
Why is self-evaluation so widely used? Because it is efficient, scalable, cost-effective, and widely embedded in regulatory and governance practices. Those advantages, however, do not make it objective.
Every governance framework relies on one fundamental assumption: organizations are capable of assessing themselves objectively.
Risk registers, control self-assessments, compliance questionnaires, and internal certifications all depend on the belief that those closest to a process are also best positioned to evaluate it. Yet there is a question that is rarely asked.
What happens when those responsible for identifying risk are also those who will bear the consequences of reporting it?
The answer is more important than it first appears. It influences not only the quality of risk reporting, but also how organizations allocate resources, prioritize corrective actions, and ultimately make strategic decisions.
The same managers who are expected to identify weaknesses are also evaluated on the quality of the areas they manage. A reported weakness may trigger additional controls, corrective action plans, increased management scrutiny, audit findings, or lower performance ratings. In other words, the people expected to disclose problems are often the same people who bear the consequences of reporting them.
In many organizations, unresolved issues are not the result of negligence. They have already been identified, documented, escalated, and accompanied by practical mitigation proposals. Yet they often become trapped within the governance process—waiting for additional information, another approval, further clarification, or simply disappearing from the agenda of the next committee meeting.
Over time, organizations unintentionally teach managers an uncomfortable lesson: honestly reporting significant risks rarely changes strategic decisions or regulatory outcomes. More often, it results in additional controls for operational teams while the underlying structural problem remains unresolved.
Even external oversight is not immune to this dynamic. Regulatory findings and audit observations are frequently routed back to the same managers responsible for the underlying process — to be explained, remediated, or contextualized — before they ever reach the board as a governance decision. The loop closes at the operational level long before it reaches the level where structural change could happen.
Self-evaluation gradually stops being an exercise in objective risk identification and becomes an exercise in organizational survival. This pattern can be seen across risk management, fraud prevention, and internal control environments. Departments are criticised, managers are replaced, controls multiply, and regulatory observations accumulate. Far less frequently is there a genuine examination of whether governance decisions themselves contributed to the risks that were ultimately reported.
Self-evaluation does not fail because managers lie. It fails because the system teaches honest people what is safe to report.
The structural conflict explains why self-evaluation becomes vulnerable. Cognitive biases explain how that vulnerability manifests in practice. Once self-evaluation becomes the primary source of information for governance decisions, a series of well-documented cognitive biases can shape the assessment process.
One of the strongest is self-serving bias. Reporting a significant weakness may imply poor management, insufficient oversight, or ineffective controls. Without any intention to deceive, managers naturally interpret evidence in ways that protect their professional identity and demonstrate that risks remain under control. The result is not necessarily inaccurate reporting, but reporting that is unconsciously optimistic.
This tendency is reinforced by confirmation bias. Once a control framework is considered effective, evidence is more likely to be interpreted as supporting that belief, while contradictory signals are explained as isolated incidents, implementation issues, or temporary exceptions. Over time, organizations become increasingly confident in controls that may never have been objectively challenged.
Another subtle mechanism is normalcy bias. Risks that remain unresolved through multiple reporting cycles gradually become accepted as part of normal operations. What initially appeared as a significant governance concern slowly loses its urgency simply because no major event has occurred. The absence of immediate consequences is often mistaken for evidence that the risk is adequately managed.
When weaknesses emerge, the framework is rarely questioned. Instead, additional controls, reporting requirements, or documentation are introduced, reinforcing the belief that the process is sound while leaving its fundamental design unchanged.The governance process itself can also create escalation of commitment. After significant resources have been invested in a particular control framework, organizations become reluctant to question the effectiveness of the framework itself. Instead of reassessing the design of the process, additional controls, reporting requirements, or documentation are introduced, increasing complexity without necessarily reducing the underlying risk.
Finally, social desirability bias influences what is ultimately reported. Managers quickly learn which answers are likely to trigger additional scrutiny, and which responses are considered acceptable. The objective gradually shifts from describing reality as accurately as possible to producing assessments that are defensible within the existing governance culture.
Still, naturally whenever people are asked to evaluate their own performance while simultaneously bearing the consequences of their conclusions, the greatest source of uncertainty is often not the risk being assessed, but the assessment process itself. The greatest risk is not that organizations underestimate operational risk. The greatest risk is that they overestimate the objectivity of the process used to assess it. Self-evaluation does not eliminate uncertainty. It merely transfers it from the operational process to the governance process itself.
A Different Approach: Cross-Functional Risk Assessment
One way to reduce this structural conflict is not to ask managers to evaluate the risks within their own departments, but to invite them to evaluate the effectiveness of the processes they share with other departments.
The difference may appear subtle, but it fundamentally changes the nature of the assessment. When managers are asked to identify risks within their own area, they naturally associate the exercise with accountability and performance evaluation. The conversation often shifts toward defending existing controls or minimizing weaknesses. When they are instead asked what could improve the efficiency of a shared process, the focus moves away from assigning responsibility and toward solving operational problems.
This shift also changes the quality of the information collected. The objective is not to replace risk identification, but to approach it through a different question that can change the psychology of the assessment. Managers no longer feel they are defending their performance or exposing weaknesses. Instead, they are invited to contribute to improving the way the organization operates and more likely to identify concrete obstacles: delays in information exchange, unclear responsibilities, duplicated controls, missing data, ineffective escalation paths, or communication gaps. These observations not only reveal where friction exists between departments but also provide practical suggestions for improvement.
Problem-Solving Approach
Which process involving another department could be improved to increase both teams’ ability to work efficiently?
What could be improved? __________
What would the improvement achieve? __________
Select the estimated impact of the improvement:
Very High / High / Medium / Low / Very Low
Other potential questions that can help to identify risks and proper solutions for its mitigation could be׃
- What works well in this process?
- What is the main difficulty or obstacle affecting the process?
- Where do delays, errors, duplication, or misunderstandings most frequently occur?
- What information, resources, or support would help your team perform this process more effectively?
- If you could change only one thing in this process, what would you change first?
The Question Behind the Assessment
The purpose of governance is not to produce assessments that look objective. It is to create conditions in which uncomfortable information can survive long enough to influence a decision. Self-evaluation will always have a place in risk management. The problem begins when it is treated as neutral simply because it is structured, documented, and embedded in a formal governance framework. The question, therefore, is not whether managers can assess risk objectively. They can, but only within the limits created by their incentives, responsibilities, organizational culture, and the consequences attached to what they report.
A stronger governance model does not try to eliminate human judgment. It recognizes where judgment is most vulnerable to bias and changes the way information is collected. The objective is therefore not to find an unbiased assessment, rather is to avoid relying on a single assessment mechanism as if it were unbiased and to design processes in which different perspectives can expose each other’s blind spots.
Sometimes the most useful risk question is not “What is the risk in your area?” but “What prevents the organization from working better?” The first question asks people to expose weaknesses. The second invites them to solve problems.