Let me raise the lance again against “risk management”

The new general counsel of General Mills, Roderick Palmore, is responsible not only for the company’s legal function but also for compliance and risk management. As reported in InsideCounsel, March 2008 at 13, the three areas are not uncommon responsibilities of a US general counsel. I thought again about that will-o’-the-wisp, “risk management.”

My view is that responsibility for enterprise risk management extends far beyond the appropriate role of a general counsel. To corral legal risk is hard enough, not to mention to ride herd on a company's panoply of risk.

Even trying to rein in legal risks is a bronco hard to break.

True, frameworks exist for assessing legal risks, such as the COSO model. To deal with legal risks you need to identify them and then estimate their potential impact. Other steps in legal risk management include to map such risks, to quantify them, and periodically to assess them.

Even with these supposed methodologies, no one knows how to quantify the risks that any staff function faces. To be saddled with responsibility for "legal risk management" is to be riddled with unknowns.