Risk Management: How Can You Anticipate Problems Before They Happen and Turn Them into Opportunities for Improvement?

‏12 اغسطس 2026 SHIREEN MIQDAD
Risk Management: How Can You Anticipate Problems Before They Happen and Turn Them into Opportunities for Improvement?
sharing

Introduction

Non-profit organisations do not operate in a stable environment where every development can be predicted in advance. Funding may be delayed, regulations may change, a supplier may fail, a key employee may leave, beneficiary data may be exposed, or community needs may change faster than a programme can respond.

The question, therefore, is not:

Will the organisation face risks?

but rather:

Will it identify them early, understand their impact, and know when to intervene before they become crises?

This is where Risk Management becomes a core component of governance and institutional management, rather than an activity that begins only after a problem has occurred.

Risk management does not aim to eliminate all risk. That is neither realistic nor desirable, and excessive risk avoidance may prevent an organisation from innovating or expanding. Instead, it seeks to understand uncertainty related to organisational objectives, determine what level of risk can be tolerated, establish appropriate controls and responses, and continuously monitor changing conditions.

Risk thinking is also not limited to avoiding loss. A risk may expose a weakness that needs to be addressed, a process that can be improved, or an opportunity that can be developed.

This article builds on the original framework, which covered the concept and categories of risk, the Risk Register, risk matrices, treatment strategies, early warning indicators, the roles of the Board and executive management, and the relationship between risk management, governance, donors, and continuous improvement.


First: What Is Risk Management?

Risk management is a continuous and systematic process that helps an organisation:

Identify Risks → Analyse Them → Evaluate Them → Treat Them → Monitor Them → Review and Learn

A risk can be understood practically as uncertainty that may affect the organisation’s ability to achieve its objectives.

This is an important point:

There is no effective risk management without clear objectives.

The question is not only:

What might happen?

but rather:

What might happen that could affect our ability to achieve a specific objective?

Risks should therefore be linked to the organisation’s strategic objectives, programmes, operations, and major decisions.

Risk management is also not the responsibility of a single department. The Board, executive management, programme managers, finance, technology, Human Resources, and other functions each hold part of the overall risk picture.


Second: Why Do Charities Need Risk Management?

A charity may face risks affecting:

  • Beneficiary and staff safety.
  • Continuity of services.
  • Financial resources.
  • Data and systems.
  • Legal and regulatory compliance.
  • Programme quality.
  • Community trust.
  • Relationships with donors and partners.
  • Organisational reputation.
  • Its ability to fulfil its mission.

The value of risk management, however, does not come from simply creating a list of possible problems.

It comes from moving from:

The problem happened. What do we do now?

to:

What could happen? How will we know it is approaching? What decision should already be prepared?

This shift from reaction to preparedness is one of the clearest signs of institutional maturity.


Third: Types of Risk in the Non-Profit Sector

Risk profiles vary by organisation and context, but common categories include:

Strategic Risks

Such as selecting an intervention that does not align with community needs, expanding faster than the organisation can manage, or depending heavily on a single funding source.

Operational Risks

Such as weak procedures, implementation errors, workforce shortages, or supply-chain disruption.

Financial Risks

Such as liquidity problems, budget overruns, delayed funding, or weak financial controls.

Legal and Regulatory Risks

Such as failure to comply with legislation, contractual obligations, regulatory requirements, or donor conditions.

Technology and Cyber Risks

Such as system outages, data loss, unauthorised access, or cyberattacks.

Reputational Risks

Such as loss of community or donor trust following an incident, poor handling of a sensitive issue, or dissemination of inaccurate information.

Safety and Security Risks

Risks affecting employees, volunteers, and beneficiaries, particularly in fragile or high-risk environments.

These categories are useful for organisation, but one principle is essential:

Risks do not exist in isolated boxes.

For example:

Cyber Incident → Data Loss → Service Disruption → Beneficiary Complaints → Reputational Crisis → Loss of Donor Confidence → Financial Impact

Organisations should therefore also consider risk interdependencies and cascading effects.


Fourth: From Reaction to Proactive Thinking

A mature organisation is not one that never experiences problems.

It is one that can detect signals before problems become crises.

This can begin with simple practices such as:

  • Reviewing the internal and external environment.
  • Analysing previous incidents.
  • Listening to employees and beneficiaries.
  • Monitoring regulatory, economic, and technological changes.
  • Discussing risk when making important decisions.
  • Updating the Risk Register regularly.
  • Considering potential scenarios.

A useful planning question is:

What must be true for this plan to succeed, and what happens if it is not?

This question often reveals assumptions and risks before implementation begins.


Fifth: Risk Appetite and Risk Tolerance — How Much Risk Can We Accept?

The objective of risk management is not to reach zero risk.

Almost every meaningful decision involves some uncertainty.

Two concepts are therefore important:

Risk Appetite

The amount and type of risk an organisation is willing to accept while pursuing its objectives.

Risk Tolerance

The acceptable boundaries of variation or exposure before intervention or escalation becomes necessary.

An organisation may be prepared to accept a calculated degree of risk when piloting a new fundraising channel or testing an innovative programme.

At the same time, it may establish a very low tolerance for risks related to:

Fraud, misuse of funds, beneficiary safety, serious misconduct, or exposure of sensitive data.

These boundaries help management answer a critical question:

When do we stop monitoring and start intervening or escalating?


Sixth: The Risk Register — The Heart of the System

A Risk Register is one of the most important tools in risk management.

It should not be treated as a document prepared for audit purposes and then forgotten.

It should be a living decision-support tool.

A Risk Register may include:

  • Risk description.
  • Objective or process affected.
  • Causes.
  • Potential consequences.
  • Likelihood.
  • Impact.
  • Risk level.
  • Existing controls.
  • Additional actions required.
  • Risk Owner.
  • Target treatment date.
  • Early warning indicators.
  • Action status.
  • Next review date.

The more clearly a risk is described, the easier it becomes to manage.

Instead of:

Funding risk.

a stronger description would be:

Risk that the primary donor does not renew funding, creating a funding gap that may disrupt continuity of essential programmes.

We now have an event, a likely cause, and an impact that can be managed.


Seventh: Inherent Risk and Residual Risk — Are the Controls Actually Working?

This is one of the most important concepts in risk management.

Suppose an organisation holds sensitive beneficiary data.

Before considering any controls, the risk of unauthorised access may be high.

This is known as:

Inherent Risk

The level of risk before considering existing controls.

The organisation may then apply controls such as:

  • Access restrictions.
  • Multi-Factor Authentication.
  • Backups.
  • Encryption.
  • Staff training.
  • System monitoring.

The risk is then reassessed.

What remains is called:

Residual Risk

The level of risk remaining after controls have been applied.

The logic therefore becomes:

Inherent Risk → Controls → Residual Risk

This leads to the most important management question:

Is the residual risk within the level the organisation is prepared to tolerate?

If not, additional treatment, escalation, or a change in the decision may be required.


Eighth: How Should Risks Be Assessed?

Risk assessment generally considers two main elements:

Likelihood

How likely is the risk to occur?

Impact

How serious would the consequences be if it occurred?

A simple scale may be used:

Low — Medium — High

or a more detailed numerical scale where appropriate.

Risks can then be positioned on a Risk Matrix to support prioritisation.

However, an important caution applies:

A Risk Score supports management judgement; it does not replace it.

A low-likelihood risk may still require major attention if its potential consequences are catastrophic.

The quality of the score also depends on the quality of the information and assumptions used to produce it.


Ninth: Practical Example — What If 65% of Funding Comes from One Donor?

Suppose a charity receives 65% of its annual income from one donor.

The risk can be analysed as follows:

Risk: Loss or non-renewal of funding from the principal donor.

Cause: High concentration of funding sources.

Impact: Disruption of essential programmes and inability to meet some commitments.

Likelihood: High.

Impact: High.

Inherent Risk: Very High.

Controls and Actions

  • Funding diversification plan.
  • Development of a Donor Pipeline.
  • Growth of unrestricted funding sources.
  • Establishment of an appropriate financial reserve.
  • Regular cash-flow forecasting.

Risk Owner

The Chief Executive or authorised fundraising/resource-development lead, depending on the organisational structure.

KRI

Percentage of total income provided by the largest donor.

Trigger

For example, if dependency exceeds the organisation’s approved threshold, escalation or corrective action becomes necessary.

Treatment

Mitigate.

Once actions have been implemented, the risk is reassessed to determine the:

Residual Risk.

This demonstrates that a Risk Register is not simply a list of concerns. It is a tool connecting risk, ownership, action, indicators, and decision-making.


Tenth: How Can Risks Be Treated?

There are four main treatment strategies.

1. Avoid

Stop the activity or change the decision where exposure is unacceptable.

2. Mitigate

Reduce the likelihood or impact of the risk through additional controls and actions.

3. Transfer / Share

Transfer or share part of the consequences with another party, such as through insurance or appropriate contractual arrangements.

However, transferring part of the exposure does not necessarily transfer the organisation’s overall responsibility.

4. Accept

Accept the risk where it remains within approved limits, while continuing to monitor it.

The question is therefore not:

How do we eliminate this risk?

but:

What response is proportionate to the level of risk, the organisation’s objectives, and the cost of treatment?


Eleventh: Risk Owner — Who Is Actually Responsible?

One common weakness is to record:

Responsible: Management

or:

All Departments

against a risk.

This weakens accountability.

Each major risk should have a clear Risk Owner with the authority and responsibility required to oversee it.

The Risk Owner is typically responsible for:

  • Monitoring the risk.
  • Reviewing its assessment.
  • Monitoring existing controls.
  • Tracking the treatment plan.
  • Monitoring early warning indicators.
  • Escalating the risk when thresholds are exceeded.
  • Updating management on its status.

Several departments may participate in treating a risk, but ownership of the risk itself should remain clear.


Twelfth: Key Risk Indicators — Do Not Wait for the Event to Happen

One of the strongest ways to move toward proactive risk management is through:

Key Risk Indicators – KRIs

KRIs help an organisation detect changes in exposure before a risk becomes a major problem.

Examples may include:

  • Rising staff turnover.
  • Declining liquidity.
  • Increasing recurring complaints.
  • Higher proportions of delayed projects.
  • Increasing system failures.
  • Repeated data errors.
  • Growing dependence on one donor.
  • Falling beneficiary satisfaction.

A KRI becomes more useful when it is connected to clear thresholds for action.

For example:

KRI: Employee turnover rate.

Normal: Below the approved threshold.

Warning: Approaching the threshold.

Escalation: Above the threshold.

The KRI then moves from being a number on a dashboard to a:

Trigger for Action.


Thirteenth: Scenario Analysis — Do Not Try to Predict the Future Precisely

An organisation cannot know everything that will happen.

But it can prepare for several plausible scenarios.

Suppose a programme depends on funding expected within three months.

The organisation might consider:

Expected Case

Funding arrives on time.

Adverse Case

Funding is delayed by several weeks.

Severe Case

Funding does not arrive or is suddenly withdrawn.

For each scenario, ask:

What will be affected?

Which critical services must continue?

Which commitments must be protected?

When must a decision be taken?

Who has authority to take it?

What alternative resources are available?

This connects risk management directly with Business Continuity.

The objective is not to forecast the future perfectly.

It is:

To think through difficult decisions before the organisation is forced to make them under crisis pressure.


Fourteenth: Risks and Opportunities — Not Every Uncertainty Is Only a Threat

Risk management can also reveal opportunities for improvement.

For example, if the organisation identifies dependence on a single donation channel as a risk, this may lead to:

Channel Diversification → Access to New Donor Segments → Greater Financial Sustainability

If the risk of manual process failure exposes weak operations, it may lead to:

Automation → Fewer Errors → Greater Efficiency

A change in community needs may also reveal an opportunity to redesign a programme so that it becomes more relevant and effective.

When reviewing a risk, the organisation can therefore ask:

What does this risk reveal about our weaknesses?

and then:

Is there an opportunity to improve the system, service, or decision while treating it?

Good risk management does not make an organisation afraid of change.

It enables the organisation to take risk consciously where the opportunity justifies it.


Fifteenth: The Role of the Board and Executive Management

Effective risk management requires clear allocation of responsibilities.

The Board

At the appropriate level, the Board may:

  • Oversee the risk-management framework.
  • Approve relevant policies.
  • Establish Risk Appetite.
  • Review major and strategic risks.
  • Monitor whether risk exposure remains within acceptable limits.
  • Hold management accountable for addressing significant risks.

Executive Management

Executive management may:

  • Implement the risk-management framework and policies.
  • Maintain the Risk Register.
  • Assign and monitor Risk Owners.
  • Implement treatment plans.
  • Monitor KRIs.
  • Escalate significant risks.
  • Provide periodic information to the Board.
  • Integrate risk into planning and operations.

Operational teams are often closest to the earliest signs of emerging risk, so they must also be active participants in the system.


Sixteenth: Build a Culture That Does Not Punish People for Raising Risks

No risk-management system can work if employees are afraid to say:

We have a problem.

If identifying a risk is interpreted as personal failure, information will reach management too late.

A mature culture encourages employees and volunteers to:

  • Report concerns early and in good faith.
  • Discuss mistakes.
  • Share Near Misses.
  • Raise concerns.
  • Document lessons learned.
  • Suggest improvements.

This does not mean removing accountability for negligence or misconduct.

It means distinguishing between:

Professionally reporting a risk and behaviour that irresponsibly created the risk.

The objective is to build an organisation that treats early risk detection as a success of the system, not as an embarrassment to be hidden.


Seventeenth: Risk Management, Governance, and Compliance

Risk management is directly connected to governance.

Governance defines who decides, who oversees, and who is accountable.

Compliance helps ensure adherence to legal, regulatory, contractual, and internal policy requirements.

Risk Management helps identify what may prevent the organisation from achieving its objectives or meeting those obligations.

Integration becomes visible when:

  • Risks are linked to strategic objectives.
  • Major risks are discussed by management and the Board.
  • Audit findings are used to update the Risk Register.
  • Risk influences resource allocation.
  • Risk assessment is integrated into new project design.
  • Risk is reviewed when major changes occur.

At that point, risk management becomes part of decision-making, rather than a parallel administrative system.


Eighteenth: How Can a Donor Know That Risk Management Is Actually Being Applied?

Having a Risk Management Policy alone does not prove that the organisation actively manages risk.

A donor or partner may look for evidence such as:

Risk Management Policy → Risk Appetite Statement → Risk Register → Risk Owners → Risk Treatment Plans → KRIs → Incident Records → Business Continuity Plans → Corrective Actions → Board Risk Reports → Lessons Learned

One of the strongest practical tests is:

Show us one major risk that increased during the past year.

Then ask:

How did you identify it?

Who was the Risk Owner?

How did its assessment change?

When was it escalated?

What actions were taken?

Were those actions completed?

What was the Residual Risk after treatment?

A documented answer to these questions demonstrates considerably more maturity than a perfect policy that is never used.


Nineteenth: How Can the Maturity of the Risk-Management System Be Assessed?

An organisation can review elements such as:

  • A clear risk-management framework and policy.
  • Alignment of risks with strategic objectives.
  • An approved Risk Appetite.
  • Regular updating of the Risk Register.
  • Clear Risk Ownership for major risks.
  • Distinction between Inherent and Residual Risk.
  • Assessment of control effectiveness.
  • Treatment Plans for significant risks.
  • KRIs and escalation thresholds.
  • Risk reporting to management and the Board.
  • Use of Scenario Analysis for major risks where appropriate.
  • Integration with Business Continuity.
  • Analysis of incidents and Near Misses.
  • Documentation of corrective actions and lessons learned.
  • Integration of risk assessment into projects, decisions, and significant changes.

Maturity should not be measured by the number of documents produced.

The real question is:

Do organisational decisions change when organisational risks change?

If not, the organisation may have a Risk Register, but risk management has not yet become a genuine part of management.


Twentieth: From Risk to Continuous Improvement

After an incident or Near Miss, the process should not end with:

The problem has been fixed.

The organisation should ask:

Why did it happen?

Why was it not identified earlier?

Were the controls inadequate, or were they not applied?

Does the same risk exist elsewhere?

What should change?

The sequence then becomes:

Incident → Root Cause → Corrective Action → Updated Controls → Updated Risk Assessment → Lesson Learned

This is how risks and incidents become inputs into institutional improvement.


Before Moving to the Next Article...

An organisation can begin with practical steps:

✓ Identify risks linked to its key objectives.

✓ Create or update the Risk Register.

✓ Assign a Risk Owner to each major risk.

✓ Assess Inherent Risk.

✓ Document existing controls.

✓ Assess Residual Risk.

✓ Define Risk Appetite and Risk Tolerance in key areas.

✓ Develop Treatment Plans for risks exceeding acceptable limits.

✓ Define KRIs for major risks.

✓ Establish clear intervention and escalation thresholds.

✓ Use Scenario Analysis for critical risks.

✓ Link risk management with Business Continuity.

✓ Review risks periodically at management and Board level.

✓ Analyse incidents and Near Misses.

✓ Turn lessons learned into actual changes to controls and procedures.


Quick Self-Assessment

Ask yourself:

□ Do we know the most important risks currently threatening our objectives?

□ Do we know how much risk we are prepared to accept?

□ Does every major risk have a clear Risk Owner?

□ Do we know the level of risk before and after controls?

□ Do we test whether controls work, or simply assume they do?

□ Do we have indicators that warn us before major risks escalate?

□ Does the team know when a risk must be escalated?

□ Do we understand how a risk in one function can create risks elsewhere?

□ Do we have prepared scenarios for critical risks?

□ Do we know which services must continue during a crisis?

□ Can employees report risks early?

□ Does the Board regularly discuss significant risks?

□ Can we provide an example of a decision that changed because risk exposure increased?

□ Can we demonstrate that treating a risk reduced its Residual Risk?

If the answer is “No” to several of these questions, the organisation may be recording risks, but it may not yet have built an institutional risk-management system.


Conclusion

Risk management is not an attempt to predict the future with precision.

It is about building an organisational capability to deal with uncertainty.

That capability begins when the organisation understands its objectives, identifies what could prevent them from being achieved, determines how much risk it can tolerate, assigns ownership of major risks, monitors early warning signals, prepares for plausible scenarios, and intervenes before risk becomes crisis.

A more mature organisation goes further.

It does not only ask:

How do we protect ourselves from this risk?

It also asks:

What did we learn from it, and what can we improve because of it?

Risk management then becomes more than a register, matrix, or reporting process.

It becomes part of governance, planning, decision-making, and organisational learning.

The organisations most capable of sustaining their missions are not those that face no risks, but those that see them early, understand them, know their limits, respond deliberately, and use what they learn to build a stronger, more resilient, and more sustainable organisation.