Summarize Articale

profilesalher
arti-v1n1-kelly.pdf

Int. J. Business Continuity and Risk Management, Vol. 1, No. 1, 2009 19

Conceptualising business risk culture: a study of risk thinking and practice in contemporary dynamic organisations

Phil Kelly Information Management and Systems Liverpool Business School Liverpool John Moores University 98 Mount Pleasant Liverpool, L3 5UZ, UK E-mail: [email protected]

Abstract: In response to the challenges regarding the way organisations think individually and collectively about and act upon risk (risk culture) plus recent calls for new approaches to risk management, we investigate risk specialists’ current thinking on risk and risk practice. In particular, we seek to review and develop the concept of risk culture in organisations. Organisational risk culture is conceptualised in terms of collective risk thinking to include risk perception and other cognitive processes and risk behaviour. Having conceptualised risk culture, we investigate its determinants and consequences – contingency theory and the concepts of dysfunctional and congruent risk cultures. Drawing on the literature and an empirical study primarily of risk specialists from 100 companies spread over 40 countries, we explore the relationships between organisational cultural variables and review the measurable components of risk culture.

Keywords: risk culture; risk practice; risk-taking culture; risk management culture.

Reference to this paper should be made as follows: Kelly, P. (2009) ‘Conceptualising business risk culture: a study of risk thinking and practice in contemporary dynamic organisations’, Int. J. Business Continuity and Risk Management, Vol. 1, No. 1, pp.19–37.

Biographical notes: Dr. Phil Kelly is both a risk practitioner and an academic. He has worked in various risk-related roles for over 20 companies in 20 countries worldwide. Formerly Risk Adviser to Asia’s highest paid CEO, he completed a Doctorate in Risk Management at Manchester Business School, UK. An external examiner for the Institute of Risk Management, he is the author of their set textbook, Information Systems Risk. Aside from an interest in information and technology systems, he has also researched human systems and risk culture in particular.

Copyright © 2009 Inderscience Enterprises Ltd.

20 P. Kelly

1 Introduction

In the 1990s, driven by turbulent world consequences, (the demise of stability – increased uncertainty) scientific and traditional management came under attack (see Daft, 2001; Child, 2001; also Bozeman, 1998; Rapert and Wren, 1998; Caruana et al., 1998). Increasingly organisations became customer oriented and responsive in order to lever success. Later, researchers and institutions such as Elliott et al. (2000), McCrae and Balthazor (2000), the Institute of Risk Managers (IRM, 2002) and, triggered by a wave of corporate disasters, the Institute of Chartered Accountants in England and Wales (ICAEW, 1999) attacked traditional risk thinking, advocating decentralised risk decision making, broad participation in risk decisions and a more open risk communications climate instead (new risk thinking in organisations). Furthermore they suggested that risk management should be embedded in the organisational culture. Environmental and organisational changes of this nature raise fundamental challenges to the way we think about and act upon risk as organisations. With the turbulent environment comes new challenges such as the problem of prediction, i.e., a lack of data to estimate risk in an uncertain world (Walklate, 1999), tension between business goals (the flexibility-control dilemma see Quinn and Rohrbaugh, 1983; Rigg, 1992; Ciborra, 2000; Child, 2001; Simons, 1995; 2000) increased operational risk (Smallman, 2000; Blacker, 2000; Elliott et al., 2000) and the need for organisations to respond and adapt in a timely manner. Thus, throughout the 1990s and into the new Millennium, arguments have been proposed for a change of approach to our risk thinking and risk culture. Such changes have been deemed necessary because the business environment has changed. Many arguments are grounded in contingency theory and the need for an organisations internal environment to fit with its external environment. However, despite the frequent use of the term risk culture and the recommendation that risk management should be embedded in the organisational culture, surprisingly little has been written about such matters.

Within this article we aim to consolidate thoughts on risk culture and behaviour in organisations and will focus on what is meant by risk culture (definition), why we need to consider it and how it might be measured. We will elaborate upon components or dimensions of organisational risk culture, treating them as variables and suggesting that individuals and organisations may be similar or different according to where they lie on a particular continuum. We will also suggest that organisational risk culture variables may be grouped in sets to form distinct patterns which differentiate one organisation from another (risk culture). Furthermore we will discuss individual employee positions on dimensions of risk culture and attempts by the organisation to influence their members’ risk thoughts and practices. We will argue that organisations must consider risk culture because risk culture impacts upon business performance (see Ouchi and Wilkins, 1983) and that risk culture needs to be dependent upon a variety of contingent factors, business-goals in particular. Treating risk culture as a variable and a determinant of organisational performance, we question whether a culture can be dysfunctional (Mumford and Beekman, 1994, p.10) and review specific issues surrounding the challenge of changing risk culture. For the purposes of this paper we will focus on business risk and organisational risk culture. Our focus will be directed more towards situations where the organisation is the risk bearer – the entity at risk. Throughout the paper we explore challenges associated with risk management and the way it might be embedded within the culture of the organisation; in short, our aim is to explore the behavioural dimensions of risk management.

Conceptualising business risk culture 21

2 Conceptualising risk culture, risk thinking and risk behaviour

Employees may engage in risky (exposing the organisation to opportunity and loss), risk free or risk mitigating behaviours, see Figure 1. Risk behaviour at the individual level has received much attention in the literature. In a theoretical paper, Sitkin and Pablo (1992) posit a number of determinants of individual risk behaviour such as risk propensity (the willingness of an individual to choose options that entail risks) and risk perception (an assessment of the risk inherent in a situation). The work of Sitkin and Pablo focuses on individual risk thinking and its determinants. They set forth a broad theoretical framework for examining risk behaviour. It is suggested that risk propensity is a product of risk preferences (risk attitudes such as risk-seeking or avoidance), inertia and outcome history and that risk perception1 is influenced by the way a problem is framed (see Prospect theory – Kahneman and Tversky, 1979), social forces (the organisations culture, attitudes to uncertainty), the Top Management Team (TMT), problem domain familiarity and organisational control systems (reward and punishment mechanisms used to channel the decision makers’ risk behaviour). Whilst the work of Sitkin and Pablo advanced our thinking on risk behaviour at the individual level it did not address the concept of collective risk behaviour, i.e., risk culture. Indeed Schein (1999, p.14) suggests that, “to explain individual behaviour, we must go beyond personality and look for group memberships and the cultures of those groups”.

Figure 1 Determinants of risk behaviour

Culture is about shared or collective ways of thinking and doing things (see Hofstede, 1984; 1997, p.180; Schein,2 1997, p.12; 1999, p.29; Trice and Beyer, 1993, pp.15, 33); thinking may be discussed in terms of values, attitudes, beliefs, experiences, cognitive processes and ‘doing things’ in terms of practice and behaviour. So what do we mean by risk culture from an organisational perspective? Several scholars have defined risk

22 P. Kelly

culture. However, there is a broad spectrum of definitions as culture is a complex construct, discussed at many levels, as is risk. Rockett (1999, p.46) concludes that there are as many definitions of risk as there are people capable of defining them. Bozeman (1998) defined risk culture in terms of the perception of employee and top manager risk-taking. His study was, however, restricted to risk-taking-culture. Bozeman measured the dimensions of bureaucracy (formal control), trust and empowerment and examined impact upon the chief dependent variable perceived risk taking. He suggested that high political control (external), levels of formalisation (procedures and rule conformance) and ‘red tape’, bureaucratic structures (‘channels’) and centralised decision making (all aspects of the organisational culture) reduced risk taking, whilst reward systems, top trust and clear goals (goals and mission statement) had the potential to cause a greater risk-taking propensity by employees. Culp (2000), adopting a more constructionist philosophy and including the management of downside risk, saw risk culture as ‘the lens through which managers and directors of a company view its financial and business risks and organisationally manage those risks’. Focussing on the two respective definitions we can identify two major differences in possible views of the meaning of risk culture. It could be about risk taking (speculative risk) or defence against harm (pure risk). The two researchers also differ in their conceptualisation of culture itself – Bozeman focussing on risk behaviour and Culp on risk thinking. We suggest a further source of confusion, particularly relevant to turbulent world arguments, to be whether we are conceptualising risk or uncertainty as a component of risk culture and note Tverskey and Wakker (1995, p.1258) who state that ‘risk can be considered as a special case of uncertainty where probabilities are given’. We define business-risk-culture to be the shared risk-taking or potentially jeopardising behaviours and the collective thinking and action directed at perceived organisational risks. Such risks may be speculative or pure but refer only to those that the organisation must bear. Our concern here is with employee behaviour, action or inaction likely to impact upon perceived risk in a positive or negative manner. It is also common to refer to the risk management culture within organisations. This perspective focuses on risk mitigation.

Having briefly discussed what is meant by risk culture we now consider whether or not it can be operationalised and measured and further elaborate on its possible dimensions. Schein (1997, p.15), a leading expert on organisational culture, informs us that ‘the biggest danger in trying to understand culture is to oversimplify it in our minds’, yet he believes that we need a way to decipher cultural patterns (p.xiii). Culture may be researched from a general (etic) or specific (emic) perspective. People who believe culture is unique to the organisation typically study it using qualitative methods. Others believe there are common aspects of culture (like the big five personality traits) that can be measured thus allowing organisations to be compared. In such cases, survey instruments may be used to collect data about specific dimensions of culture. Despite the problems with cultural surveys (see Schein, 1997, pp.59–63) they can be of value though it is generally felt that ideographic research methods will reveal unique aspects of culture.

Following a review of the literature, we have constructed a table of bipolar constructs which various researchers have, in the past, associated with risk culture or risk thinking. This may help in the deciphering and operationalisation of risk culture in organisations (see Figure 2). Risk culture itself is a variable recently viewed as a bipolar construct; organisations exist on a continuum between traditional and new. The traditional pattern of risk thinking and behaving is represented by positivist risk specialists who think rationally, as sole experts with limited participation in risk decisions. Such specialists are

Conceptualising business risk culture 23

rule-oriented organisers who favour formal control, adopt a process orientation, are less trusting of people, risk averse, secretive professionals with a greater concern for external risk. In many traditional organisations, risk specialists dominate risk thinking for the organisation, adopting a powerful central role. When their views are widely shared within an organisation we consider the organisation to have a traditional risk culture. Kelly (2003) investigated risk culture and relationships between dimensions used to conceptualise and operationalise risk culture. He also investigated determinants and consequences of risk culture in organisations. Kelly investigated 100 organisations from 40 countries and measured a large collection of variables (operationalised through approximately 175 questions) targeted at risk specialists in the main but also senior and line managers. This provided a comprehensive insight into attitudes and risk related beliefs in the context of individual and organisational characteristics.

Figure 2 Risk-culture as bipolar constructs (dimensions) (see online version for colours)

TRADITIONAL Risk-Culture

NEW Risk-Culture Stable/ predictable/ knowable Environment

Ouchi and Wilkins (1983) Dynamic/ problem of prediction/ more

uncertainty/ less data/ unknown Contingency theory oriented to physical characteristics i.e. organizational size,

age, complexity

Contingency Pugh (1973)

Contingency theory more goal driven i.e. cost efficiency or winning new business

Realists Ontological beliefs Bradbury (1989) and

Lupton (1999)

Relativists

Positivist, can calculate risk from relevant external data

Epistemological beliefs Walklate (1999)

Anti positivist/ constructionist/ Lens models

Objective/ Rational Fischhoff et al (1981) Schein (1997:89)

Subjective/ judgements concern with judgement bias and error/

decision maker characteristics and heuristics Literature dominated by natural sciences, mathematics, economics and psychology

Explicit knowledge source Literature from organizational behaviour, social psychology

Method Sole expert (narrow) Organization/ Participation

Elliott et al (2000:52) Participatory (Broad)

(group risk assessments and risk decision making)

Centralised risk decision making/ cost benefit oriented, rational decisions

Decision Making Elliott et al (2000)

Decentralised risk decision making/ sense making/ intuitive and preference based

Doctor patient help philosophy Specialist Help Philosophy Schein (1987), Coghlan (1988)

Process facilitation

Formal control/ Bureaucratic Ouchi (1983) Reduced control with reliance on goal congruence

Process orientation/ Theory X Task Orientation McGregor (1960),

Hofstede (1997:189)

Results orientation/ Theory Y

Focus on costs, cautious, risk averse, like rules

Business Goal Bozeman (1998)

Focus on gains (winning new business)

Value entrepreneurialism, creativity and risk taking

Machine like Formal/Informal Simons (1995)

Process controls Trust, Belief Systems

Managed feedback loops, exception reporting for command and control

Information use Klein (1989),

Senge

Feedback loops for self regulation, learning and adaptation

Assurance models

Risk transfer Risk Strategy Risk reduction Risk thinking starts with assets Risk Management Focus Risk thinking starts with business goals

Emphasis on homogenous strong culture Culture strength Hofstede (1997),

Peters & Waterman (1982)

Emphasis on heterogeneous weak culture

Risk culture of low significance Risk Cul ture significance Risk culture has strong significance Closed communications climate Communications Climate

Hofstede (1997:196), Schein (1997)

Elliott et al (2000)

Reliant on open communications climate

Concern with physical security Functional concern Concern with product security, fraud, revenue assurance

External/ natural risk priorities Risk Priorities Internal/ behavioural risk priorities

Professional risk specialists/ experts/ Organisers

Specialists Pugh (1997)

Parochial risk facilitators/ Behaviouralists

Reactive Elliott et al (2000:52) Proactive

24 P. Kelly

Kelly’s primary research question asked whether companies differed in the risk culture dimensions (see Figure 2) and how, if at all, these components related to one other, i.e., is there a pattern amongst components? His data suggested that the risk culture dimensions were indeed significantly related. Kelly found that positivism was correlated with rational thought. Thinking rationally was indeed significantly correlated with a belief in experts (‘you must be an expert to make risk management decisions’) and respondents who believed in experts did favour formal control, showing both an orientation towards and coming from formal/bureaucratic organisations. As expected, bureaucrats did favour a process orientation and centralised risk decision making. Respondents showing a preference for bureaucracy actually came from bureaucratic organisations and were more likely to score more towards theory X type (less trusting of people). Secretive risk specialists (‘the need to know (secrecy) rule should be automatically applied to all security risk information’ and ‘company risk information should be kept secret’) were more likely to be organisers (‘There should be more control in companies operating in the present day’), oriented to bureaucracy (in support of propositions made by Hofstede, 1997, p.196), conscientious and hold beliefs in experts. Thus, the investigation by Kelly suggested dimensions indicating traditionalist and non traditionalist tendencies. Furthermore, despite calls for the new risk culture, he found the majority of his sample to be traditional but noted that some generally traditional respondents also scored as non traditionalist on other risk culture dimensions. He concluded that traditionalism/ non-traditionalism are not dichotomous and that individuals can be traditional or non traditional in quite different ways. For example, an individual may prefer bureaucracy yet still favour a results orientation.

3 Risk thinking

According to Schein (1999, p.29), to survive and grow, every organisation must develop viable assumptions about what to do and how to do it. We can apply this notion to risk and its management. Earlier we observed that Culture is about shared or collective ways of thinking and doing things (behaviour). Any conceptualisation of risk culture must therefore consider risk thinking in organisations. An organisation must reach consensus on what risks are important and in need of attention (what Schein might refer to as basic underlying assumptions or the survival problem) and how to manage them. Risk management is about organisation (the ‘who’), the method and control (the ‘how’). Risk specialists (or others) may prioritise the protection of assets or enabling the achievement of future goals. Kelly (2003) found that when company goals were clear, the risk specialist directed his or her attention towards internal company risk matters, i.e., perceived internal risk to be more important than natural risks. Presumably knowledge of what the company wants to achieve serves as a reference point against which to evaluate risk. According to the ICAEW (1999), companies should ‘identify clear company objectives’ because this makes it easier to identify ‘critical success factors’ and ‘identify and prioritise risk’. They state that ‘a board must decide what it wants to achieve’ then it becomes ‘easy to determine risk’. Most of Kelly’s respondents perceived their organisations to have clear goals. He explored the items associated with goal clarity using correlation analysis and observed significant (p < .000) relationships with the following variables: Top Trust (.367***), Mission Clarity (.472***), Procedures (.324***) and Clear Task (.350***). Kelly found when business goals were clear, top

Conceptualising business risk culture 25

management displayed a high level of trust in employees and were more likely to have clear mission statements, tasks and procedures. Other differences were observed and in general he concluded that clear goal companies were formal companies. They favoured rule conformance and stressed the need to go through proper channels. Handy (1999, p.300), Payne (1996), Schein (1997, p.56) and Hofstede (1997, p.192) all make the connection between goals and culture – when goals are shared. Similarly, such authors describe problems of conflict and control when goals are not shared (goal incongruence). Schein (1997, p.51) discusses the problem of adaptation (to the external environment) and integration (of ‘internal processes to ensure the capacity to continue to survive and adapt’). He discusses how we cope with the changing external environment, developing organisational purpose through the mission and goals. Hofstede (1997, p.189) discusses process orientation, ‘a concern with means’ and results-orientation, ‘a concern with goals’. He suggests that results oriented cultures are comfortable in unfamiliar situations.

Risk priorities define what the risk-thinker(s) see(s) as important. In recent years several researchers have discussed operational risk (Smallman, 2000; Blacker, 2000; Elliott et al., 2000) as a new concern driven by environmental turbulence, and frequent changes to organisational practice and technology. Historically organisations focused on external natural risks and criminal damage threats until in the 1990s the emphasis shifted to a concern with manufactured technological risk and internal ‘error’ (behaviour) risk. Consequently it could be argued that contemporary risk specialists will prioritise manufactured and internal risks over natural risk. Considerable variance was observed in risk prioritisation patterns although at the highest-level respondents prioritised internal over manufactured and manufactured over natural risk (Kelly, 2003). Findings suggest that the risk priority of risk-specialists is an important predictor of risk method (the process or approaches used to support risk decision making) and risk control method (approaches used to treat risk). Kelly (2003) found respondents prioritising external (natural) risk perceive less formal control (belief system or written). Those respondents prioritising internal risks scored, on average, closer to broad participationism (measured from respondents agreement with the statement ‘When there is more than one person involved in a risk management decision it becomes a better decision’). Those more likely to prioritise internal risks were also more likely to feel that they should be involved in the management of speculative risk taking. Interestingly, Kelly also found that a concern with speculative risk taking accompanies the shift from external to internal focus. As risk specialists respond to internal changes, they believe increasingly in the proactive method.

How an organisation decides to implement its strategy and goals is the next level of culture content. Findings suggest that risk thinking is context specific and that key parts of context include company strategy, goals and the risk-thinker’s professional work role, (Kelly, 2003). The means, structure, systems and processes adopted, if successful, are believed to be the correct way, (Schein, 1999). Indeed Slovic et al. (1981, p.19) discuss ‘the vital role of experience as a determinant of perceived risk’. Experience is often specific to work roles. Within any large organisation a variety of risk-roles exist – such as security, safety, insurance, audit, etc. – each with their own goals, professional culture, values and beliefs. Role is a determinant of risk thinking and risk role is a reflection of beliefs in what are the important organisational risks are, i.e., perceived significant risk is a determinant of risk thinking. Professionals focussing on external risk such as physical security will tend to be more traditional than those who focus on internal/behavioural/operational risk. If we assume that organisational characteristics may

26 P. Kelly

determine the significant risks they face, i.e., some organisations may have a greater exposure to natural versus people risks then we should expect traditional risk cultures to be more congruent with the needs of some organisations and behaviouralist or new risk cultures to favour organisations where exposure to human centred risks is greater. It is also therefore likely that, to varying degrees organisations facing both risk sets will vary in their degrees of risk culture. It is important to recognise that people will see what they are programmed to see and that we all view things (risk) differently.

Risk thinking manifests itself in plans, systems, policies, organisation, and practices and specifically in risk controls and risk behaviour. Since there are many alternative ways to manage risk, the potential exists for organisations to be quite different – to have differing risk cultures. Shared assumptions about the best way to control or treat risk are also important aspects of the risk culture and there are a vast range of ways to control and treat risk. However there are two aspects of control defining risk culture – the amount or quantity (tightly or loosely controlled) and the preferred type. A prevalent and traditional risk control type is formalisation (quantity of rules written down) which Bozeman (1998) believed had a negative impact upon perceived risk taking. However, Kelly (2003) found that when the organisation had a clear formal belief system, top management were more likely to display high levels of trust in employees and that when such trust was placed and/or the formal belief system was clear, respondents perceived greater risk taking propensities amongst top management and employees (Clear formal belief systems result in higher degrees of perceived employee risk taking). Formal control was not found to impact directly upon risk taking but organisations with clear formal belief systems had a greater propensity towards formal written rules and procedures. Pugh found formalisation-enabled decentralisation by enabling top management trust. Pugh (1973) sought to explain observations of decentralisation stating that “‘the explanation appears to be that’ [formalisation] allows top management to [decentralise] ‘because the organisational machine will run as it has been set to run and decisions will be made in the way they were intended’”. Whereas Pugh’s argument demonstrates the role of formalisation in bringing trust and as we have seen in the study by Kelly (2003), subsequently a stronger risk taking propensity. Hofstede argues that informal and formal controls are not negatively correlated; that is to say they actually go together and one does not replace the other. Hofstede (1997) argues that if there is a control culture it is likely to manifest itself in both written and unwritten codes – “a tight formal control system is associated with strict unwritten codes” of behaviour (p.191). Simons (1995, p.33) considers two dimensions of a formal control system: (1) the belief system and (2) boundary systems (specifying what employees should not do) – neither of which are cybernetic. He believes that belief systems motivate and boundary systems constrain the search for opportunity with the two working in tandem. Peters and Waterman (1982) and Daft (2001, p.302) both agree that in turbulent environments, organisations must act as if they are small (responsive). Daft adds that large size and bureaucracy ‘have many advantages, but they do have shortcomings’. It seems that, particularly in large companies, degrees of formalisation are ‘rationally’ expected. ‘Red tape’ and ‘rules-for-rules sake’ are unacceptable. Where possible, we should seek as a default, to manage by informal means (see Ouchi, 1980; Ouchi and Wilkins, 1983) and particularly where written rules are seen as fallible. More stable codes of conduct will remain best imparted as formal documents. People like to know where they stand.

Conceptualising business risk culture 27

Thus far we have discussed risk thinking both as a precursor to risk behaviour and as

a key aspect of risk culture (when it is shared). Earlier we introduced the concept of risk perception (an assessment of the risk inherent in a situation and a part of the overall risk thinking process) and elaborate on the construct here. A constant problem for organisational risk management concerns the question of ‘who’ should assess risk, have responsibility for and implement risk decisions – matters of organisation. In determining an answer to such questions the organisation is defining aspects of its own risk culture (agreed upon ways of doing things). When risk specialists are empowered to assess and make decisions about risk, as company experts, a more traditional culture is defined. However, Kelly (2003) questions the ‘expert’ status of contemporary risk professionals. In a study of explicit risk specialist risk judgements (a reflection of perceptions) he observed large variance in the way experts estimated both the probability and impacts of a given (operational) risk in their industry. Several factors were thought to be influencing their risk perceptions and judgements. Many experts were found to be considerably underestimating and the others overestimating risks, raising concern with risk-decision-quality. Kelly (2003) went on to investigate determinants of judgement and found respondent rule orientation scores to be correlated3 with their risk judgements (.245*), such that a rule oriented respondent judged certain risks to be more significant than a respondent who was less rule (formal) oriented. Similarly, Pugh (1997) discusses ‘organisers’ and ‘behaviouralists’ with the former believing in greater control in organisations and the latter in less control. In addition, Kelly investigated variance in the resources a risk specialist would allocate to a risk reduction initiative; some respondents were prepared to spend much more than others on a risk control initiative. Interestingly, he found respondents who perceived risk to be higher were also more likely to commit more resources to control a risk. The implications of this finding are quite far reaching. If a single risk specialist, relying on subjective/intuitive risk judgement processes, has exclusive responsibility for a risk decision there will be significant variance in decisions. Some respondents allocate much more organisational resource to a particular risk. Thus, there would seem to be arguments against both the need for experts to make risk decisions (without relevant data) and for decisions to be made by a single employee. Despite these findings Kelly found that 75% of risk specialist respondents believed in centralised risk decision making, 50% believed that a single specialist could make the risk decision and 50% believed that an expert was required to make risk decisions. It would seem that traditional risks (natural or physical) call for an expert approach whilst operational risk requires a participatory style of risk management.

At the beginning of this section we discussed individual characteristics and their impact upon risk behaviour. In traditional risk cultures it is more important to consider individual characteristics as risk behaviour determinants because the risk expert often has more power and may typically act alone in such cultures. Personality was assessed in the study by Kelly who found that highly conscientious (self-disciplined, dutiful, attention to detail) risk specialists showed a greater propensity for a rule orientation (see previous paragraph) and believed there should be more control in companies operating in the present day (organisers). Indeed much of the psychology literature associates the conscientious personality type with this need for control. Recently, Nicholson et al. (2003) conducted a study into risk propensity and personality. They explored how personality dispositions underlied risk propensity and set out to build upon the influential work of Sitkin and Pablo (1992) referenced earlier in this article. They also commented

28 P. Kelly

on relationships between job function and risk orientation (for example, sales and marketing as a high-risk orientation and finance as a low-risk orientation; ‘in view of its emphasis upon systems of control’). In terms of personality, Nicholson et al. (2003), like Kelly (2003), focussed on the ‘big five measures’ expecting extroversion, a need for stimulation, and openness to experience to be associated with risk-seeking behaviour. Conversely, they believed that conscientiousness and agreeableness would be associated with risk aversion. They discussed conscientiousness as a ‘desire for achievement under conditions of conformity and control’. Nicholson et al. (2003) confirmed that overall risk taking would be predicted by high scores in extroversion and openness and by low scores in neuroticism, agreeableness and conscientiousness. They concluded that high extroversion and openness ‘supply the motivational force, low neuroticism and agreeableness supply the insulation against concern about negative consequences, and low conscientiousness lowers the cognitive barriers’. They believed conscientiousness to be ‘of greatest interest’ suggesting that ‘people with low conscientiousness can be seen as attempting to ‘get rich quick’ – securing benefits by taking chances rather than controlled effort’.

4 Determinants and consequences of risk culture

Earlier we suggested that risk culture is a variable and that, based on patterns of risk culture dimensions, organisations may be oriented more towards a traditional or ‘new’ risk culture. Thus far we have recognised several individual characteristics that might determine risk behaviour and now, drawing on the literature, consider the determinants of collective risk behaviour, i.e., risk culture. Risk culture is not designed but emerges from common assumptions about the problems faced by the organisation. From contingency theory we might suggest environment type (a source of problems) to be a determinant of risk culture – the external environment may be classified on a continuum from stable to dynamic as discussed by Ouchi and Wilkins (1983). Such environments vary from industry to industry and organisation to organisation. Turbulent environments are characterised by more uncertainty and force organisations to take a more adaptive response through organisation, consequently focusing specifically on operational risks and adopting risk methods that do not rely on historic data, i.e., a ‘new’ orientation. The environment is also a source of social factors and Hofstede (1984; 1997) suggests national (see uncertainty avoidance in particular) or professional culture (see risk professions in particular) may also determine the risk culture. Some countries are less tolerant of ambiguity and therefore show a greater propensity to organise and formalise than others. Pugh (1973) focussed on the internal environment and found that ‘big’ businesses scored high on specialisation, standardisation and formalisation but not on centralisation; he argued that specialists generate standards, rules and procedures, creating uniformity. Company age and size also determine the risk culture. Older companies have time to lay down more formal approaches and create specialists, i.e., tend to be more traditional, managing scientifically. Employees of such companies may be less expected to participate in risk decisions. The size of an organisation (number of employees) is also significantly correlated with beliefs about participation in risk decisions. Employees of younger companies enjoy more freedom and are perceived to be more risk taking. Finally, larger companies seem to be more secretive.

Conceptualising business risk culture 29

Not only are we concerned with the determinants of risk culture but also with its

consequences. Nadler (cited in Mabey and Mayon-White, 1993), discusses different ways of thinking and the views held about organisations, starting with systems views whereby organisations are deemed to be ‘composed of interdependent parts’ where ‘change in one element of the system will result in changes in other parts of the system’. With the aim of providing a ‘usable tool for managers’ they introduce an approach called a ‘Congruence Model of Organisational Behaviour’. The model recognises the environment as a major input to the system (a source of opportunity, threat and constraints), which becomes encoded in the strategy (a match of organisational resources to the environment). The inputs then enter a transformation process composed of four components: task, individual, informal and formal organisation. The task is about the work to be done; individuals are the people performing the task; formal arrangements include processes, structures and systems; and informal arrangements include organisational culture and practice. Finally the model outputs are organisational performance with reference to the goals and strategy (inputs). ‘Each component can be thought of as having a relationship with each other component. Between each pair, then, we think of a relative degree of consistency, congruence, or “fit”’ and ‘the basic hypotheses of the model is therefore that organisations will be most effective when their major components are congruent with each other’. This view of the organisation is thus a contingency approach. Changes in one component of the model may reduce its congruence with other components. Thus environmental changes in the 1990s and the new millennium, from stability to uncertainty, are expected to impact upon risk culture: risk goals, method and control systems. Inspired by Nadler, Kelly (2003) introduced a Congruence-model of Risk Management (ACORM), see Figure 3.

Figure 3 A congruence model of risk management (see online version for colours)

Exter nal envir onment

Gener al goals

Inter nal envir onment

Risk goals

Risk method

Contr ol system

Stable Dynamic

Pr oc

es s

R es

ul ts

Internal

External

Objec tive Subjec tive

Fo rm

al

In fo

rm al

Sim ple

C om

plex

Exter nal envir onment

Gener al goals

Inter nal envir onment

Risk goals

Risk method

Contr ol system

Stable Dynamic

Pr oc

es s

R es

ul ts

Internal

External

Objec tive Subjec tive

Fo rm

al

In fo

rm al

Sim ple

C om

plex

Source: From Kelly (2003)

30 P. Kelly

When the external environment is stable (top left part of the model), it is likely that the ‘best’ general goal will be process oriented (see theories of scientific management and bureaucracy). This is because the organisation has less need for adaptation and in the stability domain can specify formally and in advance, how to fulfil work-tasks. Moving anti-clockwise around ACORM, the next component after general-goals are risk-goals. Risk-goals may be internally or externally (natural hazard) oriented. When the external environment is dynamic, the internal organisational component changes in pursuit of adaptation capabilities; a ‘results’ orientation is then considered more congruent with the environment as the organisation shifts from formal to informal. Internal change, both in practice and technology, is faster and consequently the organisation becomes more ‘risky’. Thus the risk specialist directs attention towards systematic and behavioural risk; and arguably must call upon different risk management skills to deal with such risks. The next component of ACORM is risk method. From the example thus far, our concern is with ambiguity from frequent internal and external change. This is reflected in risk-goals, which will affect method in several ways. Firstly, it affects how we understand risk; the knowledge production process as objective method becomes problematic, there is little relevant data to calculate risk. Next it affects risk strategy, whether we accept, transfer or seek to reduce risk ourselves. Whereas natural risk and external criminal attack may lend themselves to actuarial assessment and therefore insurance strategies (though not exclusively), internal risks are self-manufactured and therefore somewhat more self-controllable. As a result, for internal risks, we shift control types more from the physical to the behavioural (both of which may be enabled by technology). It is then this matter, i.e., behavioural control that leads us to debate and make choices about informal or formal control mechanism; it is rarely appropriate to think of natural risk control in such terms.

A further consequence of behavioural control and ambiguity, also reflected in risk method, is the issue of participation. In stable environments where a focus may be on natural risk, driven by objective risk calculation there is little need for involvement; the facts speak for themselves and expertise can develop. Yet as uncertainty increases, the facts only whisper to us, and intuition plays a greater role. With intuition one truth does not exist and hence we find multiple perspectives pervading organisational decision making. The impact of this is clear, a shift from rational decision making models (such as the risk management process). This issue of an absence of ‘one truth’ gives way to a reduction in expert power on the grounds of ‘lower grade’ knowledge (intuition) and the role of competing values and preferences from multiple stakeholders. Participation may be directed at any one or all of the four phases of risk decisions:

1 the structuring of the risk problem

2 the generation and choice of treatment

3 the implementation of treatments/controls

4 the evaluation and monitoring of treatments.

Consequently, participation is a broad concept in risk decisions. With regard to risk-reduction-control-systems themselves, informal mechanisms are considered congruent with ambiguity, in accordance with propositions made by Ouchi and Wilkins (1983). Formal mechanisms (the remnants of scientific or bureaucratic management) are considered incongruous because of the fallibility of rules in conditions of uncertainty

Conceptualising business risk culture 31

– we cannot specify all eventualities and means to deal with them and if we could, by the time rules have been written and communicated, circumstances are likely to have changed. Whilst formal mechanisms may be superior in times of stability, they are not in conditions of uncertainty and even in stability; they may be attacked on the grounds of their demotivational properties. In summary, we have highlighted how changes in the external and internal environment demand change in the way we think and act toward risk, in risk culture. When the risk culture is congruent with the environment, the organisation is thought to be more effective. Thus, traditional risk culture may be incongruent with contemporary environments and therefore dysfunctional. The extent of this dysfunctionality will vary from industry to industry.

5 Discussion and conclusion

Contemporary organisations may ask what the term risk culture means, whether their risk culture is functional and appropriate and if not, what the desirable risk culture may be and how they therefore change risk culture. Throughout this paper we have set out to develop thoughts on the general dimensions of risk culture but recognise that all organisations will have idiosyncrasies. Figure 2 set out a broad theoretical framework to conceptualise risk culture in organisations by presenting a number of bipolar constructs aligned at one end with traditional risk thinking. What is important is that each construct is a variable and that organisations may vary between traditional, weak traditional and non-traditional in their position on any of the scales. The pattern of their scores becomes a reflection of their risk culture. However, caution must be applied in categorising risk culture in such a simple way. We have also set out, in this paper, to show that certain values, attitudes and beliefs whether held at the individual level or shared within organisational groups along with other personal characteristics impact upon risk thinking and perceptions. We then make the assumption that risk thinking and perception will impact upon risk behaviour and consequently upon organisational performance either by seeking out opportunity (speculative risk taking) or affecting exposure to pure risk, see Figure 4. Analysing risk behaviour and risk culture in this way, decomposing the numerous constructs into components and dimensions, enables organisations to better determine where they are now and, if appropriate, target areas for change.

Figure 4 Risk perception as a determinant of risk behaviour

32 P. Kelly

Based on a review of the new risk literature and the results of Kelly’s (2003) exploratory study, we identify two fundamental performance concerns for contemporary organisations operating in dynamic environments. Firstly there is the issue of risk decision quality and secondly risk culture congruence and the related problem of risk culture change. If we treat risk decisions as a determinant of organisational performance, we must understand the antecedents of such decisions. Risk-culture, organisational and national culture along with personality, experience, heuristics and mental processes offer explanation of risk decisions through mediating variables such as risk perception. Risk perceptions are also determined by contextual factors (see Sitkin and Pablo, 1992). When risk decisions are made intuitively/subjectively we need to ask who should make the decision and must understand the factors likely to determine the decision output. In this regard we think of two key risk decision outputs; the risk perception (risk problem) communicated as a risk profile or computed loss expectancy and the choice of action or inaction (risk control). If when individuals think about risk-in-context they use risk-related values, attitudes, beliefs, heuristics (see Slovic et al., 1981), memory and mental process – all of which exist as variables, then we expect variance in risk decision output. Slovic et al. (1981) note, “Subjective judgements, whether by experts or lay people, are a major component in any risk assessment. If such judgements are faulty, risk management efforts are likely to be misdirected.” One of the concerns, in this article, is with determinants of faulty perceptions (judgement bias), especially determinants that may be culturally based. To that end we found traditionalists to be more pessimistic, likely to overestimate risk and have a propensity towards control. McCrae and Balthazor (2000, p.42) argue that “Turnbull moves away from a ‘command and control’ inspection regime to a more participatory form of ‘enforced self-regulation’.” Both McCrae, Balthazor and Elliott et al. are advocating a ‘new risk management’ with characteristics that are “integrative, internalised, anticipatory and self-regulating” (McCrae and Balthazor, 2000, p.43). However, caution must be applied when implementing advice in the ‘new’ risk literature. It is not a case of all or nothing and more careful, informed thought is necessary.

Culture change is frequently discussed in the new risk literature (Elliott et al., 2000, pp.52–53; ICAEW, 1999, para.22) but a risk practitioner might ask specifically what should be changed and why. Hofstede (1997, p.199), Schein (1997, p.211) and Trice and Beyer (1993) citing Deal and Kennedy (1982) are all in agreement that aspects, particularly practices of organisational culture, are somewhat manageable. Schein (1999, p.99) discusses ‘culture change mechanisms’ referring succinctly to a set of ‘primary embedding mechanisms’ which include factors such as: ‘what leaders pay attention to, measure and control’ the allocation of resources, promotion and excommunication of organisational members. Schein (1999) also discusses ‘secondary articulation and reinforcement mechanisms’ such as organisation design and structure, systems and procedures. In addition to Figure 2 identifying congruent sets of risk culture variables, contrasting tradition and new thinking, we have developed a model to help practitioners think about managing risk in dynamic environments where the emphasis may be on operational risk and employee behaviour (see Figure 5). Figure 5 contains a representation or model of risk culture, suggesting the organisational forces at work in shaping employee risk thinking and behaviour. In our model, employee behaviour (represented by the arrow) is channelled through the use of formal and informal arrangements. When employee behaviour is aligned we might consider there to be a strong or homogenous culture as opposed to a weak heterogeneous one. We think of

Conceptualising business risk culture 33

employees completing their respective work tasks (task behaviour), a matter directly linked with performance. Task behaviours may include errors of commission or omission and undesirable risk taking. Similarly, we may think of the employees general conduct at work. This latter behaviour is more indirectly linked with performance and concerns dishonesty, integrity, dangerous, hazardous and risk mitigating or avoidance behaviours. At this level our risk thinking is primarily internal, viewing employees as sources of opportunity and threat. There are however, external threats such as those posed by nature and those posed by people. Thus we must also consider the risks that might impact upon employees during the course of their work. In order to be productive, employees must be motivated, capable and have access to required organisational assets and resources. Traditionally, risk specialists focussed on the latter. Assets and resources are needed to enable the employee to perform their task of generating wealth for the organisation. So what happens if assets and resources such as buildings, equipment, people or systems are damaged, destroyed or made unavailable due to the action of a threat? Operations are disrupted and revenue reduced. Consequently, we argue that the risk culture will include thoughts and practice aimed at asset protection. However, the primary concern may be driven by a protection of wealth or a concern with future earning capacity. We assume thinking directs behaviour and as such assume that changes to thinking may change behaviour. Under bureaucratic models, thinking is almost removed from task behaviour through the use of process control to direct how work should be done. Consequently, when process control is lifted we need to focus on the methods by which employee-thinking can be influenced. As a consequence, many new risk strategies seek to control employees by educating them and making them aware of desirable and undesirable behaviours and the potential consequences of actions. In short, contemporary organisations tend to support employees in self-regulation, often achieved through informal and flexible arrangements.

Figure 5 Risk culture model

34 P. Kelly

The risk culture model (see Figure 5) considers mechanisms to impact upon risk behaviour. Organisations may vary in the degree of control they seek to assert (organisers pushing for more control) and the way it seeks to control – formally or informally, input, process or output controls. They may also vary according to who is controlling (risk specialists, the management team, supervisors, clan-control or self-regulation) and how control is achieved at the formal level (instructions, physical and technical access controls). Formal arrangements include belief systems, boundary controls such as conduct codes, process and technical controls. They may be applied to general conduct, task behaviour or assets and if linked to a process may be applied to inputs, the process or outputs. Formal input controls may include vetting employees whilst informal input controls may focus on indoctrination, and socialisation. Output controls (diagnostics) typically use feedback loops to distribute information as a force that might be used to influence behaviour, correct deficiency or renegotiate targets. From a risk culture perspective it is important to treat output control as a variable according to the feedback recipient, which may be management (command and control regimes) or the employee directly (self-regulation, learning organisation). Formal process controls include the elements typically associated with bureaucracy. A key issue of risk-culture concerns how risk is perceived and by whom. In traditional risk cultures the risk specialist would structure risk problems and suggest means to reduce exposure. Under the new risk culture model, risk is constructed (i.e., it is not ‘real’, more akin to a belief) and more likely to involve a broad selection of the organisation. Risk specialists may facilitate risk perceptions and guide the management team. In the absence of process control there is a heavy dependence on goals as a coordinating mechanism and goal congruence as a force to align employees. Aside from goal congruence, clan control (peer pressure) may be a force at work to channel the direction of individual behaviour.

We conclude there are indeed many ways to think about risk and its management and that the problem of prediction coupled with new organisational goals (responsiveness/ results orientation) associated with a turbulent world, shifts risk patterns and the way we think about risk. New risk thinking advocates a move away from traditional risk beliefs yet Kelly (2003) found the majority of his respondents continue to espouse traditional risk views. Given that changes to fundamental beliefs take time, if they can be changed at all, this finding should not surprise us yet we must also consider the conclusion that some organisations either do not want to or do not see the need for change and that this view may or may not be correct. We should, however, be aware of the consequences for risk culture change, should it be desired and must be aware of the potential for inter-organisational sub group conflicts. Our key message for practitioners is to recognise that they are different and that there are implications arising from such differences. Specialists do not approach risk problems with a blank piece of paper (tabular rasa). Individuals or groups may vary in the importance they attach to risk and certain specific risks, the degree of control (more or less) and the types of control. They may also differ in their thinking of who should complete a variety of risk-related tasks and the manner by which they are completed (risk organisation). Similarly, organisations can vary in the strength of their risk culture; the degree to which similar risk thinking is shared amongst organisational members. Finally, we conclude that organisational risk culture is a relatively new concept, born out of turbulent world arguments. It may be considered in speculative and pure risk terms. The key issue becomes the organisational goals, which drive perceived risk priorities, with which risk culture must be congruent. Organisations

Conceptualising business risk culture 35

may pursue cost efficiency and flexibility goals simultaneously within a dynamic environment and they may emphasise one over the other. Thus there is no single best way of thinking about risk culture and a number of variations can be observed.

References Blacker, K. (2000) ‘Mitigating operational risk in British retail banks’, Risk Management:

An International Journal, Perpetuity Press, Vol. 2, No. 3, pp.23–33.

Bozeman, B. (1998) Risk Culture in Public and Private Organizations, American Society for Public Administration, March–April, Vol. 58, No. 2, pp.109–118.

Caruana, A., Morris, M.H. and Vella, A.J. (1998) ‘The effect of centralization and formalization on entrepreneurship in export firms’, Journal of Small Business Management, Milwaukee, Vol. 36, No. 1, pp.16–29.

Child, J. (2001) ‘Organizations unfettered: organizational form in an information-intensive economy’, Academy of Management Journal, Briarcliff Manor, Vol. 44, No. 6, pp.1135–1148.

Ciborra, C. (2000) From Control to Drift, Oxford University Press.

Culp, C. (2000) ‘New risk culture: an opportunity for business growth and innovation’, Derivatives Quarterly, Vol. 6, No. 4, p.9.

Daft, R.L. (2001) Organization Theory and Design, 7th ed., South-Western.

Deal, T.E. and Kennedy, A.A. (1982) Corporate Cultures: The Rites and Rituals of Corporate Life, Reading, MA: Addison-Wesley.

Elliott, D., Letza, S., McGuiness, M. and Smallman, C. (2000) ‘Governance, control and operation risk: the turnbull effect’, Risk Management: An International Journal, Perpetuity Press, Vol. 2, No. 3, pp.47–59.

Handy, C.B. (1999) Understanding Organizations, 3rd ed., London: Penguin Business.

Hofstede, G. (1984) Cultures Consequences – Abridged, Sage.

Hofstede, G. (1997) Cultures and Organizations, McGraw-Hill, p.199.

Institute of Chartered Accountants in England and Wales (ICAEW) (1999) Internal Control – Guidance for Directors on the Combined Code, The Institute of Chartered Accountants in England and Wales, London.

Institute of Risk Managers (IRM) (2002) A Risk Management Standard, AIRMIC, ALARM, IRM, pp.1–14.

ISO/IEC (2002) GUIDE 73, 1st ed., ISO/IEC.

Kahneman, D. and Tversky, A. (1979) ‘Prospect theory: an analysis of decisions under risk’, Econmetrica, Vol. 47, pp.262–291.

Kelly, P.P. (2003) ‘Managing risk in the Telecomms industry: improving the quality of decision making’, PhD thesis, John Ryland’s University Library of Manchester.

Mabey, C. and Mayon-White, B. (1993) Managing Change, The Open University.

McCrae, M. and Balthazor, L. (2000) ‘Integrating risk management into corporate governance: the Turnbull guidance’, Risk Management: An International Journal, Perpetuity Press, Vol. 2, No. 3, pp.35–45.

Mumford, E. and Beekman, G.J. (1994) Tools for Change & Progress, CSG Publications.

Nicholson, N., Fenton-O’Creevy, M., Soane, E. and Willman, P. (2003) ‘Personality and domain-specific risk taking’, Journal of Risk Research, in press.

Ouchi, W.G. (1980) ‘Markets, bureaucracies, and clans’, Administrative Science Quarterly – Ithaca, Vol. 25, No. 1, pp.129–141.

36 P. Kelly

Ouchi, W.G. and Wilkins, A.L. (1983) ‘Efficient cultures: exploring the relationship between culture and organizational performance’, Administrative Science Quarterly, Vol. 28, No. 3, pp.468–481.

Payne, R. (1996) ‘The characteristics of organizations’, in P. Warr (Ed.) Psychology at Work, Harmondsworth: Penguin, pp.338–407.

Peters, T. and Waterman, R. (1982) In Search of Excellence, 1995 edition, Harper Collins Business.

Pugh, D.S. (1973) ‘Does context determine form?’, Organizational Dynamics, Spring, pp.19–34.

Pugh, D.S. (1997) Organization Theory, 4th ed., England: Penguin.

Quinn, R.E. and Rohrbaugh, J. (1983) ‘A spatial model of effectiveness criteria: towards a competing values approach to organisational analysis’, Management Science, Vol. 29, No. 3, pp.363–377.

Rapert, M.I. and Wren, B.M. (1998) ‘Reconsidering organizational structure: a dual perspective of frameworks and processes’, Journal of Managerial Issues, Pittsburg, Vol. 10, No. 3, pp.287–302.

Rigg, M. (1992) Increased Personal Control Equals Increased Individual Satisfaction, Industrial Engineering, Norcross, February, Vol. 24, No. 2, p.12.

Rockett, J.P. (1999) Definitions are Not What They Seem, Perpetuity Press, Vol. 1, No. 3, pp.37–47.

Schein, E. (1997) Organizational Culture and Leadership, 2nd ed., San Francisco: Jossey Bass.

Schein, E. (1999) The Corporate Culture Survival Guide, Jossey Bass.

Simons, R. (1995) Levers of Control, Harvard Business School Press.

Simons, R. (2000) Performance Measurement & Control Systems for Implementing Strategy, New Jersey: Prentice Hall.

Sitkin, S.B. and Pablo, A.L. (1992) ‘Reconceptualizing the determinants of risk behavior’, Academy of Management Review, January, Vol. 17, No. 1, pp.9–30.

Slovic, P., Fischhoff, B. and Lichtenstein, S. (1981) ‘Perceived risk: psychological factors and social implications’, Proceedings of the Royal Society of London. Series A, Mathematical and Physical Sciences, Vol. 376, No. 1764, pp.17–34.

Smallman, C. (2000) ‘What is operational risk and why is it important?’, Risk Management: An International Journal, Perpetuity Press Ltd., Vol. 2, No. 3, pp.7–14.

Trice, H.M. and Beyer, J.M. (1993) The Cultures of Work Organizations, Prentice Hall.

Tversky, A. and Wakker, P. (1995) ‘Risk attitudes and decision weights’, Econometrica, Vol. 63, No. 6, pp.1255–1280.

Walklate, S. (1999) ‘Is it possible to assess risk?’, Risk Management: An International Journal, Perpetuity Press, Vol. 1, No. 4, pp.45–53.

Bibliography Bradbury, J. (1989) ‘The policy implications of differing concepts of risk’, Science Technology &

Human Values, Vol. 14, No. 4, pp.380–399.

Campbell, G.K. (2000) ‘Can security get management’s ear?’, Security Management, Arlington, February, Vol. 44, No. 2, pp.113–114.

Child, J. (1997) ‘Strategic choice in the analysis of action, structure, organizations and environment: retrospect and prospect’, Organization Studies, Berlin, Vol. 18, No. 1, pp.43–76.

Coghlan, D. (1988) ‘In defence of process consultation’, Leadership and Organization and Development Journal, Vol. 9, No. 2, pp.27–31.

Huczynski, A. and Buchanan, D. (2001) Organizational Behaviour an Introductory Text, 4th ed., Financial Times Prentice Hall.

Conceptualising business risk culture 37

Kahneman, D. and Tversky, A. (1981) ‘The framing of decisions and the psychology of choice’,

Science, Vol. 211, pp.453–458.

Klein, H.J. (1989) ‘An integrated control theory of work motivation’, Academy of Management Review, Vol. 14, No. 2, pp.150–172.

Lupton, D. (1999) Risk, Routledge.

McGregor, D.M. (1960) The Human Side of Enterprise, New York: McGraw-Hill.

Schein, E. (1996) ‘Culture: the missing concept in organization studies’, Administrative Science Quarterly, Vol. 41, No. 2, p.229.

Senge, P.M. (1992) ‘Building learning organizations’, The Journal for Quality and Participation, Vol. 15, No. 2, p.30.

Simons, R. (1999) ‘How risky is your company?’, Harvard Business Review, May–June, pp.85–94.

Sitkin, S.B. and Weingart, L.R. (1995) ‘Determinants of risky decision making behaviour: a test of the mediating role of risk perceptions and propensity’, Academy of Management, Vol. 38, No. 6, pp.1573–1592.

Smallman, C. (1999) Knowledge Management as Risk Management: A Need for Open Governance?, Perpetuity Press, Vol. 1, No. 4, pp.7–20.

Weick, K.E. and Roberts, K.H. (1993) ‘Collective mind in organizations: heedful interrelating on flight decks’, Administrative Science Quarterly, Vol. 38, No. 3, pp.357–381.

Notes 1 The ISO/IEC (2002) define risk perception as the way in which a stakeholder views a risk,

based on a set of values or concerns.

2 Schein does not include overt behaviours in his definitions of culture but does recognise that behaviour may reflect cultural assumptions.

3 * p < .05, ** p < .01, *** p < .001.