Question

What People risks should be included in the enterprise risk register and reviewed by executive leadership?

Zuna Answer
3 Views

Executive Summary A strong Enterprise Risk Register (ERR) should include People risks that (1) materially threaten strategy delivery, financial performance, customer outcomes, or operational continuity, (2) are measurable and assignable to an owner, and (3) are reviewed with clear triggers by executive leadership. Below is a practical set of People risks you can include, written in a “risk register” style (risk statement, common impact, and key leading indicators).

Key Recommendations (People risks to include in the ERR)

  1. Talent supply & critical role continuity risk
  • Risk statement: Inability to source/retain talent for critical roles, leading to delivery delays, quality issues, and leadership gaps.
  • Typical impact: missed roadmap, reduced productivity, service/customer failures, higher cost from stop-gap hiring.
  • Leading indicators (examples):
  • Coverage of critical roles (e.g., % with succession coverage/ready bench)
  • Time-to-fill vs target by critical roles
  • Voluntary attrition in critical job families
  • % roles with documented competency plans
  1. Key person & succession risk (leadership bench weakness)
  • Risk statement: Over-dependence on a small number of individuals; insufficient succession planning increases “single-point-of-failure.”
  • Typical impact: disruption during transitions, loss of institutional knowledge.
  • Leading indicators:
  • Succession plans for top leaders completed and validated (quality scoring)
  • Readiness of successors (assessment completion + development progress)
  • Interim leadership reliance rate
  1. Retention & workforce stability risk
  • Risk statement: Higher-than-tolerable turnover or disengagement in targeted segments (e.g., high performers, frontline, scarce skills).
  • Typical impact: productivity loss, increased recruitment costs, knowledge drain.
  • Leading indicators:
  • Turnover by level/department/location
  • eNPS / engagement trend (by business unit)
  • Internal mobility rate and reasons for leaving
  1. Culture, engagement & conduct risk
  • Risk statement: Culture misalignment, low engagement, or norms that enable poor conduct—creating reputational and operational harm.
  • Typical impact: productivity drag, reputational damage, policy breaches.
  • Leading indicators:
  • Staff survey trend and “hotspot” scores
  • Grievance/complaints volume and closure timeliness
  • Conduct training completion + substantiated policy breaches trend
  1. Employee relations & labor compliance risk (where applicable)
  • Risk statement: Labor/IR issues, unmanaged disputes, or failure to meet applicable obligations (jurisdiction-specific).
  • Typical impact: work stoppages, legal cost, reputational harm.
  • Leading indicators:
  • Open cases count, escalation rate, average time to resolve
  • Repeat-issue rates by manager/team
  • Audit outcomes from HR/IR compliance checks
  1. Performance management effectiveness risk
  • Risk statement: Weak performance processes leading to misalignment, underperformance, inability to differentiate, and lack of accountability.
  • Typical impact: chronic under-delivery, talent mismatch, unfairness concerns.
  • Leading indicators:
  • % completion of performance cycles to quality standard
  • Calibration outcomes (e.g., rating inflation metrics)
  • Underperformance exits vs “managed out” delays
  1. Leadership capability & management effectiveness risk
  • Risk statement: Managers lack capability in coaching, decision-making, and people leadership—causing execution and retention problems.
  • Typical impact: poor execution, high attrition, inconsistent performance standards.
  • Leading indicators:
  • Manager training coverage vs required curriculum
  • 1:1 frequency / coaching effectiveness sampling results
  • Employee feedback on manager quality
  1. Compensation, fairness & pay governance risk
  • Risk statement: Pay misalignment, inequities, or poor governance leading to retention loss, morale impact, and increased compliance exposure.
  • Typical impact: turnover, reputation issues, legal exposure (jurisdiction-specific).
  • Leading indicators:
  • Pay equity indicators (gender/grade where applicable)
  • Salary variance controls breach rate
  • Merit/promotion cycle anomalies and escalations
  1. Workplace health & safety risk (including psychosocial safety)
  • Risk statement: Inadequate safety systems or psychosocial risk management leading to injuries, burnout, and absence spikes.
  • Typical impact: operational downtime, claims/legal cost, reputational damage.
  • Leading indicators:
  • TRIR/LTIR (for relevant industries), near-miss rates
  • Absence rate, burnout/health signals, workload indicators
  • Safety training compliance and audit closure
  1. Learning & capability development risk
  • Risk statement: Insufficient capability-building to deliver strategy (skills gaps), leading to execution failure.
  • Typical impact: rework, quality issues, inability to adopt new tech/processes.
  • Leading indicators:
  • % workforce with role-relevant training completed
  • Skills gap closure rate for critical capabilities
  • Internal capability certification coverage (where relevant)
  1. HR data, HR systems & privacy risk (HR technology governance)
  • Risk statement: Failures in HRIS/HR tech (availability, data quality), or privacy/security lapses involving employee data.
  • Typical impact: payroll errors, reporting failures, legal/regulatory exposure, employee trust loss.
  • Leading indicators:
  • Payroll accuracy incidents; HR master-data quality metrics
  • System uptime and change failure metrics
  • Data access anomalies and security audit outcomes
  1. Workforce planning & cost competitiveness risk
  • Risk statement: Inaccurate workforce planning and uncontrolled labor costs (e.g., overtime, contractors, redeployment inefficiency).
  • Typical impact: margin erosion, inability to fund strategic priorities.
  • Leading indicators:
  • Forecast variance vs plan (headcount, labor cost, utilization)
  • Overtime/contractor spend vs thresholds
  • Redeployment cycle time
  1. Diversity, inclusion & accessibility risk (linked to business outcomes)
  • Risk statement: Inequitable practices or insufficient inclusion reducing talent attraction/retention and performance diversity.
  • Typical impact: talent loss, reputational risk, weaker innovation and customer alignment.
  • Leading indicators:
  • Representation and progression metrics by job family/level
  • Hiring funnel conversion by segment
  • Inclusion survey trends and accessibility compliance checks

How to structure these in the ERR (so executives can govern them)

  • Make each People risk “register-ready”:
  • Risk title (short)
  • Risk owner (typically HR + a functional exec where cross-cutting)
  • Business impact category (Strategy/Financial/Operational/Reputational/Compliance)
  • Controls (what exists today)
  • Risk rating method (likelihood x impact)
  • Mitigation actions with owners + due dates
  • Leading indicators + agreed thresholds
  • Ensure “executive visibility” by limiting to the most material 8–12 People risks initially (then expand after maturity).

Review cadence & escalation triggers (executive leadership)

  • Standard governance:
  • Monthly/quarterly deep-dive on top People risks (rotate if many)
  • Quarterly overall ERR review including movement in risk ratings
  • Trigger-based escalation examples:
  • Sudden spike in attrition in critical roles (e.g., >X% over baseline)
  • Safety incident severity threshold reached
  • Payroll/HRIS critical incident
  • Repeat labor/employee relations escalations
  • Engagement drop in a business unit with revenue/quality impact

Business Impact (what execs should look for)

  • Delivery risk: ability to staff critical workstreams on time
  • Cost risk: overtime/contractor reliance, churn costs, productivity loss
  • Customer risk: service disruption, quality failures tied to people capacity
  • Reputation risk: misconduct/culture failures, labor disputes, safety incidents
  • Compliance risk: HR governance, documentation gaps, data/privacy failures (where applicable)

Risks (common failure modes in People risk registers)

  • Too generic (“talent risk” without critical roles, thresholds, indicators)
  • No control mapping (actions listed but not tied to specific controls)
  • No thresholds or “what counts as worsening”
  • Ownership unclear (HR only, or operations only—People risks are cross-functional)
  • Metrics focus solely on lagging outcomes (attrition, incidents) without leading indicators

Immediate Next Steps

  1. Run a 60–90 minute “People risk scoping” workshop with HR, Operations/COO, Finance, and Legal/Compliance (if applicable).
  2. Draft the initial People risk register entries using the 12 categories above, but tailor to your actual critical risks (e.g., frontline safety vs. compliance-heavy environment).
  3. For each top risk, agree:
  • risk owner
  • 2–4 leading indicators
  • thresholds/triggers
  • mitigation actions for the next quarter
  1. Build an executive dashboard view of the ERR People risks (risk rating movement + indicator trends).

If you tell me which industry and whether you’re unionized / heavily regulated, I can help you prioritize the top 8–10 People risks to include and propose indicator thresholds that fit your environment.

If you need help implementing these recommendations or would like expert guidance tailored to your organization, the team at Zunavish would be happy to assist.