🎯Why Risk Is a Feature, Not a Flaw

If you're in a business that doesn’t take risk, odds are you're in a business that doesn’t make much money.

Risk is not a bug in the system; it is the system. Every growth decision, every new market entered, every product launched, every person hired… all of it carries uncertainty. The job of the CFO isn’t to eliminate that risk. It’s to underwrite it intelligently. To place the right bets, hedge the big swings, and make sure one rogue wave doesn’t tip the whole boat.

The Last of Us” Season 2: What happened in the nail-biter finale

The season finale of The Last of Us left me with more questions than answers. Also, that rogue wave was laughably big for being in a bay.

But here's the catch: the CFO is also the designated grown-up in the room. You're expected to be the one who sees the iceberg while everyone else is toasting on the deck. And in that duality, risk enabler and risk governor, is where the real job begins.

Too many finance teams fall into one of two traps:

  1. The Overbuilder: Layering process on top of process, approvals on top of approvals, until the business becomes a bureaucratic tar pit. Decisions slow down. Innovation stalls. And ironically, risk increases because now everyone’s operating through workarounds.

  2. The Cowboy: Going full speed ahead with minimal controls, trusting that “we’ll fix it later” when something breaks. That works… until it doesn’t. (See: any post-mortem from the 2008 mortgage crisis.)

The right approach is somewhere in between. It’s recognizing that some level of risk is the cost of success, but that smart controls can ensure you’re flying with a parachute—not just Red Bull.

Parachute with Travis Pastrana ...

You have to underwrite some level of risk, or else you don't have a business. But you also can’t slow down the business to the degree that people are complaining about it or can’t hit the goals you set.

So how do you enable growth without letting the wheels come off?

You build cheese.

In this post we’ll go through Risk Management 101 (a model that doesn’t suck the life out of your business):

  • Part I: The Swiss Cheese Model Explained

  • Part II: The Red Arrows… What Are You Actually Guarding Against?

  • Part III: Why Crisis Response ≠ Risk Management

  • Part IV: Building the Cheese… Proactive Controls That Actually Work

  • Part V: Why Finance Is Uniquely Positioned to Lead

  • Part VI: When Too Much Cheese Becomes a Problem

This post will position you as a thought leader when it comes to risk, giving you words to rely upon that people actually understand in their day to day lives. And it will give you a framework and mindset you can deploy within your company to stop more hazards from getting through.

Let’s get started.

Part I: The Swiss Cheese Model Explained

Risk isn’t a singular event - it’s a series of failures. Rarely does one mistake bring down a business. What usually causes the real damage is when several small breakdowns happen in sequence, unnoticed. That’s where the Swiss Cheese model comes in.

Popularized in fields like aviation and healthcare, the model works like this:

  • Each slice of cheese is a layer of defense—a control, a process, a safeguard.

  • Each hole is a weakness or gap in that defense.

  • The red arrows are the risks, trying to punch through.

  • When the holes in enough slices align, a red arrow gets all the way through.

    • That’s when bad things happen.

Visualizing It in a Finance Org

Let’s use Accounts Payable as a practical example:

  • Slice 1: Three-way match (invoice, PO, receipt must all agree)

  • Slice 2: Manual vendor verification (call the vendor, don’t trust the email)

  • Slice 3: Live customer/vendor list (no one-off mystery wires)

Each of these processes reduces the risk of paying the wrong vendor or falling for fraud. Will any one of them catch every mistake? No. But together, they drastically increase your odds. That’s the cheese doing its job.

Craig Conti, CFO of Vera Mobility, put it this way:

“If something gets through here, it's going to be enough of an exception that it'll get the right level of visibility and we’ll be able to fix our process. That’s how I think about risk management—and I think about myself as one of the pieces of cheese, too.

It’s Not Just AP — Think Cross-Functionally

  • In FP&A, budget guardrails and real-time variance alerts are slices.

  • In Sales Ops, deal desk approvals or contract value thresholds are slices.

  • In Revenue Recognition, waterfall automation and exception handling are slices.

The power of the model is that it scales. You can apply it at the department level or zoom out to a company-wide view.

But here’s the kicker: you can’t rely on any one slice to catch everything. The Swiss Cheese model is about layers of imperfect protection, not one perfect shield.

And crucially, the holes move. What worked yesterday might not work tomorrow—because your business, your risks, and your environment evolve.

So the job of a great finance leader isn’t to build perfect cheese. It’s to constantly inspect the stack, patch the gaps, and make sure the arrows don’t find an open runway.

So, The Red Arrows – What Are You Actually Guarding Against?

You can't defend against everything. But you can prioritize your defenses based on what’s most likely to hit you—and what would hurt the most if it did.

That’s the job of identifying your red arrows: the risks trying to pierce through your slices of cheese.

We’ll borrow (reluctantly) from Donald Rumsfeld here:

“There are known knowns... known unknowns... and unknown unknowns.”

For all its meme-worthiness, this taxonomy actually works.

  • Known knowns are risks we’ve already seen—fraud schemes, compliance lapses, accounting misstatements.

  • Known unknowns are risks we suspect are out there—maybe tied to an upcoming product launch, a new GTM motion, or a regulatory shift.

  • Unknown unknowns are the real nightmares. The ones you can’t yet name because they haven’t happened. But they will.

Craig Conti breaks it down well:

History gives you two-thirds of your risks. The other third? You get by talking to leadership, staying close to the front lines, and knowing how your customers behave.”

In other words, risk management isn’t just a desk job. If you want to see what’s coming, you have to be in the flow of the business.

🔍 Where Red Arrows Hide

  • Incentives: Misaligned comp plans are an underrated source of systemic risk. If someone benefits in the short term but bears no long-term consequences, don’t be surprised when they unwittingly light the match.

  • Process Assumptions: “This has always worked” is a dangerous sentence. Processes can decay slowly—until they fail suddenly.

  • Tool Gaps: A disjointed tech stack without visibility or alerting is a perfect breeding ground for error. If it takes 6 systems to trace a transaction, that’s not complexity—it’s opacity. And it spreads your surface area for bad things to happen.

  • Blind Trust in Spreadsheets: Anything that lives in Excel long enough will break. Your best analyst is human. And humans get tired.

Holding up the earth

The point isn’t to predict the future perfectly. It’s to narrow the odds. To turn unknown risks into known ones, and known ones into non-events.

Because once the red arrow hits, you’re not in risk management anymore.

You’re in crisis response. And that’s where we go next.

🚨Crisis Response ≠ Risk Management

Let’s make one thing painfully clear: Crisis response is not risk management. They’re related, yes; but they’re not interchangeable. One is about prevention. The other is about damage control.

Here’s how Craig Conti put it:

“Once something breaks through... now you're in crisis response. Very different process. Solve it, fix the process later. But treat them as different things.”

Too many teams—especially those under pressure—blur the lines. A crisis hits, and instead of fixing the root cause later, they backfill it into the risk management framework as if it had been there all along. That’s not building better cheese. That’s decorating burnt toast.

🧯 Crisis Response: The Fire Drill

Disaster Girl - Wikipedia

This is the “Oh shit, it happened” moment. Your risk controls failed (or didn’t exist). Now you’re in reactive mode:

  • Who’s on point?

  • Who informs the board?

  • How do you isolate the issue, stop the bleeding, and triage the fallout?

It’s muscle memory, not modeling.

A solid crisis response plan includes:

  • Pre-assigned roles (legal, finance, ops, comms)

  • Clear escalation paths

  • Drafted templates for incident reporting

    • This is a big one!!!! So many companies make things worse when they try to publicly communicate what happened in the moment.

  • A “commander” who makes the final call (not a committee)

    • Democracy is a shitty system during crisis

Think of it like the emergency exits on an airplane. You don’t need them often—but when you do, they better be working. And you better know where they are.

🧱 Risk Management: The Blueprint

Risk management happens before things break. It’s the stuff we covered earlier: proactive controls, layered defenses, thoughtful incentive design. It’s measured in near-misses, not disasters.

It’s not as sexy. You don’t get the adrenaline rush. But it’s the only reason the crisis response team doesn’t live on caffeine and antacids.

And here’s the critical part: after the fire’s out, you have to loop back. The red arrow made it through. Time to inspect the cheese stack.

Conti again:

“What looks like a brand-new problem today may just be a slightly tweaked version of something that happened 15 years ago.”

If your company doesn’t have a strong internal audit function, that feedback loop falls on you, the CFO. You’re the connective tissue between operational learnings and strategic protection.

You don’t want to be the person explaining to the board why this exact thing happened again… just with new actors and a slightly different invoice format.

Building the Cheese – Proactive Controls That Actually Work

Let’s talk about what actually makes up your stack of Swiss cheese slices—your proactive controls.

Good controls do two things:

  1. Intercept the most likely red arrows.

  2. Signal loudly when something’s wrong.

They don’t stop the business from moving. They guide it, with a nudge here and a hard stop there.

Think of your controls as tools to narrow the path, not close it off.

🧾 Tactical Cheese: On-the-Ground Controls

These are the everyday safeguards embedded in your operating workflows—the frontline mechanisms that quietly protect the business while letting it run fast:

  • Automated Spend Limits in Procurement Tools: Set role-based thresholds in platforms like Coupa or Zip to flag or block spend before it gets out of hand.

  • Employee Expense Policy Enforcement via Credit Card Controls: Issue smart cards (Brex, Rippling) that auto-reject out-of-policy purchases in real time—no back-end policing needed.

  • Slack-Based Budget Alerts: Set up automated Slack pings when a team hits 80% of its monthly budget, prompting review before overspend happens.

Real-life example: At a consumer tech company, Finance integrated their FP&A tool with Slack to ping budget owners the moment they crossed certain spend thresholds. The result? Budget variance dropped by 30%—not through tighter budgets, but through faster visibility.

These controls aren’t glamorous. But they work. And when they fail, they fail loud. That’s the point. They’re early-warning systems, not silencers.

They’re designed so that if a risk gets through, it does so in such an obvious way that it gets the attention it deserves. Once again, as Conti said:

“If something gets through here, it’s going to be enough of an exception that it'll get the right level of visibility and we’ll be able to fix our process.”

🧠Designing with Risk Management in Mind - Higher Level Safeguards

Not all controls live in spreadsheets and approval flows. Some of the most powerful slices come from how you design the business.

  • Incentive Alignment: Misaligned incentives are a risk accelerator. If someone benefits from short-term wins without owning long-term consequences, you’ve built a time bomb.

Real-life example: At a large lender, a salesperson was compensated on mortgage volume closed—not quality or duration. So they booked 30-year loans and funded them with 30-day commercial paper. It looked genius for one quarter. Then rates spiked. The funding dried up. And those mortgages cratered under mismatched duration risk. The sales lead made their bonus. Treasury (and the US government) wore the collapse.

  • Cross-Functional OKRs: Tightly linked goals across Sales, Finance, and Product reduce silos and create shared accountability. When teams operate on isolated metrics, they optimize locally at the expense of the whole.

Real-life example: A B2B SaaS company had Sales comped on ACV, while Product was focused on usage retention. The result? Sales sold massive multi-year contracts to customers that were a poor fit. Churn spiked. Net retention dropped. It took a full reorg to unify goals around NRR instead.

  • Segregation of Duties: Basic, yes—but still violated more often than you’d think. If the same person can approve a vendor, book an invoice, and cut the payment, you’ve got a fraud recipe.

Real-life example: A high-growth startup’s office manager was the only person handling vendor onboarding and invoice processing. She paid a fake contractor account for over a year before anyone noticed. The emails were well-crafted. The money was real. The oversight? Totally missing.

These structural controls don’t just prevent errors—they shape behavior. When done right, they create an environment where the right actions are the easiest ones to take.

🧩 Who Owns What?

Each function needs to own its slices. But Finance often becomes the de facto architect—because you’re the one who sees across the org.

A good rule of thumb:

  • Operators build the slices.

  • Finance calibrates them.

  • Internal audit tests them.

  • Leadership enforces them.

You can’t outsource judgment. And you can’t build this stack in a vacuum. It has to flex with the business—and evolve with every near-miss.

Why Finance Is Uniquely Positioned to Lead

Risk management lives everywhere. But no one sees the full chessboard (cheeseboard?) like finance.

You sit at the intersection of revenue, cost, capital, and compliance. You see how deals are structured, how spend flows, how incentives are crafted. That visibility gives you a unique superpower: pattern recognition.

And with that comes a unique responsibility: making sure the red arrows don’t get ignored just because they haven’t hit yet.

Craig Conti nails it:

“Finance people have the most information, bar none, about the company. No one else has even 10% of the visibility you do.”

Here’s how that superpower translates into leadership:

  • Finance connects dots others don’t see.

    • You notice when a vendor contract is escalating faster than usage, or when sales comp is decoupled from customer success outcomes. You see incentives misaligned across silos and how they feed hidden risk.

  • Finance sets the tone for how seriously risk is taken.

    • If you treat controls as bureaucratic hurdles, so will everyone else. But if you frame them as business enablers—and design them to be fast, fair, and feedback-driven—they’ll stick.

  • Finance turns crisis response into long-term improvement.

    • You’re in the postmortems. You work with legal. You write the board slides. Which means you’re in the best spot to loop learnings back into your risk stack.

🧀When Too Much Cheese Becomes a Problem

Let’s be real: It’s easy to get carried away with controls.

And eating too much cheese can give you gas.

You build a few slices of cheese. Then you find a few holes. So you add more cheese. Then someone flags a risk on Slack, and boom—another layer. Before long, you’ve built a stack so thick the business can’t see daylight.

And what started as smart risk management becomes operational sludge.

Craig Conti warned of this:

“You could build 1,000 slices of cheese… and slow the company to a crawl.”

The hard truth? Every control creates friction. The trick isn’t to eliminate friction—it’s to make sure it exists in the right places.

How to Know When You’ve Gone Too Far

  • Shadow systems are thriving. If teams are spinning up Airtables, Notion pages, or side deals just to bypass process, it’s a sign your controls are more obstacle than safeguard.

  • Your own team is underwater. When Finance becomes a help desk for approvals and exceptions, it’s no longer steering the business—it’s chasing it.

Real-life example: A VP of Finance at a mid-size e-comm brand realized her team was fielding 200+ requests a week just for “exceptions” to policy—because the policy had 46 pages of rules. She rebuilt it around a few key thresholds and decision trees. Exceptions dropped 70%.

  • Risk-taking dies in the planning stage. If every new initiative sparks a chorus of “Can we even get this approved?”, you’ve created a risk-averse culture masquerading as disciplined ops.

⚖️ The Art of Calibration

The right amount of cheese isn’t fixed—it’s contextual.

  • At an early-stage startup, the biggest risk is usually not moving fast enough. You’re innovating. You’re iterating. And frankly, there’s not much to defend. So you take bigger swings and tolerate more mess. Risk is the model.

  • At a later-stage or public company, the calculus flips. Now you have something to lose—brand equity, investor trust, cash flow stability. The stakes are higher. The red arrows are sharper. You don’t slow down innovation, but you start to build rails to keep the train on track.

This is where finance earns its seat as both architect and referee. You’re constantly navigating the tension between growth velocity and systemic protection.

One slice too few, and something breaks.

One slice too many, and nothing moves.

The best CFOs don’t just throw more process at problems. They adjust the controls as the company matures—adding structure where it’s needed, and pulling it back when it’s not.

It’s not about more cheese. It’s about the right cheese.

🧭 Final Thought: Risk Is a Culture

Ultimately, the best risk management programs aren’t built on tools or templates. They’re built on culture. On the idea that everyone in the business has a role to play in asking, “What could go wrong—and how would we catch it?”

You don’t need perfect cheese. You just need enough, stacked smartly, with people who care enough to check the holes.

Great CFOs don’t build fortresses. They build filters. Enough to catch the big stuff, not so much it chokes the business.

I spoke with Craig Conti, CFO of publicly traded Vera Mobility, the company responsible for the silent infrastructure behind seamless tolling, traffic enforcement, and smart mobility. Our discussion risk management, which we’ve dove into above, starts at around the 38 minute mark.

Reply

Avatar

or to participate