Final answer:
The process of risk management is mainly driven by an organization's governance and culture. The board of directors, significant in governance, works within this context and is impacted by the influence of top executives. Other institutions like auditing firms and large investors also contribute to governance, highlighting the need for strong risk management practices.
Step-by-step explanation:
The process of risk management is typically driven by organization governance and culture. While the board of directors is elected by the shareholders and is the first line of corporate governance and oversight for top executives, they work within the broader context of an organization's governance structures and culture. This encompasses the rules, practices, and processes by which a firm is directed and controlled. Additionally, top executives often have a significant influence on choosing the board members, which can affect the effectiveness of risk management.
Auditing firms and large outside investors, such as mutual funds or pension funds, also play a crucial role in corporate governance by providing additional layers of oversight. However, in the case of disasters such as the Lehman Brothers collapse, it was evident that these checks and balances were insufficient to prevent failure or to provide accurate financial information to investors. Consequently, the importance of robust corporate governance and a strong risk management culture that aligns with organizational values cannot be overstated.