I’m in the process of developing and formalizing the Risk Appetite Statement (RAS) for my organization, a public transport operator. Before we bring the draft to the Board, I’d appreciate your views on the best approach for engaging the Senior Leadership Team (SLT): Is 1:1 engagement more effective to gather candid input? Or would a group workshop be better to align perspectives and drive collective ownership? If anyone has experience developing a RAS specifically for a public transport or infrastructure-focused entity, I’d love to hear your lessons learned or key considerations. Appreciate any tips or tools!

1.6k viewscircle icon3 Comments
Sort by:
Director, Legal in Finance (non-banking)3 days ago

In my experience, organizational culture and leader preference is a consideration as well, but it might depend on what else is in place and the maturity of the risk program (i.e. are you starting from scratch or do you already have board reported KRIs and well defined risk taxonomy). If the leaders prefer to have engagement or input from their line management, then an initial bottom-up approach may yield a starting point that takes into account on the ground risk reality before discussing RAS 1:1 with the leader. This could give some comfort to the senior leader that their team was engaged. Alternatively, some leaders will be quite comfortable with articulating their appetite. I think you play a key role too, and being viewed as a partner in the process will help bear fruit i.e. by bringing to the table various thoughtful starting points, reasonable options, your own perspectives and expertise, and of course helping them understand the 'why' and what's in it for them. Good luck!

Associate Director, Risk Operations in Finance (non-banking)8 days ago

Developing a RAS(es) can be a tough gig. Taking a leaf out of Human Centred Design (HCD) approaches, I'd suggest 1-on-1 engagement is gold. Really taking the time to tease out the SLT's individual needs and how a RAS might address the same... until you gather that understanding you run a real risk of an otherwise great solution tackling the wrong problem.

Chief Information Officer in IT Services2 months ago

I have not developed RAS for a transport operator, but for other industries like Banking, Services. Best approach to get what you want from SLT is a 1:1 engagement only. Once the inputs are in, then the driving force can be from the key leadership to the specific set of audience, in a workshop.

Content you might like

Attack Surface Management40%

Account Takeovers65%

Executive Protection48%

Hacktivism/Disinformation29%

Brand Abuse/Impersonations19%

Phishing Attacks32%

View Results

Strongly support – essential for orgs in financial services13%

Support with reservations – somewhat concerned about feasibility/cost46%

Neutral/indifferent24%

Somewhat oppose – timeframe seems unrealistic14%

Strongly oppose – could be detrimental to resource allocation or operational flexibility1%

Unsure1%

View Results