When the Least Experienced Person Owns Risk
Why risk ownership drifts to those least equipped to hold it.
At some point, a leader decided that risk coordination was a good assignment for whoever had capacity. That decision has organizational consequences. They are quiet until they are not.

Key Takeaways
- Assigning risk coordination by availability rather than judgment is a leadership decision whose organizational consequences compound quietly - the risk picture you get is as good as what that person can see.
- Gary Klein's research on expert decision-making shows that experienced practitioners identify risks through pattern recognition built from prior exposure - risks that appear in no template will be invisible to coordinators who have not seen them before.
- The compensating measure when experienced coordinators are unavailable is not better process; it is structured pairing - an experienced leader actively participating in identification, not reviewing outputs after the fact.
I want to talk to the leader who made the staffing decision - not the coordinator who received it.
You had a role to fill. Risk coordinator. The documentation requirements are defined, the templates exist, and the process is not complicated to follow. Someone junior, or someone new, or someone whose calendar had open space was available. The senior people on your team were already carrying full loads. Assigning the risk role to one of them meant something else would not get done. So you assigned it to the person who had capacity, and the logic felt reasonable at the time.
Here is what you actually decided: that your risk picture would be as good as that person could see.
What Experience Provides That a Process Cannot Replace
Gary Klein spent years studying how people make decisions under uncertainty - paramedics, fireground commanders, chess grandmasters, intensive care nurses.1 His finding was consistent across domains: expert decision-makers do not outperform novices by analyzing more carefully. They outperform by recognizing patterns faster. Experienced practitioners see situations and know, often before they can explain why, what type of situation it is and what response it calls for. They carry a repertoire of prior encounters - failures, near-misses, situations that looked safe until they were not - that makes the current signal legible in a way it is not for someone seeing it for the first time.
Applied to risk identification, this means that experienced coordinators see risks that novice coordinators miss. Not because the novice is careless. Not because the process was not followed. Because the risk presented as a weak signal - an estimate that seems slightly too confident, a dependency that has failed before under different conditions, an assumption pattern that the experienced practitioner has seen collapse on three prior programs - and that signal does not yet exist in the novice's pattern repertoire. The novice documents what they are told. The experienced coordinator challenges what they hear.
Karl Weick and Kathleen Sutcliffe, studying organizations that operate reliably under genuinely high-consequence conditions - nuclear facilities, aircraft carriers, trauma centers - found that these organizations maintain what they call “collective mindfulness”: sustained organizational attention to weak signals, anomalies, and near-misses that keeps small failures from becoming catastrophic ones.2 The consistent structural feature of these organizations is that risk-relevant information gets evaluated by people experienced enough to recognize its significance. The weak signal that the expert reads as a precursor to a known failure mode does not register on the novice's radar - not from inattention, but from the absence of the pattern that would make the signal meaningful.
The risk that gets missed is not recorded in the register. The risk not recorded is not managed. The risk not managed eventually materializes - and when it does, the post-incident question is always some version of: why did no one see this coming? Someone with enough experience usually did. They were just not the person assigned to own it.
The Organizational Message You Sent
The staffing decision communicated something beyond the assignment. It communicated to your team, to the coordinator, and to the risk process itself that risk coordination is overhead - a compliance requirement to be met, a governance checkbox to be maintained, rather than a capability that protects organizational capacity to execute.
The coordinator received that message. So did the senior leaders on your team, who observed that the risk function went to whoever had capacity. So did the people who interact with the risk process downstream, who calibrate their engagement with a risk register based on their assessment of the quality of judgment it reflects.
COSO's Enterprise Risk Management framework is explicit: effective enterprise risk management requires integrating risk judgment into governance and strategy - not delegating it as an administrative task.3 The framework does not suggest that experience is one factor among many in risk coordination quality. It treats organizational knowledge and judgment as prerequisites for the identification and assessment work to mean anything. When those prerequisites are absent, the framework is being followed in form while being violated in substance.
This is not an indictment of your coordinator. They did what they were asked to do, with the experience they had. The gap is not theirs to own. The staffing decision was yours.
The Authority Dimension of the Problem
In the Four A's of Organizational Readiness™, risk coordination assigns an inexperienced practitioner to a role that, to function correctly, requires organizational standing. Not positional authority - standing. The credibility to challenge a project manager's optimistic estimate. The organizational weight to surface a concern to senior leadership without a sponsor. The confidence that comes from having been right about a risk before, in a context where the organization can remember it.
The least experienced person in the role, however capable, typically does not have that standing. They can follow the process. They cannot credibly challenge the senior technical lead who insists the schedule risk is manageable. They cannot walk into the program director's review and say: this risk is understated, I have seen this pattern before, and the organization is not treating it seriously. That observation requires both pattern recognition and organizational authority. The available person has been given the accountability without the conditions that make accountability meaningful.
This is the same structural trap that risk ownership without authority describes at the level of individual risks. At the level of the coordinator role, the trap operates across the entire risk picture. Every risk that required standing to surface - every uncomfortable estimate to challenge, every assumption to contest, every early signal to escalate - passes through a filter that cannot exercise that function, because the filter was not selected for it.
The Attention Dimension of the Problem
Experienced risk coordinators know where to look. Not from a checklist, but from accumulated organizational memory: which estimates have historically been optimistic in this organization, which dependencies get understated in this program type, which risks tend to be named and then quietly deprioritized until they are urgent. This accumulated attention map is built over time and cannot be downloaded into a role description.
When the coordinator role rotates with team changes - when institutional knowledge about the risk picture resets every time the assignment migrates to the next newest person - the organization loses that attention map. It retains the register. It loses the judgment about which entries to watch most closely, which risks are presenting as amber when they should be red, which listed mitigations are real and which are aspirational.
The result is an attention problem that looks like a documentation problem. The register is current. The entries are formatted correctly. But the organizational attention has been calibrated by someone whose pattern library is not yet deep enough to direct it toward the risks that matter most. The signals that an experienced coordinator would have flagged three months ago are still sitting in the register at the same priority they were given when they were first identified.
What You Can Do About It Now
The diagnosis does not require a staffing change you cannot make today. It requires an honest audit of what your current risk picture is actually reflecting - and a decision about what compensating measure to put in place while the gap exists.
The most effective compensating measure is structured pairing: assigning an experienced operational leader to active participation in risk identification, not review. The distinction matters. A reviewer who reads the register outputs and approves them is not compensating for a coordinator who cannot yet see the relevant signals. An active participant who is present for identification sessions, who challenges the estimates in the room, who names the risks the coordinator might not yet recognize - that is a functional substitute, for as long as you genuinely commit to it.
Over time, the organizational posture that produces durable risk management treats the coordinator role as a development position for people with organizational knowledge and judgment depth - not capacity. It builds institutional memory intentionally, through structured handoffs when coordinators transition and meaningful overlap periods when they do not. It treats the risk picture as organizational knowledge the institution owns, not personal knowledge that walks out with the last person assigned to maintain it.
The leader who made the staffing decision can make a different one. Not necessarily a different assignment - that may not be possible today. But a different level of engagement: a genuine commitment to compensating for the gap, a decision to treat the risk function as something worth protecting rather than something worth satisfying, and an honest acknowledgment that the risk picture your organization is operating on is only as good as the experience of the person who built it.
That acknowledgment is the starting point. The risks that are missed do not become visible just because you now know they might be there. But the probability that someone with the judgment to see them is now looking - that changes.
References
- Klein, G. (1998). Sources of Power: How People Make Decisions. MIT Press. mitpress.mit.edu. Klein's recognition-primed decision (RPD) model demonstrates that expert decision-making under uncertainty is built on pattern recognition accumulated through experience - not analytical superiority. The model has direct implications for risk identification: experienced practitioners recognize meaningful signals that novices cannot yet see.
- Weick, K.E. & Sutcliffe, K.M. (2007). Managing the Unexpected: Resilient Performance in an Age of Uncertainty(2nd ed.). Jossey-Bass. Research on high-reliability organizations establishes that sustained organizational attention to weak signals - “collective mindfulness” - is a structural property of organizations that prevent small failures from cascading. A consistent feature of these organizations is that risk-relevant information is evaluated by practitioners experienced enough to recognize its significance.
- Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2017). Enterprise Risk Management: Integrating with Strategy and Performance. COSO. coso.org/guidance-erm. The leading enterprise risk management framework treats experienced organizational judgment as a prerequisite for meaningful risk identification and assessment - not as an enhancement to a procedural baseline. The framework distinguishes between risk management as governance compliance and risk management as strategic capability.
- Hillson, D. (1997). Towards a Risk Maturity Model. International Journal of Project & Business Risk Management, 1(1), 35–45. risk-doctor.com. Hillson's four-level risk maturity model describes the progression from administrative risk management (procedurally correct documentation) to strategic risk management (integrated judgment that drives organizational decisions). The coordinator experience dimension is a primary differentiator between the lower and upper levels of the maturity progression.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and produced a documented 1,033% improvement in delivery velocity by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
Related Articles
Diagnose the conditions behind risk
The Executive Diagnostic measures the organizational conditions that determine how risk gets owned: whether authority sits with demonstrated judgment, whether risk information changes decisions, and whether the organization treats risk as leadership work. Who owns risk tells you whether the organization values judgment or paperwork.
