CeFPro Connect

Event Q&A
From Risk Intelligence to Business Action
Third-party and operational risk management is ultimately less about having more data and more about turning risk intelligence into timely business decisions. Leaders are most likely to act when risk is translated into business terms—ROI, severity, likelihood, and the opportunity cost of inaction—rather than presented as analysis alone. AI and predictive analytics will sharpen our ability to anticipate risk, but human judgment will remain the critical bridge between prediction and action. The future of TPRM is therefore about becoming trusted business advisors: understanding the business, challenging the data, connecting with the front line, and translating complex risk signals into practical decisions.
Sep 10, 2026
Narahari (Hari) Rao
Narahari (Hari) Rao, Global Supply Risk and Resiliency Director, Schlumberger (SLB)
Tags: Operational and Non Financial Risk Vendor and Third Party Risk AI and Technology (including Fintech) Resilience
From Risk Intelligence to Business Action
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  •         Risk data alone doesn’t drive action — executive decisions depend on judgment, confidence, and business context.
  •         Translate risk into business impact — ROI, severity, likelihood, and opportunity cost resonate most with leadership.
  •       AI will enhance prediction, not replace judgment — the real value lies in translating analytics into realistic business scenarios.
  •       TPRM must become a strategic advisor — understand the business, challenge the data, adapt to emerging risks, and stay connected to business teams.
  •       The goal is action, not more data — turn risk intelligence into timely, informed business decisions.

Ahead of the Vendor & Third Party Risk event in the USA this November, we spoke with Narahari Rao, Procurement Risk Manager, SLB, about the evolving role of third-party and operational risk in executive decision-making. He discusses why strong risk analysis does not always translate into action, which risk metrics resonate most with senior leadership, and how AI and predictive analytics can strengthen forward-looking risk management. He also shares his perspective on how TPRM teams can move beyond providing risk data to become strategic advisors who connect risk intelligence with business priorities and timely action.

 

In your experience, what is the biggest reason senior leaders fail to act on operational or third-party risk reports, even when the underlying analysis is strong?

This gets to the real communication and decision-making barriers organizations face today.

I believe the disconnect happens with the underlying analysis (confidence level) and the event actually materializing. After all, we all like to follow the path of least resistance. Pre-emptively acting on a risk that is yet to materialize takes more than just quantitative analysis; it relies on a generations-old, developed gut instinct. Acting on risk takes your eyes off revenue generation and possibly slowing down your approach. Hence, I think when senior leaders fail to act on third-party risk, it speaks at the very core of our human psychology.

What metrics or risk indicators have proven most effective in helping executive teams quickly understand supply chain and third-party risk exposure and make timely decisions?

This should reveal the measures and visualizations that resonate most with leadership.

There are a few measures that resonate. 

ROI - I invest $x to better manage my investment that is valued at $y ($y>>$x) and if I don't do anything then I might incur a loss of $z ($z>>$x).

Severity and Likelihood - These measures help to balance out the risk with how likely is it to happen and how severe will it be.

Opportunity Cost - closely tied to ROI but it essentially is the cost of inaction.

As AI and predictive analytics become more embedded in risk management, how do you see executive decision-making changing over the next three to five years?

This explores how data-driven risk insights may evolve from reporting to forecasting and scenario planning.

Indeed, AI can super-charge predictive analytics by combining numerous data sources, plotting them over several years, and calculating the likelihood/severity and the material impact to the shareholders. Decision making however, reverts back to that human intuition. I don't think we have paucity of data in our lives but we do have a deficit in understanding how that data may translate to real-life scenarios. The ability to synthesize AI generated predictive analytics and keep it grounded to reality is what would differentiate a good from a great leader.

Looking ahead, what capabilities should TPRM and operational risk teams be building now to ensure they remain strategic advisors to leadership rather than simply providers of risk data?

TPRM practitioners should first and foremost understand the business that they are managing risk for. TPRM practitioners should rely on generating sound data from various data sources; building skillsets within the teams who are able to keep up with changing risk vectors' able to tailor and adapt to a changing business model; promote a federated approach where TPRM practitioners encourage both local and central governance models; a healthy combination of confidence and skepticism in data; and lastly, staying connected with business lines and divisions to understand ground realities. 

As technology continues to evolve, what will distinguish a best-in-class ALM function over the next five years, and how will the roles of treasury, finance, and risk teams need to adapt?

Over the next five years, best-in-class ALM functions will be distinguished by AI-driven capabilities, large use of advanced analytics, and fully integrated decision-making across treasury, finance, and risk. These teams will need to work more collaboratively, using shared data and models to optimize balance sheet performance and respond quickly to changing market conditions and geopolitical scenarios. The focus will shift from producing reports to delivering strategic insights that drive business value.

Narahari (Hari) Rao Bio

Global Supply Risk and Resiliency Director I build global procurement and risk frameworks that actually work — from policy design to automated execution. Over 20 years, I've led Third-Party Risk, Procurement, and Digital Transformation for a $500M+ supplier portfolio across 30 global business units at one of the world's largest energy companies. My latest experience has been designing global governance frameworks that bridge the gap between high level policy and automated execution. My career has traversed primarily within the energy space, where I have led diverse functions ranging from Third-Party Risk Management (TPRM) and Global Strategic Sourcing to Product Engineering, Manufacturing, Quality, and Digital Process Transformation. In my current job, I have orchestrated the end to end Third Party Risk Lifecycle for a $500M+ supplier portfolio. By integrating ISO 31000 and NIST-driven frameworks into regular business processes across 30+ global business units.

Narahari (Hari) Rao
Sign in to view comments
You may also like...
ad
Related insights