Managing risk in financial services can be daunting. Risks can be abstract, complex, and often unpredictable, which makes it tempting to ignore them—especially when they feel improbable or uncomfortable. We all understand this but, unfortunately, section 912A of the Corporations Act requires AFS Licensees to maintain adequate risk management frameworks. Even worse is the fact that most Licensees treat this obligation as a box-ticking exercise instead of an essential foundation for their business.
Big Licensees often have dark academies of risk management. We understand it can be difficult; most Australian Licensees struggle to build and maintain a risk management framework appropriate for their activities or their business’s nature, scale, and complexity. Lacking the Big Licensees dark academies of risk management, they struggle to know where to start or how to engage staff with the exercise.
Maybe the best place to start is by removing barriers to participation; pseudo-science and mathematical certainties tend to intimidate and exclude the very people we need to identify and manage the risks.
So instead of elevating risk identification into an esoteric science, let’s turn it onto a game and embrace anthropomorphism to drive engagement. I appreciate using a “ten-dollar word” to drive simplicity may undermine my thesis so I’ll be clearer; try to engage ypur team about risks by using animal metaphors can help bring risk management to life. I suspect that by framing risks as animals—such as Grey Rhinos, Black Elephants, and Green Swans—we can make them more real and more understandable. It’s a simple trick but one that may help compliance managers, licensees, and advisers understand, assess, and mitigate risks more effectively, embedding risk awareness into everyday decision-making.
1. Grey Rhino: The Obvious, Ignored Threat
Let’s start with the high-impact potential risks; the Grey Rhinos.
A Grey Rhino represents a highly probable, high-impact threat that is clearly visible but often overlooked. Michele Wucker, in her book The Grey Rhino, describes how people ignore these looming dangers until it’s too late. For more information, you can explore Michele Wucker’s insights directly on her website.
“Tell us, what are the top grey rhino risks right now?”
In her article “Grey Rhino Risks and Responses to Watch in 2024,” Michele Wucker identifies “grey rhinos” – significant, highly probable, high-impact risks often neglected until they become crises. An effective Compliance function with a proactive risk management philosophy should address these looming threats, but the reality is that they seldom attract the attention they deserve. Often, businesses fail to deal with these risks because of a combination of factors, including short-term focus on profits, discomfort with confronting challenging issues, and the belief that unlikely events won’t happen to them. The perceived uncertainty of the outcome further exacerbates this belief, leading to complacency that their business will remain unaffected. This aligns with known behavioural heuristics, such as ‘optimism bias’ and ‘normalcy bias,’ where individuals underestimate the likelihood of adverse events impacting them personally. This leads to procrastination or underinvestment in mitigation efforts until the threat becomes unavoidable.
In a perfect world, a Compliance Manager could change this behaviour by fostering a risk-aware culture, ensuring risk discussions are routine rather than reactive, and linking risk management to operational resilience and long-term profitability. They could supplement this with effective communication, training, and leadership engagement to bridge the gap between awareness and action, ensuring that risks are treated with the urgency they deserve. However, it’s essential to acknowledge that not all businesses have the internal expertise, resources, or time to do this. In such cases, businesses can seek external support from specialised risk consultancies, invest in targeted training programs, or use risk management software solutions that offer pre-built frameworks and expert guidance. Collaborating with third-party experts can provide much-needed perspective and the skills to effectively identify and address risks before they escalate.
To facilitate internal discussions, you start your discussion by focusing on the following potential Grey Rhino risks threatening advisers and Australian Financial Services Licensees:
Climate Change Impacts: The increasing frequency of extreme weather events poses significant risks to financial assets and insurance liabilities. Financial institutions must integrate climate risk assessments into their frameworks to mitigate potential losses. ASIC has consistently emphasised the importance of managing climate-related risks. In its guidance for directors, ASIC advises that directors and officers of listed companies must understand and continually reassess existing and emerging risks that may apply to the company’s business, including climate risk. This should extend to both short- and long-term risks.
Technological Disruption: Rapid technological advancements, such as artificial intelligence and blockchain, could disrupt traditional financial services. Failure to adapt may result in loss of market share and relevance.
- Regulatory Changes: Ongoing reforms in financial regulations require institutions to stay vigilant and adaptable. Non-compliance or delayed responses to new rules can lead to penalties and reputational damage.
- Cybersecurity Threats: With the increasing digitisation of financial services, cyber threats are a growing concern. A significant breach could lead to substantial financial losses and erosion of customer trust.
For Example, the Hayne Royal Commission is a perfect example of a Grey Rhino. For years, the risk of ineffective monitoring and supervision and conflicted arrangements in financial advice was obvious. Biased recommendations were being made to clients, yet the industry largely ignored this risk, leading to significant fallout—including reputation damage and sweeping regulatory reforms.
How to Manage It: Proactively address visible, high-probability risks before they escalate. Consider issues like underinvestment in staff training: they may seem routine but can grow into significant liabilities if left unchecked.
2. Canary in a Coal Mine: Early Warning Signals
Now for the risks we simply shouldn’t ignore; the Canaries.
Canaries were once used in coal mines to detect toxic gases—their distress acted as a signal of imminent danger.
The “Canary in a Coal Mine” refers to early indicators of more significant problems in financial services compliance. In The Failure of Risk Management, Douglas Hubbard emphasises the need to act on these early warning signs. Below are ten additional lead indicators that financial services businesses can use to identify risks early and take appropriate action:
- Employee Turnover Rates: High turnover, especially among key personnel, can indicate underlying issues such as poor culture or dissatisfaction, which may impact compliance.
- Increased Customer Complaints: A sudden rise in customer complaints may point towards deeper operational or product suitability issues.
- Policy Exceptions and Breaches: A growing number of policy exceptions can indicate operational weaknesses or gaps in internal controls.
- Audit Findings: Recurring internal or external audit issues indicate areas needing immediate attention.
- Decline in Customer Satisfaction Scores: Negative customer satisfaction trends can signal problems with service quality or product suitability.
- Training Completion Rates: Low completion rates of mandatory staff training may highlight a poor compliance culture or a need for more awareness of regulatory requirements.
- Regulatory Inquiries: Increased inquiries or information requests from regulators may indicate that the business is scrutinised more closely.
- Operational Incidents: Repeated operational disruptions or incidents can reflect systemic issues that need resolution.
- Missed Deadlines: Failing to meet critical project or regulatory deadlines may be a warning sign of poor project management or resource allocation.
- Supplier and Vendor Issues: Problems with third-party vendors, such as non-compliance or performance issues, can signal potential risks to the business if dependencies are not well managed.
For Example, A sudden surge in customer complaints about product suitability often indicates deeper problems in advisory practices. Ignoring these complaints can lead to significant compliance issues and reputational damage, which might have been contained with timely intervention.
How to Manage It: Treat early warning signs, like spikes in customer complaints, as red flags that require immediate investigation and resolution.
By leveraging cost-effective compliance monitoring software like [complye] and fostering open dialogue, even smaller licensees can act on early warning signs without significant financial strain. For instance, automating the tracking of policy exceptions can provide real-time insights into operational weaknesses, enabling timely intervention.
3. Black Elephant: The Obvious Crisis That’s Ignored
Did you watch the Licensees’ testimony at the Royal Commission and wonder how they could possibly have acted as stupidly as they did? Incompetence, ineptitude and incentives certainly played their part, but perhaps the Licensees simply didn’t recognise the Black Elephants.
A Black Elephant combines elements of a “Black Swan” and the “Elephant in the Room.” It represents an obvious, looming crisis that everyone is aware of but no one wants to address—until it’s too late. Consider whether vertical integration and the failure to manage conflicts of interest could also be seen as Black Elephants in financial services. These issues are often well known, yet they are frequently ignored or inadequately addressed, usually leading to significant adverse outcomes.
In financial services, there is often a tendency to ignore these issues in favour of simply remediating them when they become unavoidable. This approach may seem more cost-effective and advantageous in the short term. Still, it often leads to more significant costs in the long run, including regulatory penalties, reputational damage, and diminished client trust. For example, remediation programs initiated after the Royal Commission are a prime example of the high costs institutions incur when they fail to prevent misconduct initially and, in many cases, actively ignore or reward misconduct.
ASIC’s enforcement actions also highlight the financial and reputational damage resulting from inadequate compliance and risk management practices. Although institutions may have chosen to remediate client losses as they arose rather than address the root causes and prevent those losses, this ultimately led to major fallout, including significant regulatory actions, fragmentation, and reputational harm. For example, the Australian financial services sector anticipated substantial remediation costs following the Hayne Royal Commission. In contrast, the total remediation costs across major institutions were estimated to exceed $10 billion; the actual cost to date is $4.7 billion. Admittedly, the remediation costs have been substantial and are still ongoing, but they are significantly less than some earlier projections made post-commission. However, financial costs are not the only significant impact. The industry continues to face compliance and consumer trust challenges, which may lead to further expenses as institutions strive to rectify past misconduct and enhance their operational frameworks. Even this ignores the human and opportunity costs associated with these failures. AMP alone has reported approximately $1.7 billion in remediation expenses.
In contrast, proactive investments in compliance systems and preventive measures are significantly less costly over time. Reports suggest enhancing compliance frameworks and adopting regulatory technology can reduce potential remediation costs.
For Example, The Royal Commission itself was a Black Elephant. Concerns about misconduct in the financial services industry were well-documented, yet the sector only acted when forced by the Commission’s findings.
How to Manage It: Foster a culture of transparency and accountability so that systemic issues, such as non-compliance, are acknowledged and resolved before they explode into crises. As part of a forward-facing risk management focus, the Compliance Team should highlight the importance of early intervention to mitigate immediate risks and build a more sustainable, resilient business model. To generate conversation about risks people actively choose not to address, use hypotheticals as teaching tools to abstract risks from your own business. Challenge inaction by reframing risk identification as a “fear-setting” exercise.
4. Turkey Problem: Overreliance on Historical Data
Sure, there are numerous turkeys in institutional licensees, but we’re focusing on something more specific in this context.
The Turkey Problem, popularised by Nassim Nicholas Taleb, is a particularly American construction that warns against assuming the future will mirror the past. Compliance people know that past performance is no guarantee of future performance, but they also know, from watching Suits, that current conduct is the most reliable indicator of past conduct. Not everyone is as nuanced as Compliancers, and most people rely too heavily on historical data.
Just as a turkey trusts its caretakers until Christmas, relying too heavily on historical trends can expose one to unpredictable shifts.
For Example, The Global Financial Crisis (GFC) is a classic Turkey Problem. Market participants over-relied on a consistent upward trend in housing markets, leading to overconfidence and unchecked risk-taking. When the housing bubble burst, it revealed the limitations of relying purely on historical data. Similarly, Chartism—using historical price patterns to predict future movements—can often result in a misplaced sense of security. Bitcoin’s recent price history offers a modern parallel, where overreliance on past trends and overconfidence in continuous growth has led to unchecked risk-taking, similar to the GFC. Many other examples illustrate how relying too heavily on historical data can still be a significant vulnerability in today’s financial markets.
How to Manage It: Continuously stress-test your assumptions. Recognise that past performance is not always a reliable predictor of future outcomes. When assessing or identifying risks, ask, “What if that assumption is wrong?”. Or take the lead from Annie Duke’s “Thinking in Bets” and ask those relying on assumptions to confirm their confidence in their assumptions and conclusions publicly.
5. Dragon King: Predictable Extremes
I appreciate you’re probably expecting a reference to the 2010 NRL Grand Final, or to the most successful Rugby League of all time (11 premierships in a row), but in this context “Dragon Kings” are extreme events that deviate from standard patterns but can still be predicted with some foresight. Like Black Swans, they are not entirely random because they often have identifiable warning signs.
The “Dragon King” term, introduced by Didier Sornette, a professor of entrepreneurial risks at the Swiss Federal Institute of Technology in Zurich, describes situations that are predictable to an extent due to early warning signs and specific underlying conditions (for example, investment showing rapid growth and high leverage). The theory highlights the importance of recognising these indicators to preempt significant crises. Its application is particularly relevant in financial markets where, if carefully monitored, extreme market events can sometimes be foreseen and mitigated, such as unsustainable asset bubbles or overly concentrated market positions. Although more generally applied to investment research, it’s still a valuable metaphor for internal discussions about risk. For example, you may assess an adviser as a Dragon King because their practice indicates high levels of client concentration on a specific demographic and frequent staff turnover.
For Example, some high-risk investment schemes in Australia exhibit “Dragon King” tendencies—rapid growth, unsustainable leverage, and implausibly high returns. Such indicators suggest an impending collapse. Some licensees exhibit similar tendencies—high adviser-to-staff ratios, a ramp-up of industry media and promotion, significant product inflows limited to specific products or high rates of clean-skin applications.
How to Manage It: Monitor for unsustainable growth patterns or excessive leverage, which may signal imminent problems.
6. Green Swan: Climate-Related Financial Risks
As ASIC increases its focus on ESG, it’s prudent to keep your eyes peeled for Green Swans.
Coined by the Bank for International Settlements, Green Swans represent climate-related risks with uncertain timing but potentially massive consequences. In Australia, we tend to focus on direct environmental changes such as floods and fires, but climate change, coral bleaching, and water scarcity are relevant considerations. From a licensee’s perspective, to what extent should these risks (including their consequences and implications) be considered in portfolio construction, product recommendations and general operations? How does it affect the business, the business’ clients, or the broader economy?
For Example, Regulatory bodies such as ASIC and APRA have encouraged institutions to integrate climate-related risks into their risk frameworks. Ignoring these risks could lead to market volatility and asset revaluations as the effects of climate change become more pronounced.
How to Manage It: Incorporate climate risk assessments into your risk management frameworks to understand how environmental changes could impact asset values and operational resilience.
7. Black Swan: The Unforeseen Extreme
This last animal is known to everyone working in financial services – not only those who’ve pretended to have read Nassim Nicholas Taleb’s book about the impact of highly improbable events.
A Black Swan is a rare, unpredictable event that has massive consequences. Made famous by Taleb, Black Swans often reveal biases and flaws in our approach to uncertainty. Predicting or anticipating such rare events requires embracing a mindset that accepts uncertainty and actively looks for weak signals that may precede significant shifts. Scenario analysis, stress testing, and diversification are some of the practical tools Licensees and advisers can use to prepare for these occurrences. Additionally, encouraging a culture of curiosity, where team members are empowered to question assumptions, can help an organisation be better positioned to identify the early warning signs of such extreme events. Although predicting Black Swans’ exact timing or nature is impossible, these strategies can increase readiness and resilience against unforeseen disruptions.
For Example, COVID-19 was a quintessential Black Swan, shaking markets and institutions globally. Its impact showed how vulnerable the financial system can be to unexpected disruptions.
How to Manage It: Build adaptable and resilient risk management strategies. Prepare for the unexpected by maintaining liquidity reserves and ensuring flexible business models to handle extreme scenarios. Speak to your Compliance people; you may find they’re obsessed with these risks.
Applying the Menagerie in Financial Services
I know what you’re thinking – these are cute ideas and St George-Illawarra is the best Rugby League Club of all time – but so what?
Let me first commend you on your exceptional good judgment (Go Dragons!) before emphasising that these animal metaphors aren’t just interesting visuals—they’re practical tools for increasing engagement and assisting people in identifying, appreciating, and addressing different real risks and their practical impact. The imagery provides a common language and makes risk management more accessible to those who generally consider it an academic or bureaucratic pursuit.
The metaphors democratise the topic and provide an accessible shorthand for those seeking to apply compliance obligations practically, meaningfully, and effectively.
Whether you wear a Black Hat or a White Hat, here’s how you and your Compliance Team can apply these metaphors to your compliance and risk management framework:
- Grey Rhino: Identify and address obvious threats head-on, like underinvestment in technology that could lead to cybersecurity vulnerabilities or inadequate business capital.
- Canary in a Coal Mine: Treat early complaints or irregularities as opportunities for preemptive action, not annoyances to dismiss. Monitor and escalate trends. Look for recurring issues and connections between unrelated complaints. Investigate why no complaints are recorded.
- Black Elephant: Develop an open culture that doesn’t shy away from systemic risks, encouraging candid conversations and action. Explicitly question internal reporting. Consider the general financial reporting about financial services and the recurring themes identified by legislators, regulators and other stakeholders in the media.
- Turkey Problem: Remain vigilant and challenge your assumptions—just because it hasn’t happened yet doesn’t mean it won’t. Everything is good until it’s not. Think about chances, bets or probabilities to avoid the lazy assumption that what happened yesterday will happen today. Regardless of the pattern you see, remember that just because the last three coin-tosses were heads doesn’t guarantee that, like last time, the next one will be tails.
- Dragon King: Track extreme outliers and respond decisively when excessive growth or instability indicators arise. Celebrate successes but try to identify the real reasons for the success to differentiate puffery from performance.
- Green Swan: Factor environmental risks into your strategic planning to be better prepared for the inevitable impacts of climate change. There’s a tendency to dismiss these risks as too big for you to handle, but they are too big and pressing to ignore.
- Black Swan: Accept that some risks are unpredictable and plan for resilience, not just risk mitigation. Appreciate that your business can never be risk-free or one hundred per cent insulated against risk—build tolerance rather than pursuing immunity.
Conclusion: From Theory to Action
Animal metaphors like Grey Rhinos, Black Elephants, and Green Swans bring risk management concepts to life, making them relatable and actionable for financial services professionals. The Hayne Royal Commission highlighted how poorly Licensees understood the risk and underscored the cost of ignoring these risks. Risk management cannot be an esoteric discipline that is only understood by Poindexters and slumming mathematicians. Risk Management aims to identify the real issues that threaten the business, its clients and its capacity to provide services. It requires the wisdom of crowds, and engaging these people requires compliance to make the exercise more accurate, accessible, and relatable. Metaphors, like the risk menagerie, help. By understanding and using these metaphors to facilitate introspection and debate, you can build a culture of proactive risk management that enhances your business’ stability and integrity.
Critically, implementing a robust risk management framework involves recognising the grey rhinos and setting actionable steps to address them. This can include regular risk assessments, scenario planning, and leveraging technology for real-time risk monitoring. Engaging with external consultants can provide fresh perspectives and specialised expertise to ensure that your compliance strategies are proactive and resilient.
Whether you run a large financial institution or a small AFS licensee, implementing these metaphors into your compliance frameworks doesn’t require exorbitant resources. Start with simple steps: regular team discussions, clear communication of risks, and using affordable compliance tools designed for small-scale operations.
If your organisation needs help embedding robust risk management practices or interpreting regulatory obligations, contact Assured Support for expert guidance. We provide tailored compliance consultancy, licensee reviews, and client file assessments to help you confidently navigate financial services compliance. Contact us today to safeguard your business against tomorrow’s risks.
If you liked this, we think you might enjoy
Why risk and compliance should be joined
Frequently Asked Questions
1. What are Grey Rhinos in financial services risk management?
Answer:
Grey Rhinos represent highly probable, high-impact risks that are often ignored despite being obvious. Examples in financial services include climate change impacts, technological disruptions, and cybersecurity threats. Proactively addressing Grey Rhinos involves regular risk assessments, scenario planning, and embedding risk awareness into business decision-making.
2. How can financial services professionals identify early warning signs of risk?
Answer:
Early warning signs, often referred to as “Canaries in a Coal Mine,” include trends such as increased customer complaints, policy breaches, or high employee turnover. Monitoring these indicators can help businesses take preventive actions. Leveraging compliance software or conducting periodic audits can aid in identifying and addressing these risks.
3. What is the Turkey Problem, and how does it apply to financial compliance?
Answer:
The Turkey Problem highlights the danger of overreliance on historical trends to predict the future. In financial services, this could lead to complacency in risk management. To mitigate this, stress-test assumptions regularly and challenge the belief that past success guarantees future performance.
4. What role do Green Swans play in risk management for financial services?
Answer:
Green Swans symbolise climate-related risks with uncertain timing but potentially massive consequences. Financial institutions can address these risks by integrating climate risk assessments into their frameworks and considering environmental impacts in their strategic planning to build resilience.
5. Why is proactive risk management important for Australian Financial Services Licensees?
Answer:
Proactive risk management ensures compliance with obligations under the Corporations Act 2001, Section 912A. Addressing risks early prevents crises, avoids regulatory penalties, and builds client trust. Using tools like animal metaphors makes risk management relatable, encouraging engagement and action across all business levels.