News & Blogs

Beyond Quantification: Norman Marks on Common Sense in Risk Management

Global · · normanmarks.wordpress.com

Norman Marks challenges the conventional wisdom of exhaustive risk quantification, arguing that for many situations, a common-sense approach informed by reliable information is more effective. This perspective is crucial for internal auditors who often grapple with the practicalities of risk assessment and the value derived from overly complex methodologies.


The Bridge Tournament Analogy: Risk in Everyday Life

Norman Marks uses the relatable scenario of driving to a duplicate bridge tournament to illustrate the complexities and often impracticalities of traditional risk management. He meticulously lists various risks, from car accidents and traffic delays to personal performance and health concerns. This detailed, yet everyday, example serves as a foundation for his argument against the automatic quantification of every single risk.

Marks questions the utility of individually quantifying and aggregating these risks, asking whether such an exercise would genuinely influence his actions or provide meaningful information. He highlights the constraints involved, such as the cost-benefit of leaving hours early to mitigate traffic or hiring a professional bridge player. This analogy effectively demonstrates that in many real-world situations, a pragmatic, common-sense approach, rather than an exhaustive analytical one, is often the most sensible path.

Implications for Internal Audit and Risk Management

The core takeaway for internal audit and assurance professionals is Marks' assertion that "sometimes all you need is reliable information about the risks and some common sense." He acknowledges that there are indeed situations where quantifying individual and aggregated risks is valuable, but only when it provides necessary information for decision-making. This challenges the often-ingrained practice within organizations to quantify every perceived risk, regardless of its impact on strategic decisions or operational effectiveness.

Marks' perspective encourages auditors to critically evaluate the purpose and value of their risk assessment methodologies. Instead of blindly applying complex models, internal audit should focus on ensuring that risk information is reliable and that the chosen approach to risk management genuinely supports informed decision-making. This means understanding when a detailed quantitative analysis is truly beneficial versus when a more qualitative, experience-based assessment is sufficient and more efficient.

Rethinking Risk Assessment Practices

For internal auditors, this article prompts a re-evaluation of current risk assessment practices. It suggests that a rigid adherence to quantification can sometimes lead to an over-engineered process that consumes resources without yielding proportional benefits. Instead, auditors should consider:

  • Contextual Relevance: Is the level of risk quantification appropriate for the specific objective and its potential impact?
  • Information Utility: Does the risk information, however derived, genuinely inform and influence management's decisions?
  • Efficiency: Are the resources spent on risk assessment proportionate to the insights gained?
  • Common Sense Integration: How can practical judgment and experience be better integrated into formal risk management frameworks?

By adopting a more nuanced approach, internal audit can ensure that risk management efforts are both effective and efficient, providing valuable assurance without unnecessary complexity.


Read more
Comments

No comments yet. Be the first.


Sign in to join the discussion.

Sign in or Create account
Subscribe

By email

Get audit & assurance news in your inbox.


By feed reader

We publish RSS, Atom, and JSON feeds sliced by category and region.

View all feeds →

Have a tip? Submit a story or job →

Subscribe by email

Get audit & assurance news in your inbox. Or use a feed reader — view all feeds →