The four themes highlighted above constitute the driving sensibilities of the analysis which follows, namely attention to the institutional construction of a risk management process, a process expressed and materialized in standards and guidelines and mobilized in the name of good governance and oppor-tunity. Since the mid-1990s new categories and ideas have re-shaped discourses of risk management, giving them a more central role in organ-izational governance, aligning them with ideals of enterprise and subsuming more traditional forms of risk analysis. This re-organization and reconcep-tualization of management activity in the name of risk marks a distinctive form of administrative innovation, involving the diVusion of new process frameworks, the organization of new concepts of risk and its management;
28 / Organized Uncertainty
and the creation of new classes of organizational actors as authorized representatives of best risk practice. The aura of scientiWcity of risk analysis is being placed in a larger, rationalized, managerial, governance, and regula-tory frame of meaning.
The chapters that follow deal with the details of this broad process of change. Chapters 2 and 3 deal with the genesis and design of new blueprints for risk management processes. Chapter 2 analyses an important dimension of the shift from risk analysis to risk governance, namely the ‘turning inside out’
of organizations as a consequence of the rise of corporate governance from the beginning of the 1990s. While the idea of corporate governance is itself complex and multifaceted, a common feature across all global and national initiatives is an emphasis on the integrity of ‘internal control’ systems. This chapter describes how internal control came to acquire conceptual autonomy from Wnancial auditing and was reframed as risk management. This helped to create the necessary conditions for ‘whole-of-entity’ approaches to risk management with near universal applicability. In this story, the internal auditor emerges from the shadows as a signiWcant organizational and regulatory actor, speaking for a logic of opportunity and seeking a foothold in a competitive space inhabited by risk analysts and strategists.
Chapter 3 takes up the focus on ‘whole-of-enterprise’ risk management by examining the diVerent origins of this idea, one coming out of the develop-ments described in Chapter 2 and another with a more technical foundation in the Weld of Wnance, risk analysis, and control theory. The chapter analyses the emergence of standardized and formalized generic approaches to risk management, and their consequences for all organizations, including states adopting risk-based approaches to regulation. It is argued that a massive institutionalization of process-based risk management has taken place with important implications for the moral economy of organizations, not least the accountability of senior management for the management of risk. New actors, such as the chief risk oYcer, have emerged to oversee value-adding risk management empires, to supervise expert risk analysts, and to ensure the integrity of the organizational self and its responsibility for risk governance.
Taken together, Chapters 2 and 3 provide evidence of the distinctive subsumption of risk analysis within managerial and business frameworks for risk management. This in turn reXects neoliberal ambitions for the constitution of a new kind of organizational self. Chapters 4 and 5 provide two further case studies of this process, paying particular attention to new Organized Uncertainty / 29
concepts and new forms of organizational risk narrative. Chapter 4 deals with the emergence of the category of operational risk in the banking sector during the late 1990s, analysing both the occupational tensions between diVerent claimants on the Weld of operational risk, and the diVerent degrees of allegiance to calculation and management in the organization of risk. The case is more generally instructive about the role of concepts and categories as catalysts for practical change, and the sense in which the creation of new risk objects is fundamentally a practical and organizational achievement. The category of operational risk is an invented and Wctional one with concrete signiWcance for the governance of diverse risk management communities and for a potential consolidation of the risk ‘archipelago’ (Hood and Jones, 1996a).
Chapter 5 focuses on another signiWcant category within recent risk management thinking, namely ‘reputation’. Reputation has come to be an object of governing signiWcance for organizations as they operate in densely populated and active institutional environments. The chapter explores the many diVerent interests which Wnd a common opportunity in the idea of reputation and seeks to explain why reputation has become a signiWcant object of concern for organizations and governments. Reputations can be at risk, but the management of reputation, and ethics and CSR, are also conceptualized as organizational opportunity: ‘social responsibility is good business’ is another much invoked slogan. Yet, despite evident management salience, reputational risk management is paradoxical not least because external forces are prominent in deWning and calculating organizational reputation. In addition the inherently pervasive nature of reputational issues demands meta-practices of oversight by cross-functional committees rather than a new unit or department.
Having examined the contours of designs for risk management in terms of a new accent on rationalized internal processes, and new risk categories and oYcerships, Chapter 6 provides a more critical analysis of these developments.
It is argued that the extension of risk management and the language of risk both into new domains and also upwards along the organizational hierarchy represents a new phase in the ‘audit society’, as states, organizations and individuals internalize the imperative to demonstrate that things are in control. In place of uncertainty as the space of entrepreneurialism, organizations of all kinds are being organized, legalized, and made auditable.
Beneath the claims for strategic signiWcance and the logic of opportunity lie 30 / Organized Uncertainty
fears and anxieties about accountability and blame. The production of defend-able proof about the management of risk pervades the construction of risk management.
Chapter 7 draws together the arguments of the book as a whole and suggests three avenues for future analytical and empirical enquiry which may correct some of the overstatement in the current argument. First, more needs to be done to examine the social construction of risk objects and managerial pro-cesses and their entanglements with each other. Second, the world-level role of speciWc risk governance designs, such as enterprise risk management, in deWn-ing a self-validatdeWn-ing set of moral norms needs to be explored further in speciWc organization settings. Third, more work is needed to understand the working out of the logic of auditability. If arguments for its pervasive and constitutive nature are not grossly overstated, there are some important policy implications, not least a need to rethink standard strategies for de-regulation. Individuals, corporations and governments may have little choice but to organize the uncertainties they face, but policy makers need to recognize that the organiza-tional obsession with risk management since the mid-1990s embodies immacu-late images of organizational process, and fantasies of opportunity and value, which may be self-defeating.
Notes
1. The category of tax risk, as a new basis for selling professional services, has become recently prominent on the back of this general expansion in risk management ideas. See Godman (2006a; 2006b).
2. See, for example, Franklin (1997); Denney (2005); Richter et al. (2006).
3. See for example, NAO (2000); HSE (2001); Cabinet OYce (2002); Dibb (2003); Raban and Turner (2003). Managing Risk (London: European Business Forum and Marsh, 2003); Living Dangerously, Economist Survey, January 2004.
4. See for example, Hanley (1999); EIU (2001); Larkin (2002); Lam (2003). Journals include:
Due Diligence and Risk Management; Healthcare Risk Management; Risk Management; Energy and Power Risk Management; Australia Institute of Risk Management Journal; International Journal of Risk Assessment and Management; Opthalmic Risk Management Digest; Australian Risk Management; Operating Room Risk Management; Strategy and Risk Management; Public Sector Risk Management; Community Risk Management and Insurance News; Risk; Operational Risk and Compliance.
5. The UK Treasury website has links to a number of these associations as knowledge resources, including the IIA, GARP, and the IRM.
Organized Uncertainty / 31
6. See section 17 on ‘risk management’ from Royal College of Anaesthetists (2000). Events like the football world cup and the Olympic games are also explicitly organized with risk management principles in mind. See Jennings (2005). Football clubs which are publicly listed must also make disclosures about how they have managed risk.
7. See Day and Klein (2004).
8. See also Callon (1998) for whom ‘calculative agencies’ have become more important in constituting economic life than calculation itself.
9. Economic theory has become more sensitive to concepts of culture and mission which go beyond a purely contractualist model. For example, see Ghatak and Besley (2005).
10. While ‘isomorphism’ may be a useful analytical description of certain organizational processes of copying from the outside, it may not be adequate to the self-description of speciWc organizational practice, except in the loose sense that practitioners admit to explicitly copying best practice.
11. This is also called ‘disaster incubation theory’. See Rijpma (2003).
12. See J. McGregor ‘Gospels of Failure’, Fast Company Magazine, www.fastcompany.com Issue 91, February 2005, 62.
13. In March 2005, a UK conference on risk perception and assessment addressed the topic of
‘Risk Hypochondria—are we looking too hard for risk?’.
14. See Starr et al. (1976) for a conceptual framework for risk-beneWt analysis.
15. From Knight’s (1921) point of view, such a trust in numbers amounts to a distrust of forms of judgement and enterprise in the face of radical uncertainty.
16. See also Hood and Jones (1996b: chapter 4).
17. For a sociological review and critique of this work see Heimer (1988).
18. This critique is replicated within insurance studies which argues that actuarial practices of risk calculation and classiWcation play a decisive role in modes of social control and identity formation (Simon, 1988; Ericson and Doyle, 2004).
19. See the Preface to Hood and Jones (1996b: xi).
20. See National Research Council (1996). For further discussion see also Okrent and Pidgeon (1998).
21. Among the largest in the UK are the Health and Safety Executive (HSE), The Food Standards Agency (FSA), The Financial Services Authority (FSA), The Environment Agency. Work in the Weld of socio-legal studies has shown how inspection, compliance and analysis are outcomes of complex organizational processes. Research has also shown the persistence of institutional heterogeneity in the manner in which risks are processed by these state agencies; the ‘government of risk’ is by no means uniform across problems and functions and risk analysis is embedded in very diverse frameworks. In particular, the manner in which public perceptions and moral frameworks are incorporated within risk regulation is a source of variation across these ‘risk regulation regimes.’ (Hood et al., 2001).
22. In the UK the Phillips Report on the BSE crisis (http://www.bseinquiry.gov.uk/index.htm) was criticized for being too traditional in its conception of risk analysis.
23. The Treasury Risk Support Team absorbed the work of an earlier UK Interdepartmental Liaison Group on Risk Assessment (UK-ILGRA).
24. Phrase attributed to GeoV Mulgan speaking at a conference entitled ‘Panic Attack’, 9 May 2003, The Royal Institution, London.
25. Based on an allegedly leaked memorandum reported in the UK press in late April 2004.
26. See for example Stirling (1998) and Okrent and Pidgeon (1998).
32 / Organized Uncertainty
27. In the USA, Vaughan is a counterexample of the inXuence of social science. She wrote one of the chapters in the Columbia shuttle enquiry and ideas about the ‘normalization of deviance’ have had some policy inXuence as a consequence.
28. It is highly debatable whether the world is ‘more risky’ or more objectively dangerous now than in the past. It has also been argued that Beck ignores serious distributive issues in favour of the ‘democracy of the toxin’ (Smith and Tombs, 2000: 17–19) and has an objectivist view of risk, risk analysis, and expertise.
Organized Uncertainty / 33