Governance, Risk and Compliance Blog Post

Effective Risk Management Depends on Effective Change Management

Jason Franks September 21, 2026 3 min read
Effective risk management depends on effective change management

Why Change Management Is Essential to Risk Management 

Risk management is fundamentally about anticipating what could go wrong and taking appropriate steps to reduce the likelihood or impact of those events. But identifying risks and developing policies to address them are only part of the equation. Organizations also need to ensure that those policies translate into everyday practices.

That is where change management becomes essential.

Organizations frequently conduct assessments and develop new policies in response to identified risks. Having those policies in place is important, but simply issuing a new policy does not ensure that employees will follow it effectively. Organizations need to consider how the policy will affect day-to-day processes, how employees will incorporate it into their workflows, and how leadership will ensure that the intended changes occur.

Help Employees Understand the Bigger Picture

One of the biggest barriers to change is straightforward: people become comfortable with existing processes. A new requirement might be perceived as disruptive, cumbersome, or simply another obstacle standing between employees and the work they need to accomplish.

Leadership therefore needs to do more than announce a change. Leaders need to explain why it is necessary and help employees understand the bigger picture. Employees should understand not only how a change affects their individual responsibilities, but also how it benefits the broader organization. Different teams also need to examine the change from their own perspectives and determine how it should be incorporated into their everyday activities.

Effective communication, however, is only one component of change management. Organizations also must recognize that change itself can introduce risk.

Consider something as seemingly routine as installing new software. If the organization has not performed sufficient due diligence, the software might lack necessary security patches or might not be configured securely. A change intended to improve operations could inadvertently introduce vulnerabilities and expose systems or data.

The same principle applies to routine software patches. Before deploying them broadly, organizations should test them in an appropriate environment to determine whether they might unexpectedly disrupt other systems. In other words, managing change requires considering unintended consequences before they become operational problems.

Test Changes Before the Stakes Are High

Change management should not begin after leadership hands down a new requirement. Organizations should proactively identify where changes might be necessary and evaluate those changes before an actual incident forces the issue.

Incident response illustrates the point. Organizations typically conduct lessons-learned activities after an incident to identify what worked, what failed, and what needs to improve. But they also can uncover many of those issues before an incident occurs through exercises that simulate realistic situations.

Tabletop exercises are one option. Participants gather to work through a hypothetical scenario, responding to new information as it is introduced and discussing the actions they would take. The exercise should extend beyond IT personnel. Operations and communications personnel, leadership, and other stakeholders all might have responsibilities during a real event.

For a 911 center, for example, an exercise might explore what happens when computer-aided dispatch or call-handling systems slow down or fail completely. Participants can examine when leadership needs to become involved, how internal and external communications should be handled, whether agreements with other agencies are adequate, and whether an incident could produce downstream effects for partner organizations.

Go Beyond the Tabletop

Tabletop exercises are only one way to evaluate readiness. Three other highly effective tactics exist: functional, technical, and integrated exercises.

Functional exercises evaluate operational capabilities by having participants perform their assigned responsibilities within a simulated environment. Instead of simply describing what they would do, participants carry out their roles.

Technical exercises focus primarily on IT and security personnel. These exercises can evaluate capabilities such as detecting an incident, investigating what happened, containing the problem, and eradicating the threat.

Integrated exercises expand the scope even further by bringing together leadership, technical and communications personnel, external partners, and vendors. This is particularly important when an organization relies on outside organizations to support critical systems or incident response.

An integrated exercise also can reveal difficult tradeoffs. Imagine that an organization discovers during an incident that the problem originated with a vendor. The immediate reaction might be to disconnect that vendor. But what happens if doing so also causes the organization to lose an essential service? Exercises allow stakeholders to work through those decisions before they must make them under the pressure of a real emergency.

Creativity Strengthens Change Management

The connection between change management and risk management ultimately comes down to preparation. Risks evolve, policies change, technology changes, and organizations must continually adapt. But every adaptation can have consequences of its own.

That makes creativity an important component of effective change management. Organizations should develop realistic but challenging scenarios and use the appropriate combination of tabletop, functional, technical, and integrated exercises to put proposed processes and responses through their paces.

The objective is not simply to imagine the most likely problem. It is to explore what could happen, identify vulnerabilities, understand downstream effects, and determine how people, processes, partners, and systems will respond.

Effective risk management requires effective change management. And effective change management requires organizations to test assumptions before real-world events test them instead.

Jason Franks is MCP’s risk management analyst. Email him at JasonFranks@MissionCriticalPartners.com.



Don't forget to share this post!

Jason Franks

Related posts

Industry News Consulting

Effective Organizational Change Management Is as Necessary as Change Itself

July 2, 2024
Jennifer Wray
Cybersecurity

Vulnerability Management is Best Achieved via a Risk-Based Approach

June 28, 2023
Jason Franks