Close this search box.
Close this search box.

5 Ways To Improve Board Risk Oversight

“Tone at the top” is a term often used to describe how an organization’s leadership creates an environment that fosters ethical and responsible business behavior. While tone at the top is important and a vital foundation, is it enough?

While leaders communicate the company’s vision, mission, core values and commitment to ethical behavior, what really drives the culture and resonates with employees is what they see and hear every day from their supervisors. If the behavior of middle managers contradicts the messaging and values conveyed from the top, it won’t take long for lower-level employees to notice. Because the top-down emphasis on responsible business behavior in an organization is only as strong as its weakest link, it is vital that the tone at the top be trans­lated into an effective “tone in the middle” before it can reach the rest of the organization.

Three dynamics drive this collective culture, or the “tone of the organization”:

1. Don’t assume that both tone in the middle and tone at the bottom are aligned with tone at the top. Alignment is the name of the game. The greater the number of layers of management in the organi­zation, the greater the risk of incongruities in the respective tones at the top, middle and bottom. Likewise, there’s a greater risk of executive management being unaware of serious financial, operational and compliance risks that may be common knowledge to middle managers and rank and file employees. Information is often distorted as it moves up the management chain, creating disconnected leaders.

2. Don’t assume everyone is engaged. The extent of engagement is vital to building a strong, ethical culture. A lack of engagement drives absenteeism, turnover, fraud, misappropriation of assets, safety incidents, quality defects and loss of customer focus.

3. Recognize the stakes: Many financial, operational and compliance risks are embedded in the organization’s processes. Many decisions are made and many actions are undertaken on the front lines by middle managers and their teams, not by executive management. The decisions to act or not to act present opportunities for excellence, as well as the potential to undermine the organization. To the extent these actions result in policy violations and significant omissions, they pres­ent risks in a wide variety of areas, such as product or environmental liability, health and safety, trading, employee retention, or security and privacy concerns. Risks can fester and smolder when repeated errors and omissions occur within processes, creating the potential for significant surprises later.

To address these “tone of the organization” dynamics, executive management and directors should:

  • Make every effort to implement a strong tone at the top. Without this starting point, it’s game over. Be aware of inappropriate performance pressures, a myopic short-term focus on profitability or a “fear of the boss” within the ranks. In certain areas of the organization, management may look the other way when people act inappropriately rather than take fair and appropriate disciplinary action. Issues may exist even when executive management is of the view that a strong tone at the top exists.
  • Ascertain whether the organizational structure supports or impedes the culture. For example, flattening the organization may reduce the risk of executive management being unaware of embedded risks. Compensation arrangements may encourage inappropriate risk-taking behavior (e.g., competing metrics, such as cost and schedule, trumping safety).
  • Consider conducting a periodic assessment oftone in the middle and tone at the bottom. Seek periodic independent assessments of the organiza­tion’s culture and tone up and down the organization to affirm the belief system driving behavior. Address any lack of alignment with leadership.
  • Ensure the organization has effective escalation processes. An ethics survey noted the percentage of an organization’s employees who witnessed misconduct at work was 45 percent in 2011, down from 49 percent in 2009. Of those employees, 65 percent reported the misconduct they saw, up from 63 percent in 2009. While the rate of escalation is improving, there is still room for improvement.<href=”#_ftn4″ name=”_ftnref4″ title=””>[4]
  • Act on the warning signs in audit reports. Internal audit can play a key role in monitoring the tone of the organization either as part of a comprehensive assess­ment or through aggregating relevant findings from multiple audits in different areas. Incongruities among the tones at the top, in the middle and at the bottom warrant reaffirmation of core values and beliefs.

Questions for Directors

Following are some suggested questions that boards of directors may consider, in the context of the nature of the entity’s risks inherent in its operations:

· Is the board alert for warning signs that the tone at the top may not be optimal (e.g., turnover of key executives, tolerance of significant control issues, a warrior culture, a shortsighted focus on profitability and evidence of an overly dominant chief executive)?

· Does executive management work closely with middle, line and functional managers to ensure everyone is effectively aligned in terms of the organization’s vision, mission, core values and strategy, so the right messag­ing and behavior are stressed across the organization?

· Are there effective escalation processes to ensure significant problems are recognized and addressed at the appropriate level of the organization?

Jim DeLoach is a member of Protiviti’s Executive Council to the CEO and assists companies with integrating risk management with strategy setting and performance management.





  • Get the CEO Briefing

    Sign up today to get weekly access to the latest issues affecting CEOs in every industry
  • upcoming events


    Strategic Planning Workshop

    1:00 - 5:00 pm

    Over 70% of Executives Surveyed Agree: Many Strategic Planning Efforts Lack Systematic Approach Tips for Enhancing Your Strategic Planning Process

    Executives expressed frustration with their current strategic planning process. Issues include:

    1. Lack of systematic approach (70%)
    2. Laundry lists without prioritization (68%)
    3. Decisions based on personalities rather than facts and information (65%)


    Steve Rutan and Denise Harrison have put together an afternoon workshop that will provide the tools you need to address these concerns.  They have worked with hundreds of executives to develop a systematic approach that will enable your team to make better decisions during strategic planning.  Steve and Denise will walk you through exercises for prioritizing your lists and steps that will reset and reinvigorate your process.  This will be a hands-on workshop that will enable you to think about your business as you use the tools that are being presented.  If you are ready for a Strategic Planning tune-up, select this workshop in your registration form.  The additional fee of $695 will be added to your total.

    To sign up, select this option in your registration form. Additional fee of $695 will be added to your total.

    New York, NY: ​​​Chief Executive's Corporate Citizenship Awards 2017

    Women in Leadership Seminar and Peer Discussion

    2:00 - 5:00 pm

    Female leaders face the same issues all leaders do, but they often face additional challenges too. In this peer session, we will facilitate a discussion of best practices and how to overcome common barriers to help women leaders be more effective within and outside their organizations. 

    Limited space available.

    To sign up, select this option in your registration form. Additional fee of $495 will be added to your total.

    Golf Outing

    10:30 - 5:00 pm
    General’s Retreat at Hermitage Golf Course
    Sponsored by UBS

    General’s Retreat, built in 1986 with architect Gary Roger Baird, has been voted the “Best Golf Course in Nashville” and is a “must play” when visiting the Nashville, Tennessee area. With the beautiful setting along the Cumberland River, golfers of all capabilities will thoroughly enjoy the golf, scenery and hospitality.

    The golf outing fee includes transportation to and from the hotel, greens/cart fees, use of practice facilities, and boxed lunch. The bus will leave the hotel at 10:30 am for a noon shotgun start and return to the hotel after the cocktail reception following the completion of the round.

    To sign up, select this option in your registration form. Additional fee of $295 will be added to your total.