into either your organization's operational budget or your proposal that you're submitting to a funer.

Now, the advantage to doing it this way is that you have data to then defend your budget because we all know budgets get submitted to funders and they get the red pen out and they start going through things left and right. And they may not really understand what they're cutting, but when they start to do that, you can then go back to them and say, "But we did this risk analysis." And if you frame it as a risk analysis, it gives it more weight, right? We did this risk analysis. Now, if you're cutting these elements, we're not going to be able to provide the assurance that you'd like us to or be able to achieve the objective as we've described. So, we have two options.

One, right? You can give us the additional resources and we can go after the objective. Or two, we'll need to shift the objective. What would you like to do? And a lot of times the funders find the resources or they better understand why you asked for it. Um, you know, and other times they say, actually, this is all we have, so let's go and adjust the objective. But either way, the organization is then in a much better negotiating position. The power hasn't been shifted, it's been balanced. And that's what we actually want to do. Shift the power, I think, is a great slogan. I don't think it happens in reality. Balancing the power. We can do that. And this is one way to do it.

Where the room to get creative is

16:24

I love the way you've brought in the notion or the possibility, the opportunity for becoming creative um and curious when you're talking about the objectives and framing it through risk and giving it that waiting seems to be a way of playing the game. And that's a whole debate on whether the game should be played uh versus just we have an environment and we live and work and operate in a space where um you don't need to play the game. You just live. Um and it comes down to me there the opportunity the reality behind failure and accepting failure and being willing to fail and failing forwards as a management spiel term for something but I think it highlights the point particularly well and I just wonder when we're talking about the different approaches to risk management and the purpose behind managing risk we get to sort of executive senior leadership level decision making.

Um, and if there isn't an appetite, an environment within an organization to fail, to enable, to enjoy failing forwards, then you're going to create an environment where you bottleneck decisions in executive leadership. and executive leaders, particularly when it comes to points of conflict, points of tension, points of uncertainty, points of high risk, there's a tendency to repeat pattern behavior, to revert back to what worked before, even if it doesn't necessarily apply directly to the scenario that you're you're working with. There's a sort of safe thinking that you can't be criticized for something that worked in the past. And so where does the where does your view on risk visav intent and appetite for failure sit?

I mean it's it's a huge element like we have in everyday um life right we don't want to fail even if it's something small right um it takes a real effort to have a mind shift to safe to fail kind of that safe to fail thinking um uh a lot of this can go back to your organizational culture right and so I do a lot of organizational culture work around risk number one again because it's already been shown um that when you have an organization where you have a speak up speakout culture you're very you know nuts and bolts risk to like your fraud reduction and your safeguarding reduction and stuff like that goes up because people are willing to speak up and say hey something's not right here and they feel safe doing it right so on a practical level that improves on a practical level when you have a speak up speakout culture you also have better um creativity more innovation people are willing to suggest ideas that maybe hadn't been done before and a lot of times those ideas are probably better than what we've been doing for 30 years right but again they feel that they have a safe space to do that and they won't be uh punished or retaliated against or kind of harmed in any way.

Um when it comes to senior level, you know, so I'm a trustee on a on an organization uh for a charity and I've also worked very closely with trustees. I've reported to trustees as head of risk. I also work with trustees in some of the training programs I run. Um and that is really a very interesting multi-dimensional dynamic too because you typically have you know what, six, seven, eight, nine trustees. They all have their own personalities. Then you have your executive team which you know is two, three, four, five, six people depending on how big your organization is and they all have their own personalities. The consistent thing that I've found though is that information that may be unwelcome or perceived as unwelcome tends to get um you know the word that was told was sanctified as it moves up through the organization, right?

So the pointy edges end up getting sanded down. So, you may have a middle manager who's like, "Red flag. This isn't going to work out." By the time it gets to the board, it's like everything is, you know, puppy dogs and ice cream and unicorns and aren't we great. Um, because usually it's that senior level of management that wants to show the board that they're everything is going well. I worked with an organization who was trying to do some systems change work, right? I'll leave it at that. They had been trying to do it for, you know, seven years, spent a ton of money on it. It wasn't going anywhere, right? Um when the leadership was asked why are we continuing to do this? Why aren't we trying something different?

The response was well we promised the board that we would do it. Um and I see this so often particularly when I do strategy work with organizations when you have that typical fiveyear or six year strategy that people put down on paper all of a sudden they're handcuffed to it. their free will, their ability to make decisions goes out the window because they've got something on, you know, on a piece of paper and two years into their strategy, they'll go, "Well, crap, man. This isn't working, but we have to keep doing it for the next three years because we committed to a fiveyear strategy." And so, one of the things that I encourage organizations to do is actually do a three plus three, right? Do a three-year strategy, plan a reflection in the middle, and then move on to your next three.

So, when you're doing your strategy development, spend a lot of time and detailing around your first three years. plan in a reflection and then have a general direction for those second three years. Once you get through those first three years, you're going to have a pretty good sense of where you are. You're going to have that reflection. Then you can have the ability, you give yourself, even though you don't really need it, but mentally people give themselves that ability to pivot for that second three years and then you build your three years on from that and it becomes it almost builds in this flexibility that we naturally have, but we feel like when we put something on paper, we can't make these decisions anymore. So, it's it's huge culture stuff and you know, usually when I go into organizations, one of my biggest um cheerleaders is the people and culture team, the HR team, which is really funny to me because they tend to want to do these things.

They see these things. They see burnout. They see people are stressed. They see people are, you know, reporting the same repeat offender for retaliation or whatever, and the organization isn't changing. And when I come in and I start talking about it through risk, they go, "Oh, we can hook on to that because they'll take you seriously, but they're not taking us seriously anymore." And actually, yeah. No, we've talked about this and this is I love this so much because as you know a lot of this the work that I do is spent thinking about how what we can learn about complex and collaborative change right and like it's real sticky it is it's challenging stuff and a lot of times people are getting stuck on it right now and so we've talked about finding the cracks of opportunity for change right so when you can't just kind of go in and say we're going to change everything from a from a psychological perspective.

What are the cracks of opportunity and how do you get in there and kind of um and kind of embed yourself? And you said this before, Sabrina, and I thought it was so it's so practical, which is why I like it. People understand the language of risk and they listen to the language of risk. So if I go in with like squishy psychology and culture and like you know mindset change people kind of glaze over systems change they like run away. But if you go in with the language of risk people understand that especially people in power understand that. So talking about a crack of opportunity if you can reframe whatever you're trying to change using the language of risk and using your definition. It's such a holistic definition that you really can do it in good conscious.

You're not trying to trick anyone. um it's just an a really interesting entry point and I do think it changes how pe the how people will perceive it and then the actions that they're able to take. So um I have been thinking about that quite a bit recently about how even in my own world to kind of code switch and it is code switching. So for anyone out there who doesn't live in the world of risk it is does feel like code switching for a little while.

Three things noticed about risk last year

Ali Al Mokdad24:10

Yeah. three things I noticed last year especially last year when it comes to risk management. The first one it was the card that been used over and over again whenever the conversation goes toward localization or working with local or national actors. The second thing I also noticed that when international nos's they started doing the restructuring organizational change XY Z at global level one of the roles that they started cutting from the structure was this risk management adviser risk management specialist operations advisor XY Z and later on they realized that oh now who's leading that who's providing advice on that etc and then they wanted to go back to that and try to fix it and the third thing is not is not like um an observation.

It's something I also used when I was working at country level. If you want to get some attention, especially if you are country, you want to get region or HQ attention, you brand it as a risk. So if you need support at program level or access level or you need someone to be deployed from HQ to provide some kind of training or check something or you just brand it as a risk. You say we have operational risk, we have program related risk, we have XY Z risk and then you get attention. So I also think that sometimes it's overused but other times it's a political tactic to get some kind of attention from region or HQ if you are working at that level.

Risk as a political tactic

25:33

I'm willing to use it as a political tactic if we can get risk sharing and localization on the table. I'm absolutely willing to use that as a Trojan horse. So how do you how do you use it Sabrina when So there's a lot of I'm seeing or in organizations and in leadership kind of two different ways of responding at this point. The first is um I think Thomas mentioned this, people are just defaulting. They feel like they need to act. They're not pausing and they're defaulting to action, but that means that they're going with what they're used to, right? What might have worked five years ago is probably not going to work right now, but that's what they're comfortable with. So, they're kind of going with that.

And then the second is analysis paralysis where people are just so overwhelmed they're stuck and they're kind of frozen. They're still in that bunker mode. um how do you use risk to get to have people make decisions but like intentional deliberate values-based decisions because that's what get that's what's getting to your like rebalancing power all that type of thing.

26:28

Yeah. I mean, well, again, I think if we go back and we break down risk, right? So, so many people use risk, you know, they just say risk, our big arm wave, right? I really try and not to get too technical, but talk about threats and opportunities because that's what risk is. It's threats and opportunities. Um, so if we talk about people who are in analysis paralysis, reframe it around opportunities, that typically can wake people up. Well, you know, how many more children can we reach? How many more hectares of forest can we protect? How many more elderly people can we check in on and make sure that they've got, you know, food and heating oil for the winter time and things like that, right?

That typically kind of can snap people out, at least our people in the sector, snap people out of the doom spiraling, right? Let's get read them refocus them on the positive and even by just doing a um you know a risk analysis against opportunities that is valuable, right? You don't always need to look at the threat. So that's one way of kind of getting people out of that doom spiral. Um there's a really interesting Are you guys familiar with Dave Snowden and the Canvan model. Um if not definitely check that out. Yeah. Okay. You are Thompson. Yeah. Um so it's um it's he does a lot of work around um like complexity thinking and particularly complex adaptive systems um and he uses a lot of kind of organic uh language um organisms and things like that the substrate and stuff like that to just to describe it.

But that's where I think we are right now. Right. So obviously when everything happened last January, it was a shock to everybody's system and like you said Thomas, you know, people are grieving and I think people are still grieving. You see it on social media all the time, right? And I think we need to continue to acknowledge that. What people were trying to do um in the immediate aftermath of that was respond to a chaotic environment, right? So if you look at the KVan model um and I'm probably going to misquote this and so if Dave's listening, please don't get mad at me. Um, but you know with it when you're in chaos, you have to immediately react and then you can kind of pause and you can kind of regroup and then put some thinking behind it.

Um, what's interesting about chaos though is chaos doesn't last very long. Chaos eventually settles. It settles into some sort of pattern. Whether it's complex or complicated, it will settle. And so your kind of best bet is to anything that you have control over, take action. I do a lot of um organizational fragility work with organizations as well because when we're talking about threats, so much effort is put on predicting. How can we predict this? How can we predict that? And I always say don't predict, prepare. And what that means is look at where your organization is fragile versus where your organization is resilient. When you identify areas where your organization is fragile, then ask yourself, is this part fragile because it is inherently fragile and there's nothing I can do about it?

In which case we need to start talking about how we can buffer that part of the organization. So fundraising right reliance over reliance on one big funer sound familiar to anybody? That's a huge fragility for an organization and that was on people's risk registers till the cows came home. So how effective were the risk registers with diversified funding? Not very right. But if we do organizational fragility and we say look this is a fragile element. If your only funer is going to be one and that's just the way you're designed. Okay. How do you buffer that? But if you have the ability to redesign that fragile element of your organization so that it can be more resilient, do it. Right? So, so in chaos when all of this was happening, you quickly found out where your organization was fragile and you didn't have the luxury of time to buffer or build or redesign it.

Right? That's kind of where we are now, though. So, you had to stop the bleeding and now you have to kind of stand back and say, what did we learn from this? And what are we going to take that learning and apply it to moving forward? And I think that the fragility lessons are huge. people know what they are, but they may not want to write them down or say them out loud, but you know what those fragility things were when you were going through the past 18 months. Um, and then really having hard conversations about what's our mission, what's our purpose, right? Why are we here? Have we had scope creep over the past x number of years and what are we going to double down on?

And the organizations that I see that are kind of coming out of this redesign or whatever they're going to call it, um are the ones that are really being very honest about their scope and being very honest with their staff about the scope and just keeping things within that scope till they have a better sense of what the future's going to hold. So in the current climate, the current moment um when big INOS are being forced to question um how they exist and what their role is in a wider sort of ecosystem of aid and a much broader much more diverse scope of humanitarian space and actors are considered part of humanitarian space. How can the risk management conversation help navigate into a new environment, a new way of being as opposed to being too familiar a language that we continually just stay stuck in a pre-existing mindset and a kind of way of being able to just survive as we were and revert back to the way of being that we have been for decades with that global top global north top down.

Um we're looking at a status quo. We're looking at the power of kind of unilateral one-size fits-all. We're a hammer looking for a nail. Multilateral aid as an architecture being the dominant provider of the value of humanity. Um, how can we how can we shift that? And I'll go back to the example I gave earlier of this project that was being conducted. Um and the sort of subtext the plot or at least you and I may have been sort of at the end of a Chinese whisperers chain on this but the subtext to that discussion in terms of safeguard the interests of the organization was very much around that project that initiative those ideas they're going to change who we are. They're going to shift our way of being.

And that's a discomforting thought to have. Um and it challenges foundational understandings that certain people have become entrenched with and become identifying with and you can you can argue that moving forward we're not in the same space as organizations and as an industry and say it's come back to the way you framed using risk as a Trojan horse that kind of makes me feel both slightly uncomfortable but also slightly inquisitive at the same time. uncomfortable in the sense that is it not just perpetuating a norm perpetuating a status quo perpetuating a way of managing an institutionalized response in a managerialist manner and I'm inquisitive because the way you framed it seems like the philosophy you're approaching with is very much about enabling shifts and change.

Um not sure if there's much of a question in there but there's certainly some thoughts. What do you think?

33:11

I love this question. Kim, did you want to add something before? Well, I know because both of us here like our body language was like thing Sabrina, you might be thinking the same thing or you might be thinking something different is why do we have to reframe what we mean by impact and sustainability? Do we not like sustainability in the example that you just gave Thomas sustainability for that subgroup of people was the sustainability of the organization but if you reframe it to the sustainability of the mission and the impact then it doesn't matter who does it and that's it's easier said than done because you're you're seating power you're seating livelihoods you're seating and it's and when you sit in at a as a trustee as a board as an executive you are thinking about people's salaries their children their healthare care, all of these things and that is that is real but in the big picture if you are looking at the sustainability of the work and the impact that changes the calculus.

The same story, differently heard

Sabrina Segal34:09

So I think um Thomas you and I were on the same end of the Chinese whisperers because I have heard a similar story. [laughter] I'm sure this happens in lots of organizations but I will tell you that this was absolutely the story was you know again an initiative was going on. It wasn't working. it had been funded you know consistently for five seven years.

uh when the organization was asked how much have you actually spent on this initiative over this length of time they couldn't actually come up with the number which is its own problem but when the CEO was asked why do you continue doing this if the data that we have is showing that it's not really progressing the response was well you know donors get what donors want and with that response kind of tells you everything you need to know about the mentality of some not all right some organizational leadership it's very kind of you know you know selfp protective it's it's kind of you know well our organization has to exist to do this um so I think um you know that happens I think that is a way of thinking that's gotten us into the situation that we're in right now and I do think as Kim was talking about earlier we have a crack in the door with everything we've gone through in the past 18 months to kind of say that way of thinking needs to be challenged whenever you hear it and you need to be confident challenging it now we go back to do we have the organizational culture to challenge and all of that.

So that group of people that kind of identified themselves to protect the organization, they were protecting the entity. They weren't actually protecting the organization's purpose, right? They were protecting the organization as being a an ongoing concern, as they say. You know, we're going to be an ongoing charity because we have, you know, enough money coming in. We've got a balanced sheet and we also have reserves, right? These things that trustees, you know, I sit on the um audit risk and fund, you know, finance committee and that's like, oh, do we have a balanced sheet? Well, are we achieving our objectives? Right? Do we have a balance sheet so that we can achieve our objectives? It all comes back to that. They get they get crazy when I ask those questions.

But let me go back to the Trojan horse thing, right? Because um I see where you're coming from and I'm going to riff off of what Kim said about refraraming risk because you're coming at risk with a traditional vintage approach of risk, right? We're looking at risk from the funers point of view and by doing that we're going to continue to replicate a system that's not actually working for anyone. whereas I want to change it and I want to look at risk from the objectives point of view and this is this is goes into my primary research that I'm doing for my thesis right now is saying you as Ali said earlier right you've got different people who see risks in different ways but we should all see the objective let's take a project objective right child and maternal health right in upper Egypt it's a project I worked on when I was living in Egypt right we all want to reduce you know uh you know early childhood um you know deaths and women you know who are giving birth we will reduce that.

Right? That's our objective. Now, your funers is going to have a view on it. Your intermediary is going to have a view on it, and your local partner is going to have a view on risk, right? They're all going to have different, but everyone agrees on what the objective is. So, what I say about being a Trojan horse is we need to bring risk to the table so that the funer at the funer end of the risk spectrum and the implementing partner end of the risk spectrum understand where the other one is coming from. we start to use common language and instead of doing risk transfer which is the traditional vintage way of doing risk we do risk sharing. So instead of thinking about delivery as a chain right and the weakest link is the one that will break we want to think of it as a woven rope.

So the concerns that the funer has are woven to the end for the delivery and the concerns that frontline delivery have are woven to the funer and you have the organizations that are in the proper power and resource position to be able to address and absorb the risks that they can because right now you have the highest power highest resource player transferring it down to the lowest power lowest resource player. This is the problem, right? And when we talk about localization and bless everybody with localization, we've been talking about it for like 10 years now. And we've achieved a lot when it comes to, for example, you know, um, you know, uh, um, collaborative project design, right? We can get 15 midwives around a table and talk about how we can reduce child mortality and you know, mother mortality.

But what we haven't done is we haven't gone into the back room where finance and due diligence and procurement and all those things that our frontline technical experts think happen in a dark room in a black box somewhere and no one wants to dive into. That's the part of risk sharing that I'm interested in because if we can get that shifted, if we can shift the perspective on the funer side around that, then we are really going to start moving somewhere.

Ali Al Mokdad38:46

Yeah. So um one thing I have noticed working on not only risk management but also organizational change strategy processes policies risk management that sometimes although we try to go back to first principles and build from there. The challenge is what it doesn't have. It's not about how it all leads to the final thing but what it didn't include. Um I'm organizing my thoughts while I'm talking. So there is this old joke uh where a man enters a coffee shop and he say he asks the waitress he say hi uh I want to have coffee without cream. The waitress say sorry we don't have coffee without cream we have coffee without milk. So from materials perspective coffee without cream and coffee without milk it's exactly the same.

It's black coffee. But the moment we start looking at what's missing, we start seeing ideology class because cream and milk they are not the same. They present different ideologies. They present different class. They present different way to approach that coffee shop or etc. So what I'm trying to say just from risk management perspective that risk management without an Excel sheet is not the same like risk management with the Excel sheet and risk management without let's say that over compliance and XY Z is not exactly the same like risk management with it because in the end of the day there are certain things unfortunately in the sector international or national organization donor or foundation or whatever they are actually either a process fetish or something related to ideology or that's how they are used to do things because yes you can do risk management and think about it and experiment with it in so many different ways but large part of the community and the people working in it they still define that risk register or XY Z because it is it is part of this culture as you said or it's part of that ideology and approach toward risk management or it's part of the way we are seeing operations and programs.

So what I'm trying to say here is that sometimes it's actually about what it doesn't have not about what it has and what will deliver in the end. Those are just some thoughts and observations I noticed not only talking about risk management but also strategy and processes and so many other things that the first thing that people start paying attention to what it doesn't have and when the moment you start looking at those things that it doesn't have you start realizing that's a culture issue. It's not really purely a process issue and that's a ideology toward working at different levels. It's not exactly about the tool or the technique or the endline

41:37

philosophy now. Yeah. I'd like to add on to your philosophy and um Ali because I know I know how Sabrina feels very strongly about the risk register. Anyone who follows you on LinkedIn knows your feelings on the on the risk register and I don't I don't have to be honest with you, I'm a little risk register agnostic. I understand. I don't really have a ton of opinions on it. The where I what I want to hear from you because I have been I've been thinking about this for quite a while is we talk a lot about transfer from risk transfer to risk sharing and in principle I don't know how you can disagree with that. That makes complete sense but you talk about the difference between in the back room in with the procurement and the risk and the compliance and all these people and the finance people.

What does that actually look like? I love your analogy of the chains versus the rope and that makes sense. But in the world we live in today, if I had a project, a funded project today, at some point there is a report and there is there are there reproduct re uh repercussions if something happens and the buck stops with someone. And so how do you actually live risk sharing in real life when there are like legal and fiscal consequences? So look at Mackenzie Scott.

A funder willing to trust

42:57

Sure. But we don't all have Mackenzie Scott money. No, no, you're right. No, you're right. But what if we're asking about the structure and the methodology? That's the structure and the methodology. Right. Now granted, we don't all have, you know, and she's an outlier, right? A funder who is willing to kind of trust, god forbid, the organization that she's funding and say, "Oh, you don't have to create any super special unicorn sparkly report for me every two and a half weeks on my format. I'm willing to accept your annual report because I've done my due diligence on you because she does what does she call it? She calls it like quiet review or something like that or quiet checks or something like that where organizations that she's looking at funding don't even know that they're being looked at, right?

And so she must have found some way to do due diligence without asking an organization to fill out a 720 questionnaire. Real questionnaire that I've worked with by the way in the past. Um so you know how does she do it? It's not magic. It's not, you know, elves and pixies, but she does the work because she says, "I don't want to have to have the organizations that I'm partnering with fill out a thousand of my forms. I want them to focus on what they're doing. I believe in what they're doing. They have a track record and I'm going to, again, god forbid, trust them, right? That word." So, how do we get risk sharing in? Well, the first thing we need to do with risk sharing is again, we need to go upstream.

I talk a lot about going upstream. We have to go upstream. We have to get the funders engaged. I've been part of the grand bargain risk sharing work stream um for you know a year and a half two years now and I you know I attend the calls I listen to everybody everyone's giving each other high fives look at the pilots that we've done but we never have funders in the call and you know funders have the power funders have the money so if they're not present they're not interested I don't care how many people say but I've had these quiet backroom conversations with them okay great these backroom conversations are they turning into anything practical I haven't seen it and certainly I'm not seeing it now right so we have to go upstream And what we have to do is we have to get the funders who are open to this to engage their colleagues.

The funders have to convene themselves and they have to say if we're genuinely interested in having an impact and doing it in a way that is not going to exacerbate the starvation cycle that all of these organizations that we say that we love are going through right now, how are we going to do it? So there's a methodology that um that I work with. It's called the 3P framework, right? It stands for project, partner, and patron. And what we do with the 3P framework is we have very short like 12 question surveys. So we go to the um we ask both the patron who's the funer and the partner what is your risk perception of this project that you're being asked to do and you end up with two different perceptions.

Right? Again because people are looking at the same thing from a different point of view. We then ask the partner not what is you know are you a high, medium or low risk partner. We ask them what their risk capacity is framed within their operating environment. So, for example, if you are a women's organization that's been around since 1993 in Sudan, but the fact that you can't provide insurance for your staff and volunteers makes you high risk according to a western or a northern donor, you know, and this is a real story. Talking to that organization in Sudan, they were like, SP, there's not even an insurance market here. Even if we wanted to buy insurance, it doesn't. So, how on earth are we considered high-risisk within our operating environment?

We've, you know, never had a safeguarding problem. We are very attentive, you know, with our staff and volunteers. here's all the things we've done. We have a good reputation with the communities that we're working with. Just because we don't fit some western view of a checklist doesn't make us high risk. So what we do is we reframe the partner around their operating context and their risk capacity, their capacity to manage risk. So an unpredicted shock that might come or something that might happen during the project. My favorite part of the 3P framework though comes with the patron. What we do with the patron is we ask them to fill out again 12 15 questionnaire about their flexibility of funding and then we plot them on a continuum.

One end is command and control. The other end is trust. So our full Mackenzie Scots, they love to say that they are on the trust and oh we are partners and we localize and this and the other. But when they go through that questionnaire they typically end up in the command and control side. Now what we have is data that we can start to triangulate and come up with common language and then the partner understands the flexibility that the patron may or may not have and the patron understands more the operating environment that the partner is coming from. Then we will sit down with the patron and say how much flexibility do you have? Can you adjust this procurement rule? Can you adjust this financial accounting rule?

Can you adjust the reporting rule or whatever? When you say Kim well it's legal and it's regulatory. Nine times out of ten it's not nine times out of ten it's just the requirements that the funders put around their money right now we're talking about bilaterals and multilaterals fine right but a lot of times there is flexibility

47:31

or even the recipient sometimes the recipient just has higher standards than they than they actually need so what I'm hearing from you is that you're trying to weave that rope yeah and the thing is that the our sector has been really awesome at talking to ourselves we have lots of convenings and calls and organizations that are all about reimagining this and shifting the power that we talk to ourelves till we're blue in the face. Problem is that the people who are holding power aren't at the table, you know, and it's just it's at this point I think we have to say we've fought the good fight. Unless we really start getting upstream, we're not going to get much more traction when it comes to risk sharing.

When pragmatic optimism gets hard

48:06

I'm rapidly getting to that point and that's where pragmatic optimism gets hard. Yeah. But I there's ways we can do it. Sorry. I also think we are in general. This is our generational fight. I believe that's what we have to get done. All those nonsense about risk management, compliance processes, some random things and structures, we have to deal with this. We have to fix it. We need to focus at the big issues. If we are worried about climate change or hunger or health and all that, we need to get rid of this nonsense with policies and processes and outdated governance and outdated way of thinking and all that. I fundamentally believe that those who came before us, okay, they set the stage, they set the foundation, they did so many things so that now we could start focusing at the issues.

But now for those people who would come after us, we need to fix this. We need to do something about it. And yes, of course, there are so many things like the grand bargain or so many tons of working groups here and there and meetings here and there and documents being generated every day and webinars and podcast and articles and all that things. And you know, maybe we have to do more. the main thing we need to get this done and I'm I'm so happy Sabrina that you are working on that and I'm more than happy that also like many people who are listening to our conversations they are also trying to address it um but this is our generation fight from my perspective

49:30

couldn't agree more I'm getting pumped here let's do it risk see risk we could do it with risk who knew that risk was going to be so you know energizing [laughter] I did but I mean no I love it I absolutely love it Sabrina the energy you've brought to the conversation uh around risk in particular, also just the dialogue today has been absolutely wonderful. Uh I think we're probably at time. So, we're gonna have to say thank you for everything that you've you've brought to the conversation. I really think it's been a conversation. It's been an episode that people are going to love listening to because it's kind of grounding an awful lot of the sort of fears of change and the direction of change, the trajectory that people need to go in into a language that they're familiar with.

And we talked around that quite a lot. We talked about the traps of familiarity and pattern behavior, but also the potential the opportunity that people have got with their existing frameworks and structures on risk to navigate a way forward. And your headline message, if I understand it right, is shift from managing risk as a compliance strategy to managing the risk of not meeting objectives or the risk of objectives. Um, that's that's a great way to think about it. So hopefully it will be a useful episode for people to listen to. So thank you very much. and Kim, Ali, thank you as always.

50:43

Risk in the round. I love that. Thank you guys so much. And I'm going to pick up the flag with Ali. This is our generational um our fight here. I think this is what we got to do. Thank you so much. Bye. Bye. Bye.

Read the companion essay
Risk in the Round: From Compliance to Strategy, and the Generational Fight
Read the essay

← All episodes