Adrianus Darmawan

Structuring risk-based options for executive decisions under uncertainty.

Risk | Strategy | Capital | Resilience

Risk Management for Better Decisions Under Uncertainty

Risk management is prudent decision making under uncertainty. It should operate where objectives, uncertainty, choices and consequences meet, before outcomes become irreversible.

01 / Core thesis

Decision quality under uncertainty

Risk Management Should Improve Decisions

Risk does not exist in isolation. It becomes meaningful in relation to an objective, a choice or an expected outcome. Starting with a list of risks therefore begins one step too late. The first task is to understand what the organization is trying to achieve and what the decision relies upon.

Important decisions rarely offer a clean choice between safe and unsafe. They involve competing objectives, incomplete evidence and different consequences across growth, profitability, customers, operations, capital, reputation and regulation. A proposal may look attractive through one lens while creating fragility through another. Risk management should make that full decision visible.

This is why risk management should be centered on decision quality. It structures the objective, evidence, assumptions, alternatives, downside scenarios, trade offs, conditions, limits, escalation triggers and accountable actions around a material choice. The point is not to add ceremony. It is to improve the decision before commitment makes the outcome expensive or difficult to reverse.

A useful risk opinion does more than describe exposure. It explains how uncertainty could transmit into consequences, distinguishes symptoms from drivers and identifies which management actions remain practical. It may support the proposal, impose conditions, narrow the boundary, require safeguards or object where the exposure is not understood or cannot be contained.

Outcomes before outputs

Reports, models, policies and committees are tools. They are not the outcome of risk management. The outcome is earlier recognition, clearer choices, deliberate use of capacity, stronger protection of critical objectives and faster action when conditions change.

A risk function should therefore be judged by the quality of organizational judgment it enables. Did management understand the assumptions? Were realistic alternatives considered? Were conditions defined before approval? Did the organization act before a limit was breached? Could it explain why the final choice was reasonable based on the information available at the time? These are more meaningful tests than the number of registers produced.

Signal

What changed or may be emerging?

Cause

Why does it matter and what drives it?

Scenario

How could it develop or combine?

Impact

Which outcomes and capacities are affected?

Action

What decision, condition or trigger follows?

A practical mental map

From objective to ownership

Seven connected questions give executive discussion a disciplined path. Uncertainty is not a separate step. It tests every step.

  1. 01

    Objective

    What outcome matters, what value should be created and what must be protected?

  2. 02

    Options

    What realistic courses of action are available, including delay or inaction?

  3. 03

    Trade-offs

    What is gained, lost, consumed or newly exposed under each option?

  4. 04

    Conditions

    What must be true, evidenced or completed before proceeding?

  5. 05

    Guardrails

    Which limits, safeguards and decision rights keep exposure within bounds?

  6. 06

    Triggers

    What change requires review, escalation, adjustment, remediation or exit?

  7. 07

    Ownership

    Who decides, acts, challenges and monitors, and by when?

02 / Strategic risk

Assess. Pressure test. Embed.

Strategy, risk and corporate action

Strategic risk is not a separate list attached after the plan has been written. It is the uncertainty within the strategic choice itself: what the plan assumes, where it can break and whether the organization has the capacity to respond.

Effective challenge begins by assessing the plan on its own terms. What customer, market, regulatory, operational and financial assumptions must hold? What capabilities are already stretched? What external signals could make the intended path less attractive? The aim is not to rewrite strategy. It is to make the strategy stronger before it meets the real world.

Pressure testing then examines breakpoints. It explores timing slips, concentration, dependencies, second order consequences and the possibility that several adverse developments occur together. A scenario is useful only when it changes the understanding of a decision. It should reveal what breaks first, how much time management has and which response remains executable.

Embedding converts the analysis into the strategy. Assumptions become indicators. Appetite becomes boundaries. Scenarios become triggers. Management actions become prepared options with owners and timing. This connects planning with the signals that should cause leaders to accelerate, adapt, pause or exit.

Assess

Understand what the plan relies on

Separate evidence from assumption. Identify external signals, internal constraints, required capabilities and the outcomes the strategy must protect.

Pressure test

Find the breakpoints and hidden dependencies

Test timing, concentration, behavior, execution, capital and combined scenarios. Ask what fails first and what follows.

Embed

Put the response inside execution

Translate analysis into appetite, conditions, indicators, escalation triggers, decision rights and management actions.

Corporate actions and parenting structure

Mergers, acquisitions, divestments, joint ventures and group restructuring concentrate uncertainty into a limited decision window. Transaction economics matter, but they are only one part of the judgment. Leaders also need to test strategic fit, the assumptions behind value creation, capital consumption, funding, execution capacity, governance rights, cultural integration, risk concentration and the cost of delay or failure.

The parenting structure is part of the risk assessment. A group can create value through capital allocation, expertise, standards, shared services and oversight. It can also create ambiguity if decision rights, legal responsibilities and support expectations are not aligned. The key question is not simply whether the parent can intervene, but when it should, under which authority and with what consequences for local accountability.

A defensible corporate action therefore requires a clear mandate map, delegation of authority, conflict declarations, an evidence trail, fair value boundaries, integration milestones, exception governance and explicit remediation or exit conditions. These disciplines do not replace commercial judgment. They protect it from hidden assumptions and unclear ownership.

Corporate action decision test

Strategic logic
What value is created, and which assumptions carry that logic?
Capacity
Can capital, funding, management attention and operations absorb the transaction and its downside?
Control
Are governance rights, information access and decision authorities sufficient for the exposure?
Execution
Which milestones prove integration, and what happens when they are missed?
Exit
What evidence would invalidate the thesis and require remediation, repricing or exit?

03 / Financial capacity

Capital, solvency and ALM

Capital should guide choice, not only absorb failure

Strategy determines where an organization intends to compete, invest and grow. Risk frames the uncertainty attached to those choices. Capital determines how much loss, volatility and adverse development can be absorbed. These are one management conversation.

A strategy can appear attractive based on growth or accounting return and become less compelling after considering capital consumption, liquidity, earnings volatility, concentration, management capacity and the behavior of the balance sheet under stress. The objective is not to choose the lowest risk option. It is to choose a risk return profile that is understood, acceptable and supported by capacity.

Solvency is therefore more than a regulatory ratio. The current number is only a starting position. Management needs to understand what drives available and required capital, how the position changes under the business plan, how sensitive it is to combined movements and what buffer is needed to act without being forced into value destroying choices.

Forward assessment asks whether the position remains sustainable through time. Stress testing asks what breaks first, when it breaks and which management actions remain executable. Reverse stress testing starts from a nonviable outcome and identifies the conditions that could produce it. Both should connect to early warnings, action zones and a management playbook rather than ending as model output.

Asset and liability management beyond duration

Asset and liability management is balance sheet steering, not a single duration gap. An apparently matched position can still carry material exposure when cash flow timing, liquidity, optionality, asset quality, policyholder or customer behavior, collateral needs and reinvestment conditions are not understood.

Good ALM connects liability behavior with asset cash flows and asks how the relationship changes under stress. It challenges assumptions about rates, lapses, utilization, liquidity, guarantees and market access. It examines both economic and accounting effects, because a response that protects one measure can weaken another.

The management question is not merely whether assets and liabilities are matched today. It is whether the organization can continue meeting obligations, preserve sufficient capital and rebalance when behavior, markets or cash flows depart from plan.

Monitor

Position, buffer and leading indicators

Diagnose

Drivers, sensitivities and interaction

Decide

Options, trade offs and action zone

Execute

Owner, authority, timing and evidence

04 / Governance and control

Authority, evidence, assurance

Governance is a decision system

Governance is not the existence of committees, policies and delegated authorities. It is the system through which important decisions are proposed, challenged, approved, executed, monitored and revisited.

A sound system makes roles explicit. Who proposes? Who challenges? Who decides? Who approves? Who executes? Who monitors? Who escalates? The answer can vary by decision, but it should never remain implied. Ambiguity creates both delay and unowned risk.

Governance also protects the decision trail. It should preserve the objective, evidence, assumptions, alternatives, objections, conditions and reasons for the final choice. This is not bureaucracy for its own sake. It allows the organization to explain its judgment, revisit it when information changes and learn without rewriting history.

Good governance should make decisions defensible without making them slow. Proportionality matters. A low impact and reversible decision should not carry the same burden as a transaction, product, exposure or operational change that can create irreversible consequences.

Internal control environment and Three Lines alignment

An internal control environment becomes credible when control design, operating behavior and assurance tell a consistent story. A written control may be well designed but poorly executed. A control may operate but lack reliable evidence. An issue may be recorded but never reach verified closure. These are different weaknesses and require different responses.

The Three Lines model, sometimes described as the first, second and third lines of defense, helps when it clarifies accountability, not when it creates organizational distance. The first line owns the business decision, the associated risks and the controls embedded in execution. The second line owns the framework, method, independent challenge, risk opinion and escalation. The third line provides independent assurance over governance, risk management and control.

Alignment does not mean merging these roles. It means using common definitions, traceable evidence and coordinated coverage while preserving independence. The first line should not outsource ownership to risk. The second line should not represent its monitoring as audit. The third line should remain able to assess both without having designed the controls it reviews.

LinePrimary accountabilityEvidence of effectiveness
First line

Owns decisions, risks, processes and controls in daily execution.

Control operation, exceptions, corrective action and accountable ownership.

Second line

Sets the method, challenges, forms the risk opinion and escalates.

Independent monitoring, thematic review, challenge record and transparent position.

Third line

Provides independent assurance over governance, risk and control.

Risk based assurance, findings and verified management response.

Continued control assurance

Control assurance should be continuous in logic even when tests occur periodically. It follows a closed loop: define the control objective, assess design, collect operating evidence, identify exceptions, assign remediation and verify closure. The loop is incomplete when an issue disappears from reporting before the underlying weakness has been retested.

Practical maturity begins with authority and evidence before sophisticated tooling. Establish clear ownership, a reliable repository, version control, approval records, an issue log and exception governance. Then strengthen methodology, coverage and automation. A complex system cannot compensate for unclear accountability or weak evidence.

Control objectiveDesignOperating evidenceExceptionRemediationVerified closure

05 / Emerging risk

From Insight to Foresight to Action

Foresight before hindsight

Historical data is necessary but insufficient. Major disruptions often begin as weak signals that appear unrelated until their transmission paths become visible.

Signals may emerge across regulation, markets, customers, operations, technology, geopolitics and social expectations. Individually they can look immaterial. Together they may change a strategic assumption, accelerate customer behavior, increase liquidity pressure or expose an operational dependency. Foresight is the discipline of connecting those signals before urgency removes choice.

This requires causal reasoning, not disconnected storytelling. A scenario should explain the direction of relationships, the time lag, the assumptions and the point at which an effect becomes material. It should distinguish a root driver from a symptom and reconcile the narrative with financial and operational measures.

Risk categories remain useful for ownership and measurement, but material events rarely stay within one category. A market movement can create liquidity pressure, customer action, operational strain and a hurried management decision. A regulatory change can alter product economics, capital, systems, behavior and reputation at the same time. The most dangerous exposure may be the combination of risks assessed separately.

Regulatory change as a strategic issue

Regulatory change should not begin as a document or system implementation exercise. Changes in solvency, accounting, governance, customer protection or capital can alter strategy, product economics, asset allocation, data, operating models, management incentives and customer outcomes.

The first question is therefore: which management decisions will this change alter? Once the strategic and economic implications are understood, the organization can translate them into policy, process, system and reporting requirements. Technical compliance without strategic interpretation is an incomplete implementation.

Anticipate

Scan signals, test assumptions and identify plausible changes before the threat becomes obvious.

Integrate

Connect causal paths across strategy, customers, operations, finance, capital and reputation.

Activate

Convert insight into thresholds, decision options, accountable actions and escalation.

06 / Organizational resilience

Protect critical outcomes

Resilience is built before disruption

Resilience is not simply recovery after an incident. It is the ability to anticipate, adapt and continue delivering critical outcomes when normal assumptions, resources or processes no longer hold.

The starting point is the outcome or service that must be protected. Which customers, obligations or public interests depend on it? What level and duration of disruption can be tolerated? Which people, technology, facilities, data, funding and third parties are necessary? This outcome view exposes dependencies that functional continuity plans can miss.

Business continuity plans are necessary but not sufficient. A resilient organization knows the trade offs that become acceptable in stress, who has authority to make them and which alternative arrangements are genuinely ready. It also has communication discipline, financial capacity and management actions that have been tested rather than merely documented.

Resilience improves through learning. Incidents, near misses, exercises and control failures should update assumptions, tolerances, dependencies and response arrangements. Recovery is not complete when service resumes. It is complete when the organization understands why the disruption propagated and changes the system accordingly.

Critical outcome test

Priority

Which outcome must be protected first, and why?

Tolerance

How much disruption can customers and obligations bear?

Dependency

Which internal and external resources make it possible?

Authority

Who can make trade offs when normal governance is too slow?

Alternative

What tested arrangement works when the primary path fails?

Risk culture is how people think before acting

Risk culture is not primarily a communication campaign. It is visible in daily choices: whether people test assumptions, raise bad news early, own exceptions and welcome challenge before commitment. The strength of culture is not measured by the frequency of risk terminology. It is measured by whether people act differently because they understand the uncertainty and consequence.

A healthy culture asks what could go sideways, which assumption may be wrong, who may be affected, what evidence supports the decision and what should cause reconsideration. It treats escalation as responsible behavior rather than disloyalty. It also protects dissent long enough for a concern to be examined on its merits.

“Culture becomes visible at the moment a person decides whether to surface an uncomfortable fact or let the organization continue with a comfortable assumption.”

07 / Technology and judgment

Human accountability

Artificial intelligence should amplify judgment, not substitute for it

Technology can improve the speed, consistency and scale of risk analysis. Artificial intelligence can help find signals, organize evidence, generate scenarios and reveal patterns that would otherwise take longer to see.

Those capabilities are valuable, but automated confidence is not the objective. A model does not carry management accountability. It cannot decide which trade offs are acceptable, whether an assumption is reasonable in context or whether an apparently efficient choice creates unfair or unacceptable consequences.

The output should remain explainable, auditable and challengeable. Users need to know the source of evidence, the limitations of the method and where human interpretation entered the result. Material uses require clear ownership, validation, monitoring, change control and a practical route for human override.

The strongest application is a partnership between machine scale and human judgment. Technology expands the field of vision. People determine causal meaning, materiality, fairness, action and accountability.

Technology can support

  • Research and signal surveillance
  • Evidence synthesis and pattern recognition
  • Scenario generation and sensitivity exploration
  • Documentation, comparison and monitoring

Human judgment must retain

  • Context and causal interpretation
  • Materiality, fairness and consequence
  • Acceptable trade offs and decision authority
  • Accountability for action and outcome

08 / Applicability

Across multiple industries

The framework travels. The context changes.

The approach applies wherever leaders allocate resources, accept uncertainty, maintain controls and protect important outcomes. The framework is consistent across industries; the evidence, risk drivers, capacity measures and obligations are not.

Cross industry applicability should not mean forcing every organization into one risk taxonomy. It means beginning with the same disciplines: clarify the objective, identify uncertainty, trace consequences, compare options, test capacity, set conditions and assign action. Industry knowledge then determines what matters within each discipline.

01

Financial services

Capital, solvency, liquidity, asset and liability management, product economics, conduct and regulatory change.

Can the strategy remain viable when market, behavior, liquidity and capital stresses occur together?
02

Diversified groups

Corporate parenting, delegation, shared services, concentration, portfolio choices, acquisitions and integration.

Do governance rights, risk ownership and group support match the exposures created across the portfolio?
03

Technology and digital

Cyber risk, third parties, data, artificial intelligence, service reliability, model governance and rapid change.

Which critical outcomes depend on technology, and what human decision remains accountable when automation fails?
04

Infrastructure and public services

Continuity of essential services, long dated assets, public accountability, safety, mandate and financial capacity.

Which services must continue, within what tolerance, and who has authority when normal procedures are too slow?
05

Consumer and operating companies

Customers, supply chains, quality, pricing, working capital, conduct, operational control and brand trust.

How could an operational weakness transmit into customer harm, financial loss and a wider loss of confidence?

A practical decision standard

Ten questions for every material risk discussion

If an assessment cannot improve these answers, it may not yet be decision ready.

  1. 01

    Objective

    What outcome are we trying to achieve, and for whom?

  2. 02

    Decision

    What must management or the board decide now?

  3. 03

    Uncertainty

    What is not known, stable, controllable or independently verified?

  4. 04

    Material risk

    What could materially weaken, delay or prevent the intended outcome?

  5. 05

    Options

    What realistic courses of action, including inaction, are available?

  6. 06

    Trade offs

    What is gained, lost, consumed or newly exposed under each option?

  7. 07

    Conditions

    What must be true, evidenced or completed before proceeding?

  8. 08

    Guardrails

    What limits, safeguards and decision rights are required?

  9. 09

    Triggers

    What change requires review, escalation, remediation or exit?

  10. 10

    Ownership

    Who decides, acts, challenges and monitors, and by when?

Essential questions

A concise guide to the professional view

01What is risk management?

Risk management is prudent decision making under uncertainty. It connects an objective with the assumptions behind it, the ways it can be weakened, the options available, the capacity to absorb adverse outcomes and the actions required if conditions change. Its value is measured by better judgment and earlier action, not by the volume of risk documentation.

02How should risk management connect with strategy?

Risk should enter while strategy is still being shaped. It should assess what the plan relies on, pressure test breakpoints and hidden dependencies, and embed appetite, conditions, indicators and response options into execution. Risk does not rewrite strategy. It helps make the strategic choice stronger before it meets the real world.

03What is independent risk judgment?

Management owns the business decision and its execution. The risk function owns an independent view of the uncertainty, exposure, conditions, limits and escalation required. Independence does not mean distance from the business. It means that challenge and risk position remain clear even when the commercial decision is difficult.

04How do the Three Lines work together?

The first line owns business decisions, risks and controls. The second line owns the framework, method, independent challenge, risk opinion and escalation. The third line provides independent assurance. Alignment requires shared evidence and explicit roles without collapsing these distinct accountabilities.

05What does operational resilience protect?

Operational resilience protects critical outcomes and services, not simply systems or process maps. It identifies what must continue, the tolerance for disruption, the dependencies that matter, the authority to act and the alternatives available when normal conditions no longer apply.

06How can artificial intelligence support risk management?

Artificial intelligence can accelerate research, surveillance, synthesis, scenario development and pattern recognition. Its outputs should remain explainable, auditable and challengeable. Human judgment remains responsible for context, causal interpretation, fairness, materiality and the trade offs that the organization is prepared to accept.

Professional view

Risk management is not a blocker to strategy. It is a discipline for pursuing strategy with greater clarity about uncertainty, capacity and consequence.
What can be done.Under what conditions.Within what limits.With what trade offs.With what response if circumstances change.

Author and professional context

Adrianus Darmawan

Structuring risk-based options for executive decisions under uncertainty.

Chief Risk Officer | Strategic & Enterprise Risk | Capital & ALM | Governance & Resilience

A risk, strategy and capital professional with experience across financial services consulting, banking and insurance. His work connects independent risk judgment with strategy, the balance sheet, governance and organizational resilience.

The position presented here is objective oriented: management owns the business decision and execution; the risk function owns independent challenge, risk position, conditions, limits, escalation and monitoring.