← Back to all posts

Founder Notes

You Can't Trust Your Traditional Risk Assessment

October 6, 2026 · Jesse McKenna

You can't trust your traditional risk assessment. Not because someone did it badly, but because the method can't produce something trustworthy in the first place.

Think about reporting a metric to your board, your examiner, or your budget committee. You'd want to know it doesn't depend on who happened to collect it. You'd want to see how it was calculated. You'd want to know it still describes the business you're running today, and that it's comparable to the last one so you can tell whether things are getting better or worse. The traditional assessment fails every one of those tests, and it fails them by design.

The answer depends on who asked

A traditional assessment is built from interviews. Somebody sits down with your department heads and asks them how risky things are. What comes back is shaped by the interviewer's experience, their skill, which follow-up questions they thought to ask, and whatever opinions they walked in with.

Put two equally qualified assessors in front of the same organization and you'll get two different answers. You can't tell how much of the result is your organization and how much is the person holding the notepad, and neither can they.

It can't show its work

Ask why a risk was rated high and you'll get a judgment call, delivered with confidence. There's no model to inspect, no weighting to challenge, and no logic an auditor or examiner can trace from the inputs to the conclusion. It's a finding you're asked to accept on the reputation of whoever wrote it.

If you can't trace it, you can't defend it. And a rating you can't defend is an opinion with a cover page.

It was stale on delivery, and you can't measure the drift

The deliverable is a static document describing the organization as it looked while the interviews were happening. Then a vendor changes, a product launches, a peer gets a consent order, and the document stays exactly as it was.

Next year's version won't help you, either. Different interviewer, different questions, different scoring, so the two can't be compared directly. The one question your board will actually ask, "are we getting better or worse?", has no trustworthy answer, because you're holding two opinions from two moments and nothing to line them up against.

Everything about the process discourages doing it again

It's time-consuming and expensive, because the labor is people in rooms, one conversation at a time. It's disruptive, because every department head pulled into an interview is a department head not doing their job. And it needs serious lead time: scoping, budgeting, contracting, scheduling a dozen calendars, so the assessment you need this quarter lands two quarters from now.

So it happens annually, at best. Nobody chose that cadence because risk changes once a year. It's simply the most often anyone can stand to do something this painful. Access reviews work the same way: a spreadsheet, a few weeks of chasing managers, once a year, while people change roles constantly. The cadence tells you what the process costs, not how fast the risk moves.

Add it up and the traditional assessment is an unrepeatable, untraceable snapshot of what a few people said, on a few days, to one particular interviewer. That is what's driving your risk budget.

What earns trust instead

Trust comes from properties the traditional method can't have. Replace it with something that does:

That's the difference between a document you file and a program you run.

Pull out your most recent assessment and ask three things of it. Can I see how it reached its conclusions? Can I compare it to the one before? Does it describe the business as it is today? If the answer to any of them is no, you aren't holding a risk strategy. You're holding a document that asks you to trust it, and it hasn't earned that.

Jesse McKenna has over 20 years of experience in fraud detection, financial crime, and enterprise risk - building detection systems at PayPal and eBay, leading threat research at Silver Tail Systems and RSA, and building SAR prediction models at Refine Intelligence. He is the Founder of VeloRisk, a risk strategy platform for regulated industries.
← Back to all posts