COO Risk Management: How the Operating Chief Owns Enterprise Risk

The person who runs the day-to-day is the person best placed to see where it breaks. That is why risk lands on the Chief Operating Officer. Not because the COO is the company's insurance policy, but because the COO owns the machine that risk actually threatens: the plants, the vendors, the systems, the people, the cash cycle. When a single supplier fails or a payment system goes down, it is the COO's operation that stops.
This article is about ownership, not method. If you want the step-by-step mechanics of scoring and ranking threats, that lives in the risk assessment framework. Here the question is different: what does it mean for a COO to own risk, where does that ownership start and stop, and how do you run it so it protects the company without smothering it?
The short version: a strong COO treats risk as a standing part of how the business is run, wired into weekly operating reviews, budgets, and vendor decisions. A weak one treats it as an annual binder that gets dusted off for the audit committee and ignored the other fifty weeks of the year.
Why risk belongs to the COO, not just a committee
Most large organizations have a risk committee, and some have a Chief Risk Officer. That does not move accountability off the COO's desk. A committee sets appetite and reviews the register; a CRO in financial services owns models and regulatory capital. But the COO owns execution — the actual controls, the actual redundancy, the actual response when something fails at 2am. Risk that is not owned by whoever runs the operation tends to be documented, not managed.
The distinction between the roles matters, and confusing them is a common failure:
| Question | COO owns | Chief Risk Officer / committee owns |
|---|---|---|
| Focus | Operational and execution risk across the running business | Risk appetite, aggregate exposure, regulatory/financial risk |
| Primary output | Working controls, redundancy, tested response plans | Risk register, appetite statements, capital models |
| Time horizon | This quarter's operations and next year's capacity | Enterprise-wide, multi-year exposure |
| When it fails | The COO's line is accountable for the response | The committee is accountable for oversight and appetite |
How to do it: put risk on the agenda of your regular operating review, not a separate quarterly ceremony. When you review a plant's output or a region's numbers, review its top exposure in the same conversation. Risk that shares a meeting with performance gets managed; risk that has its own rarely-attended meeting gets filed.
The operating model: three lines and a single owner
The cleanest way to structure who-does-what is the three-lines model, and the COO's job is to keep all three honest.
- First line — the people who run the process own the day-to-day controls. A warehouse manager owns stock accuracy; an IT lead owns access controls. They live closest to the risk and catch it first.
- Second line — risk and compliance functions set standards, monitor, and challenge the first line. They do not run the operation; they check that it is being run safely.
- Third line — internal audit independently tests whether the first two lines actually work, and reports to the board, not to management.
Alongside this sits risk appetite: an explicit statement of how much of each risk the company is willing to carry. A concrete example: a mid-sized manufacturer might decide it will tolerate a single-source supplier only where switching is possible within four weeks, and will hold dual sources everywhere else. That is an appetite the COO can actually operate against when a procurement lead proposes a cheaper sole-source deal. Without a written appetite, every risk decision becomes an argument from scratch.
Wiring risk into how the business already runs
The mark of mature risk ownership is that it disappears into normal operations. Established operating disciplines already carry risk controls — the COO's job is to use them rather than bolt a parallel process on top.
- Process work (lean, Six Sigma DMAIC, or a simple PDCA loop) surfaces the failure modes and variation that create operational risk in the first place. Reliable processes are the cheapest risk control you own.
- Business continuity and disaster recovery plans turn "what if it goes down" from a fear into a tested runbook. The key word is tested — a continuity plan that has never been rehearsed is a document, not a capability.
- Supplier redundancy is the practical answer to concentration risk; the mechanics of building it out are covered in supply chain resilience.
- Change management (a Kotter-style approach, for instance) reduces the risk that a transformation quietly breaks the operation it was meant to improve.
Cyber, supply chain, and people: where COOs get tested most
Three exposures dominate most COOs' real risk load, and each has a matching operating response rather than a slogan.
Technology and cyber. The exposure is not only a breach; it is downtime, a ransomware lockout, or a vendor system failure that stops your operation. Ownership here means the COO knows which systems the business cannot run without, what the recovery time actually is when one fails, and whether staff can spot the phishing email that starts most incidents. The deeper playbook sits in the cybersecurity handbook; the COO's part is making sure recovery is tested, not assumed. Supply chain and operations. Concentration is the silent risk — one supplier, one port, one component. A strong COO maps the single points of failure and holds either a backup source or a deliberate, documented decision to accept the concentration. Building the broader capacity to absorb shocks is the subject of operational resilience. People and culture. Key-person risk, retention of critical skills, and a workforce that either flags problems early or hides them are all operating risks. The controls are unglamorous: succession plans for roles that would hurt if they emptied, and a culture where raising a near-miss is rewarded rather than punished. A team that hides small failures guarantees large ones.Reporting risk up: the board conversation
Owning risk includes owning the story the board hears about it. This is where many capable operators stumble — they either drown the board in a hundred-row register or reassure them with a green dashboard that hides the two things that actually matter.
Strong board reporting is short and honest: the handful of exposures that could genuinely threaten the plan, what is being done about each, what has changed since last time, and what decision (if any) the board needs to make. Weak reporting is a color-coded grid with no narrative, where everything is amber and nothing demands attention. The skills that make this land are the same ones covered in board communication, and the CEO should never be surprised by a risk in front of the board — align the message before the meeting, never during it.A simple structure that works: lead with the two or three risks that moved, state whether each is inside or outside appetite, and end with any decision you need. Reserve the full register for an appendix. Boards remember what you highlight, not what you attach.
Key takeaways
- Risk ownership follows operational ownership. The COO runs the machine risk threatens, so the COO owns operational and execution risk — a committee or CRO sets appetite and oversight, but does not run the controls.
- Embed, do not bolt on. Risk that shares a meeting with performance gets managed. Use existing disciplines — lean, continuity plans, change management — as your controls rather than building a parallel process.
- Write down the appetite. An explicit tolerance ("dual-source unless switching takes under four weeks") turns every future risk decision from an argument into a check.
- Test, don't document. A continuity or recovery plan that has never been rehearsed is not a capability. The proof of real risk management is a rehearsed response and an operating decision that actually changed because of a risk.
- Report the two that matter. Boards act on the handful of exposures you highlight, framed against appetite — not on a hundred-row amber grid.