Enterprise Risk Management

Stop Asking Executives What Keeps Them Up at Night

A risk workshop should expose disagreement, test assumptions, and force decisions. It should not spend ninety minutes building a list in public.

By Eric Kennedy · Thu Sep 03 2026 · 9 min read

Stop Asking Executives What Keeps Them Up at Night
TL;DR: A productive enterprise risk workshop does not begin with a blank slide and the question, “What keeps you up at night?” Collect individual input first. Use the room to challenge assumptions, trace how risks reach financial and strategic outcomes, and decide who will act. In ninety minutes, a strong workshop should produce a short set of decision-ready risk statements, named owners, escalation thresholds, open questions, and agreed next actions.

Most executive risk workshops begin with good intentions and a bad opening question.

“What keeps you up at night?”

The loudest person names cybersecurity. Someone adds talent. Supply chain follows. The facilitator captures each answer, combines a few duplicates, and asks the group to vote. Ninety minutes later, leadership has a familiar list and a cleaner heat map.

It feels productive because everyone participated. But the workshop has confused participation with analysis.

A useful enterprise risk workshop should not merely collect concerns. It should expose where leaders disagree about the plan, test how an event could travel through the business, and force a small number of decisions.

What is an enterprise risk workshop?

An enterprise risk workshop is a structured working session in which leaders identify, challenge, prioritize, and assign action for risks to business objectives. It is one input to an enterprise risk assessment, not the assessment by itself.

That distinction matters. A workshop can reveal cross-functional dependencies that interviews miss. It can also create false consensus, anchor the group to the first idea raised, and turn uncertain estimates into precise-looking scores.

COSO’s enterprise risk management guidance connects risk with strategy and performance. ISO 31000 treats communication and consultation as continuing parts of the risk process. Those principles point to a simple design rule: the workshop should be built around business objectives and informed challenge, not around filling in a risk template.

Do not use the meeting to generate the first draft

The highest-value design choice happens before anyone enters the room.

Ask each participant for written input independently. Give them the same decision context, the same time horizon, and the same prompts. Do not circulate everyone’s answers in advance.

Why? Live brainstorming is not neutral. Controlled experiments by Michael Diehl and Wolfgang Stroebe found that interactive groups produced fewer ideas than comparable collections of individuals, with production blocking playing a major role. Their research was not conducted in executive risk workshops, so it should not be treated as a direct estimate of workshop performance. It does support a practical guardrail: let people think before they have to listen, react, and defend a position at the same time. Read the study record.

The pre-work should take fifteen to twenty minutes. Ask for no more than three risks from each person, written as scenarios rather than labels.

Weak input: “Cybersecurity.”

Better input: “A ransomware event disrupts order processing during the fourth-quarter peak, delaying shipments and collections while recovery costs rise.”

The better statement gives the room something to challenge. It identifies a trigger, a path through the business, and an outcome. That is the beginning of the KRG Risk Chain: trigger, transmission, constraint, financial outcome.

In the weak version, the room starts with a blank slide, the first answer anchors the group, everyone edits the same list, and the session ends in a vote. In the stronger version, leaders submit independent input, challenge scenarios, trace exposure to the plan, and assign owners, actions, and thresholds.

Comparison of a weak risk workshop that builds a familiar list with a decision-focused workshop that uses independent input, challenge, exposure tracing, and assigned owners and thresholds.

Who should be in the room?

Invite the people who understand the assumptions, dependencies, and response capacity behind the plan. Title alone is a poor selection rule.

For a mid-market company, the core group is often six to ten people. It may include the CFO, operating leader, technology leader, people leader, legal or compliance leader, internal audit leader, and one or two business leaders closest to the current strategic priorities.

The exact list should change with the decision context. A workshop on a new market entry may need sales, pricing, tax, and supply chain expertise. A session on a major system implementation may need process owners who will never appear on the executive committee chart.

Official New Zealand digital-government guidance recommends multidisciplinary workshops because they bring different perspectives and skills to risk identification. It also warns that workshops miss risks when relevant stakeholders are absent. Its guidance is written for information-system risk, not enterprise-wide strategy, but the participation lesson transfers cleanly. Review the guidance.

Keep observers to a minimum. A crowded room changes what people will say, especially when the risk involves a leader’s plan, an underfunded control, or a workaround that management has quietly accepted.

A 90-minute enterprise risk workshop agenda

The agenda below assumes the facilitator has already consolidated the independent input into eight to twelve draft scenarios. It is designed for an executive team, not a large risk-identification event.

TimeFocusRequired output
0 to 10 minutesConfirm the objective, time horizon, and decisions this assessment must informOne agreed decision context
10 to 25 minutesReview the independent input and identify material omissions or duplicatesEight to twelve draft risk scenarios
25 to 50 minutesTrace the most important scenarios from trigger to financial or strategic outcomeClear risk chains and shared dependencies
50 to 70 minutesChallenge exposure, existing controls, response capacity, and confidence in the evidenceA short list of priority risks and open questions
70 to 85 minutesAssign an accountable owner, near-term action, and escalation thresholdNamed owners, actions, thresholds, and dates
85 to 90 minutesRead back decisions and unresolved disagreementsA confirmed record of what changed
Six-stage 90-minute executive risk workshop agenda from decision context through confirmed decisions, with a required output for each stage.

Start with the decision context

Do not ask the group to assess “the company’s risks” without a boundary. That scope is too broad to produce disciplined answers.

Name the objective and time horizon. For example:

“What could cause us to miss the next twelve months of the operating plan, and where would management need to act before the fourth quarter?”

That question directs attention to the plan without telling participants which risks matter. NIST’s current guidance for integrating cybersecurity risk into ERM makes the same basic connection: risk decisions should be understood in light of enterprise objectives. See NIST IR 8286 Rev. 1.

Use the room for challenge

Once the draft scenarios are visible, do not move straight to voting. Ask the group to test each important scenario:

This is where a workshop earns its cost. Finance may see working-capital exposure that operations missed. Technology may identify a recovery dependency hidden inside a supplier discussion. Internal audit may know that a control is documented but inconsistently performed.

The facilitator’s job is not to drive the group toward agreement. It is to make disagreement usable.

Separate estimates from confidence

A single risk score hides two different judgments: how severe the scenario may be and how much evidence supports that estimate.

Ask for both.

A high-impact scenario supported by incident data, contract terms, and tested recovery times is different from a high-impact scenario based mainly on intuition. Both may deserve attention, but the second may require validation before it requires a major investment.

Research on risk discussion reinforces the caution. A 2024 systematic review screened 843 articles and included 60. It found that interpersonal discussion was often associated with higher perceived risk, but the evidence on causality was not strong. The review also describes discussion as a mechanism that can make participants’ perceptions more similar. The studies covered many settings, not executive ERM workshops, so the finding is a warning about group influence rather than a formula for workshop design. Read the review.

Record a confidence judgment beside the exposure estimate: high, medium, or low confidence, with the reason. Do not average away a material disagreement. Capture it and assign the evidence needed to resolve it.

What the workshop should produce

The output is not a transcript and it is not a list of everything discussed. Within one business day, participants should receive a concise decision record containing:

  1. The decision context and time horizon.
  2. Eight to twelve clearly written risk scenarios.
  3. The priority risks, including the rationale for their position.
  4. Material risk chains and shared dependencies.
  5. Accountable owners, immediate actions, escalation thresholds, and due dates.
  6. Open questions, evidence gaps, and named people responsible for closing them.

Every priority risk needs one accountable owner. A committee may coordinate the response, but “the committee” cannot own an exposure. Ownership means authority to coordinate action, escalate a constraint, and bring a decision back to leadership.

The workshop record should also show what changed. If the session did not change a priority, an assumption, an action, or a decision, ask whether the meeting was necessary.

Four failure modes to stop in the room

1. The first speaker sets the ceiling

A senior leader names a concern and every later comment becomes a variation of it. Prevent this with independent pre-work and a silent first review before open discussion.

2. Labels replace scenarios

“Talent,” “AI,” and “competition” are categories. They do not say what might happen or why leadership should care. Rewrite each priority item as a cause-and-effect statement.

3. The group debates decimals

If leaders spend ten minutes arguing whether likelihood is 3 or 4 on a five-point scale, the scale is driving the discussion. Move to the business consequence, the evidence, and the decision that would differ between the two scores.

4. Ownership is assigned without authority

The named owner leaves with accountability but no control over the functions, budget, or decision rights needed to respond. Surface that constraint before the workshop ends.

The honest counterpoint: not every assessment needs a workshop

A workshop is expensive. Ten executives in a ninety-minute meeting consume fifteen leadership hours before preparation and follow-up.

Skip or narrow the workshop when the question is technical, the relevant evidence is held by two or three people, or leadership has no decision to make. Interviews, data analysis, or a short working session may produce a better answer.

The case for a workshop is strongest when the risk crosses functions, the facts are incomplete, participants hold different assumptions, and leadership can act on the result.

That is the decision rule. Use a workshop when the value comes from structured disagreement. Use another method when the room would only confirm what is already known.

A final test for the facilitator

Before scheduling the session, finish this sentence:

“At the end of this workshop, leadership will be able to decide ______.”

If the blank cannot be completed, the agenda is not ready.

A strong enterprise risk workshop does not try to make every participant equally comfortable. It gives each person a fair way to contribute, then makes the group confront the assumptions and dependencies that could break the plan.

If your current process produces a polished list but weak ownership, unclear escalation, or little connection to executive decisions, the ERM Program Diagnostic can identify where the operating model is breaking down and what to fix first.

Frequently Asked Questions

How long should an enterprise risk workshop last?

For an executive session with pre-work completed, 90 minutes is often enough to challenge eight to twelve scenarios and assign actions. A full assessment may require interviews, analysis, and follow-up sessions; the workshop is only one input.

What should participants prepare before a risk workshop?

Each participant should receive the business objective, time horizon, and common scenario prompts, then submit no more than three risks independently. The facilitator should consolidate them without erasing meaningful differences.

Who should facilitate an enterprise risk workshop?

Use a neutral facilitator who understands the business context, can challenge senior leaders, and has no incentive to defend a particular score or function. The facilitator may be internal or external.

What should an enterprise risk workshop produce?

The session should produce decision-ready risk scenarios, named owners, immediate actions, escalation thresholds, evidence gaps, due dates, and a record of unresolved disagreements.