Mission Intelligence Systems
Risk · Authority · Attention

The Risk Experience Deficit

Why never having failed leaves organizations blind to risk.

Organizations routinely assign their greatest uncertainties to their least experienced coordinators. When the coordinator leaves, the role migrates to the next newest team member. This is not a staffing convenience. It is a structural signal about how the organization values uncertainty - and it quietly degrades the confidence of every risk assessment the organization produces.

A risk-lookout post whose operator keeps rotating to a newer hire each period while serious signals go unseen, showing how rotating the role separates risk identification from experience.

Key Takeaways

The pattern is consistent enough to be predictable. A new project or program needs a risk coordinator. The role goes to whoever is available - frequently the most junior team member, the newest hire, or the person whose schedule has the most open space. When that person rotates off the team, the role follows the same selection logic: whoever is available, whoever is newest, whoever has capacity. The organizational risk picture cycles through a series of custodians whose primary qualification was not being otherwise occupied.

No one intends this outcome. The selection logic feels rational at the time: risk coordination is procedural work, the documentation requirements are clear, and freeing senior team members for higher-value activities seems reasonable. What the logic misses is the distinction between risk documentation and risk identification - between recording the risks that were nominated and recognizing the risks that matter. That distinction turns entirely on experience.

What Experience Provides That Process Cannot

Gary Klein's research on expert decision-making, documented in Sources of Power, established a finding with direct implications for risk coordination: experienced practitioners do not make better decisions by analyzing more options more carefully. They make better decisions because they recognize meaningful patterns faster and with less conscious effort.1 In Klein's framework, experts use recognition-primed decision making - they perceive a situation, recognize it as a familiar type, and know what response is appropriate, often before they can articulate why. Novices, lacking the pattern library, either miss the signal entirely or spend the analytical time they do not have constructing a picture that the expert read intuitively.

Applied to risk coordination, this means that experienced practitioners see risks that novice coordinators cannot: not because the novice failed to follow the process, but because the risk presented as a weak signal - a subtle deviation, a familiar early indicator, an assumption pattern that has failed before - that only becomes legible through the lens of accumulated organizational experience. Experienced coordinators know which estimates tend to be optimistic in their organization, which dependencies are routinely understated, which risks have appeared before under different names. Novice coordinators document what they are told. Experienced ones challenge what they hear.

Karl Weick and Kathleen Sutcliffe's research on high-reliability organizations reinforces this point from a different direction.2 Organizations that operate reliably under high-consequence conditions - nuclear power facilities, aircraft carriers, air traffic control - maintain what Weick and Sutcliffe call “collective mindfulness”: a sustained organizational attention to weak signals and near-misses that prevents small failures from cascading into large ones. A consistent feature of these organizations is that risk-relevant information is evaluated by people with enough experience to recognize its significance. The weak signal that the expert reads as a precursor to a known failure mode is invisible to the novice, not because the novice lacks diligence but because the pattern is not yet in their repertoire.

The risks that hurt organizations most are rarely the ones no one could have seen. They are the ones that were visible to experienced practitioners but were never surfaced, because the people running the risk process were not yet experienced enough to recognize them.

The Administrative Signal and What It Communicates

When risk coordination is assigned by availability rather than judgment, the assignment itself communicates something beyond the staffing decision. It communicates that risk management is overhead - a compliance requirement to be satisfied, a governance checkbox to be maintained, rather than a strategic capability that protects organizational capacity to execute.

This is a version of a pattern that appears across organizational functions that organizations say are important but treat as administrative: lessons learned, knowledge management, configuration management, data quality, documentation. Each of these is assigned to whoever has capacity when a vacancy opens. Each is consequently managed at the level of documentation rather than at the level of organizational learning. And each, when it fails - when the lessons are never learned, when the knowledge walks out the door, when the configuration diverges from the documentation - fails in the same way: the accumulated deficit between what was recorded and what was actually understood finally becomes visible in a moment of consequence.

The organizational message of “we assign this to whoever is available” is received clearly by the people being assigned. It signals that the function is not considered a development opportunity, a path to influence, or a role that requires organizational judgment. It attracts people who are available, and it produces outputs calibrated to what available people can produce: procedurally correct documentation that does not carry the confidence of expert judgment.

The Cynefin Dimension: Risk Operates in the Complex Domain

David Snowden and Mary Boone's Cynefin framework distinguishes between domains of decision-making based on the relationship between cause and effect.3 In the “obvious” domain, best practices apply and can be followed procedurally. In the “complicated” domain, good practices exist but require expert analysis to identify and apply. In the “complex” domain, cause and effect are only coherent in retrospect - the situation must be probed rather than analyzed, and expert judgment about what to watch for is the primary navigational tool.

Most organizational risk - the risks that matter, the risks that can actually derail initiatives and programs - operates in the complicated and complex domains. The risks are not obvious. They require expert analysis to recognize and characterize, and they involve interactions and dependencies that only become coherent through organizational experience. Treating risk coordination as a procedural task suited to the obvious domain, assigning it based on availability and rotating it freely, mismatches the complexity of the work with the capability of the person assigned to do it.

COSO's Enterprise Risk Management framework is explicit on this point: effective enterprise risk management requires integrating risk identification and assessment into governance and strategy - not delegating it as a compliance task.4 The PMBOK® Guide similarly emphasizes that effective risk identification requires “engaging stakeholders with relevant expertise and organizational knowledge,” not simply following a risk identification procedure.5 Both frameworks treat experienced judgment as a prerequisite, not an enhancement.

The Four A's Dimensions at Work

The risk experience deficit is simultaneously an Authority problem and an Attention problem in the Four A's of Organizational Readiness™ framework.

It is an Authority problem because the risk coordination role, when assigned by availability, typically does not carry the organizational standing to challenge estimates, push back on assumptions, or escalate concerns to senior leadership without a sponsor. The experienced operational leader who could credibly challenge a project manager's optimistic schedule estimate does not occupy the risk coordinator role; the newest team member does. The result is a risk identification process in which the person best positioned to surface uncomfortable truths lacks the organizational authority to make them heard, and the person given the authority lacks the experience to know what to say.

It is an Attention problem because experienced risk coordinators know where to look. The Attention-Based View of the Firm, developed by William Ocasio,6 argues that organizational outcomes depend not just on what resources an organization possesses but on where organizational attention is directed - what gets noticed, what gets prioritized, what gets brought into decision-making. Risk identification is fundamentally an attention allocation exercise: directing organizational scrutiny toward the uncertainties that carry the most consequence. Experienced coordinators carry a mental model of where the dangerous uncertainties tend to hide. Novice coordinators follow the checklist and document what they find.

What Mature Risk Coordination Looks Like

Organizations with mature risk management treat the coordinator role as a leadership development position, not an administrative one. Coordinators are selected for organizational knowledge depth and credibility, not capacity. They accumulate institutional memory across projects and programs, building the pattern library that makes risk identification qualitatively better over time. Senior leaders participate actively in risk identification - not as reviewers who bless outputs, but as contributors who bring domain expertise and challenge assumptions that the coordinator might not have the standing to challenge alone.

In practice, this means that risk coordination responsibility does not rotate freely with team changes. When a coordinator transitions, the organizational knowledge they carry is explicitly managed: through structured handoffs, documented reasoning, and a meaningful overlap period during which the outgoing coordinator actively transfers context that cannot be captured in a register. The risk picture is treated as institutional knowledge that the organization owns, not personal knowledge that walks out the door with the last coordinator assigned to maintain it.

For organizations where experienced coordinators are not immediately available, the most effective compensating measure is structured pairing: assigning the coordination role to a less experienced practitioner while explicitly committing an experienced operational leader to active participation in identification, not just review. The pairing only works if the experienced leader is genuinely engaged - present for identification sessions, available to challenge assumptions, and willing to name risks that the coordinator might not recognize. A reviewer who reads outputs and approves them does not compensate for a coordinator who cannot yet see the signals that matter.

A Maturity Progression for Risk Coordinator Experience

David Hillson's Risk Maturity Model, introduced in 1997 and widely adopted by risk practitioners globally, describes organizational risk practice across four levels.7 Applied to the experience dimension of risk coordination, the progression looks like this:

Level 1 · Administrative

Risk coordination is a rotating collateral duty. The role migrates to whoever is newest or has the most capacity. Institutional knowledge resets with every team change. The register exists because governance requires it.

Level 2 · Compliance

Registers are maintained and updated on a defined cadence. Experienced leaders participate in periodic reviews but are not active contributors to identification. The output satisfies audit requirements without necessarily reflecting the organization's real uncertainty.

Level 3 · Operational

Experienced managers actively coach risk coordinators and validate assessments. Identification is a judgment exercise, not a documentation task. The coordinator role carries real organizational credibility, and escalation is structured rather than improvised.

Level 4 · Strategic

Risk identification is embedded in leadership conversations and continuously informed by experienced practitioners across the organization. The RIMS Risk Maturity Model8 describes this as the level at which risk management drives value creation rather than simply protecting against loss. Risk is owned at the highest organizational levels, with the experience to match.

Most organizations that assign risk coordination by availability operate at Level 1 or 2. Moving to Level 3 does not require a restructuring - it requires a deliberate decision about who holds the role and what senior participation looks like in practice.

Organizations reveal what they truly value not by what they say is important, but by who they trust with the work that matters most.

Risk coordination done well is not a documentation function. It is a judgment function: the organizational capacity to look at a complex, uncertain situation and surface the risks that actually matter - not the risks that are easiest to document, most politically comfortable to acknowledge, or most obviously derived from a standard risk checklist. That capacity is built through experience, and it cannot be rotated to whoever is available without cost. The cost does not appear in the risk register. It appears in the surprises that the register was supposed to prevent.

References

  1. Klein, Gary. Sources of Power: How People Make Decisions. MIT Press, 1998. mitpress.mit.edu. Klein's recognition-primed decision model demonstrates that expert judgment in uncertain, time-pressured situations depends on accumulated pattern recognition rather than analytical process - directly applicable to experienced versus novice risk identification.
  2. Weick, Karl E., and Kathleen M. Sutcliffe. Managing the Unexpected: Resilient Performance in an Age of Uncertainty. 2nd ed. Jossey-Bass, 2007. wiley.com. The definitive study of how high-reliability organizations use experienced collective mindfulness to detect weak signals before they cascade into failures.
  3. Snowden, David J., and Mary E. Boone. “A Leader's Framework for Decision Making.” Harvard Business Review, November 2007. hbr.org. The Cynefin framework establishes that organizational risk operates in the complex and complicated domains, which require expert judgment rather than procedural execution.
  4. Committee of Sponsoring Organizations of the Treadway Commission (COSO). Enterprise Risk Management - Integrating with Strategy and Performance. 2017. coso.org/guidance-erm. The leading enterprise risk management framework, explicitly requiring integration of risk management into governance and strategy with engaged, experienced leadership - not administrative delegation.
  5. Project Management Institute. A Guide to the Project Management Body of Knowledge (PMBOK® Guide), 7th ed. PMI, 2021. Risk management principles in Section 4.14 explicitly address the requirement for “engaging stakeholders with relevant expertise and organizational knowledge” as a prerequisite for effective risk identification.
  6. Ocasio, William. “Towards an Attention-Based View of the Firm.” Strategic Management Journal 18, S1 (1997): 187–206. doi.org/10.1002. Establishes that organizational outcomes depend on where organizational attention is directed - foundational to understanding why experienced risk coordinators produce qualitatively different risk pictures than novice ones.
  7. Hillson, David. “Towards a Risk Maturity Model.” International Journal of Project and Business Risk Management 1, no. 1 (1997): 35–45. risk-doctor.com. Hillson's foundational Risk Maturity Model established the four-level progression (Naive → Novice → Normalized → Natural) that became the standard reference for assessing organizational risk management capability - including the role of experienced practitioners at each level.
  8. Risk and Insurance Management Society (RIMS). Risk Maturity Model for Enterprise Risk Management. RIMS, 2006; updated 2017. rims.org. The RIMS RMM benchmarks organizational ERM capability across five competency drivers; organizations at higher maturity levels consistently demonstrate experienced leadership engagement in risk identification as a distinguishing characteristic.
DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and produced a documented 1,033% improvement in delivery velocity by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.

Related Articles

Assess Your Risk Coordinator Experience

The updated Risk Management Maturity Assessment now includes a dedicated dimension on Risk Coordinator Experience - measuring whether the people responsible for your risk picture have the organizational judgment to recognize the risks that matter, not just document the risks they are told about.