Risk Strategy
Risk Owner vs. Action Owner: Stop Giving One Person Three Jobs
A name in the owner column can hide three different jobs. Separate who decides about the exposure, who runs the control, and who delivers the change.
By Eric Kennedy · Thu Sep 24 2026 · 10 min read
A risk owner is accountable for the business decision about an exposure. A control owner runs a repeatable activity intended to keep that exposure within bounds. An action owner delivers a defined change by an agreed date.
Those jobs can sit with one person in a small company. They should not be treated as the same job.
When a risk register has a single “owner” column, the name often belongs to the person chasing the mitigation plan. That person may have no authority to accept the remaining exposure, fund the response, or change the operating plan. The register looks complete while the decision remains unowned.
The owner field hides three different questions
Most ownership disputes are not really about willingness. They start because the organization has not said what the named person owns.
Consider three questions:
- Who decides whether the current exposure is acceptable and what response the business will take?
- Who operates and evidences the controls that are supposed to work today?
- Who is responsible for completing a specific improvement?
If the answer is “the risk owner” in all three cases, the label is doing too much work.
The Orange Book, updated July 29, 2026, says roles should support appropriate escalation, aggregation, and delegation. Its section on risk treatment separately calls for identifying the people accountable and responsible for approving and implementing the chosen response. That distinction is useful even outside government.
The Orange Book applies to UK central government organizations. It is not a rule for US mid-market companies, and it does not prescribe the three-role model below. The model is KRG's practical interpretation of a common operating problem.
Risk owner: owns the exposure and the decision
The risk owner should be able to explain how the exposure could affect an objective, what the business is doing about it, and what would cause a different decision.
That requires enough authority to recommend or approve a response, obtain resources within delegated limits, and escalate when the exposure exceeds those limits. It does not require the risk owner to perform every control or manage every task.
A useful risk-owner assignment passes a simple test: if the current response stopped making sense tomorrow, would this person have the authority and operating context to bring the right decision forward? If not, the register may name a coordinator rather than an owner.
Control owner: owns repeatable operation and evidence
A control owner is responsible for a specific control that already operates, such as reviewing privileged access, reconciling inventory, or approving pricing outside stated limits.
The control owner should know the purpose of the control, how often it operates, what evidence it leaves, what counts as an exception, and where the exception goes. “Finance monitors it” is not a control assignment. Neither is a person’s name without the activity and evidence.
Control ownership is narrower than risk ownership. A daily exception report may help manage a revenue-recognition exposure. The person who reviews the report does not automatically decide how much exposure the company should carry or whether a system replacement should be funded.
Action owner: owns a defined change
An action owner is responsible for delivering a specific improvement, such as qualifying a second supplier, changing a contract, or replacing a manual approval with system workflow.
The action needs a deliverable, a completion condition, a date, required resources, and a path for raising a constraint. “Improve vendor resilience” is not an action. “Complete qualification testing for the alternate component and obtain quality approval” is.
Completion also needs evidence. A project marked 100 percent complete does not establish that the change reduced the exposure. The risk owner still needs to decide whether the result works well enough and whether the residual exposure is acceptable.
Keep internal audit out of management ownership
The IIA's Three Lines Model places responsibility for managing risk within management. First-line roles act to achieve objectives and manage risk. Second-line roles add expertise, monitoring, support, and challenge. Internal audit provides independent assurance and advice.
That means a CAE can challenge a weak owner assignment, facilitate a workshop, or recommend clearer decision rights. Internal audit should not quietly become the owner because it maintains the risk register or follows up on actions.
The IIA model also recognizes that companies distribute responsibilities differently. It does not require a particular job title to own each risk. The point is to preserve management accountability and internal audit independence, not to force a large-company organization chart onto a lean team.
Assign the work from the decision outward
Start with the decision the company may need to make, not with the person who has the most tasks.
Ask who can decide among the realistic responses. Then identify the controls supporting the current response and the changes intended to improve it. Assign those narrower responsibilities to people with the knowledge and capacity to perform them.
The questions below keep the assignments honest. They are a management check, not a new standard or proprietary maturity model.
Use the test in this order:
- Who can decide whether to accept or change the exposure? Name the risk owner. If the decision exceeds that person's authority, document the escalation route instead of assigning a more senior name that will never engage.
- Who runs and evidences the repeatable control? Name the control owner and state the activity, frequency, evidence, exception condition, and recipient.
- Who delivers the defined change by the agreed date? Name the action owner and specify the output, resources, dependencies, and evidence of completion.
Someone who supplies data, attends a review, or supports implementation may be important. That does not make the person an owner. Calling every contributor an owner makes the word useless.
An illustrative handoff
Consider a constructed manufacturer, not a KRG client engagement. A legacy pricing interface can send incomplete updates to the invoicing system during the close. Management is relying on a daily exception review while a replacement interface is being built.
The VP of Finance owns the risk because that executive can decide whether the current response is acceptable, request additional resources, change the close process, and escalate a material financial-reporting concern.
An accounting manager owns the control. Each business day, the manager reviews the interface exception report, retains evidence of the review, and escalates unresolved exceptions under the stated procedure.
The transformation director owns the action to deliver and test the replacement interface by the approved date. The director reports delivery constraints, but does not decide whether Finance should keep relying on the temporary process.
When the replacement is delivered, the action owner provides completion evidence. The control owner confirms what is operating. The risk owner decides whether the temporary control can be retired and whether the remaining exposure is acceptable.
This separation prevents a familiar mistake: treating project progress as proof that today's exposure is managed. The distinction also helps when an action is late. The risk-acceptance decision belongs with the person authorized to carry the exposure, not automatically with the person responsible for finishing the work.
Put enough information beside each name
A second column for “action owner” will not fix the problem if the record still omits the decision and the evidence.
For material risks, keep the following information together:
Ownership record in detail
| Record | What it should establish | Useful evidence |
|---|---|---|
| Exposure and objective | What could affect which operating or financial objective. | Current assumptions, affected commitments, and material constraints. |
| Risk owner | Who makes or escalates the response decision. | Decision authority, review cadence, escalation boundary, and current response. |
| Control owner | Who operates the control relied on today. | Control activity, frequency, evidence, exception criteria, and recipient. |
| Action owner | Who delivers the agreed improvement. | Defined output, target date, resources, dependencies, and completion evidence. |
| Residual exposure | What remains after current controls and completed actions. | Current assessment, limitations, and the person authorized to accept it. |
| Reopening trigger | What forces an earlier review or a new decision. | Threshold breach, failed control, missed dependency, or changed assumption. |
A larger register will not help. Keep the few fields that explain who decides, who operates, and who delivers during a live management review or escalation.
The Orange Book's risk-treatment guidance similarly calls for the rationale, proposed actions, accountable and responsible people, resources, measures, constraints, timing, and basis for monitoring. Again, its government scope matters. A mid-market company should adapt the principle to its size rather than reproduce a government process.
One person can hold more than one role
Separation is not the goal by itself. In a lean company, a controller may legitimately own the financial-reporting risk, operate a key review control, and sponsor a process change.
The arrangement can work if the controller has the authority, time, and access needed for each job, and if somebody provides appropriate challenge. One person wearing several hats is manageable. A record that hides the hats leaves everyone unsure which obligation has been met when exposure changes or the deadline slips.
There is also a point where additional labels become overhead. A routine operational risk with a clear manager, stable controls, and no major change may not need three separate names. Use the distinction where the exposure is material, crosses functions, depends on a significant action, or regularly produces confusion about who can decide.
What the next review should ask
Choose one material risk with an open action and ask four questions:
- Does the named risk owner have authority over the response or a documented escalation route?
- Can the control owner produce current evidence without rebuilding it for the meeting?
- Can the action owner state what completion means, not just the percent complete?
- Who decides whether the residual exposure is acceptable after the action closes?
If the same name answers all four, that may be appropriate. Confirm it deliberately. If four people point to one another, the register has recorded participation rather than accountability.
Clear ownership should make the next decision easier. It should also make assurance mapping more reliable because reviewers can see which management assertion they are testing and who is responsible for the evidence.
Can your risk report show who has to decide?
A board-ready report should make the exposure, current response, owner, and required decision visible without asking the committee to decode a project tracker. The Board-Ready Risk Reporting Scorecard is a quick way to test whether your current reporting does that.
Take the Board-Ready Risk Reporting Scorecard
Frequently Asked Questions
What is the difference between a risk owner and an action owner?
A risk owner is accountable for the business decision about an exposure, including the response, escalation and residual risk. An action owner is responsible for delivering a specific improvement by an agreed date. Completing the action does not transfer the decision about the remaining exposure away from the risk owner.
What is the difference between a risk owner and a control owner?
A control owner operates and evidences a repeatable activity intended to manage risk. The risk owner considers the overall exposure and decides whether the combination of controls and other responses is adequate. One person may fill both roles, but the responsibilities should remain explicit.
Can one person be the risk owner, control owner and action owner?
Yes, especially in a lean organization, if the person has the authority, capacity and knowledge required for each role. The record should still distinguish the decision, recurring control and defined improvement so that completing one obligation is not mistaken for completing all three.
Should internal audit be a risk owner?
Internal audit can facilitate, challenge and advise, but management remains responsible for managing risk. Giving internal audit a management ownership role can impair the independence needed to provide assurance over that area.