Back to Blog

Risk management investment return: the affirmative case

RC

Risk Companion

July 21, 2026
9 min read

Key Takeaways

  • Research by Arthur D. Little found that every euro invested in injury prevention returns two euros or more, and a small organisation that invested EUR 50.000 in safety improvements saved over EUR 1 million in costs across five years, a 20 to 1 return.
  • McKinsey's research on large capital projects found that unmanaged risk is a leading driver of cost overruns, with megaprojects on average running 80 percent over budget partly because risk exposure was priced on optimism rather than evidence.
  • The CFA Institute frames risk management not only as a defensive discipline but as an offensive one: organisations that understand their risk exposure can choose which risks to take, giving them options that less well-managed competitors simply do not have.
  • The total cost of risk model developed by Arthur D. Little captures retained losses, insurance costs, and risk management investment together, which is the only honest way to see whether your current approach is actually saving money.
  • A risk management investment only generates return when it has named ownership, consistent monitoring, and a tool the team opens between audits, because a register that sits unread protects nothing and measures nothing.

The assumption that makes risk management expensive

Most organisations treat risk management as a cost. A compliance line in the budget. Something that gets funded because an auditor, an insurer, or a regulator expects to see it, not because anyone believes it generates return.

That framing is both wrong and expensive. When risk management is treated as overhead, it gets under-resourced, treated as an annual exercise, and handed to whoever has capacity rather than whoever has accountability. The result is a register that exists on paper and does almost nothing in practice.

The business case for risk management investment return is not that it prevents bad things from happening, though it does that too. Done properly, it improves the quality of every decision the organisation makes, protects the return on investment you have already committed to, and creates a structural advantage over competitors who are still flying blind. The case is commercial, not just regulatory.

The numbers behind the business case

The most frequently cited data point on risk management investment return comes from injury prevention research, but its logic applies far beyond safety. Arthur D. Little's work on the total cost of risk found that for every euro invested in injury prevention, organisations recover two euros or more. A small organisation that invested EUR 50.000 in targeted safety improvements saved over EUR 1 million in costs across five years. That is a 20 to 1 return, measured, not estimated. We cannot link directly to the underlying report, as the original publication is not publicly available, but the methodology has been widely cited in occupational health and safety literature and forms the basis of the total cost of risk model described below.

The mechanism is not mysterious. Unmanaged risks carry retained costs: insurance claims, production downtime, regulatory fines, reputational damage, and management time spent on incidents that should have been prevented. Those costs are real and recurring. They just tend not to appear on the same spreadsheet as the risk management budget, which is why the investment looks expensive and the problem looks free.

The total cost of risk model corrects that accounting error. It adds together retained losses, insurance premiums, and risk management investment to produce a single figure. When you run that calculation honestly, the question stops being "can we afford to invest in risk management?" and becomes "can we afford not to?"

The evidence on project and contract risk is just as stark. McKinsey's research on large capital projects found that megaprojects run on average 80 percent over budget, with schedule and cost risk systematically underestimated at the outset. The root cause is not incompetence. It is that risk exposure is priced on optimism rather than evidence, and the gap between the two gets carried by the organisation as unplanned cost. For any business that prices projects on an assumed return, unmanaged risk is not a theoretical concern. It is the mechanism by which profitable projects quietly become loss-making ones.

Risk management as an offensive tool, not just a defensive one

The CFA Institute's Introduction to Risk Management draws a distinction that many organisations miss entirely. Risk management is not only about avoiding bad outcomes. It is about understanding your risk exposure well enough to choose which risks are worth taking in pursuit of your objectives.

That reframing matters. An organisation with a clear picture of its risk exposure can pursue opportunities that a less well-managed competitor cannot, because it knows which risks are already accepted, which have headroom, and which are genuinely off-limits. It can price contracts accurately. It can allocate capital to the opportunities with the best risk-adjusted return rather than the opportunities that feel safest on a Monday morning.

Picture a construction business bidding on three projects simultaneously. Without systematic risk management, the bid team works from experience and instinct. They discount some risks, overlook others, and price contingency based on gut feel. With a structured process, they know the probability and financial exposure of the risks on each project, the cost of the measures already in place, and the residual exposure they are being asked to carry. They can price it correctly, decline the project where the risk-adjusted return does not justify the bid, and concentrate resources on the two that do. That is better resource allocation, which is one of the things risk management is actually for.

The BCG framing on risk management under uncertainty makes the same point from a strategy angle: organisations that treat risk as information rather than as threat are better positioned to act when competitors are frozen. When a market disruption hits, the organisations that have already mapped their exposure and stress-tested their plans do not spend three weeks figuring out where they stand. They already know.

Why the return requires the right infrastructure

The evidence for risk management investment return is solid. The reason so many organisations do not see it is that they invest in the appearance of risk management rather than the substance of it.

A risk register that is updated twice a year, where half the owners have left the organisation, and where no measure has a due date or a progress figure, does not generate return. It generates compliance theatre. Auditors can read it. Nobody is managing anything.

The return on risk management investment depends on three things working together.

Named ownership. Every risk needs an owner who is accountable for it between reviews, not just someone whose name appears in a column. The moment ownership is unclear, the risk sits unmanaged. That is not a process failure. It is a structural one, and no amount of policy language fixes it.

Consistent monitoring. Risks change. A risk that was amber in January may be red by March if a supplier has collapsed or a regulatory threshold has shifted. A review cycle that runs once a quarter, or once a year, cannot catch that. The organisations that see return from risk management are the ones where risks get looked at regularly, where owners get reminded before deadlines pass, and where the register reflects current reality rather than the situation as it was when the last workshop ran.

A tool the team actually uses. This is where most risk management investment fails. Enterprise GRC tools take months to implement and require dedicated administrators. Spreadsheets have no ownership, no reminders, and no visual overview. Both options create a register that gets opened during audits and ignored the rest of the time.

The infrastructure for risk management return is not complicated. It is a risk register where every risk has a named owner, a current assessment and a target, and a set of measures with due dates and owners. It is a risk matrix that shows the team where the high-probability, high-impact risks cluster without anyone having to dig for the information. It is configurable alerts that remind owners before deadlines pass rather than after. And it is something lightweight enough that the operations lead actually opens it on a Tuesday, not just in October.

Measuring the return you are generating

One gap in most organisations' approach to risk management investment is measurement. The investment is visible in the budget. The return is not tracked anywhere.

The total cost of risk model gives you a framework for that measurement. Taken together, retained losses, insurance spend, and risk management investment produce a number you can track year on year. If risk management is working, retained losses fall faster than the investment rises. If they are not, you have evidence that the current approach is not generating return and a basis for changing it.

At the project level, Monte Carlo simulation gives you a probabilistic view of financial exposure before a project starts, rather than a single contingency figure someone picked in a meeting. When you run the same simulation at mid-project and the P85 exposure has dropped because measures are working, you have a measurable return on the investment you made in managing those risks. That is the kind of evidence that holds up when a finance director asks what the risk management budget is actually buying.

There is an honest caveat here. The return on risk management investment is clearest in operational and project contexts, where risks are concrete, costs are measurable, and the link between a measure and an outcome can be traced. For strategic and reputational risks, the return is real but harder to quantify. That does not make it less important. It means you should be realistic about how you measure it rather than forcing a number that does not hold up under scrutiny.

Treating risk management as a commercial decision

The organisations that generate the highest return from risk management are the ones that stop treating it as a compliance function and start treating it as a commercial one. They ask not "what does risk management cost?" but "what is our current exposure costing us, and what would it cost to reduce it?"

That shift in framing changes everything: how the function is resourced, how it is owned, and how it is measured. Risk management moves from a line in the audit budget to a tool the operations lead uses to make better decisions about where to allocate capacity, which contracts to price aggressively, and which risks are genuinely worth carrying.

The return is real. The research is consistent. But the return requires infrastructure that works in practice, not just on paper, and a team that uses it between audits, not only because of them.

If you want to see what practical risk management infrastructure looks like, our risk management guide is a good place to start. It covers the fundamentals without the theory overhead, so you can assess where your current process stands and what it would take to make it generate return.

Ready to improve your risk management?

See how Risk Companion can help you implement these best practices with powerful, easy-to-use tools. Sign up and we'll prepare a demo project tailored to your company.

Risk assessments
AI assistance
Bowtie models
Simulations

Frequently Asked Questions

Arthur D. Little's work on the total cost of risk found that every euro invested in injury prevention returns two euros or more, and a small organisation that invested EUR 50.000 in safety improvements saved over EUR 1 million across five years. McKinsey's research on large capital projects shows that unmanaged risk is a primary driver of cost overruns, with megaprojects running on average 80 percent over budget when risk exposure is priced on optimism rather than evidence. The return is measurable when you track retained losses, insurance spend, and risk management investment together using a total cost of risk model.