There is a school of thought that says that risk management is really simple. I happen to disagree. I think risk management is really complicated, but we need to find simple ways of conveying the messages. Sometimes I think that we over simplify it with three by three matrices that really mean nothing at all. We are going to have to find and develop much better presentational methods to enable better discussion of risk in organisations. In the meantime, let’s not think that risk management is so simple that we can do it in five steps and “bish bosh” the job is done.
Here is a short video talking about exactly this issue: http://risk.ybc.tv/rabusiness/