Risk and Resilience

Risk Transparency Is Not Risk Control: Build Portfolio Coping Capacity

A visible portfolio risk is not a controlled risk. Leaders need both risk transparency and the organisational capacity to prevent, absorb and respond.

EraNorth Insights · 30 Aug 2026 · 9 min read

A portfolio can understand its risks clearly and still be unable to do anything useful about them.

The risk dashboard is comprehensive. Dependencies are documented. Each project has a register. The portfolio heatmap is updated monthly. Senior leaders can see where exposure is rising.

Then a common supplier fails, three projects lose the same specialist capability, a shared technology assumption proves wrong and the organisation discovers that it has no practical response capacity.

The risk was visible. It was not controlled.

This distinction is central to portfolio resilience. Risk management is not only a sensing discipline. It is also a capability discipline.

The Strategic Context

Teller and Kock's empirical study of 176 firms examined how portfolio risk-management practices relate to project portfolio success. Their model separates risk-management quality into two constructs: risk transparency and risk coping capacity.

Risk transparency concerns the organisation's ability to identify, understand and communicate portfolio risk. Risk coping capacity concerns the ability to prevent, absorb and respond to risk when it emerges.

The study found that portfolio risk identification, process formalisation and risk-management culture were directly associated with transparency. Risk prevention, risk monitoring and integration of risk information into project portfolio management were directly connected to coping capacity. Both transparency and coping capacity were positively associated with portfolio success in the tested model, although the hypothesised complementary interaction between them was not confirmed.

The important management implication is straightforward: the organisation should not equate knowing with being ready.

What Leaders Commonly Misread

The first misread is that a complete risk register demonstrates strong risk management. A register is an inventory of stated concerns. It does not prove the organisation can respond.

The second is that portfolio risk equals the sum of project risks. Portfolio-level exposure can emerge from common dependencies, shared resources and correlations that are not material inside any single project. Three projects may each carry an acceptable supplier risk while the portfolio as a whole is dangerously concentrated on one supplier.

The third is that more monitoring is automatically better. Teller and Kock found risk monitoring positively related to coping capacity, but also found a negative direct association between risk monitoring and portfolio success in their regression model. The authors discuss possible explanations including excessive detail, mistrust and reduced flexibility. That result should not be read as proof that monitoring causes failure. It is a warning that control activity can create cost and behavioural consequences of its own.

The fourth is that risk ownership can be delegated entirely to projects. Some risks are created by the portfolio's structure, not by poor project management.

Reframing the Issue

Portfolio risk management should be treated as a sensing-and-response architecture.

Risk transparency answers:

  • What could materially affect portfolio value?
  • Where are risks shared or correlated?
  • Which assumptions are becoming weaker?
  • What exposure is accumulating across projects?

Risk coping capacity answers:

  • What can the organisation prevent?
  • What can it absorb?
  • What can it switch, substitute or reallocate?
  • How quickly can it act?
  • Who has authority to activate the response?

A resilient portfolio needs both disciplines, even if their relationship is not a simple mathematical interaction.

Related article: Risk Belongs in Portfolio Decisions Before Projects Fail

Transparency Begins with Culture, Not Software

One of the strongest findings in Teller and Kock's study was the importance of risk-management culture for transparency. An open and frank culture helps risks surface before they become formally visible in reports.

This matters because risk information is socially produced. A project manager can know that a milestone is weak but delay escalation because the governance culture punishes bad news. An engineer can see a technical dependency but assume it belongs to another project. A supplier manager can recognise concentration exposure but report only contract performance. The organisation may have data while still lacking transparency.

Formal processes help because they create common expectations for identification and analysis. But process without candour produces polished uncertainty.

Leaders should therefore ask whether the organisation rewards early risk revelation or only accurate late reporting.

Coping Capacity Is Designed Before the Crisis

An organisation cannot improvise all resilience after a risk materialises.

Coping capacity can include alternative suppliers, modular architecture, cross-trained capability, management reserves, schedule contingency, staged investment, flexible contracts, data portability, pre-agreed escalation rights and the ability to move resources across initiatives.

These responses cost money or reduce apparent efficiency. That is why they are often removed during optimisation. The portfolio becomes leaner but more brittle.

The executive trade-off is not “risk management versus efficiency”. It is determining how much resilience is economically justified given the concentration, reversibility and consequence of exposure.

A highly diversified portfolio with weak interdependencies may not justify the same portfolio-risk infrastructure as a tightly coupled transformation program. Teller and Kock themselves note that portfolio risk management carries cost and may not deliver equal value in every context.

Decision Framework: The Visibility–Response Matrix

Leaders can classify material portfolio risks using two dimensions: visibility and response capacity.

StateVisibilityResponse capacityLeadership interpretation
Blind and fragileLowLowHighest concern: exposure may emerge without warning and with few options
Visible but helplessHighLowRisk reporting is strong, but resilience investment or decision authority is weak
Capable but blindLowHighThe organisation has options but may activate them too late
AdaptiveHighHighRisks can be seen early enough for credible response options to matter

Then test each material risk through five questions.

1. Concentration

Does this exposure appear across several projects, suppliers, technologies, locations or critical people?

2. Propagation

If the risk materialises, where does it travel next? Look beyond the directly affected project.

3. Response inventory

What specific actions could reduce probability, reduce impact, transfer exposure, create substitution or accelerate recovery?

4. Activation threshold

What evidence triggers action? A contingency plan that requires crisis-level proof may activate too late.

5. Response ownership

Who can move money, people, sequence or scope when the response crosses project boundaries?

Related article: Interdependencies Are Portfolio Risk: Why Project Dashboards Miss the System

From Strategy to Execution

Immediate action is to take the ten largest portfolio risks and separate the transparency question from the response question. For each, write two sentences: “What do we know?” and “What can we do?” Any risk with a strong first answer and a weak second answer is an exposed capability gap.

Medium-term capability building should connect portfolio risk with resource management, procurement, architecture, finance and business continuity. Risk functions often identify exposure but do not own the levers required to change the portfolio. Those levers must be built into governance.

Long-term strategic positioning means designing resilience selectively into the portfolio. This can include reducing common-mode dependencies, preserving alternative pathways and making major commitments more reversible where uncertainty is high.

The goal is not to eliminate risk. It is to prevent avoidable fragility.

Signals to Monitor

Warning signs include rising dependence on a small number of suppliers or specialists, repeated risks that appear in several project registers without a portfolio owner, increasing monitoring effort without faster decisions, late escalation of known issues, contingency plans that depend on the same constrained resources as the primary plan, and high-severity risks whose responses require approvals that have never been tested.

A positive signal is that the organisation can describe not only its largest risks but the options it has retained because those risks exist.

References

  • Teller, J. & Kock, A. 2013, 'An empirical investigation on how portfolio risk management influences project portfolio success', International Journal of Project Management, vol. 31, no. 6, pp. 817–829.

Questions for the Leadership Team

  1. Which major portfolio risks are visible but currently lack a credible response option?
  2. Where are several projects exposed to the same supplier, technology, resource or assumption?
  3. Does our risk culture reward early uncertainty or only confirmed problems?
  4. Which monitoring activities inform decisions, and which mainly create reporting workload?
  5. What resilience have we removed in the name of efficiency?
  6. Who has authority to reallocate resources when a risk crosses project boundaries?

Closing Perspective

Risk transparency is valuable because it makes uncertainty discussable. It is insufficient because organisations do not succeed by seeing danger clearly; they succeed by preserving credible choices before the danger becomes unavoidable. The mature portfolio does not merely know what could go wrong. It has deliberately built enough capacity, authority and flexibility to respond when it does.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.