Krishna Priyan

Why Every Department Thought Someone Else Owned the Risk

A Case Study on Ownership Gaps and Organizational Accountability

A rapidly growing manufacturing company was experiencing recurring operational issues. Purchase orders were delayed, vendor payments were frequently disputed, production schedules slipped without warning, and customer complaints were steadily increasing. Individually, none of these incidents appeared severe. Collectively, however, they were costing the business significant time, money, and customer trust.

When senior management initiated an internal review, every department had a logical explanation. Procurement believed production should have forecasted demand more accurately. Production pointed to delayed material deliveries. Finance argued that approvals from department heads were incomplete. Quality maintained that defects originated during manufacturing, while Operations believed supplier performance was the root cause.

Everyone had an answer.

No one had ownership.

From an internal audit perspective, the problem was not process failure—it was ownership failure. Every function had clearly documented responsibilities, yet the risks that existed between departments had no defined owner. The organization had invested heavily in policies and systems, but very little attention had been given to accountability for cross-functional risks.

Rather than auditing departments independently, I would map the complete business process from customer order to product delivery. The objective would be to identify every point where work changed hands between functions. These transition points often expose the greatest risks because responsibilities become blurred, approvals are delayed, and assumptions replace accountability.

The review would focus on questions such as:

  • Who owns the risk if a supplier fails to deliver?
  • Who monitors delays between procurement and production?
  • Who is accountable when incomplete information reaches Finance?
  • Which department is responsible for resolving issues that span multiple functions?

Instead of recommending additional controls, I would recommend establishing clear risk ownership across every critical business process. Each key operational risk should have a designated owner, measurable accountability, escalation procedures, and regular cross-functional reviews. Performance metrics should reward collaboration, not just departmental success.

Key Takeaway

Businesses rarely lose money because departments fail independently. They lose money because critical risks exist in the spaces between departments, where everyone is involved, but no one is accountable. Effective internal audit is not just about evaluating controls—it is about ensuring every significant business risk has a clear owner before it becomes everyone’s problem.

Leave a Comment

Your email address will not be published. Required fields are marked *