Law360 Canada (August 10, 2026, 12:23 PM EDT) --
 |
| Heidi J. T. Exner |
There is a small but significant trend developing in the professional services marketplace. Although more prevalent in the private investigation field, I am seeing it in law as well. It begins with a familiar word — one that lawyers use constantly and clients fear instinctively: risk.
“Risk advisory” is becoming a versatile marketing accessory for legal professionals. Attach it to a practice group, title, service offering or PowerPoint deck, and it suggests foresight, sophistication and boardroom relevance. Legal risk. Regulatory risk. Cyber risk. Reputational risk. Strategic risk. Operational risk. The word is doing considerable heavy lifting.
But true, complete and qualified risk management is known as “enterprise risk management” (ERM), and it requires an expertise of its own. It encompasses the full universe of enterprise risk. The difficulty is that legal competence, while critical, is absolutely not synonymous with this qualified risk management advisory. They overlap, and they inform each other. Heck, they often sit in the same executive meetings. But they are not interchangeable. How do I know this? Because in addition to my relatively new law career, I am a fully qualified and experienced enterprise risk management adviser.
drogatnev: ISTOCKPHOTO.COM
The distinction matters because clients are increasingly offered “risk management” advice by legal professionals whose actual expertise is legal analysis, regulatory compliance or policy drafting — which are indeed valuable competencies. However, they are simply not, standing alone, ERM expertise.
A client would not assume that a real estate lawyer is qualified to engineer a bridge merely because both professionals understand the consequences of structural failure. Nor should a board assume that someone who can identify legal exposure is automatically qualified to design, implement, assess or assure an organization-wide risk management framework.
The issue is not whether lawyers should participate in risk management. They should. The issue is whether we are being sufficiently precise about what we are actually qualified to do.
Legal advice is not risk management
Legal advice begins with law. A competent lawyer identifies the applicable legal framework, interprets it, applies it to facts, assesses likely consequences and advises their client on options. That work may involve contracts, litigation, regulatory matters, governance, investigations, employment, tax, privacy, competition, securities, insolvency or a host of other legal domains.
Legal work requires education, judgment, professional responsibility and, often, the ability to tell clients things they would rather not hear.
Compliance work is closely related but has its own practical focus. It asks which legal, regulatory, contractual or internal requirements apply — and whether an organization is meeting them. Compliance professionals build policies, conduct training, monitor conduct, test controls, investigate concerns, report deficiencies and oversee remediation. This work turns “you must” into “this is how we will demonstrate that we did.”
Both legal and compliance functions deal with risk. Legal risk arises where legal rights, duties or exposure may affect an organization. Compliance risk arises where the organization may fail to meet applicable requirements. Neither category, however, even begins to exhaust the full universe of risk.
ERM begins somewhere else entirely — it begins with organizational objectives.
Qualified risk advisers ask what could positively or negatively affect the achievement of these objectives. They examine uncertainty across strategic, operational, financial, technological, reputational, people, supply chain, environmental, geopolitical and legal dimensions. They help management decide which risks it is prepared to accept, which it must reduce, which it can transfer, which it should monitor and which it may choose to pursue. This is not merely a more expansive version of legal advice; it is a different discipline all together, within a different realm of expertise.
ISO 31000 frames risk management as an integrated approach that supports governance, strategy, planning, reporting, values and culture. It contemplates identifying, analyzing, evaluating, treating, monitoring and communicating risk across an organization. This framework is not a lawyer’s playbook, and it is not a compliance manual either. It is an independent organizational management discipline.
The difference is more than mere vocabulary
A lawyer may correctly identify that a business strategy creates antitrust, securities, privacy, employment or other exposure. A compliance professional may correctly determine that a new regulation requires updated procedures and staff training. Both assessments are essential.
But proper risk advisory requires additional questions. And a lot of them!
How does the legal or compliance issue affect strategic objectives? Who owns it? What is the organization’s risk appetite? How does the issue compare with cyber, financial, operational or supply chain risks competing for management attention and budget? What controls exist? Are they designed effectively? Are they operating effectively? What are the residual risks after controls? What indicators should management and the board receive, how often and in what form? What happens when an issue escalates? The list goes on.
These questions require more than cursory subject-matter knowledge and legal skills. They require risk methodology, governance fluency, facilitation skills, thorough knowledge and sound judgment regarding controls and assurance, and a working understanding of organizational behaviour. Risk management is as much about decision-making, accountability and culture as it is about identifying unpleasant possibilities.
It is also not a task completed by delivering a report or a handsome risk register. A spreadsheet with red, amber and green boxes may be useful, but it may also be theatre. The difference lies in whether the information is grounded in appropriate information and influences decisions, resource allocation, accountability and action. A risk register that no one uses is not risk management, it is archival decor.
The expanding ‘
risk’
marketplace
There is a reason risk language is becoming ubiquitous. Boards and senior management face a broader and less forgiving risk landscape. Cyber incidents, artificial intelligence, privacy obligations, third-party failures, geopolitical disruption, fraud, labour shortages, climate-related impacts, economic volatility and heightened regulatory expectations have ensured that risk is no longer a discrete agenda item near the end of a board meeting.
Organizations are seeking trusted advisers who can help them anticipate trouble before it becomes a headline, a regulatory proceeding or a late-night call from the chief executive.
Some legal professionals have recognized this need and responded, perhaps with dollar signs in their eyes or perhaps from hubris, by dabbling in risk-related services. Legal teams are ideally placed to advise on litigation, regulatory enforcement, investigations, disclosure, contractual allocation of risk, governance duties and legal exposure. Compliance professionals are equally indispensable where regulatory obligations must be operationalized and monitored. These sound an awful lot like risk management to an uninformed client.
My concern arises when the title “risk adviser” implies a broader competence than the service actually provides.
There is no shame in being a lawyer. And there is no shame in saying an assignment requires an ERM specialist, internal auditor, cyber professional, actuary, financial expert, control specialist or operational leader.
The danger, in my view, lies in legal professionals who mistake their realm of understanding of risk with a practice for which they are unqualified, suggesting that the word “risk” erases these professional boundaries.
Expertise requires more than proximity
In many organizations, legal, compliance, ethics, privacy, investigations and enterprise risk functions operate closely together. In-house counsel may report to the same executive as the chief risk officer. A chief compliance officer may sit on a risk committee. An internal auditor may provide assurance over risk management.
This proximity is productive. It encourages collaboration and allows organizations to see connected risks before they become disconnected crises.
But it can also produce professional overreach. A legal department that contributes to an enterprise risk assessment or monitors regulatory obligations is not automatically qualified to determine enterprise risk appetite. Conversely, an internal audit function that evaluates risk management must be especially careful not to become management’s substitute risk owner.
The Institute of Internal Auditors’ Three Lines Model offers useful clarity on this matter, which is one of many concepts a true risk management expert understands thoroughly. Management is responsible for achieving objectives and managing risk. Second-line functions may provide expertise, support, monitoring and challenge. Internal audit provides independent and objective assurance regarding governance, risk management and control. This is not bureaucratic hair-splitting. It is about accountability.
When everyone claims to manage risk, no one may actually own it. When the adviser who designs a process later assures the board that the process works, independence can disappear with remarkable speed. When legal acumen is presented as enterprise risk assurance, clients may believe they are receiving a level of analysis and expertise they are not.
Words matter here, because reliance follows words.
Competence includes knowing our limits
The professional obligation for lawyers is straightforward. Competence includes recognizing the limits of one’s knowledge, skill and ability and taking appropriate steps to ensure that a client receives the level of service their legal matter warrants.
I am suggesting that the same obligation of legal competency applies with particular force when risk management is offered as a side service by legal professionals who do not adequately understand enterprise risk management.
A lawyer asked to provide “risk advice” should clarify the assignment before accepting the label. Is the client seeking legal risk analysis? Great. Regulatory compliance advice? Sure.
A review of policies and controls? Facilitation of an organization-wide risk assessment? Development of an enterprise risk framework? An assessment of governance and reporting? Independent assurance for the board? Full and complete strategic business advisory? Yikes, no! For these critical undertakings, legal acumen is not the correct qualification.
These are not interchangeable instructions, and almost no lawyer is adequately equipped to perform proper enterprise risk functions or advisory. I have yet to personally meet a lawyer aside from myself who is properly qualified, knowledgeable or experienced in the ERM realm, in fact.
Lawyers have an important role
None of this diminishes the role of lawyers in risk management. Quite the opposite.
Lawyers bring disciplined analysis, an understanding of legal exposure, knowledge of governance duties, appreciation for evidentiary standards and, where appropriate, the protection of solicitor-client privilege. They can identify emerging legal issues, challenge optimistic assumptions, advise boards and executives on accountability and help organizations understand the consequences of poor decisions before those consequences become public.
The strongest risk management programs make room for legal contribution. But they do not mistake it for the whole program.
Lawyers who wish to provide genuine risk management or business advisory cannot merely assume they possess this expertise; they need to build the necessary competence deliberately. This takes years to do, and it is a separate endeavour from legal practice. It requires the study of recognized frameworks, acquiring practical methodology, working with experienced risk professionals, understanding the boundaries between advisory and assurance, demonstrated competence in business practices, and assembling multidisciplinary teams where needed.
I am not making an argument for professional gatekeeping. Rather, I am making an argument for integrity and professional honesty.
Most clients have as little understanding about ERM as lawyers. However, clients deserve to know whether they are receiving duly qualified proper risk management advisory or if what they are paying for is merely rooted in legal experience. Each has value. Each has a proper place. Each requires different expertise.
The legal profession’s credibility is strengthened, not diminished, when lawyers make that distinction clearly and refrain from encroaching on other professions. After all, the first rule of good risk management is to understand what you do not know.
And the first rule of good lawyering may be much the same.
Heidi J. T. Exner is an award-winning white-collar crime fighter, and she is passionate about making the world a better place. She is the founding partner of Ethical Edge Advisors, the founder and chair of the Exner Foundation, and is advancing licensure to practise law in New York State and Alberta.
She welcomes you to find her on LinkedIn or check out her biography page on Ethical Edge’s website.
The opinions expressed are those of the author(s) and do not necessarily reflect the views of the author’s firm, its clients, Law360 Canada, LexisNexis Canada or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.
Interested in writing for us? To learn more about how you can add your voice to Law360 Canada, contact Analysis Editor Peter Carter at peter.carter@lexisnexis.ca or call 647-776-6740.